Instant downloadAuditor-writtenSecure Stripe checkout
ISO 27701: The Complete Guide to Privacy Information Management — ISO Toolkits

ISO 27701: A Guide to Privacy Information Management

ISO 27701 privacy information management is a globally recognised approach for building, running and demonstrating a Privacy Information Management System (PIMS) on top of an existing information security programme. Published as ISO/IEC 27701:2019, the standard extends the well-established ISO/IEC 27001 and ISO/IEC 27002 security frameworks to cover how an organisation collects, uses, shares and protects personally identifiable information (PII). Rather than reinventing governance from scratch, it lets you bolt privacy-specific requirements and controls onto the security management system you may already have.

This guide explains what the standard is, who needs it, how it is structured, and how to move from a standing start to certification. It also compares ISO 27701 to a related framework and answers the questions implementers ask most often. Throughout, the emphasis is practical: what you actually have to build, in what order, and how to avoid the traps that slow projects down.

Whether you are scoping your first PIMS or extending an existing ISO 27001 certificate, the goal is the same – a defensible, repeatable way to govern personal data that stands up to independent audit and to customer scrutiny alike.

This article is for general guidance only and is not legal or regulatory advice. Consult a qualified privacy professional or lawyer for decisions about compliance in your jurisdiction.

What ISO 27701 privacy information management is and why it matters

At its core, ISO 27701 privacy information management defines the requirements and guidance for a PIMS. A PIMS is a structured, auditable way of governing PII throughout its lifecycle, with clear accountability, documented controls, and continual improvement built in.

The most important thing to understand is that ISO/IEC 27701:2019 is an extension, not a stand-alone standard. You cannot certify to ISO 27701 on its own. The organisation must hold ISO/IEC 27001 certification or implement ISO/IEC 27001 at the same time, because the PIMS reuses the Information Security Management System (ISMS) as its foundation. In practice, certification bodies audit the combined ISMS-plus-PIMS scope together.

Why does this matter? Privacy regulation has multiplied across the world, and customers increasingly expect a demonstrable, independently verified privacy posture. A recognised certificate gives buyers, regulators and partners confidence that your privacy claims are backed by a working system rather than good intentions. It also gives internal teams a common, structured language for managing PII.

There is a commercial dimension too. In competitive procurement, especially for cloud and B2B services, buyers increasingly send privacy and security questionnaires before they sign. A PIMS built to ISO 27701 privacy information management gives you a consistent, evidenced answer to most of those questions, shortens sales cycles, and reduces the number of bespoke customer audits your team has to absorb. For many organisations, that operational efficiency is as valuable as the certificate itself.

The standard also helps you move from reactive privacy work – responding to incidents, complaints and last-minute regulator requests – to a proactive posture. Because a PIMS embeds privacy risk assessment, data mapping and control monitoring into a repeatable cycle, privacy stops being a one-off project and becomes part of how the business runs. That shift is often the real return on the investment.

Who needs ISO 27701

The standard is written to apply to organisations of any size that process PII, and it explicitly addresses two distinct roles:

  • PII controllers – organisations that determine the purposes and means of processing personal data (for example, a company handling its own customers’ and employees’ data).
  • PII processors – organisations that process personal data on behalf of, and under the instructions of, a controller (for example, a SaaS vendor or an outsourced payroll provider).

An organisation can be a controller for some processing and a processor for other processing, and the standard is designed to accommodate that dual role. Typical adopters include cloud and SaaS providers, data-heavy B2B vendors, healthcare and financial services firms, and any business that wants to reassure regulators and customers that PII is handled responsibly.

You are most likely to benefit from ISO 27701 privacy information management if one or more of the following is true: you already hold or plan to pursue ISO 27001; your customers are asking for evidence of privacy governance; you operate across multiple jurisdictions with overlapping privacy laws; or you process significant volumes of sensitive personal data. Smaller organisations sometimes assume the standard is only for large enterprises, but because scope can be tailored to the processing activities that matter, a focused PIMS is realistic for a small team too.

Conversely, if you do not process meaningful amounts of PII, or you have no near-term driver such as a customer requirement or regulatory pressure, the effort may outweigh the benefit today. The standard rewards organisations that genuinely handle personal data and want a defensible, repeatable way to govern it – so match the decision to your actual data footprint rather than to a checkbox.

The structure and key requirements of the standard

ISO/IEC 27701:2019 builds directly on the structure of ISO/IEC 27001 and ISO/IEC 27002, adding privacy-specific requirements, extended guidance and role-based control sets. The main building blocks are:

  • PIMS-specific requirements related to ISO/IEC 27001 – how the ISMS clauses (context, leadership, planning, support, operation, performance evaluation, improvement) are read and applied for privacy.
  • PIMS-specific guidance related to ISO/IEC 27002 – how the security controls are interpreted when PII is in scope.
  • Annex A – additional controls for organisations acting as PII controllers.
  • Annex B – additional controls for organisations acting as PII processors.

