Back to ISO 27701

What is ISO 27701? Everything you need to know

Privacy professional working on ISO 27701 Photo: Unsplash

What is ISO 27701? It is an international privacy management standard that extends an ISO 27001 information security management system (ISMS) into a privacy information management system (PIMS). It helps organizations assign privacy responsibilities, manage risks involving personally identifiable information (PII), and produce evidence that those practices operate consistently.

This guide covers:

  • How ISO 27701 extends ISO 27001 and ISO 27002
  • The different obligations of PII controllers and PII processors
  • Why customers increasingly request independent privacy assurance
  • What implementation and certification typically involve

Connecting privacy requirements to everyday operations

GIF via GIPHY


Key takeaways

  • ISO 27701 turns privacy principles into a managed system. It requires defined scope, accountable owners, risk treatment, operating records, audits, and continual improvement.
  • It builds on ISO 27001. Organizations commonly implement or certify ISO 27701 alongside an ISMS rather than treating privacy as a disconnected project.
  • Your data role drives the controls. A business may be a PII controller in one workflow and a PII processor in another, so roles must be documented by processing activity.
  • Certification is assurance, not immunity. A certificate may support customer trust and regulatory accountability, but it does not automatically prove compliance with every privacy law.
  • Operational evidence matters most. Auditors typically sample completed assessments, requests, approvals, training, incidents, supplier reviews, and corrective actions—not policies alone.

What is ISO 27701?

ISO/IEC 27701 provides requirements and guidance for establishing, implementing, maintaining, and continually improving a PIMS. Its control framework adds privacy-specific requirements to the management system structure used by ISO/IEC 27001 and the security controls associated with ISO/IEC 27002.

In practical terms, a PIMS answers five recurring questions:

  1. Which organizations, products, teams, systems, and processing activities are in scope?
  2. What PII is processed, for what purpose, and under which controller or processor role?
  3. Which privacy risks exist for individuals and the organization?
  4. Which controls address those risks, and who owns them?
  5. What records demonstrate that the controls operate as designed?

ISO 27701 is useful because privacy work often spans legal, security, engineering, product, procurement, HR, and customer support. The PIMS supplies a common governance layer: leadership objectives, documented responsibilities, risk methods, competence requirements, performance measurement, internal audit, and corrective action.

ISO 27701 is not a privacy law. It does not replace jurisdiction-specific analysis, determine a lawful basis for every processing activity, or guarantee that a regulator will agree with every decision. It provides a repeatable way to manage privacy obligations and demonstrate accountability.


How ISO 27701 works

ISO 27701 follows the management system cycle already familiar to ISO 27001 teams:

  • Plan: Understand organizational context, interested parties, scope, privacy risks, and measurable objectives.
  • Do: Assign responsibilities and operate controls across the PII lifecycle.
  • Check: Monitor metrics, test controls, run internal audits, and conduct management reviews.
  • Act: Correct nonconformities, address root causes, and improve the PIMS.

The extension adds privacy considerations to relevant ISO 27001 requirements and includes control guidance for PII controllers and processors. Teams commonly document applicability in a privacy-focused Statement of Applicability or an integrated ISMS/PIMS control matrix. That record should state whether a control applies, why, how it is implemented, who owns it, and where evidence is stored.

An effective PIMS is integrated into normal workflows. A product launch may trigger a privacy assessment; onboarding a data vendor may trigger security and privacy due diligence; a data subject request may create a tracked service ticket; and an incident may invoke both security response and privacy notification analysis.

For a broader view of the foundation, read The ultimate ISO 27001 guide and ISO 27001 vs ISO 27701: what’s the difference?.


PII controllers vs PII processors

ISO 27701 distinguishes organizations that determine why and how PII is processed from organizations that process PII on another party's behalf. Terminology in privacy laws varies, but the operational distinction is essential.

Decision point PII controller PII processor
Determines purpose and essential means Typically yes Typically no; follows documented instructions
Primary focus Fair, transparent, purpose-limited processing Controlled processing under customer instructions
Typical evidence Privacy notices, purpose and lawful-basis records, rights workflows, retention decisions Processing instructions, customer commitments, subprocessor approvals, deletion or return records
Individual requests Owns response and identity-verification decisions Commonly assists the controller within agreed timelines
Third parties Defines processor requirements and oversight Manages subprocessors and communicates changes

A company may occupy both roles. For example, a SaaS provider may act as controller for employee and prospect information while acting as processor for customer-uploaded records. The privacy lead should maintain a processing inventory that identifies the role for each purpose—not assign one role to the entire company.

Control owners also differ. Legal or privacy commonly owns notices and rights interpretation; product owns purpose and feature decisions; engineering owns technical deletion and access restrictions; procurement owns contract routing; and security supports incident, access, and supplier controls. A RACI matrix can prevent requests from being lost between teams.


Why buyers ask for ISO 27701

Enterprise buyers need more than a statement that a vendor “takes privacy seriously.” They may need assurance that the vendor understands its data, controls subprocessors, supports individual rights, manages incidents, and reviews privacy risks before changing products.

ISO 27701 can help buyers by providing:

  • A recognizable, independently assessed privacy management framework
  • Defined accountability across controller and processor activities
  • A structured connection between privacy and information security
  • Evidence of internal audits, management oversight, and corrective action
  • A common basis for vendor questionnaires and contract discussions

Certification may reduce repetitive diligence, but it will not eliminate it. Buyers commonly still ask about service-specific data flows, residency, retention, subprocessors, artificial intelligence use, and contractual terms. The strongest approach pairs a certificate with a current scope statement and concise evidence package.

