All frameworks
Certifiable extensionGlobal

ISO 27701

ISO/IEC 27701

ISO/IEC 27701 extends an ISO 27001 ISMS into a privacy information management system (PIMS), adding controls for controllers and processors of personally identifiable information. It is the most common certifiable way to evidence GDPR-aligned privacy management.

Who it reaches

  • ISO 27001 certificate holders that process personal data at scale or for others.
  • Processors whose controller customers audit them under GDPR Article 28.
  • Organisations wanting a certificate to stand behind their privacy programme.

What the audit checks

  1. 01Audited as an extension of the ISO 27001 certification, by a body accredited for 27701, in the same three-year cycle.
  2. 02The auditor checks the PIMS-specific requirements and the Annex A (controller) and Annex B (processor) controls in scope.

A typical engagement

Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.

PhaseWeeks
Determine controller and processor roles1 to 2
Gap assessment against Annex A and B2 to 4
Privacy controls, records, rights processes6 to 16
Integrated internal audit and certification2 to 6

Evidence to have ready

  • PIMS scope and roles (controller, processor, both)
  • Records of processing and purposes
  • Privacy impact assessments
  • Consent and rights handling records
  • Processor and sub-processor agreements
  • Transfer mechanisms
  • Privacy by design evidence in projects
  • Breach handling with notification timelines

Questions people ask

Can I get ISO 27701 without ISO 27001?
Not under the current edition: 27701 extends 27001 and is certified alongside it. A revision to make it standalone has been in development.
Is ISO 27701 GDPR certification?
No, but it is the closest certifiable proxy, and its Annex D maps the controls to GDPR articles.

Go deeper