ISO/IEC 27701

ISO 27701 certification,
explained plainly

ISO/IEC 27701 is the international standard for a privacy information management system, and since the 2025 edition you can certify against it on its own. Here is what it actually requires: the management clauses, the Annex A controls for PII controllers and PII processors, the shared security controls, how the standard lines up with the GDPR and the Swiss FADP, and how teams that already run ISO 27001 add privacy to the same Swiss-hosted workspace.

Book a conversation
Every framework
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • Swiss nFADP
  • NIST CSF 2.0
  • OWASP
  • EU AI Act
The standard

What ISO/IEC 27701 actually requires

ISO/IEC 27701 certifies a privacy information management system (PIMS), not compliance with a particular law. The 2025 edition pairs the familiar management clauses with an Annex A of privacy controls, split by the role you play for the personal data you process.

Standalone since 2025

The 2019 edition was an extension of ISO 27001. The 2025 edition is a management system standard in its own right, with clauses 4 to 10, that you can certify with or without an ISMS.

Controls by role

Annex A has 78 controls: 31 for PII controllers, 18 for PII processors and 29 information security controls that apply to both. Your role decides which tables you must consider.

Built on ISO 27001 and 27002

The clauses mirror ISO 27001:2022 and the shared controls extend ISO 27002:2022 with PII-specific requirements, so an existing ISMS carries most of the structure.

A system, not a legal opinion

Certification confirms that your privacy processes work and are audited, from the record of processing to rights requests and breach notification. It does not replace legal compliance with the GDPR or the FADP, it evidences it.

The full picture

ISO 27701, from the 2019 extension to the 2025 standard

A plain-language walkthrough of what the standard asks for, how it changed in 2025, and what keeps a certificate valid between audits.

01

What is ISO/IEC 27701?

ISO/IEC 27701 is the international standard for a privacy information management system, PIMS for short. It does not certify that you comply with a particular privacy law. It certifies that you run a working system for protecting personally identifiable information: you know which PII you process and why, on which lawful basis, with which processors and in which countries, you assess the risks to the people behind the data, you answer their requests, you notify breaches, and you audit and improve all of it.

The standard uses its own vocabulary, taken from ISO/IEC 29100. PII is personally identifiable information, the PII principal is the person the data is about, the PII controller decides purposes and means, and the PII processor processes PII on a controller’s behalf. If you know the GDPR, read personal data, data subject, controller and processor.

2019 versus 2025

The first edition, ISO/IEC 27701:2019, was an extension to ISO/IEC 27001 and 27002. You could only certify it on top of an ISO 27001 certificate, and its control numbering still referred to the 2013 edition of ISO 27002. The second edition, ISO/IEC 27701:2025, published in October 2025, rebuilt it as a standalone management system standard with the harmonized clause structure, aligned it with ISO 27001:2022 and ISO 27002:2022, and consolidated the two former control annexes into one Annex A split by role. You can now certify a PIMS on its own, though most organizations still integrate it with their ISMS.

02

The clauses, 4 to 10

The requirements follow the harmonized structure ISO uses for all management system standards, so they look like ISO 27001 with privacy in place of information security. Clause 4 is context: which role you play for each processing activity, which privacy laws and contracts apply, and what the PIMS covers. Clause 5 is leadership: top management owns the privacy policy, the objectives and the assignment of roles, including a data protection officer where the law requires one. Clause 6 is planning: a privacy risk assessment that weighs consequences for the people behind the data, not only for the organization, a risk treatment process that ends in a statement of applicability against Annex A, and measurable privacy objectives.

Clause 7 is support: resources, competence, awareness, communication and documented information, which for a PIMS includes the record of processing, impact assessments, processor contracts and consent records. Clause 8 is operation: running the processes, repeating the risk assessment before new or changed processing, and carrying out the treatment plan. Clause 9 is performance evaluation: privacy metrics, internal audit and management review. Clause 10 is improvement: nonconformities, corrective action and continual improvement.

