This ISO 27701 2025 pack is built for the second edition of the standard, published in October 2025, which changed what ISO 27701 fundamentally is: a standalone, independently certifiable management system rather than an extension bolted onto ISO 27001. 79 editable Word and Excel templates across five sections, downloadable the moment you check out. On this page:
- What is in the toolkit
- Why ISO 27701 2025 is a different proposition from the 2019 version
- Who needs ISO 27701 2025
- How the documents map to the framework
- Frequently asked questions
- Related toolkits
What is in the ISO 27701 2025 pack
The structure mirrors the second edition rather than the old extension model, which matters because the annexes were reorganised. The five sections are:
- 00 Start Here – a read-me explaining the structure, the scoping decisions to make first and the order to work through
- 01 PIMS Core, Clauses 4 to 10 – context, leadership, planning, support, operation, performance evaluation and improvement written as a management system in its own right
- 02 Annex A1 Controller – the controls that apply when you determine the purposes and means of processing, including lawful basis, consent, transparency and data subject rights
- 03 Annex A2 Processor – the controls that apply when you process on a customer instruction, including processing records, sub-processor control and customer assistance obligations
- 04 Annex A3 Security – the security controls the PIMS relies on, so the system stands up whether or not you also hold ISO 27001

Why ISO 27701 2025 is a different proposition from the 2019 version
The first edition of ISO 27701 was an extension to ISO 27001. You could not be certified to it on its own; it rode on an existing ISMS certificate. The second edition, published in October 2025, makes it a management system standard in its own right, with its own clauses 4 to 10 and its own certification route.
That is a commercial change as much as a technical one. An organisation whose customers ask for privacy assurance but which has no appetite for a full ISO 27001 programme now has a proportionate answer. Equally, an organisation that already holds ISO 27001 can run the two systems together and reuse the shared clauses rather than maintaining two sets of paperwork.
If you built a PIMS to the 2019 edition, the work is not wasted, but the mapping is not one-to-one – the annex structure moved and the core clauses are new. This ISO 27701 2025 pack is written to the second edition throughout, so you are tailoring current documents rather than retrofitting superseded ones. The official record for the second edition is on the ISO/IEC 27701:2025 page at iso.org.
Who needs ISO 27701 2025
Processors under pressure from enterprise customers who want privacy assurance in writing and will accept a certificate instead of another questionnaire. Controllers who need to show a regulator, a board or an acquirer that privacy is run as a system rather than a policy. SaaS and outsourcing providers who want an independently certifiable privacy position without committing to ISO 27001 first. And organisations already certified to ISO 27001 who want to add privacy without duplicating the management system.
How the ISO 27701 2025 maps to the framework
Annexes A1 and A2 are kept separate rather than merged, because most organisations are a controller for some processing and a processor for others, and conflating the two is the fastest way to fail an audit. Each control has a document or a register behind it, and the security annex is populated so the PIMS is defensible as a standalone system. Because the structure follows the standard rather than a vendor framework, the system stays portable if you change certification body.
Frequently asked questions
Do we still need ISO 27001 first?
No. That was the constraint in the 2019 edition. The 2025 edition is a standalone management system standard with its own certification route, and this pack includes the security annex so the PIMS stands on its own.
We have a PIMS built to the 2019 edition. Can we reuse it?
Much of the substance carries over, but the mapping is not one-to-one: the clause structure is new and the annexes were reorganised. Expect to rehome content rather than renumber it.
Does this cover GDPR?
ISO 27701 is written to be mappable onto privacy regimes rather than tied to one. It supports a GDPR programme but is not a substitute for GDPR-specific records. For that, pair it with the GDPR Toolkit.
How many documents are included?
79 editable templates – 60 Word documents and 19 Excel workbooks – plus a read-me, an FAQ and a licence file.
Will this get us certified on its own?
Documentation is roughly half the work. You still have to operate the system, collect genuine records, run an internal audit and hold a management review before a certification body will recommend certification.
Related toolkits
Privacy rarely sits on its own. Pair this with the ISO 27001 Toolkit if you are running both systems, the GDPR Toolkit for European records and data subject rights, or the CCPA-CPRA Toolkit for California. For India, see the DPDP Act Toolkit. Organisations subject to UK law should add the UK GDPR toolkit, and the privacy risk management toolkit covers the NIST Privacy Framework alongside it.
Implementing for clients? The Consultant Package licenses all 86 toolkits and assessment tools on this site for unlimited client engagements, under one firm-wide licence. One payment of $1,399, no subscription and no per-client fee.
Delivery, format and licence
Your ISO 27701 2025 downloads immediately after checkout as native Microsoft Word and Excel files. Nothing is watermarked or locked, so you can rebrand the documents, bring them under your own document control and revise them for as long as you need them.
One-time purchase. No subscription and no annual renewal. Because the source files are yours, revising a procedure after an audit finding or a change of scope is an internal edit rather than another purchase.














Reviews
There are no reviews yet.