ISO 27701 vs ISO 27001: What the 2025 Edition Changed
ISO 27701 vs ISO 27001 is a comparison that most published guidance now gets wrong, because ISO 27701 was revised in 2025 and the change was structural. The short version: ISO 27001 protects information, ISO 27701 protects the people that information describes, and as of the current edition you can certify to either one on its own.
This post covers the difference between the two standards, what the revision changed, and how to sequence them. For the full picture on the privacy standard by itself, see the ISO 27701 guide.
The Core Difference in One Line
ISO 27001 asks: is this data protected?
ISO 27701 asks: should we have this data, and are we honoring the rights of the person it belongs to?
Those are not the same question, and passing one does not answer the other. You can run a perfectly encrypted, tightly access-controlled, continuously monitored database full of personal data you had no lawful reason to collect, kept far longer than you told anyone, shared with vendors nobody vetted. An ISO 27001 audit would not flag any of that. Every control would pass. The security is real.
ISO 27701 is the standard that flags it.
Side by side
| Dimension | ISO 27001 | ISO 27701 |
|---|---|---|
| Subject | Information assets | Individuals whose data you hold |
| Core question | Is it secure? | Should we have it? |
| Management system | ISMS | PIMS |
| Certifiable alone | Yes | Yes, since the 2025 edition |
| Key artifact | Statement of Applicability | Processing inventory and role determination |
| Buyer signal | We will not get breached | We will not misuse your customers' data |
| Regulatory anchor | None directly | Maps to GDPR, UK GDPR, DPDPA, LGPD |
The last row is the commercial reason ISO 27701 exists. ISO 27001 has no direct regulatory counterpart. ISO 27701 was built to produce the evidence that privacy regulators ask for.
What the 2025 Revision Changed
ISO/IEC 27701:2025 replaced the 2019 edition in October 2025. If you read only one section of this post, read this one, because the change invalidates most of the comparison content currently ranking for this topic.
The 2019 model: an extension
The withdrawn 2019 edition was published as an extension to ISO 27001 and ISO 27002. It had no management system requirements of its own. In practice that meant:
- You had to implement ISO 27001 first
- ISO 27701 was audited as an add-on to your existing ISMS certificate
- Standalone ISO 27701 certification was not available
This is the model nearly every vendor comparison page still describes. Several of the pages ranking for this topic today state flatly that you cannot certify to ISO 27701 alone. That was true. It is not true now.
The 2025 model: a standalone standard
The 2025 edition drops "extension" from its title and sets out full requirements for a privacy information management system. The consequences:
Standalone certification is permitted. An organization can now be certified to ISO 27701 without holding ISO 27001. The privacy management system is audited in its own right.
The annexes were restructured around role. Rather than a single bolt-on control set, the 2025 edition organizes controls by whether you act as a PII controller, a PII processor, or both, alongside information security controls.
Published control counts went stale. The "24 clauses and 114 controls" figure that circulates widely describes the 2019 edition. Do not use it for scoping. Counts quoted by secondary sources for the 2025 edition vary enough that you should confirm against the standard text or your certification body before planning around any specific number.
Transition timing is not yet settled. Organizations holding a 2019 certificate will need to move to the 2025 edition, but accreditation bodies had not published final transition rules at the time of writing. There is no confirmed deadline. Ask your certification body what timeline they are working to rather than assuming the usual three-year window.
The practical takeaway: when you read anything comparing ISO 27701:2019 against ISO 27701:2025, or any comparison that does not name an edition at all, check the publication date before you trust the certification claims in it.
Where the Two Standards Overlap
The overlap is real, and it is the reason doing both is cheaper than doing each separately.
Both standards are built on the same ISO management system scaffolding. If you already hold ISO 27001, these are already built and ISO 27701 reuses them:
- Context and scope definition — who you are, what you do, what is in the system
- Leadership commitment and policy — documented management ownership
- Risk assessment methodology — the process, not the results
- Internal audit program — the function, extended to privacy
- Management review — the cadence, with privacy topics added
- Corrective action and continual improvement — same machinery
- Competence, awareness, and training — same program, new module
- Document and record control — same system
That is a meaningful share of total implementation effort, already paid for. This is why adding ISO 27701 to a live ISO 27001 system is a materially smaller project than either one from scratch, and why the sequencing question below usually resolves toward ISO 27001 first.
The security controls overlap too. A privacy management system still needs access control, encryption, logging, and incident response. Those are the same controls, not privacy-specific versions of them.
What ISO 27701 Adds That ISO 27001 Has No Equivalent For
Four categories of work are genuinely new.
Role determination
For every processing activity, you declare whether you act as a PII controller, a PII processor, or both. This is not a labeling exercise. The control set you are audited against depends on the answer.
Most SaaS companies are both at once: a processor for customer data flowing through the product, and a controller for their own marketing lists, job applicants, and employee records. Getting this wrong at scoping time is the most common early mistake, and it is expensive to unwind mid-implementation.
