✨ Standpoint covers ISO 27701 readiness free for 14 days. Start your free trial →
Standpointby AI Service Pro
Frameworks / ISO 27701
Privacy · Certifiable standard (ISO 27001 extension)

ISO 27701

ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS) — a structured, certifiable way to manage how your organization handles personal data. It's built as an extension to ISO 27001: you take your existing information security management system (ISMS) and add the privacy requirements and personally identifiable information (PII) controls on top. If customers, regulators, or enterprise buyers are asking you to prove you manage privacy properly — especially under GDPR — this is the framework that answers them with an independent audit. Here's the plain-language version: what it is, how it extends ISO 27001, the controller-vs-processor split, how it supports GDPR, how certification works, and how to get ready.

What
ISO/IEC 27701 — an extension to ISO 27001 and ISO 27002 that adds a Privacy Information Management System (PIMS), a system for managing the protection of personal data.
Built on ISO 27001
it isn't standalone — you implement it on top of an ISMS, adding privacy-specific management requirements and PII controls for two roles:…
Who
any organization that collects or processes personal data and wants to prove privacy accountability — SaaS vendors, processors, and controllers alike.
Supports GDPR & other laws
its requirements map closely to privacy obligations like the EU General Data Protection Regulation (GDPR), so it's widely used to evidence privacy readiness.
// What Standpoint gives you

ISO 27701 checklist

A PIMS & PII-control implementation checklist.

Free readiness assessment

See your ISO 27701 gaps in minutes.

Map to other frameworks

How ISO 27701 maps to GDPR, ISO 27001 & SOC 2.

// What the framework covers
ContextGAP
LeadershipPARTIAL
PlanningDONE
SupportGAP
OperationPARTIAL
Performance evaluationDONE

Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.

// Go deeper

What is ISO 27701?

ISO/IEC 27701 is a privacy management-system extension — it doesn't certify a single product, it certifies the system you use to manage the protection of personal data across your organization. Rather than starting from scratch, it reuses the management-system structure of ISO 27001 and adds privacy-specific requirements plus a set of PII-protection controls. The result is a Privacy Information Management System (PIMS): privacy that is governed, risk-based, documented, and continually improved, sitting on the same foundation as your information security program. It is maintained jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).

You build it on top of an ISO 27001 ISMS

This is the key thing to understand: ISO 27701 is not a standalone standard. It extends ISO 27001 (the ISMS requirements) and ISO 27002 (the security controls) into the privacy domain. In practice, an organization first has — or builds — an information security management system, then broadens its scope to cover privacy and layers on the ISO 27701 requirements. That means the concepts you already know from ISO 27001 (context, leadership, risk assessment, documented information, internal audit, management review) get re-read through a privacy lens, and a set of role-specific PII controls is added. You can certify to ISO 27701 alongside an existing ISO 27001 certification, extending the same management system rather than running two separate ones.

Who needs ISO 27701?

It fits any organization that collects, stores, or processes personal data — which today is nearly all of them. Teams typically pursue ISO 27701 when: - customers or enterprise buyers want proof that you manage personal data responsibly before they'll sign; - they operate under GDPR or a similar privacy law and want a recognized way to demonstrate accountability; - they already hold ISO 27001 and want to extend it to cover privacy without starting a new program; - they act as a processor for other businesses and need to show data-protection maturity to win and keep contracts.

Controller vs. processor — and why it matters

PII controller — You determine why and how personal data is processed — for example, deciding to collect customer data and set its purposes. You carry the accountability for lawful basis, notices, and honoring individuals' rights. PII processor — You process personal data on behalf of a controller — for example, a SaaS vendor handling a client's user data. Your obligations centre on acting within the controller's instructions and protecting the data you're entrusted with. ISO 27701 recognizes that privacy responsibilities depend on your role in handling personal data, mirroring the roles used …

How ISO 27701 maps to and supports GDPR

ISO 27701 was designed to align with major privacy regulations, and its requirements map closely to obligations in the EU General Data Protection Regulation (GDPR) — such as records of processing, lawful basis and consent, data-subject rights, privacy by design, data protection impact assessments (DPIAs), and controller-processor agreements. It doesn't replace GDPR or make you automatically compliant, and holding the certificate isn't the same as legal compliance. What it does is give you a structured, auditable way to demonstrate privacy accountability — a recognized system that shows regulators, customers, and partners that you have privacy governance in place. Many organizations use it as evidence toward GDPR and other privacy-law readiness precisely because the mappings line up so well.

The management-system requirements, applied to privacy

Because ISO 27701 extends ISO 27001, the familiar management-system clauses are reused — but read as privacy requirements. In our own words, the PIMS management requirements cover: We describe the structure in our own words. For the authoritative requirements and control text, consult your licensed copy of ISO/IEC 27701 (and the ISO/IEC 27001 and 27002 standards it extends).

ISO 27701 work counts elsewhere too

The crosswalk maps your ISO 27701 evidence onto the frameworks it overlaps — so you move forward on several at once.

ISO 27001GDPR

Get your ISO 27701 readiness score.

Free to start. No card, no demo wall. You decide what leaves your device.

Run your free check →