top of page

ISO/IEC 27701

Independent internal audits, gap analyses, and hands-on implementation support for the privacy management standard — now a standalone certification as of the 2025 edition. We help you manage personal data properly and prove it.

WHAT IT IS

Privacy management

A system for handling personal data (PII)

CURRENT VERSION

ISO/IEC 27701:2025

Now a standalone standard

CERTIFIABLE?

Yes

Through an accredited certification body

BEST FOR

Data-heavy businesses

Anyone needing to evidence GDPR work

STANDARD EXPLANATION

What is ISO 27701?

ISO 27701 is the international standard for a Privacy Information Management System — a PIMS. In plain terms, it's a structured way of managing how your organisation collects, uses, stores, and protects personal data, and of being able to demonstrate that you do it responsibly. It covers your obligations as both a data controller and a data processor.

In October 2025 the International Standard Organisation (ISO) made ISO 27701 a standalone standard — you no longer need ISO 27001 certification first, which was a requirement under the old 2019 version where 27701 was just an "extension." It now follows the same harmonised structure as ISO 9001 and ISO 42001, consolidates its privacy controls, and adds new guidance on privacy risks from AI like profiling and automated decisions.

Crucially for UK and EU businesses, the standard maps closely to regulations like the GDPR. Certification can serve as credible evidence that you've operationalised your privacy obligations — though it doesn't replace getting the law itself right.

If your notes on 27701 mention "needing ISO 27001 first" — they're out of date. Since October 2025 it's a standalone standard. You can implement and certify a PIMS on its own, which lowers the barrier considerably for privacy-focused teams.

WHY PEOPLE COME TO US FOR IT

Do you actually need ISO 27701?

It tends to matter most for organisations where personal data is central to what they do. The trigger usually looks like one of these.

01

You handle a lot of personal data. You process meaningful volumes of customer or employee data and want a recognised framework to manage the risk properly.

02

Customers want more than a security cert. Clients or partners are asking specifically about privacy, and an ISO 27001 certificate alone doesn't fully answer the question.

03

You want GDPR work to be demonstrable. You'd rather have a structured, auditable system than a folder of policies you hope would hold up under scrutiny.

HOW WE HELP

Two ways in. Same principle throughout.

Whether we're independently auditing your PIMS or helping you build it, you stay involved and walk away understanding it. Here's how that splits for ISO 27701.

Audit & Assessment · Independent

We check your system against the standard.

Impartial, evidence-based work — and kept separate from your certification body, so nobody's marking their own homework.

  • Gap analysis against ISO 27701 before you commit

  • Internal audits to satisfy clause 9.2 (required to certify)

  • Review of how your controls map to the GDPR

  • Clear findings — conformities, nonconformities, observations

Implementation Support · Collaborative

We help you build the PIMS — alongside you.

Hands-on help with the parts that genuinely need it, with your team driving the work so you can run it afterwards.

  • Scoping the PIMS and clarifying the controls vs processor roles.

​​

  • Mapping where personal data actually flows

  • Writing privacy policies and procedures with you, not for you

  • Aligning the system to GDPR and prepping for audit

COMMON QUESTIONS

ISO 27701 questions we hear a lot

Do I need ISO 27001 before ISO 27701?

Not any more. Under the 2019 version you did — 27701 was an extension that required an existing ISMS certification. The 2025 edition made it a standalone standard, so you can now implement and certify a privacy management system on its own. This does not mean that you can't still pair the two standards together though.

Is ISO 27701 the same as being GDPR compliant?

No. ISO 27701 is a management framework that helps you operationalise and demonstrate good privacy practice, and it maps closely to the GDPR — but it isn't a substitute for meeting the law itself. Think of it as strong, auditable evidence rather than a legal guarantee. The ball is still in your court for upkeeping and ensuring GDPR compliance day to day.

What actually changed in the 2025 version?

The headline change is that it became standalone. It also adopted the harmonised high-level structure (aligning it with other standards like ISO 27001, 9001 and 42001), consolidated its controller and processor controls, and added guidance on privacy risks from AI, such as profiling and automated decision-making.

Is an internal audit required?

Yes. Clause 9.2 requires you to run internal audits of your PIMS at planned intervals. You need evidence of internal audits both to achieve certification and to keep it at each surveillance visit. Using an independent auditor keeps those findings credible — and is exactly the kind of work we do.

Can I integrate it with my existing ISMS?

Yes. Even though it's now standalone, it's designed to integrate cleanly with ISO 27001, so if you already run an ISMS you can extend it to cover privacy rather than starting fresh. This standard can also be implemented alongside any other ISO standard that runs the high-level structure, as well as any other standard/frameworks with a few mapping exercises.

Do you issue the certificate?

No — and that separation matters. The certificate is issued by an accredited certification body after their own Stage 1 and Stage 2 audits. We're independent of that process. We help you get ready and run the internal audits the standard requires, but we don't mark our own work or yours.

RELATED STANDARDS

Often comes up alongside

ISO 27001

The security counterpart, frequently run as an integrated management system with ISO 9001.

Information Security
ISO 42001

The newer standard for managing AI responsibly - increasingly relevant for tech companies handling data.

AI Management
GDPR

The law itself. ISO 27701 helps you demonstrate the privacy work that the GDPR expects.

Data Protection Regulation

If you need a clear view of where you stand - let's talk.

A 30-minute discovery call costs nothing. We'll tell you whether we're the right fit, what the work would involve, and what you'd get out of it. No pitch, no pressure.

bottom of page