The controller and processor control sets in Annex A and Annex B are organised around privacy themes such as conditions for collection and processing, obligations to PII principals (data subjects), privacy by design and by default, and PII sharing, transfer and disclosure. The exact number of controls should be confirmed against the current text of the standard – verify the latest version, as counts and mappings can change with revisions.

Because the requirements sit on top of ISO/IEC 27001, an organisation that already runs a mature ISMS will recognise most of the management-system machinery. What ISO 27701 privacy information management adds is the privacy lens: extended controls, additional documentation, and a mapping between your obligations as a controller or processor and the technical and organisational measures you operate.

A few concepts are worth understanding before you begin. The standard introduces privacy-specific terminology, most notably the “PII principal” (the individual the data relates to) and the distinction between PII controllers and PII processors that determines which annex applies to you. It also extends the risk assessment approach of ISO 27001 so that risks to the rights of individuals – not only risks to the organisation – are considered. That reframing is central: a mature ISMS protects the business, whereas a PIMS additionally protects the people whose data you hold.

The standard is deliberately technology-neutral and outcome-focused. It tells you what needs to be governed – lawful basis, transparency, data minimisation, retention, sharing, and the handling of individuals’ requests – without prescribing specific tools. That flexibility is a strength, but it also means you must translate each requirement into concrete measures that fit your environment, which is where a well-structured toolkit and clear documentation pay off.

Step-by-step implementation and certification process

The path to certification follows the familiar management-system lifecycle, extended for privacy. A typical sequence looks like this:

  • 1. Secure the ISO 27001 foundation. Either hold a current ISO/IEC 27001 certificate or plan to implement the ISMS in parallel. Without it, a PIMS cannot be certified.
  • 2. Define scope and roles. Determine which processing activities are in scope and where you act as a PII controller, a PII processor, or both. This drives whether Annex A, Annex B, or both apply.
  • 3. Run a gap analysis. Compare current practice against the PIMS requirements and the relevant control set to identify what is missing.
  • 4. Perform a privacy risk assessment. Assess risks to PII and, where relevant, conduct data protection or privacy impact assessments.
  • 5. Build documentation and controls. Develop policies, procedures, records of processing, and the Statement of Applicability that records which controls you apply and why.
  • 6. Operate and generate records. Run the PIMS for a period so there is evidence of it working – handling requests from PII principals, managing suppliers, responding to incidents.
  • 7. Internal audit and management review. Check the PIMS against the standard and address findings before an external auditor arrives.
  • 8. Certification audit. An accredited certification body conducts a Stage 1 (documentation readiness) and Stage 2 (implementation effectiveness) audit, typically covering the combined ISMS and PIMS scope.
  • 9. Maintain and improve. Certificates are generally maintained through periodic surveillance audits with a recertification cycle – confirm the current cycle with your certification body.

Documentation involved

Strong documentation is where most of the effort lands. While exact requirements depend on your scope, a PIMS commonly includes a privacy policy and supporting procedures, records of processing activities, the Statement of Applicability, a privacy risk assessment methodology and results, data subject request procedures, breach and incident response procedures, supplier and processor agreements, records of consent and lawful basis where relevant, and internal audit and management review records.

Reusing your existing ISO 27001 documentation set is the single biggest accelerator. Much of the management-system paperwork can be extended rather than rewritten, so the privacy layer becomes an addition rather than a duplicate.

The Statement of Applicability deserves particular attention. In a PIMS it must reflect the ISO 27001 controls plus the ISO 27701 controller and/or processor controls that apply to your scope, with a justification for each inclusion or exclusion. Auditors read it closely, because it is the bridge between your risk assessment and the controls you actually operate. Keep it accurate and current rather than treating it as a one-time form.

Records of processing activities are the other document that underpins everything else. A clear inventory of what PII you hold, why you hold it, where it flows, who it is shared with, and how long it is retained makes the privacy controls concrete and auditable. Weak data mapping is the most common reason projects stall, so treat the inventory as a living asset that is reviewed as processing changes.

Timeline and cost drivers

Timelines vary widely with organisation size, existing maturity and scope. As a rough guide, an organisation with a mature ISO 27001 ISMS might reach a certification audit in a matter of a few months, while an organisation implementing security and privacy together should plan for considerably longer. Treat any single figure as indicative and validate it against your own context.

The main cost drivers are:

  • Whether you already hold ISO/IEC 27001 or must implement it in parallel.
  • The breadth of scope and the number of processing activities and locations.
  • Whether you act as controller, processor, or both, and therefore how many controls apply.
  • Internal effort versus external consultancy and tooling.
  • Certification body fees, which scale with audit days and organisation size.

A useful way to control both time and cost is to scope tightly at first. Certifying a well-defined product, service or business unit is faster and cheaper than attempting the whole enterprise at once, and you can widen the scope at a later recertification. Front-loading the data mapping and the gap analysis also prevents expensive surprises during the Stage 2 audit, when remediation is hardest to absorb.

