Book an Appointment

ISO/IEC 27701 – the Privacy Information Management System

How to turn the handling of personal data into a certifiable management system – and what the independently certifiable revision ISO/IEC 27701:2025 means for ISMS operators and data processors.

ISO/IEC 27701 specifies requirements for a Privacy Information Management System (PIMS) – a management system for protecting personally identifiable information (PII) that turns privacy from a one-off project into a permanently governed organisational responsibility. The first edition from 2019 was formally an extension of ISO/IEC 27001 and ISO/IEC 27002 and therefore effectively required a certified ISMS. With the revision ISO/IEC 27701:2025, published on 14 October 2025, the standard has become a standalone management system standard: a PIMS can now be established and certified without ISO 27001 certification. For companies subject to the GDPR, the standard is above all attractive as a structured evidence framework – it does not replace legal obligations, but it helps to systematically underpin accountability and the requirements placed on processors.

The Essentials at a Glance

01

What ISO/IEC 27701 covers

The standard defines requirements and implementation guidance for a PIMS: policies, roles, risk assessment and controls for the processing of personal data – each from the perspective of the organisation as a PII controller and/or PII processor. Like other management system standards, its clauses 4–10 follow the harmonised structure of the ISO management system standards: context, leadership, planning, support, operation, performance evaluation and improvement. The PIMS is therefore not a catalogue of measures but a continuously operated governance framework with defined responsibilities and documented evidence.

02

The :2025 revision – independently certifiable for the first time

The second edition, published on 14 October 2025, replaces the 2019 version and turns ISO/IEC 27701 into a standalone standard: ISO 27001 certification is no longer a prerequisite for a PIMS certificate. In parallel, ISO/IEC 27706:2025 was published, setting out requirements for certification bodies performing PIMS audits; it replaces the previous ISO/IEC TS 27006-2. A three-year transition period applies: certification bodies must complete their own transition by the end of October 2027, and existing certificates issued against ISO/IEC 27701:2019 will lose their validity no later than the end of October 2028. Certified organisations should therefore factor the transition into their regular surveillance and re-certification cycles.

03

Relationship to ISO 27001 and integration into an existing ISMS

Standalone does not mean detached: the new edition is aligned with ISO/IEC 27001:2022 and ISO/IEC 27002:2022 and adopts their updated control language and terminology. For organisations with an existing ISMS, integration remains the obvious route – a shared context, a shared risk methodology and a Statement of Applicability extended to cover privacy, rather than a parallel structure. The harmonised clause structure also makes it easier to combine the PIMS with other management systems, for example ISO 9001 or ISO/IEC 42001. What is new is the freedom of choice: organisations without an ISMS certificate can start with the PIMS and add information security certification later.

04

Controller and processor controls in Annex A

The controls in the new edition are consolidated in a single Annex A and organised by role: 31 controls for PII controllers (including legal bases, consent, data subject rights, privacy by design and transparency), 18 controls for PII processors (including processing only in line with the customer agreement, supporting the controller, return and deletion, disclosures, and sub-processors), plus a third block of shared security controls for both roles. The previous split into Annex A (controller) and Annex B (processor) in the 2019 edition has been dropped; Annex B now contains implementation guidance. Determining your role remains a key scoping step: depending on the processing, many organisations are both and must consider both control sets.

05

The link to the GDPR: an evidence framework, not a legal substitute

ISO/IEC 27701 does not replace legal requirements, but it operationalises key GDPR obligations: a documented, audited PIMS supports accountability under Art. 5(2) GDPR and gives processors robust evidence of the “sufficient guarantees” required by Art. 28 GDPR – for example in DPA negotiations and customer audits. One important clarification: an ISO 27701 certificate is not a certification under Art. 42 GDPR; such mechanisms must be approved by the supervisory authorities or the European Data Protection Board. The PIMS certificate demonstrates a functioning management system – the legal assessment of individual processing activities remains unaffected.

06

Who benefits from a PIMS

The value is greatest for organisations that process personal data on behalf of customers and must regularly demonstrate this: processors, cloud and SaaS providers, and managed service providers, for whom PIMS evidence shortens due diligence reviews and contract negotiations. For companies with an existing ISO 27001 ISMS, the extension is the most efficient way to integrate privacy into established governance structures. Internationally active organisations benefit from the fact that the standard is designed to work across jurisdictions and can be applied to multiple privacy regimes. Since the :2025 revision, they are joined by organisations that deliberately want to start with the privacy management system without certifying an ISMS first.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO/IEC · 2025

ISO/IEC 27701:2025 – Privacy information management systems

Second edition dated 14 October 2025; standalone certifiable PIMS standard with role-based controls in Annex A, replacing ISO/IEC 27701:2019.

Amtsblatt der EU / EUR-Lex · 2016

Verordnung (EU) 2016/679 (DSGVO)

Art. 5(2) (accountability), Art. 28 (processors, data processing agreements) and Art. 42 (approved certification mechanisms) as the legal frame of reference for the PIMS.

DNV · 2025

ISO/IEC 27701 Standard Update Release

Announcement of the revision by the certification body: publication on 14 October 2025, standalone status and alignment with ISO/IEC 27001:2022 and 27002:2022.

A-LIGN · 2025

ISO 27701 Updates: What You Need to Know

Detailed description of the new structure (clauses 4–10, consolidated Annex A, Annex B as implementation guidance) and of ISO/IEC 27706:2025 for certification bodies.

ISMS.online · 2025

ISO 27701 Transition Guide: 2019 to 2025

Transition planning, with 2019 certificates expiring in October 2028, and a breakdown of the Annex A controls (31 controller, 18 processor, shared security controls).

Want to know where ISO/IEC 27701 fits for your business?

We will work with you to assess whether a PIMS is worthwhile for your organisation – as an extension of your existing ISMS or on a standalone basis under the :2025 revision. Book a no-obligation initial consultation.