Purpose and lawful basis documentation
Each processing activity needs a documented purpose and a justification for it. ISO 27001 never asks why you hold something, only how well you guard it. This is the work that most closely resembles a GDPR record of processing activities, and the two artifacts should be built once and shared.
Individual rights handling
Access, correction, deletion, portability, and objection each need a working procedure with a named owner and a response clock. Not a policy that says you will honor them. A procedure that has been tested.
Transfer and vendor governance
Where personal data moves to another organization or another country, you document the mechanism and the safeguards. Your vendor inventory becomes a privacy artifact, not just a security one, which connects directly to your GDPR data processing agreement work.
ISO 27701 Certification and GDPR: Not the Same Thing
This is where vendor content oversells most reliably, so it is worth stating plainly.
ISO 27701 certification does not make you GDPR compliant. No certification does. GDPR compliance is a legal state assessed by regulators and courts. No accredited certification body has authority to certify it under Article 42 unless specifically approved for that purpose.
What ISO 27701 gives you instead:
- Evidence that GDPR expects. Article 5(2) requires you to demonstrate compliance, not merely achieve it. A PIMS is a demonstration engine.
- Operational coverage. Processing records, rights procedures, transfer documentation, and vendor governance all sit in scope.
- A verifiable artifact. A prospect's security team can check a certificate in seconds. They cannot check your self-assessment at all.
If your goal is closing enterprise deals with privacy-sensitive buyers, that third point is usually the whole business case.
Which One First?
For most companies, ISO 27001 first. Three reasons:
- It is what gets asked for. Enterprise security questionnaires and vendor reviews name ISO 27001 or SOC 2. ISO 27701 rarely appears as a hard requirement.
- It builds the scaffolding. Everything in the overlap section above gets built once and reused.
- It is the broader signal. ISO 27001 covers your whole information estate. ISO 27701 covers the personal data subset.
Lead with ISO 27701 instead when one of these is true:
- Your product's core function is processing other people's personal data at scale
- EU or UK customers are raising privacy-specific objections that a security certificate does not answer
- You are a processor whose customers are themselves heavily regulated on privacy, and they are pushing those obligations down your contract
- You already hold SOC 2 covering the security question and need the privacy half, not a second security certificate
Do both together if you are starting from nothing and know you need both within eighteen months. One scoping exercise, one risk methodology, one internal audit program, one certification body, one audit cycle. The incremental cost of adding privacy scope during initial implementation sits far below the cost of a separate project later.
A note on the neighboring standard people often raise here: if AI governance is also on your roadmap, ISO 42001 shares the same management system backbone and the same integration logic. See ISO 42001 vs NIST AI RMF for where that one fits.
For the standalone privacy standard in depth, see the ISO 27701 guide and the ISO 27701 service page. For the security side, start with the ISO 27001 checklist and what to expect in an ISO 27001 audit, or the ISO 27001 service page. If your privacy obligations are GDPR-driven, the GDPR compliance checklist is the operational companion to this one.
Frequently Asked Questions
What is the primary purpose of ISO 27701? ISO 27701 sets the requirements for a privacy information management system. It governs why personal data is collected, on what basis, how long it is kept, who it is shared with, and how rights requests are answered. ISO 27001 governs how well data is protected once you hold it. ISO 27701 asks whether you should hold it at all.
What is the current version of ISO 27701? ISO/IEC 27701:2025, published October 2025. It replaced the 2019 edition, which ISO has withdrawn. The editions differ materially, so check the edition date on any guidance you read before trusting its certification claims.
How many controls are in ISO 27701? Check the edition before you trust any count. The commonly quoted 24 clauses and 114 controls describe the withdrawn 2019 edition. The 2025 edition restructured its annexes by role, with separate control sets for PII controllers, PII processors, and information security. Confirm the current figure against the standard text or your certification body before scoping against it.
Can you certify to ISO 27701 without ISO 27001? Yes, since the 2025 edition. The withdrawn 2019 edition was an extension with no management system of its own, so standalone certification was not possible. The 2025 edition sets out full requirements and does not depend on ISO 27001. It is still cheaper to add it to an existing ISMS than to build a PIMS from nothing.
Which should a SaaS company get first, ISO 27001 or ISO 27701? Usually ISO 27001, because it is what buyers ask for by name and it builds the management system scaffolding ISO 27701 reuses. Lead with ISO 27701 when your product's core function is handling other people's personal data, or when privacy-specific procurement objections are the thing blocking deals.
Not Sure Which Certificate Your Buyers Actually Want?
ShieldKey Solutions scopes ISO 27001 and ISO 27701 programs for SaaS companies, including combined implementations that share one management system across both. We start by looking at what your prospects are actually asking for in their security reviews, then build the shortest path to answering it.