What does ISO/IEC 27701 mean?
ISO/IEC 27701 is the international standard that sets out the requirements for a privacy information management system. It was developed by ISO in response to organisations’ need to protect the personally identifiable information they collect, store and process, providing a structured framework for managing privacy risks.
What is a Privacy Information Management System (PIMS)?
A privacy information management system, known as a PIMS (Privacy Information Management System), is the set of policies, procedures and controls through which an organisation manages personal data. In practice, a PIMS extends the principles of information security to a specific area: the protection of the privacy and personal data of data subjects.
From an extension of ISO 27001 to a stand-alone standard
Initially, in the 2019 edition, the ISO 27701 standard functioned as an extension of ISO/IEC 27001 and ISO/IEC 27002 – which meant that an organisation had to already have an ISO 27001 information security management system in place in order to be certified. With the publication of the ISO/IEC 27701:2025 edition (October 2025), the standard has become a stand-alone management standard: it adopts the common high-level structure (clauses 4–10), aligns with ISO 9001, ISO/IEC 27001:2022 and ISO/IEC 42001, and can be implemented and certified independently. Organisations certified under the 2019 edition benefit from a three-year transition period, until October 2028.
Who is the ISO 27701 standard aimed at?
The ISO 27701 standard is aimed at both data controllers (those who determine the purposes and means of processing) and data processors (those who process data on their behalf). It applies to organisations of any size and from any sector that collect or process personal data and wish to demonstrate, through a risk-based approach, that they comply with data protection requirements.
ISO 27701 and GDPR compliance
One of the most significant advantages of the ISO 27701 standard is the direct support it provides for compliance with the General Data Protection Regulation (GDPR). ISO 27701 provides a practical framework through which an organisation can assess, manage and mitigate the risks associated with the processing of personal data, translating legal requirements into concrete controls. ISO 27701 certification does not automatically equate to GDPR compliance, but it does provide strong evidence that the organisation has implemented appropriate technical and organisational measures – exactly what Article 32 of the GDPR requires.
The benefits of ISO 27701 certification
Certification of a confidential information management system brings tangible benefits:
- provides confidence and a competitive advantage by protecting the personal information of customers and consumers;
- demonstrates and supports efforts to comply with privacy laws and regulations, including the GDPR;
- identifies and mitigates risks by implementing rigorous confidentiality controls;
- demonstrates a genuine commitment to the continuous improvement of the privacy management system;
- strengthens relationships with partners and customers who process or transfer personal data;
- facilitates integration with other management systems, such as ISO 27001 (information security) or ISO 9001 (quality management).
Is ISO 27701 certification compulsory?
ISO 27701 certification is not, in itself, required by law. However, compliance with the GDPR is mandatory for any organisation that processes the personal data of individuals in the European Union, and ISO 27701 is one of the most effective tools an organisation can use to structure and demonstrate its compliance. Furthermore, ISO 27701 certification is increasingly sought after in contractual relationships, data processing chains and tenders, as evidence of responsible management of personal data.
How do you obtain ISO 27701 certification?
The ISO 27701 certification process with SRAC follows clear stages. Once the information security management system has been implemented, the organisation undergoes a conformity assessment by SRAC’s auditors.
The stages and the certification audit
- Submission of the request for quotation and finalisation of the contractual details.
- The ISO 27701 certification audit comprises the following stages:
- review of the management system documentation (including the Statement of Applicability).
- Stage 1, in which the specific conditions at the client’s site are assessed; analysis of the stage of implementation of the applicant’s management system and their understanding of the standard’s requirements; assessment of the level of implementation of the PIMS, etc.
- Stage 2, in which a practical check is carried out within the company to verify whether the written procedures are actually applied in day-to-day operations.
- Addressing any non-conformities and implementing corrective actions.
- Issuance of the ISO 27701 certificate, valid for 3 years, subject to annual surveillance audits being carried out.
- The recertification audit (certification renewal), to extend the validity of the certificate for a further three-year period.
The cost of ISO 27701 certification
The cost of ISO 27701 certification is not fixed, but depends on the size of the organisation, the number of employees, the volume and complexity of data processing operations, the number of sites and the scope of the system. To find out the exact cost of ISO 27701 certification, the best option is to request a personalised quote.
Validity and renewal of the certificate
The ISO 27001 certificate is valid for three years, provided that certification is maintained by successfully passing annual surveillance audits. At the end of this period, if the organisation wishes to extend the validity of the certificate, a recertification audit (certification renewal) is carried out.
