Home/Services/Certification/ISO/IEC 27701:2019

ISO/IEC 27701:2019

International standard for Privacy Information Management Systems (PIMS).

Overview
What is ISO/IEC 27701?

ISO/IEC 27701:2019 is an extension to ISO/IEC 27001 and ISO/IEC 27002 that provides requirements and guidance for establishing, implementing, maintaining, and continually improving a Privacy Information Management System. It specifies requirements for processing personally identifiable information and maps its controls directly to the obligations of both personal data controllers and personal data processors.

The standard helps organizations manage privacy risks, protect personal data, clarify privacy responsibilities, and demonstrate accountability in the processing of personal information. Certification to ISO/IEC 27701 provides independently verified evidence that an organization has implemented a structured, auditable framework for managing privacy — a framework that maps directly to the accountability requirements of data protection legislation including the GDPR.

ISO/IEC 27701 supports organizations acting as personal data controllers, personal data processors, or both. Its requirements address the full processing lifecycle, from purpose limitation and data minimisation through to data subject rights management, third-party disclosures, and the security of personal information throughout its handling.

Key Themes
What does the standard focus on?
Privacy Governance
Organizations must establish clear policies, roles, responsibilities, and accountabilities for privacy management, demonstrating that leadership has made an active commitment to protecting personal information and meeting applicable privacy obligations.
Personal Data Protection
The standard requires organizations to implement technical and organizational controls for protecting personally identifiable information throughout its lifecycle, from collection through retention, transfer, and deletion.
Data Subject Rights
Organizations must establish procedures for handling data subject requests relating to access, rectification, erasure, restriction, portability, and objection, ensuring that rights can be exercised within applicable timeframes.
Privacy Risk Management
The standard requires organizations to assess privacy risks associated with personal data processing activities, implement risk treatment measures proportionate to the assessed risk, and monitor and review risks over time.
Controller and Processor Responsibilities
ISO/IEC 27701 provides distinct requirements for controllers and processors, reflecting the different roles and legal responsibilities each holds under data protection frameworks such as the GDPR and equivalent legislation.
Continual Improvement
Organizations must continually improve the effectiveness of the PIMS through performance monitoring, internal audit, management review, and corrective action, ensuring that privacy management keeps pace with changes in processing activities and the regulatory environment.
Applicability
Who typically implements ISO/IEC 27701?
Technology Companies
Software, platform, and data services organizations processing user personal information at scale, subject to growing customer and regulatory privacy expectations.
Cloud Service Providers
IaaS, PaaS, and SaaS providers acting as data processors for customer personal data and required to demonstrate compliance with processor obligations under data processing agreements.
Financial Institutions
Banks, insurers, and investment managers processing sensitive personal and financial data under strict regulatory privacy and data security obligations.
Fintech Organizations
Payment processors, digital lenders, and financial technology platforms handling personal financial data subject to PSD2, GDPR, and equivalent privacy frameworks.
Healthcare Organizations
Providers and processors of sensitive health and patient information subject to heightened privacy obligations under sector-specific and general data protection legislation.
Telecommunications Providers
Network operators and service providers holding subscriber communications data and metadata subject to privacy and electronic communications regulations.
E-Commerce Platforms
Online retailers and marketplace operators processing customer personal, payment, and behavioral data subject to consumer privacy and marketing regulations.
Digital Service Providers
Advertising technology, analytics, and digital media organizations managing personal data across complex data supply chains involving multiple controllers and processors.
Professional Services Firms
Law firms, accountancies, and consultancies acting as processors of confidential client personal information and subject to data processing agreement obligations.
Organizations Processing Personal Data
Any organization that processes personal data at meaningful scale and wishes to demonstrate structured, independently verified accountability for privacy management.
Benefits
Why organizations pursue certification
Improved Privacy Governance
A structured framework for managing personal data risks, processing activities, data subject rights, and third-party disclosures.
Enhanced Regulatory Confidence
Demonstrable alignment with GDPR accountability requirements and equivalent data protection legislation, supported by independent audit.
Better Protection of Personal Data
Systematic controls for protecting personally identifiable information reduce the risk of privacy incidents, data breaches, and regulatory penalties.
Increased Customer Trust
Internationally recognized privacy certification provides independently verified assurance to customers that their personal data is handled responsibly.
Clear Privacy Responsibilities
Defined roles, responsibilities, and accountabilities for privacy management across controller and processor functions, reducing ambiguity in data processing relationships.
Reduced Privacy Risk
Privacy risk assessment and treatment processes reduce the likelihood and impact of privacy incidents, supporting regulatory compliance and organizational resilience.
Improved Stakeholder Confidence
Certification supports data processing agreements, investor ESG assessments, and engagement with regulators by providing independent evidence of privacy management maturity.
Continual Improvement
Built-in monitoring, review, and corrective action mechanisms ensure privacy management keeps pace with regulatory changes and evolving processing activities.
Regulatory Context
Is ISO/IEC 27701 certification required?

ISO/IEC 27701 certification is generally voluntary. However, organizations are increasingly expected to demonstrate accountability for the protection and management of personal data. Privacy regulations, contractual requirements, customer due diligence activities, and international business expectations frequently drive organizations to implement structured privacy management systems — and certification provides the most credible, independently verified form of that demonstration.

