ISO 27701·10 min read

ISO 27701: The Standalone Privacy Information Management Standard

ISO 27701 is the international standard for a Privacy Information Management System. The 2025 edition made it a standalone standard you can certify on its own, and if you already hold ISO 27001 most of the work is done and the remaining gap is narrower than teams expect.

This guide covers what the standard actually requires, what the 2025 revision changed, how it differs from ISO 27001, what certification costs, and when it beats the alternatives. For the service view, see the ISO 27701 consulting page.


What ISO 27701 Actually Is

ISO 27701 defines requirements for a Privacy Information Management System, usually shortened to PIMS. It uses the same management system machinery as ISO 27001, pointed at a different question.

An information security management system asks one core question: is this data protected from compromise? A privacy information management system asks a different set:

  • Should we be holding this data at all?
  • For what stated purpose, and under what legal justification?
  • For how long, and what triggers deletion?
  • Who else receives it, and under what terms?
  • What happens when the person it belongs to makes a request?

Security controls answer none of those. You can run a flawlessly encrypted, tightly access-controlled database full of personal data you had no business collecting. ISO 27001 would not flag it. ISO 27701 would.

What the 2025 revision changed

ISO/IEC 27701:2025 replaced the 2019 edition in October 2025, and the change is structural rather than cosmetic.

The 2019 edition was published as an extension to ISO 27001 and ISO 27002. You could not certify to it on its own, because it had no management system of its own to audit. ISO has since withdrawn that edition. The 2025 edition drops "extension" from its title, sets out full requirements for a privacy information management system, and no longer depends on implementing ISO 27001 or ISO 27002.

Two consequences follow.

You can now certify to ISO 27701 without holding ISO 27001. That was not possible under the 2019 model. Whether you should is a separate question, covered below.

Most published guidance is out of date. A large share of the comparison content still describes ISO 27701 as an extension you cannot hold alone. Check the edition date on anything you read, including vendor pages and certification body marketing.

Alignment still matters commercially. ISO 27701 is designed to sit alongside an ISO 27001 system, so it remains far cheaper for organizations that already hold ISO 27001 than for organizations starting from nothing. What changed is that starting from nothing is now permitted.

On transition timing. Organizations holding a 2019 certificate will need to move to the 2025 edition, but the accreditation bodies had not published final transition rules at the time of writing, so there is no confirmed deadline to plan against yet. Ask your certification body what timeline they are working to rather than assuming the usual three years.


ISO 27701 vs 27001: Where the Line Sits

The comparison people search for is ISO 27701 vs 27001, and the honest answer is that they are not alternatives. They cover different subjects and are designed to run together.

DimensionISO 27001ISO 27701
ProtectsInformation assetsIndividuals whose data you hold
Core questionIs it secure?Should we have it, and are we honoring rights?
Certifiable aloneYesYes, since the 2025 edition
Key artifactStatement of ApplicabilityProcessing inventory and role determination
Buyer signalWe will not get breachedWe will not misuse your customers' data

What ISO 27701 adds

ISO 27701 introduces four categories of work with no ISO 27001 equivalent:

Role determination. For every processing activity, you declare whether you act as a controller, a processor, or both. This is not paperwork. The control set you are audited against differs depending on the answer, and most SaaS companies are processors for customer data and controllers for their own marketing and HR data simultaneously.

Purpose and lawful basis documentation. Each processing activity needs a documented purpose. ISO 27001 never asks why you hold something, only how well you guard it.

Individual rights handling. Access, correction, deletion, portability, and objection all need working procedures with defined owners and response clocks.

Transfer governance. Where personal data moves to another organization or another country, you document the mechanism and the safeguards.

If you want the security side first, start with the ISO 27001 checklist and the ISO 27001 service page.


ISO 27701 and GDPR: Certification Is Not Compliance

This is the most important thing to get right, and the place most vendor content oversells.