The commercial case is strongest when privacy reviews regularly delay deals, customers handle sensitive PII, or the organization operates across multiple jurisdictions. Smaller teams may first use ISO 27701 as an internal framework, then pursue certification as buyer demand matures.


How ISO 27701 fits a privacy program

A privacy program translates legal, contractual, customer, and ethical expectations into decisions and repeatable work. ISO 27701 supplies governance and assurance around that program.

Common PIMS workflows include:

  • PII inventory: System and process owners record categories of people and PII, purpose, recipients, locations, retention, security measures, and controller/processor role.
  • Privacy risk assessment: Privacy and business owners evaluate potential effects on individuals, choose treatment, approve residual risk, and review material changes.
  • Privacy by design: Product intake prompts teams to assess collection, defaults, transparency, access, deletion, and third parties before release.
  • Rights requests: Support or privacy logs intake, verifies identity, searches systems, coordinates responses, records decisions, and meets applicable timelines.
  • Supplier oversight: Procurement collects privacy and security evidence, legal approves terms, and owners monitor material changes.
  • Incident coordination: Security contains and investigates while privacy evaluates affected PII, roles, contracts, and notification obligations.

The system should connect evidence to controls. A policy establishes the rule; a procedure explains the workflow; and records prove execution. For example, a retention policy is weak evidence without approved schedules, configured deletion jobs, exception records, and periodic checks.

Organizations aligning ISO 27701 with European privacy obligations can also use Your 8-step guide to GDPR compliance audits to structure legal and operational review.


ISO 27701 certification overview

Certification is typically performed by an independent certification body. Because ISO 27701 extends ISO 27001, organizations commonly align the PIMS scope and audit cycle with the ISMS. Confirm the certification body's requirements early, especially if the ISO 27001 and ISO 27701 scopes differ.

A typical path includes:

  1. Scope and gap analysis: Define boundaries and compare current practices with requirements.
  2. Implementation: Create or improve policies, assessments, records, and supporting controls.
  3. Operation: Run the PIMS long enough to produce representative evidence.
  4. Internal audit and management review: Independently test conformity and obtain leadership decisions.
  5. Stage 1 audit: The auditor reviews scope, design, documentation, and readiness.
  6. Stage 2 audit: The auditor samples operating effectiveness through records and interviews.
  7. Corrective action: The organization resolves findings and supplies evidence.
  8. Surveillance: Periodic audits assess continued conformity during the certification cycle.

Timelines vary. An organization with a mature ISO 27001 ISMS and established privacy operations may prepare in several months. A business with incomplete inventories, undefined roles, or inconsistent rights and supplier workflows may need longer. Build the schedule around evidence quality and process operation rather than a desired certificate date alone.

For detailed implementation sequencing, see The ultimate guide to ISO 27701.


How to get started

Begin with a two-week discovery sprint:

  • Appoint an executive sponsor and PIMS program owner.
  • Draft scope boundaries, including products, entities, locations, systems, and interfaces.
  • Select five to ten representative processing activities and document data flows.
  • Determine controller and processor roles for each purpose.
  • Inventory existing privacy policies, assessments, contracts, tickets, and metrics.
  • Interview legal, security, product, engineering, HR, procurement, and support.
  • Create a gap register with risk, owner, evidence needed, dependency, and target date.

Prioritize foundational gaps first: scope, inventory, role assignment, risk methodology, and ownership. These inform downstream policies and controls. Then run high-volume workflows—such as product reviews, supplier reviews, rights requests, and retention—through the designed process and retain records.

Use weekly working sessions for owners and a monthly steering review for decisions, overdue risks, resources, and scope changes. Typically, the PIMS owner coordinates evidence; control owners operate processes; an independent internal auditor tests them; and top management reviews performance.


Streamline ISO 27701 readiness with SecureSlate

SecureSlate helps privacy and security teams turn ISO 27701 requirements into owned, evidence-backed work.

  • Map PIMS requirements and controller or processor controls to accountable owners
  • Centralize policies, assessments, inventories, and operating evidence
  • Track privacy risks, remediation, approvals, and corrective actions
  • Monitor readiness and organize evidence for internal and certification audits

Get started for free: Create your SecureSlate account


FAQ: ISO 27701

Is ISO 27701 the same as GDPR compliance?

No. ISO 27701 is a certifiable privacy management standard; GDPR is a binding regulation for processing in its territorial scope. Controls may overlap, but certification does not itself establish GDPR compliance.

Do you need ISO 27001 before ISO 27701?

ISO 27701 is designed as an extension to an ISO 27001 ISMS. Organizations commonly implement them together or add ISO 27701 to an existing ISMS. Confirm certification prerequisites and scope expectations with the selected certification body.

What does a PIMS include?

A PIMS typically includes scope, roles, privacy policies, PII inventories, risk assessments, applicable controls, operational procedures, training, metrics, internal audits, management reviews, and corrective-action records.

How long does ISO 27701 certification take?

Timing depends on scope, privacy maturity, ISMS maturity, resources, and available evidence. Several months is common, but complex or immature environments may require longer.

Does ISO 27701 apply only to technology companies?

No. Any organization processing PII as a controller or processor may use it, including financial services, healthcare, professional services, public-sector suppliers, and software providers.


Disclaimer (legal note)

SecureSlate is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws and regulations, you should consult a licensed attorney.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.9(137 reviews)

Keep reading

Jul 30, 2026 · ISO 27701

ISO 27701 compliance checklist: build an audit-ready PIMS

Jul 29, 2026 · ISO 27701

How to get ISO 27701 certified: a step-by-step guide

Jul 28, 2026 · ISO 27701

ISO 27701 vs GDPR: what’s the difference?

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?