ISO 27701
ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS) — a structured, certifiable way to manage how your organization handles personal data. It's built as an extension to ISO 27001: you take your existing information security management system (ISMS) and add the privacy requirements and personally identifiable information (PII) controls on top. If customers, regulators, or enterprise buyers are asking you to prove you manage privacy properly — especially under GDPR — this is the framework that answers them with an independent audit. Here's the plain-language version: what it is, how it extends ISO 27001, the controller-vs-processor split, how it supports GDPR, how certification works, and how to get ready.
ISO 27701 checklist
A PIMS & PII-control implementation checklist.
Free readiness assessment
See your ISO 27701 gaps in minutes.
Map to other frameworks
How ISO 27701 maps to GDPR, ISO 27001 & SOC 2.
Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.
What is ISO 27701?
ISO/IEC 27701 is a privacy management-system extension — it doesn't certify a single product, it certifies the system you use to manage the protection of personal data across your organization. Rather than starting from scratch, it reuses the management-system structure of ISO 27001 and adds privacy-specific requirements plus a set of PII-protection controls. The result is a Privacy Information Management System (PIMS): privacy that is governed, risk-based, documented, and continually improved, sitting on the same foundation as your information security program. It is maintained jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).
You build it on top of an ISO 27001 ISMS
This is the key thing to understand: ISO 27701 is not a standalone standard. It extends ISO 27001 (the ISMS requirements) and ISO 27002 (the security controls) into the privacy domain. In practice, an organization first has — or builds — an information security management system, then broadens its scope to cover privacy and layers on the ISO 27701 requirements. That means the concepts you already know from ISO 27001 (context, leadership, risk assessment, documented information, internal audit, management review) get re-read through a privacy lens, and a set of role-specific PII controls is added. You can certify to ISO 27701 alongside an existing ISO 27001 certification, extending the same management system rather than running two separate ones.
Who needs ISO 27701?
It fits any organization that collects, stores, or processes personal data — which today is nearly all of them. Teams typically pursue ISO 27701 when: - customers or enterprise buyers want proof that you manage personal data responsibly before they'll sign; - they operate under GDPR or a similar privacy law and want a recognized way to demonstrate accountability; - they already hold ISO 27001 and want to extend it to cover privacy without starting a new program; - they act as a processor for other businesses and need to show data-protection maturity to win and keep contracts.
Controller vs. processor — and why it matters
PII controller — You determine why and how personal data is processed — for example, deciding to collect customer data and set its purposes. You carry the accountability for lawful basis, notices, and honoring individuals' rights. PII processor — You process personal data on behalf of a controller — for example, a SaaS vendor handling a client's user data. Your obligations centre on acting within the controller's instructions and protecting the data you're entrusted with. ISO 27701 recognizes that privacy responsibilities depend on your role in handling personal data, mirroring the roles used …
How ISO 27701 maps to and supports GDPR
ISO 27701 was designed to align with major privacy regulations, and its requirements map closely to obligations in the EU General Data Protection Regulation (GDPR) — such as records of processing, lawful basis and consent, data-subject rights, privacy by design, data protection impact assessments (DPIAs), and controller-processor agreements. It doesn't replace GDPR or make you automatically compliant, and holding the certificate isn't the same as legal compliance. What it does is give you a structured, auditable way to demonstrate privacy accountability — a recognized system that shows regulators, customers, and partners that you have privacy governance in place. Many organizations use it as evidence toward GDPR and other privacy-law readiness precisely because the mappings line up so well.
The management-system requirements, applied to privacy
Because ISO 27701 extends ISO 27001, the familiar management-system clauses are reused — but read as privacy requirements. In our own words, the PIMS management requirements cover: We describe the structure in our own words. For the authoritative requirements and control text, consult your licensed copy of ISO/IEC 27701 (and the ISO/IEC 27001 and 27002 standards it extends).
ISO 27701 work counts elsewhere too
The crosswalk maps your ISO 27701 evidence onto the frameworks it overlaps — so you move forward on several at once.