ISO 27701 certification does not make you GDPR compliant. No certification does. GDPR compliance is a legal state determined by regulators and courts, and no accredited body has authority to certify it under Article 42 unless specifically approved for that purpose.

What ISO 27701 gives you is different, and still valuable:

  • A management system that produces the evidence GDPR expects. Article 5(2) requires you to demonstrate compliance, not merely achieve it. A PIMS is a demonstration engine.
  • Structured coverage of the operational obligations. Processing records, rights procedures, transfer documentation, and vendor governance are all in scope.
  • A third-party audited artifact. A prospect's security team can verify a certificate in seconds. They cannot verify your self-assessment at all.

Where the mapping is strong

Processing inventory, rights-request handling, privacy by design, vendor and sub-processor governance, and breach handling all map cleanly onto the operational requirements a privacy program needs to satisfy.

Where the mapping leaves gaps

Certification will not decide your lawful basis for you, will not settle whether a Data Protection Impact Assessment is required for a given product decision, and will not resolve jurisdiction-specific questions about international transfers. Those need legal judgment. The management system tells you the questions are being asked and answered consistently. It does not answer them.

For the practical GDPR view, see the GDPR compliance checklist and the GDPR service page.


Who Should Certify, and Who Should Not

Strong fit

You already hold ISO 27001 and privacy questions are stalling deals. This is the clearest case. The marginal cost is small and the sales objection it removes is concrete.

You are a processor selling to European controllers. Your customers carry accountability obligations for their processors. A certificate makes their due diligence cheap, which makes buying from you easier.

You handle sensitive categories at scale. Health, financial, biometric, or children's data raises the stakes on every privacy question. An audited system is worth more here.

You are answering the same privacy questionnaire every quarter. Certification collapses a recurring cost into a fixed one.

Weak fit

You have no ISO 27001 and no near-term plan for it. The 2025 edition lets you certify ISO 27701 on its own, so this is no longer a hard block. It is still usually the wrong order. Buyers who ask for a privacy certificate almost always ask for a security one too, and a PIMS with no ISMS underneath it leaves you explaining why the security half is missing. Certify ISO 27001 first unless a specific customer is asking for ISO 27701 alone.

Your buyers only ever ask for SOC 2. In a purely US mid-market motion, SOC 2 remains the dominant currency. Add ISO 27701 when European or privacy-led buyers appear, not before. The ISO 27001 vs SOC 2 comparison covers that trade-off.

You are pre-product or pre-revenue. Build the processing inventory now because it gets exponentially harder later. Skip the audit until a customer asks.


What Certification Actually Costs

Cost splits into two very different buckets, and teams routinely budget for the wrong one.

Certification body fees are the smaller number, and what you pay depends on how you certify. For an organization already holding ISO 27001 that audits both together, the privacy scope costs a fraction of a first-time certification, because the auditor reuses your existing scope, sampling, and audit cycle rather than starting fresh. Certifying ISO 27701 standalone removes that reuse, so quote it as its own certification rather than an increment. Ask your certification body for both figures.

Internal preparation is the real cost, and it is concentrated in work most companies have never done:

  • Building a complete processing inventory across every system that touches personal data
  • Determining controller and processor roles per activity, then living with the consequences
  • Writing retention schedules that someone will actually enforce
  • Standing up rights-request workflows with named owners and response clocks
  • Papering sub-processor relationships properly

Companies with a mature ISO 27001 program often reach audit readiness in three to four months. Companies treating privacy as a net-new discipline should plan for six or more.

The sequencing that saves money

Align the ISO 27701 Stage 2 audit with an existing ISO 27001 surveillance or recertification visit. One auditor, one site visit, one evidence pull. Certifying off-cycle is the single most common way teams overpay.