03

Annex A: the controls, by role

Annex A is where the privacy substance lives, and it is organized by the role you play. Table A.1 holds 31 controls for PII controllers, grouped into conditions for collection and processing (purpose, lawful basis, consent, impact assessment, processor contracts, records), obligations to PII principals (information, access, correction, erasure, objection, portability, automated decisions), privacy by design and by default (collection and processing limits, accuracy, minimization, retention, disposal, transmission), and sharing, transfer and disclosure (transfer basis, destination countries, records).

Table A.2 holds 18 controls for PII processors: processing only on the customer’s documented instructions, no use for the processor’s own or marketing purposes, flagging unlawful instructions, giving customers what they need to demonstrate compliance and to answer their PII principals, returning or deleting data at the end, and the full sub-processor discipline of disclosure, prior authorization, flow-down contracts and change notice. Table A.3 holds 29 information security controls taken from ISO 27002:2022 and sharpened for PII, from classification and access rights to logging, backup, cryptography, secure development and test data. Annex B gives implementation guidance for every control.

04

ISO 27701 and the GDPR, the Swiss FADP and other laws

The standard is deliberately law-neutral. It asks you to identify the privacy laws that apply to you and to run a system that meets them, and its Annex A controls are written so that the obligations of the major privacy laws have a home: the record of processing, the lawful basis, the impact assessment, the data protection officer, the processor contract, the transfer basis, the rights of access, correction, erasure and portability, and breach notification are all there. The standard also carries annexes that map its controls to other privacy frameworks.

That makes it the natural bridge between an ISMS and privacy law. An organization that runs ISO 27001 and is subject to the GDPR or the Swiss FADP typically finds that most of its legal obligations already have a process, but no management system around them: nobody audits the rights request process, the processor register lives in a spreadsheet, and the impact assessments are wherever the last project left them. ISO 27701 puts those processes under the same discipline as the security controls, with the same audit and review cycle.

05

How ISO 27701 certification works, step by step

Certification is carried out by an accredited certification body in the same two stages as ISO 27001. Stage 1 is a readiness review of the documented PIMS: scope, privacy policy, role determination, risk assessment and treatment, the statement of applicability against Annex A, and whether internal audit and management review have run. Stage 2 is the implementation audit: the auditor samples processing activities, follows a rights request through the process, checks processor contracts and transfer records, tests the breach procedure and interviews the people who run it.

Since the 2025 edition you choose between a standalone PIMS certificate and an integrated audit with ISO 27001, where one audit programme, one management review and one corrective action process serve both. Organizations certified to the 2019 edition transition to the 2025 edition on the timeline their certification body publishes. The certificate then follows the usual three-year cycle: a surveillance audit in years one and two and a recertification audit in year three.

06

Staying certified: what changes between audits

Privacy is the part of a management system that changes most between audits. New processing starts, providers and sub-processors change, an adequacy decision falls, a new law applies, and every one of those events has to reach the record of processing, the risk assessment, the notices and the contracts. Surveillance auditors follow exactly those trails: they pick a processing activity that started since the last visit and ask for its assessment, its contract and its notice.

Teams that keep the record of processing, the processor register and the assessments in one place, tied to the controls they satisfy, answer that in minutes. Teams that keep them in separate spreadsheets rebuild the trail before every audit.

07

What drives the cost of ISO 27701

The certification body charges for the Stage 1 and Stage 2 audits and for each surveillance audit, scaled to the size and complexity of the processing in scope. If you integrate the audit with ISO 27001, the added audit days are modest. That fee is usually the smaller part.

The larger cost is the system: building and maintaining the record of processing, running impact assessments before launches instead of after, contracting and monitoring every processor, answering rights requests within deadlines and keeping evidence of all of it. Two levers move that cost. Scope, because certifying the processing your customers actually ask about is cheaper than certifying everything. And integration, because an existing ISMS already provides the audit programme, the management review, the corrective action process and most of the Table A.3 controls.