The transition to ISO/IEC 27701:2025
Organisations certified to the ISO/IEC 27701:2019 standard have a three-year transition period (until October 2028) to migrate to the new ISO/IEC 27701:2025 standard. The transition can be incorporated into the next surveillance or recertification audit to minimise costs and effort. Organisations seeking certification for the first time may do so directly under the new edition.
Find out from the attached article HERE what the main changes are compared with the previous edition of the standard.
Author: Dr Cristian Roncea, Eng., Technical Director, SRAC CERT
Why SRAC – IQNET international recognition
SRAC enjoys international recognition through its partnership with IQNET (The International Certification Network). Certified organisations receive, at no additional cost, both the SRAC certificate and the IQNET certificate, which ensures genuine recognition of ISO 27701 certification both on the domestic market and internationally.
Join the leading companies and institutions in Romania that have chosen the SRAC brand: over 10,000 certified organisations, with more than 25,000 certificates awarded over the past 30 years. From top brands to major public institutions, leading companies have chosen our services.
Choose the leader in certification – Get certified with SRAC!
The principles and roles set out in ISO 27701
Like ISO 27001, the ISO 27701 standard is based on a risk-based approach, but tailored to personal data. The standard makes a clear distinction between the two main roles in data processing: the data controller, who determines the purposes and means of processing, and the data processor, who processes the data on behalf of the controller. For each role, ISO 27701 sets out specific controls and responsibilities, so that the organisation can demonstrate that it handles personal identifiable information responsibly, regardless of its position in the processing chain.
The requirements of the ISO 27701 standard
The requirements of ISO 27701 cover both the elements of a management system (organisational context, leadership, planning, performance evaluation and continuous improvement) and specific confidentiality controls. These include identifying the legal bases for processing, managing consent, ensuring the rights of data subjects, keeping records of processing activities and managing relationships with data processors. In the ISO/IEC 27701:2025 edition, the controls are organised in a dedicated annex, structured according to the roles of controller and processor, and aligned with ISO/IEC 27001:2022 and ISO/IEC 27002:2022.
Frequently Asked Questions (FAQ)
What is ISO 27701 and what is it used for?
ISO 27701 is the international standard for privacy information management (PIMS). It is used to structure the way in which an organisation protects personally identifiable information and to demonstrate, through certification, compliance with privacy requirements, including the GDPR.
What is the difference between ISO 27001 and ISO 27701?
ISO 27001 covers information security in general (the information security management system), whilst ISO 27701 focuses on the protection of personal data (the privacy information management system). ISO 27701 began as an extension of ISO 27001, and from the 2025 edition onwards it can also be implemented as a stand-alone standard.
Is ISO 27001 still required in order to obtain ISO 27701?
In the 2019 edition, ISO 27701 could only be certified by organisations that already held ISO 27001. From the ISO/IEC 27701:2025 edition onwards, the standard has become a stand-alone standard, meaning it can be implemented and certified independently, without the prior requirement to hold ISO 27001 certification.
How does ISO 27701 help ensure compliance with the GDPR?
ISO 27701 translates confidentiality requirements into specific controls and provides a framework for assessing and mitigating risks associated with the processing of personal information. Certification does not automatically equate to GDPR compliance, but it does provide strong evidence of the appropriate technical and organisational measures required by the Regulation.
How much does ISO 27701 certification cost?
The cost of ISO 27701 certification varies depending on the size of the organisation, the volume of data processing operations, the number of sites and the scope of the system. For an exact price, we recommend that you request a personalised quote.
How long is the ISO 27701 certificate valid for?
The ISO 27701 certificate is valid for 3 years, provided that certification is maintained by successfully passing annual surveillance audits. At the end of this period, if the organisation wishes to extend the validity of the certificate, a recertification audit (certification renewal) is carried out.
What has changed in ISO/IEC 27701:2025?
The most significant change is that ISO/IEC 27701:2025 has become a stand-alone management standard, rather than merely an extension of ISO 27001. It adopts the high-level structure (clauses 4–10), aligns with ISO/IEC 27001:2022 and ISO/IEC 27002:2022, and includes updated controls. Organisations certified to the 2019 edition have until October 2028 to transition to the 2025 version.
Who is ISO 27701 certification aimed at?
The certification is aimed at any organisation that collects or processes personal data, whether as a data controller or a data processor, regardless of its size or sector of activity.
What do I need to do to get started?
The first step is to submit a request for a quote to SRAC. You will receive a personalised quote and the details you need to begin the ISO 27701 certification process.