Common challenges and how to avoid them

Several pitfalls recur across ISO 27701 privacy information management projects. Being aware of them early saves rework:

  • Treating 27701 as stand-alone. The most common misconception. Plan the ISO 27001 foundation from day one.
  • Misclassifying controller and processor roles. Getting this wrong leads to applying the wrong control set. Map each processing activity carefully.
  • Thin records of processing. Incomplete data mapping undermines almost every other control. Invest in an accurate inventory of PII flows.
  • Confusing certification with legal compliance. Certification demonstrates a managed privacy system; it does not by itself prove you meet any specific law.
  • Documentation without operation. Auditors look for evidence the PIMS actually runs. Generate real records before booking the Stage 2 audit.
  • Under-resourcing after certification. A PIMS needs ongoing ownership. Assign clear accountability so surveillance audits find a living system, not a project that was abandoned once the certificate arrived.

The thread running through all of these is that ISO 27701 rewards genuine operation over paperwork. Teams that embed privacy into everyday processes – onboarding new suppliers, launching new products, handling individuals’ requests – find audits straightforward. Teams that treat the standard as a documentation exercise tend to struggle, because auditors probe for evidence that controls work in practice, not merely that a policy exists.

How ISO 27701 privacy information management compares to GDPR

Implementers frequently ask how the standard relates to the EU General Data Protection Regulation. They operate at different levels: ISO 27701 is a voluntary, certifiable management-system standard, while the GDPR is binding law. ISO/IEC 27701:2019 includes mappings that help you relate PIMS controls to regulatory requirements, which makes it a useful operational scaffold – but a certificate is not proof of GDPR legal compliance.

This article is for general guidance only and is not legal or regulatory advice. Certification to ISO 27701 does not establish compliance with the GDPR or any other law; seek qualified legal advice for your circumstances.

AspectISO/IEC 27701:2019GDPR
NatureVoluntary international standardBinding EU regulation (law)
Certifiable?Yes, via accredited bodies (as an extension of ISO 27001)No single certificate proves compliance in itself
ScopeAny organisation processing PII, worldwideProcessing of personal data linked to the EU/EEA
Roles addressedPII controllers (Annex A) and PII processors (Annex B)Controllers and processors under EU law
EnforcementAudits by certification bodies; certificate can be suspended or withdrawnSupervisory authorities; administrative fines and legal remedies
Primary valueDemonstrable, structured privacy managementLegal obligation with statutory penalties

The pragmatic takeaway: ISO 27701 privacy information management can strengthen and evidence the operational side of your GDPR programme, but you still need legal analysis to confirm compliance with the regulation itself.

It is worth noting that GDPR is not the only regulation the standard can support. Because the PIMS approach is jurisdiction-neutral, the same system can be mapped to other privacy laws around the world – for example national data protection acts or sectoral rules – so a single, well-run PIMS can serve as the operational backbone for a multi-jurisdiction privacy programme. As always, the mapping is an aid to good practice, not a substitute for legal advice on any specific law.

Frequently asked questions

Can I get certified to ISO 27701 without ISO 27001?

No. ISO/IEC 27701:2019 is an extension of ISO/IEC 27001, so you must either already hold an ISO 27001 certificate or implement the ISMS at the same time. Certification bodies audit the combined scope.

What is the difference between Annex A and Annex B?

Annex A contains additional controls for organisations acting as PII controllers, while Annex B contains additional controls for PII processors. Which annex applies depends on your role for each processing activity, and many organisations use both.

Does ISO 27701 certification prove GDPR compliance?

No. The standard maps to regulatory requirements and supports good practice, but a certificate is not legal proof of GDPR compliance. This is general guidance, not legal advice – confirm your legal position with a qualified professional.

How long does implementation take?

It depends heavily on existing maturity and scope. Organisations with a mature ISO 27001 ISMS can move relatively quickly, while those implementing security and privacy together should plan for a longer programme. Treat published timeframes as indicative and verify against your own situation.

What is a PIMS?

A Privacy Information Management System is the set of policies, processes, roles and controls that govern how an organisation manages PII. ISO 27701 defines the requirements for building and operating a PIMS as an extension of the ISMS.

Which version of the standard is current?

The published version is ISO/IEC 27701:2019. Standards are reviewed periodically, so verify the latest version and any amendments before relying on specific clause numbers or control counts.

Is ISO 27701 the same as certification to a privacy seal or GDPR certification scheme?

No. ISO 27701 is an international management-system standard audited by accredited certification bodies, whereas GDPR-specific certification schemes are approved under a different regulatory mechanism. They can complement each other, but they are not interchangeable. As with any regulatory question, seek qualified legal advice for your situation.

ISO 27701 privacy information management toolkit templates
The editable ISO 27701 Toolkit — PIMS policies, RoPA and SoA templates.

Related guides

For the official standard, see the ISO/IEC 27701:2019 page at iso.org.

Ready to start building your PIMS? Our editable ISO/IEC 27701:2019 toolkit gives you the policies, procedures and Statement of Applicability templates you need to implement ISO 27701 privacy information management and move confidently toward certification.

Shopping Cart