Book an Appointment

ISO/IEC 27701 – the Privacy Information Management System

How to turn the handling of personal data into a certifiable management system – and what the independently certifiable revision ISO/IEC 27701:2025 means for ISMS operators and data processors.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

31controls for PII controllers in the consolidated Annex A
18controls for PII processors in the consolidated Annex A
3years of transition period for moving to the :2025 revision
2028:2019 certificates lose validity no later than the end of October

ISO/IEC 27701 specifies requirements for a Privacy Information Management System (PIMS) – a management system for protecting personally identifiable information (PII) that turns privacy from a one-off project into a permanently governed organisational responsibility. The first edition from 2019 was formally an extension of ISO/IEC 27001 and ISO/IEC 27002 and therefore effectively required a certified ISMS. With the revision ISO/IEC 27701:2025, published on 14 October 2025, the standard has become a standalone management system standard: a PIMS can now be established and certified without ISO 27001 certification. For companies subject to the GDPR, the standard is above all attractive as a structured evidence framework – it does not replace legal obligations, but it helps to systematically underpin accountability and the requirements placed on processors.

From revision to transition

The ISO/IEC 27701:2025 milestones — tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

PIMS explorer: roles, ISMS, GDPR

Four perspectives on ISO/IEC 27701 — from the Annex A controls to the legal frame of reference.

31 controls
  • Annex A consolidates 31 controls for PII controllers — including legal bases, consent, data subject rights, privacy by design and transparency.
  • Determining your role remains a key scoping step: depending on the processing, many organisations are both and must consider both control sets.
Legal basesConsentData subject rightsPrivacy by designTransparency

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO/IEC · 2025

ISO/IEC 27701:2025 – Privacy information management systems

Second edition dated 14 October 2025; standalone certifiable PIMS standard with role-based controls in Annex A, replacing ISO/IEC 27701:2019.

Amtsblatt der EU / EUR-Lex · 2016

Verordnung (EU) 2016/679 (DSGVO)

Art. 5(2) (accountability), Art. 28 (processors, data processing agreements) and Art. 42 (approved certification mechanisms) as the legal frame of reference for the PIMS.

DNV · 2025

ISO/IEC 27701 Standard Update Release

Announcement of the revision by the certification body: publication on 14 October 2025, standalone status and alignment with ISO/IEC 27001:2022 and 27002:2022.

A-LIGN · 2025

ISO 27701 Updates: What You Need to Know

Detailed description of the new structure (clauses 4–10, consolidated Annex A, Annex B as implementation guidance) and of ISO/IEC 27706:2025 for certification bodies.

ISMS.online · 2025

ISO 27701 Transition Guide: 2019 to 2025

Transition planning, with 2019 certificates expiring in October 2028, and a breakdown of the Annex A controls (31 controller, 18 processor, shared security controls).

Want to know where ISO/IEC 27701 fits for your business?

We will work with you to assess whether a PIMS is worthwhile for your organisation – as an extension of your existing ISMS or on a standalone basis under the :2025 revision. Book a no-obligation initial consultation.