The GDPR's accountability principle requires organizations to implement appropriate technical and organizational measures to protect personal data and to be able to demonstrate those measures to regulators and data subjects on demand. ISO/IEC 27701 was developed with explicit reference to the GDPR and provides a management system framework that maps directly to these accountability obligations. The European Data Protection Board has recognized ISO/IEC 27701 as a candidate certification mechanism under Article 42 of the GDPR.

Customer-driven requirements for privacy assurance are increasing, particularly in B2B technology and professional services markets. Organizations seeking to contract with regulated entities, government bodies, or multinational corporations are increasingly expected to demonstrate ISO/IEC 27701 certification — or equivalent independently verified privacy governance — as a baseline condition of entering or maintaining data processing relationships.

Certification Journey
The certification lifecycle
01
Application
The organization submits an application for certification. Exelera reviews the scope of activities, sites, applicable standard, and certification requirements. For ISO/IEC 27701, the existing ISO/IEC 27001 certification scope and status is confirmed at this stage.
02
Application Review
Exelera evaluates the application, confirms scope boundaries, identifies any specific requirements, and prepares the certification proposal and audit program.
03
Stage 1 Audit
Review of PIMS documentation, scope boundaries, processing activity records, and organizational readiness for the Stage 2 conformance assessment.
04
Stage 2 Audit
On-site evaluation of the implementation and effectiveness of the privacy information management system against all applicable standard requirements.
05
Certification Decision
Independent review of the audit report and findings by a Certification Decision Maker not involved in the audit, followed by a formal certification decision.
06
Certificate Issuance
Following a positive certification decision, Exelera issues the certificate and publishes the organization on the public certification register.
07
Surveillance Audit — Year 1
Scheduled surveillance visit conducted no later than 12 months after the certification decision to verify continued conformance and system effectiveness.
08
Surveillance Audit — Year 2
Continued verification of management system implementation, performance, and the effectiveness of corrective actions from prior audits.
09
Recertification Audit
Comprehensive reassessment of the full management system scope before renewal of the certification cycle at the end of year three.
10
Certification Renewal
Following a successful recertification audit and positive certification decision, a new three-year certification cycle commences.
FAQ
Common questions
Yes. ISO/IEC 27701 is an extension to ISO/IEC 27001, not a standalone standard. It specifies additional requirements and guidance that build directly on an existing information security management system. Organizations must hold a current ISO/IEC 27001 certification before they can pursue ISO/IEC 27701 certification. Exelera conducts ISO/IEC 27701 assessments in conjunction with ISO/IEC 27001 certification or as an extension of an existing certification program.
Information security and privacy are related but distinct disciplines. Information security focuses on protecting the confidentiality, integrity, and availability of all information assets — including personal data — from unauthorized access, modification, or disclosure. Privacy is specifically concerned with how personally identifiable information is collected, used, shared, retained, and deleted in a manner that respects individuals’ rights and meets applicable legal obligations. ISO/IEC 27001 addresses the former; ISO/IEC 27701 extends it to address the latter.
Yes. ISO/IEC 27701 was developed with explicit reference to data protection legislation — particularly the GDPR — and its requirements map directly to many of the obligations that data protection law imposes on controllers and processors. Certification does not constitute legal compliance in itself, but it provides independently verified evidence of the technical and organizational measures an organization has implemented, which is directly relevant to demonstrating compliance with the GDPR’s accountability principle and equivalent frameworks.
For organizations that already hold ISO/IEC 27001 certification, adding ISO/IEC 27701 is typically faster than an initial standalone certification. The additional audit activities focus on the privacy-specific extension requirements. The timeline depends on the maturity of existing privacy management practices and the complexity of the organization’s data processing activities. Exelera can advise on the expected scope of work following an initial review of the organization’s current position.
Both. ISO/IEC 27701 includes separate sets of requirements and guidance for personal data controllers and personal data processors, reflecting the distinct roles and legal responsibilities each holds under data protection legislation. Organizations that act as both a controller and a processor — which is common in the technology and professional services sectors — must meet both sets of requirements within their certification scope.
Nonconformities identified during an audit are documented formally. Major nonconformities must be closed — through verified corrective action — before certification can be granted or maintained. Minor nonconformities require a corrective action plan to be submitted within an agreed timeframe, with verification of effectiveness at the next scheduled audit. Exelera auditors assess the quality of the corrective action as well as its effectiveness when verifying closure.
Following initial certification, surveillance audits are conducted annually — with the first surveillance no later than 12 months after the certification decision and the second no later than 24 months. For organizations holding both ISO/IEC 27001 and ISO/IEC 27701 certifications, Exelera conducts combined surveillance audits, reviewing both standards in the same visit to reduce the overall audit burden.
Certification transfers are possible in most cases. Exelera will review the existing certification, audit history, and current conformance status as part of the transfer assessment. Transfer audits are typically shorter than initial certification audits, reflecting the documented history of conformance. Contact Exelera for specific guidance on the transfer process for both ISO/IEC 27001 and ISO/IEC 27701 certifications.
Applications can be submitted through the Exelera website or by contacting the certification team directly. The application process involves providing information about the organization’s existing ISO/IEC 27001 certification, the scope of personal data processing activities, and current privacy management documentation. Exelera will review the application and prepare a certification proposal covering the combined ISO/IEC 27001 and ISO/IEC 27701 scope.
Related Standards
Standards commonly pursued alongside ISO/IEC 27701