The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools treat privacy as a document set. The expensive part is the years after: the processing that started without an assessment, the sub-processor nobody announced, the rights request that missed its deadline because it arrived in the wrong inbox. That is the part a surveillance auditor finds, and the part no document set was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
3-year cycle
audit-readyCertSurveillance 1Surveillance 2
Point-in-time tools — scramble & drift
devguard — a state you keep
Run it in devguard

Your PIMS, in the same workspace as your ISMS

The clauses and the Annex A controls as two adopted frameworks, mapped to ISO 27001, ISO 27002, the GDPR and the Swiss FADP, with the record of processing, assessments and processor contracts kept as evidence. Pick one to see it.

Annex A, filtered to your role

Adopt the 78 Annex A controls as a catalogue, mark the tables that do not apply to your role as not relevant, and see coverage roll up per control from the policies, evidence and tasks that implement it.

Learn more
Control coverage64%
Asset managementCovered
CryptographyPartial
Supplier securityGap
Document once. Reuse across every standard you add.

ISO 27701 shares its clauses with ISO 27001 and its Table A.3 controls with ISO 27002, and its controller and processor controls map to the GDPR, the Swiss FADP and the SOC 2 privacy criteria. Map them once in devguard and the same record of processing, assessments and contracts satisfy every framework they appear in.

See the full feature comparison

Already certified and dreading the next cycle? See how we help certified companies stay audit-ready.

Already certified? Move your ISO 27701 system across

If you already hold ISO 27701, whether the 2019 or the 2025 edition, you do not want to rebuild your PIMS from a blank page. In a scoped conversation we agree exactly what moves (your record of processing, statement of applicability, assessments, processor register, audit history and management review records) and run that migration with you, for a fixed scope and a date set before we start. Your existing setup stays untouched and exportable until you are satisfied the new one holds up side by side.

Book a conversation
ISO/IEC 27701 FAQ

ISO/IEC 27701, answered plainly.

Do I need ISO 27001 to certify ISO 27701?

Not since the 2025 edition. ISO/IEC 27701:2025 is a standalone management system standard and can be certified on its own. Under the 2019 edition it was an extension that required an ISO 27001 certificate. In practice most organizations still integrate the two, because the clauses are the same and Table A.3 of Annex A is built on ISO 27002 controls an ISMS already runs.

Is ISO 27701 the same as GDPR compliance?

No. ISO 27701 certifies a management system, not compliance with a law, and a certificate is not a legal opinion. It is designed so that the obligations of the GDPR, the Swiss FADP and similar laws have a place in it, and it gives you the audited processes to demonstrate that you meet them. Regulators and customers treat it as strong evidence, not as proof.

Which Annex A controls apply to my organization?

It depends on your role. PII controllers consider Table A.1 and Table A.3, PII processors Table A.2 and Table A.3, and an organization that is both, which is common for SaaS providers with their own customer data, considers all three. Your statement of applicability records which tables and controls apply and justifies the rest.

I am certified to ISO 27701:2019. What changes?

The substance of the controller and processor controls carries over, renumbered into Table A.1 and Table A.2 of the new Annex A. What is new is the full set of management clauses 4 to 10, the shared security controls in Table A.3 aligned with ISO 27002:2022, and the option to certify standalone. The transition from the 2019 edition runs three years from publication and ends in October 2028; confirm with your certification body when your own certificate has to be transitioned.

Does ISO 27701 require a data protection officer?

The standard requires that responsibilities for the PIMS are assigned and that a data protection officer or equivalent is appointed where applicable law requires one. Whether the law requires it depends on your processing and jurisdiction. Where it does not, you still need a named privacy lead who owns the PIMS and reports on it to top management.

Is devguard a privacy management tool?

devguard is a compliance workspace, and it carries the management-system side of ISO 27701: clause and Annex A coverage by role, the cross-framework mapping to ISO 27001, ISO 27002, the GDPR and the Swiss FADP, the record of processing, assessments and processor contracts as evidence, internal audits, corrective actions and management reviews. Where you already run ISO 27001 in devguard, ISO 27701 slots into the same system.

See how your ISO 27701 system would look in devguard.

The fastest way to know if this fits is a short conversation about how you handle privacy today: where the record of processing lives, how requests and breaches are handled, and whether it should share a workspace with your ISMS. No deck unless you want one.

Book a conversation
Sign in
Start for free
Book a conversationStart for free