Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 27701

Privacy Information Management Systems

Management Systems Published: 2025 ✓ Certifiable

ISO 27701:2025 at a glance

Current edition
ISO/IEC 27701:2025 - Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance
Published
2025
Status
Published
Type of standard
Management system standard
Certifiable
Yes — organizations can be certified by an accredited body
Previous edition
ISO/IEC 27701:2019
Official ISO page
View ISO 27701:2025 on iso.org
Last verified

Overview

Certifiable requirements for a privacy information management system (PIMS); the 2025 second edition is a standalone standard, no longer an extension to ISO/IEC 27001

ISO/IEC 27701:2025 specifies requirements, and gives guidance, for establishing, implementing, maintaining and continually improving a privacy information management system (PIMS). The second edition replaces ISO/IEC 27701:2019 and represents a structural change: where the 2019 edition was written as an extension to ISO/IEC 27001 and ISO/IEC 27002 and could only be certified on top of an existing ISMS certification, the 2025 edition is a standalone management system standard that can be implemented and certified independently, while still integrating with ISO/IEC 27001 for organizations that hold it.

The standard applies to both PII controllers and PII processors, and to organizations of all types and sizes, including public bodies and non-profits. Because privacy obligations differ sharply by role, the standard requires the organization to determine its role for each processing activity and apply the corresponding requirements — a distinction that mirrors the controller/processor split in the GDPR and similar laws worldwide.

Structurally it follows ISO's harmonized management system structure: context of the organization, leadership, planning, support, operation, performance evaluation and improvement, with privacy-specific content added to each. Privacy risk assessment sits alongside information security risk assessment, and the system requires identification of applicable privacy obligations, determination of the purposes and lawful bases for processing, and management of the full processing lifecycle.

Operational content addresses the substance of privacy programmes: privacy by design and by default, records of processing, purpose limitation and data minimisation, retention and deletion, accuracy, transparency notices and consent management, handling of data subject rights requests, privacy impact assessments, controls on international transfers, breach handling, and contractual and assurance arrangements between controllers and processors and with sub-processors.

Accredited third-party certification is available. ISO/IEC 27706:2025 specifies the requirements for bodies providing audit and certification of privacy information management systems, replacing reliance on the earlier ISO/IEC TS 27006-2. Organizations holding certificates against the 2019 edition transition to the 2025 edition through their certification body under the applicable transition arrangements.

ISO/IEC 27701 is frequently used to give structure to GDPR, UK GDPR, CCPA/CPRA, LGPD and PIPL programmes. It is important to be precise about what that means: certification demonstrates a governed, auditable privacy management system, and supports accountability obligations, but it is not a legal finding of compliance with any particular data protection law, and no data protection authority treats it as one.

Related standards include ISO/IEC 27001 and ISO/IEC 27002 (information security), ISO/IEC 29100 (privacy framework and terminology), ISO/IEC 29134 (privacy impact assessment guidance), ISO/IEC 29151 (code of practice for PII protection) and ISO/IEC 27018 (PII protection in public clouds).

Purpose

To specify auditable requirements for a privacy information management system covering both PII controllers and PII processors, so that an organization can govern personal data processing systematically and demonstrate accountability through independent certification.

Key Benefits

  • Provides certifiable requirements for privacy management, now implementable as a standalone system
  • Covers both PII controller and PII processor roles within one framework
  • Supports accountability and demonstrable governance obligations under GDPR and comparable laws
  • Integrates with ISO/IEC 27001 where an ISMS already exists, avoiding duplicate structures
  • Establishes a repeatable process for data subject rights requests and privacy impact assessments
  • Formalises records of processing, retention schedules and lawful basis determinations
  • Extends privacy obligations into the supply chain through processor and sub-processor requirements
  • Provides recognised third-party evidence for customers, partners and procurement due diligence
  • Backed by ISO/IEC 27706:2025, which sets the accreditation requirements for certification bodies
  • Applicable to organizations of any size and sector, including public and non-profit bodies

Key Requirements

  • Determine internal and external issues, interested parties and the scope of the privacy information management system
  • Determine the organization's role as PII controller, PII processor, or both, for each processing activity
  • Identify applicable privacy obligations, including legal, regulatory and contractual requirements
  • Establish privacy policy and assign roles, responsibilities and authorities, with top management commitment
  • Perform privacy risk assessment and risk treatment, alongside information security risk management
  • Determine and document the purposes and lawful basis for each processing activity
  • Maintain records of PII processing activities
  • Apply privacy by design and privacy by default in systems and processes
  • Implement data minimisation, purpose limitation, accuracy, retention and secure deletion controls
  • Provide transparency information to PII principals and manage consent and its withdrawal
  • Operate a process for handling data subject rights requests within required timeframes
  • Conduct privacy impact assessments where processing is likely to result in high risk
  • Control international transfers of PII and document the safeguards applied
  • Establish contractual and assurance arrangements with processors and sub-processors, and manage privacy breaches
  • Monitor, measure, internally audit, review and continually improve the privacy information management system

Who Needs This Standard?

Any organization processing significant volumes of personal data or acting as a processor for others — SaaS and cloud providers, marketing and adtech firms, financial services, healthcare, HR and payroll providers, retailers, and public sector bodies — particularly where customers or regulators expect demonstrable privacy governance.

Where to get ISO 27701

The full text of ISO 27701 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 27701 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Send me the implementation checklist for ISO 27701, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Need help getting certified?

Certificates for ISO 27701 are issued by accredited certification bodies, not by ISO itself. Tell us what stage you are at and we will put you in touch with people who work with this standard — implementation support, audit or training. Free and no obligation.

Get help with ISO 27701 certification

Related Standards