ISO 27701 certification — the closest Management System to certifiable GDPR.
A Privacy Information Management System extension to ISO 27001 — formal, certified, and accepted by supervisory authorities as evidence of GDPR governance.
Overview
A privacy layer on top of ISO 27001 — not a standalone standard.
ISO/IEC 27701 extends ISO 27001 by adding a Privacy Information Management System (PIMS) layer on top of an existing ISMS. Where ISO 27001 focuses on protecting information from a security perspective, ISO 27701 focuses on managing personal information from a privacy perspective — addressing the why and how of personal data processing.
ISO 27701 cannot be certified standalone — it requires ISO 27001 (or ISO 27002 as a normative reference) as its foundation. Certification is issued by the same accredited bodies operating across the EU — AFNOR (France), TÜV (Germany), TrustCB (Netherlands), AENOR (Spain), plus EU-wide players like Bureau Veritas, BSI, LRQA, SGS, DNV — and appears on the same certificate as ISO 27001. Annex D maps directly to GDPR articles, making it the closest thing to a certifiable GDPR compliance framework currently available.
Who ISO 27701 is for
ISO 27001-certified organisations handling personal data
Adds the privacy governance layer ISO 27001 alone does not provide.
Data processors serving regulated-sector clients
Cloud, SaaS, payroll, MSPs are increasingly required to demonstrate ISO 27701 — especially in financial services, healthcare, and public sector.
Organisations seeking certifiable GDPR evidence
Independently verified, accepted by supervisory authorities (including the CNIL) as evidence of Article 32 compliance.
Multi-jurisdiction privacy operators
Maps to GDPR, LGPD (Brazil), PDPA (Singapore), UK GDPR — one certification, multiple regimes.
Organisations with existing or voluntary DPOs
Provides the documented framework within which the DPO operates — formalising privacy notices, DPIA procedures, data-subject rights workflows.
Tender differentiators
Where multiple vendors hold ISO 27001, ISO 27701 differentiates privacy commitment in RFPs, vendor risk assessments, and enterprise due diligence.
Four extension areas
What ISO 27701 adds to ISO 27001.
- 01Clauses 5–8
PIMS-specific extensions to ISO 27001
Privacy context, leadership obligations, risk assessment methodology, and documented privacy objectives.
- 02Annex A
31 controls for data controllers
Conditions for collection, consent management, privacy notices, privacy by design, data minimisation, retention, data subject rights, third-party disclosure.
- 03Annex B
18 controls for data processors
Obligations to the controller, sub-processor management, breach notification to controller, return/deletion of personal data at contract end.
- 04Annex D
GDPR mapping
Direct mapping between ISO 27701 controls and GDPR articles — used as evidence of GDPR compliance.
Consequences
No statutory penalties — but GDPR penalties apply to underlying privacy.
ISO 27701 itself is voluntary. There are no statutory fines for not certifying. But the GDPR penalties for the privacy practices ISO 27701 governs are very real — €20M or 4% of global turnover for the most serious violations.
Certification is increasingly a contractual requirement in regulated-sector procurement (financial services, healthcare, public sector). Without it, expect to lose tenders. With it, GDPR Article 32 is largely covered, customer due diligence is accelerated, and supervisory authorities give it weight in their accountability assessments.
Underlying GDPR risk
€20M / 4%
turnover. ISO 27701 covers a large slice of this exposure.
Procurement leverage
Regulated
sectors increasingly require ISO 27701 as a vendor qualification.
Our approach
A privacy program structured for maximum GDPR coverage.
What we deliver
- Privacy gap analysis against ISO 27701 controller and processor requirements
- Existing GDPR documentation review — what reuses, what needs building
- PIMS design and ISMS extension: privacy context, risk methodology, privacy objectives
- ROPA enhancement to PIMS standard
- Annex A controls implementation: privacy notices, consent, DPIA process, retention, data subject rights workflows
- Annex B controls (where you act as processor): processor obligations, sub-processor management, breach-to-controller
- Privacy-specific internal audit and corrective-action support
- Certification audit support — combined with ISO 27001 surveillance or recertification where possible
Typical timeline
Depends on whether ISO 27001 is already in place.
4–8 months
With existing ISO 27001
Privacy gap analysis, PIMS extension, controls implementation, internal audit, certification audit (combined with ISO 27001 surveillance).
10–14 months
ISO 27001 + ISO 27701 together
Combined integrated program — faster, cheaper, less internal disruption than sequential implementation. Ends with a single certificate covering both.
FAQ