The standard defines requirements and implementation guidance for a PIMS: policies, roles, risk assessment and controls for the processing of personal data – each from the perspective of the organisation as a PII controller and/or PII processor. Like other management system standards, its clauses 4–10 follow the harmonised structure of the ISO management system standards: context, leadership, planning, support, operation, performance evaluation and improvement. The PIMS is therefore not a catalogue of measures but a continuously operated governance framework with defined responsibilities and documented evidence.
ISO/IEC 27701 – the Privacy Information Management System
How to turn the handling of personal data into a certifiable management system – and what the independently certifiable revision ISO/IEC 27701:2025 means for ISMS operators and data processors.
31controls for PII controllers in the consolidated Annex A
18controls for PII processors in the consolidated Annex A
3years of transition period for moving to the :2025 revision
2028:2019 certificates lose validity no later than the end of October
ISO/IEC 27701 specifies requirements for a Privacy Information Management System (PIMS) – a management system for protecting personally identifiable information (PII) that turns privacy from a one-off project into a permanently governed organisational responsibility. The first edition from 2019 was formally an extension of ISO/IEC 27001 and ISO/IEC 27002 and therefore effectively required a certified ISMS. With the revision ISO/IEC 27701:2025, published on 14 October 2025, the standard has become a standalone management system standard: a PIMS can now be established and certified without ISO 27001 certification. For companies subject to the GDPR, the standard is above all attractive as a structured evidence framework – it does not replace legal obligations, but it helps to systematically underpin accountability and the requirements placed on processors.
From revision to transition
The ISO/IEC 27701:2025 milestones — tap a milestone for details.
14 Oct 2025
The :2025 revision is published
The second edition replaces the 2019 version and turns ISO/IEC 27701 into a standalone certifiable standard. ISO/IEC 27706:2025, setting out requirements for certification bodies performing PIMS audits, is published in parallel.
End of Oct 2027
Certification bodies complete their transition
By this point, certification bodies must complete their own transition to the new edition.
End of Oct 2028
:2019 certificates expire
Certificates issued against ISO/IEC 27701:2019 lose their validity no later than this date. Certified organisations should factor the transition into their regular surveillance and re-certification cycles.
The Essentials at a Glance
Six topic blocks — tap to expand.
PIMS explorer: roles, ISMS, GDPR
Four perspectives on ISO/IEC 27701 — from the Annex A controls to the legal frame of reference.
- Annex A consolidates 31 controls for PII controllers — including legal bases, consent, data subject rights, privacy by design and transparency.
- Determining your role remains a key scoping step: depending on the processing, many organisations are both and must consider both control sets.
Legal basesConsentData subject rightsPrivacy by designTransparency
- 18 controls for PII processors — including processing only in line with the customer agreement, supporting the controller, return and deletion, disclosures, and sub-processors.
- A third block of shared security controls applies to both roles; the 2019 split into Annex A and Annex B has been dropped.
Customer agreementReturn and deletionDisclosuresSub-processorsShared security controls
- The new edition is aligned with ISO/IEC 27001:2022 and ISO/IEC 27002:2022 and adopts their updated control language and terminology.
- For organisations with an existing ISMS, integration remains the obvious route: a shared context, a shared risk methodology and a Statement of Applicability extended to cover privacy.
- What is new is the freedom of choice: organisations without an ISMS certificate can start with the PIMS and add information security certification later.
ISO/IEC 27001:2022ISO/IEC 27002:2022Statement of ApplicabilityISO 9001ISO/IEC 42001
- A documented, audited PIMS supports accountability under Art. 5(2) GDPR.
- It gives processors robust evidence of the “sufficient guarantees” required by Art. 28 GDPR — for example in DPA negotiations and customer audits.
- An ISO 27701 certificate is not a certification under Art. 42 GDPR; the legal assessment of individual processing activities remains unaffected.
Art. 5(2)Art. 28Art. 42AccountabilityDPA
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
ISO/IEC 27701:2025 – Privacy information management systems
Second edition dated 14 October 2025; standalone certifiable PIMS standard with role-based controls in Annex A, replacing ISO/IEC 27701:2019.
Verordnung (EU) 2016/679 (DSGVO)
Art. 5(2) (accountability), Art. 28 (processors, data processing agreements) and Art. 42 (approved certification mechanisms) as the legal frame of reference for the PIMS.
ISO/IEC 27701 Standard Update Release
Announcement of the revision by the certification body: publication on 14 October 2025, standalone status and alignment with ISO/IEC 27001:2022 and 27002:2022.
ISO 27701 Updates: What You Need to Know
Detailed description of the new structure (clauses 4–10, consolidated Annex A, Annex B as implementation guidance) and of ISO/IEC 27706:2025 for certification bodies.
ISO 27701 Transition Guide: 2019 to 2025
Transition planning, with 2019 certificates expiring in October 2028, and a breakdown of the Annex A controls (31 controller, 18 processor, shared security controls).
Want to know where ISO/IEC 27701 fits for your business?
We will work with you to assess whether a PIMS is worthwhile for your organisation – as an extension of your existing ISMS or on a standalone basis under the :2025 revision. Book a no-obligation initial consultation.