Certifiable extensionGlobal
ISO 27701
ISO/IEC 27701
ISO/IEC 27701 extends an ISO 27001 ISMS into a privacy information management system (PIMS), adding controls for controllers and processors of personally identifiable information. It is the most common certifiable way to evidence GDPR-aligned privacy management.
Who it reaches
- ISO 27001 certificate holders that process personal data at scale or for others.
- Processors whose controller customers audit them under GDPR Article 28.
- Organisations wanting a certificate to stand behind their privacy programme.
What the audit checks
- 01Audited as an extension of the ISO 27001 certification, by a body accredited for 27701, in the same three-year cycle.
- 02The auditor checks the PIMS-specific requirements and the Annex A (controller) and Annex B (processor) controls in scope.
A typical engagement
Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.
| Phase | Weeks |
|---|---|
| Determine controller and processor roles | 1 to 2 |
| Gap assessment against Annex A and B | 2 to 4 |
| Privacy controls, records, rights processes | 6 to 16 |
| Integrated internal audit and certification | 2 to 6 |
Evidence to have ready
- PIMS scope and roles (controller, processor, both)
- Records of processing and purposes
- Privacy impact assessments
- Consent and rights handling records
- Processor and sub-processor agreements
- Transfer mechanisms
- Privacy by design evidence in projects
- Breach handling with notification timelines
Questions people ask
- Can I get ISO 27701 without ISO 27001?
- Not under the current edition: 27701 extends 27001 and is certified alongside it. A revision to make it standalone has been in development.
- Is ISO 27701 GDPR certification?
- No, but it is the closest certifiable proxy, and its Annex D maps the controls to GDPR articles.