ISO 27701

Privacy · Certification

ISO 27701 certification — the closest Management System to certifiable GDPR.

A Privacy Information Management System extension to ISO 27001 — formal, certified, and accepted by supervisory authorities as evidence of GDPR governance.

Overview

A privacy layer on top of ISO 27001 — not a standalone standard.

ISO/IEC 27701 extends ISO 27001 by adding a Privacy Information Management System (PIMS) layer on top of an existing ISMS. Where ISO 27001 focuses on protecting information from a security perspective, ISO 27701 focuses on managing personal information from a privacy perspective — addressing the why and how of personal data processing.

ISO 27701 cannot be certified standalone — it requires ISO 27001 (or ISO 27002 as a normative reference) as its foundation. Certification is issued by the same accredited bodies operating across the EU — AFNOR (France), TÜV (Germany), TrustCB (Netherlands), AENOR (Spain), plus EU-wide players like Bureau Veritas, BSI, LRQA, SGS, DNV — and appears on the same certificate as ISO 27001. Annex D maps directly to GDPR articles, making it the closest thing to a certifiable GDPR compliance framework currently available.

Who ISO 27701 is for

  • ISO 27001-certified organisations handling personal data

    Adds the privacy governance layer ISO 27001 alone does not provide.

  • Data processors serving regulated-sector clients

    Cloud, SaaS, payroll, MSPs are increasingly required to demonstrate ISO 27701 — especially in financial services, healthcare, and public sector.

  • Organisations seeking certifiable GDPR evidence

    Independently verified, accepted by supervisory authorities (including the CNIL) as evidence of Article 32 compliance.

  • Multi-jurisdiction privacy operators

    Maps to GDPR, LGPD (Brazil), PDPA (Singapore), UK GDPR — one certification, multiple regimes.

  • Organisations with existing or voluntary DPOs

    Provides the documented framework within which the DPO operates — formalising privacy notices, DPIA procedures, data-subject rights workflows.

  • Tender differentiators

    Where multiple vendors hold ISO 27001, ISO 27701 differentiates privacy commitment in RFPs, vendor risk assessments, and enterprise due diligence.

Four extension areas

What ISO 27701 adds to ISO 27001.

  1. 01Clauses 5–8

    PIMS-specific extensions to ISO 27001

    Privacy context, leadership obligations, risk assessment methodology, and documented privacy objectives.

  2. 02Annex A

    31 controls for data controllers

    Conditions for collection, consent management, privacy notices, privacy by design, data minimisation, retention, data subject rights, third-party disclosure.

  3. 03Annex B

    18 controls for data processors

    Obligations to the controller, sub-processor management, breach notification to controller, return/deletion of personal data at contract end.

  4. 04Annex D

    GDPR mapping

    Direct mapping between ISO 27701 controls and GDPR articles — used as evidence of GDPR compliance.

Consequences

No statutory penalties — but GDPR penalties apply to underlying privacy.

ISO 27701 itself is voluntary. There are no statutory fines for not certifying. But the GDPR penalties for the privacy practices ISO 27701 governs are very real — €20M or 4% of global turnover for the most serious violations.

Certification is increasingly a contractual requirement in regulated-sector procurement (financial services, healthcare, public sector). Without it, expect to lose tenders. With it, GDPR Article 32 is largely covered, customer due diligence is accelerated, and supervisory authorities give it weight in their accountability assessments.

  • Underlying GDPR risk

    €20M / 4%

    turnover. ISO 27701 covers a large slice of this exposure.

  • Procurement leverage

    Regulated

    sectors increasingly require ISO 27701 as a vendor qualification.

Our approach

A privacy program structured for maximum GDPR coverage.

What we deliver

  • Privacy gap analysis against ISO 27701 controller and processor requirements
  • Existing GDPR documentation review — what reuses, what needs building
  • PIMS design and ISMS extension: privacy context, risk methodology, privacy objectives
  • ROPA enhancement to PIMS standard
  • Annex A controls implementation: privacy notices, consent, DPIA process, retention, data subject rights workflows
  • Annex B controls (where you act as processor): processor obligations, sub-processor management, breach-to-controller
  • Privacy-specific internal audit and corrective-action support
  • Certification audit support — combined with ISO 27001 surveillance or recertification where possible

Typical timeline

Depends on whether ISO 27001 is already in place.

  1. 4–8 months

    With existing ISO 27001

    Privacy gap analysis, PIMS extension, controls implementation, internal audit, certification audit (combined with ISO 27001 surveillance).

  2. 10–14 months

    ISO 27001 + ISO 27701 together

    Combined integrated program — faster, cheaper, less internal disruption than sequential implementation. Ends with a single certificate covering both.

FAQ

Common questions.

Is ISO 27701 certification the same as GDPR compliance?
No — but it is the closest certifiable approximation. Annex D maps controls directly to GDPR articles, and supervisory authorities (including the CNIL) recognise it as evidence of Article 32 compliance and the accountability principle. However, certain GDPR obligations — determining the correct lawful basis per processing activity, mandatory DPO designation, supervisory authority consultation for high-risk DPIAs — require separate legal work that ISO 27701 does not replace.
Can we pursue ISO 27701 without ISO 27001?
No — ISO 27701 explicitly requires ISO 27001 (or ISO 27002 as a normative reference) as its foundation. There is no standalone ISO 27701. If you do not yet hold ISO 27001, the right approach is to implement both standards together in one integrated program — more efficient than sequential, with one integrated management system certified against both.
What's the difference between ISO 27701 and a GDPR audit?
A GDPR audit is point-in-time — useful for understanding current position but produces no ongoing certification. ISO 27701 certification is independently assessed, continuously maintained, formally certified, renewed through annual surveillance audits and three-year recertification. Carries significantly more weight with enterprise clients, procurement, and supervisory authorities.
Does ISO 27701 apply to both controllers and processors?
Yes — Annex A contains controller controls, Annex B contains processor controls. Many organisations are both: controller for their own employee/customer data, processor for clients' data. ISO 27701 accommodates the dual role; you implement relevant controls from both annexes and clearly define your roles in the Statement of Applicability.
How does ISO 27701 affect our DPO obligation?
It does not eliminate or substitute for the mandatory DPO designation requirement under GDPR Article 37. If your organisation is required to appoint a DPO, you must do so regardless of ISO 27701. They work powerfully together — the standard provides the documented PIMS framework within which the DPO operates. We frequently implement both ISO 27701 and DPO as a Service in one integrated privacy governance program.
Is ISO 27701 recognised outside the EU?
Yes — designed as a global privacy management standard. Annex D maps to GDPR, Brazil LGPD, Singapore PDPA, UK GDPR, and others. Organisations processing personal data from multiple regions can use ISO 27701 as the core privacy framework, supplemented by jurisdiction-specific addenda.