The Realistic Implementation Path

  1. Confirm your scope. If you hold ISO 27001, the PIMS will normally inherit it, so if your ISMS scope is narrower than where personal data actually flows, fix that first. If you are certifying ISO 27701 on its own, define the PIMS scope directly around your processing activities.
  2. Determine roles per processing activity. Controller, processor, or both. This drives which control annex applies.
  3. Build the processing inventory. Systems, data categories, purposes, retention, recipients, transfer mechanisms. Nearly every subsequent artifact is generated from this one.
  4. Run a gap assessment. Against the PIMS requirements and the applicable controller and processor controls.
  5. Close gaps and operate. Most gaps are procedural, not technical. You need three to six months of operating evidence before an auditor can sample it.
  6. Stage 1 and Stage 2 audit. Documentation review, then the operating audit, ideally bundled with your ISO 27001 cycle.

The processing inventory is the load-bearing step. Teams that rush it spend the rest of the project rebuilding downstream artifacts on a broken foundation.


What the Auditor Will Actually Test

Knowing where auditors concentrate saves months of preparing the wrong evidence.

Role determination consistency. The auditor will pick a processing activity and check that your declared role matches reality. If you claim to be a processor for customer data but your contracts let you use that data for your own product analytics, you are acting as a controller and your documentation is wrong. This is the most common major finding.

Inventory completeness. They will name a system that was not in your inventory and ask why. Shadow systems, the marketing team's standalone email tool, and data in spreadsheets are the usual sources of a gap.

Rights requests as operated, not as written. Having a documented procedure is not enough. The auditor wants evidence of actual requests handled inside the stated window, with the decisions recorded. If you have received none, expect to walk through a test case.

Retention enforced, not just scheduled. A retention schedule with no deletion evidence behind it is a finding. Show the job, the log, or the ticket.

Sub-processor governance. Named sub-processors, current agreements, and evidence you assessed them before onboarding.

Notice what is not on this list: new security tooling. Companies that already hold ISO 27001 rarely fail the privacy audit on technical controls. They fail on documentation of purpose and on rights handling, which is exactly the work the certification exists to force.


If you are weighing this against other frameworks, the ISO 27001 vs SOC 2 comparison covers the security certificate decision, and GDPR data processing agreements covers the contract layer that sits underneath processor obligations. For staffing questions raised by a privacy program, see DPO vs privacy officer. Service pages: ISO 27701, ISO 27001, and GDPR.


Frequently Asked Questions

What is the main purpose of ISO 27701? It gives you a certifiable way to prove you manage personal data responsibly. Privacy laws define the outcomes you owe people. ISO 27701 provides an auditable management system for delivering those outcomes consistently, plus a certificate a customer can verify.

What is the main difference between ISO 27001 and ISO 27701? ISO 27001 protects information. ISO 27701 protects people. Security asks whether data is safe from compromise. Privacy asks whether you should hold it at all, for what purpose, for how long, and what happens when someone asks you to delete it. Since the 2025 edition, ISO 27701 is a standalone standard you can certify on its own, though it is built to align with ISO 27001 and most organizations run the two together.

How much does it cost to get ISO 27701 certified? Audited alongside ISO 27001, the privacy scope costs a fraction of a first-time certification, because the auditor reuses your existing scope and cycle. Certified standalone, which the 2025 edition permits, it is priced as its own certification. The bigger cost either way is internal: the processing inventory, retention schedules, and rights-request workflows.

How do you get ISO 27701 certified? Confirm your scope, determine controller and processor roles per activity, build the processing inventory, run a gap assessment, close gaps, then operate for three to six months to generate evidence. Finish with Stage 1 and Stage 2 audits through an accredited certification body, bundled with your ISO 27001 visit if you have one.


Ready to Scope ISO 27701?

ShieldKey Solutions scopes ISO 27701 against the current 2025 edition, whether you are layering privacy onto an ISO 27001 program you already run or certifying a privacy management system on its own. We start with the processing inventory and role determination, close the privacy gaps, and where you already hold ISO 27001 we align the audit with your existing certification cycle so you pay for one visit instead of two.

Schedule a scoping call →