Back to Frameworks
Frameworks

ISO/IEC 27701

Framework Name

‍ISO/IEC 27701

Type

‍Voluntary

Region / Jurisdiction

‍Global

Enforcing Body / Certifying Party

‍International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), with certification issued by independent, accredited certification bodies

Penalty / Consequence of Non-Compliance

‍No legal penalty. The consequence is commercial and reputational: difficulty proving privacy accountability to regulators, partners, or customers who expect a structured privacy program alongside your security certification

What It Is & Why It Matters

ISO/IEC 27701 sets requirements for a Privacy Information Management System (PIMS), a structured way to manage personal data responsibly, covering how it's collected, used, shared, and protected. Until October 2025, it only existed as an add-on to ISO 27001, meaning a company had to already run an ISO 27001 security program before it could layer privacy management on top. The 2025 edition changed that: it now stands on its own, so a company can pursue a PIMS certification independently, though pairing it with ISO 27001 remains common and often makes practical sense.

ISO 27701 matters because it gives companies a certifiable way to show they take privacy seriously, not just security. Laws like GDPR require accountability and evidence of good data practices, but they don't hand you a system for organizing that work. ISO 27701 fills that gap, translating legal privacy obligations into a management structure an auditor can actually verify, which is useful anywhere in the world, regardless of which specific privacy law applies to you.

Who Needs It

  • You already hold or are pursuing ISO 27001 and want privacy management built into the same system
  • Customers or partners are asking how you handle personal data, beyond just security controls
  • You operate under multiple privacy laws (GDPR, CCPA, DPDPA) and want one structured program instead of managing each separately
  • You want a certifiable way to demonstrate privacy accountability, not just a policy on paper

Note on the Certification Path

‍Companies certified under the 2019 edition have until October 2028 to transition to the 2025 edition, so this isn't an urgent scramble for anyone already certified. For a new implementation, the 2025 edition is the one to build against, not 2019. If you're already ISO 27001:2022 certified, the transition tends to be more manageable, since both standards now share a similar structure.

Book A Demo