ISO/IEC 27701
ISO/IEC 27701 extends ISO/IEC 27001 and ISO/IEC 27002 with requirements and guidance for a Privacy Information Management System (PIMS), covering the processing of personally identifiable information (PII).
What ISO/IEC 27701 is, in plain terms
ISO/IEC 27701 is the privacy extension to ISO/IEC 27001 and 27002. It turns an existing information security management system into a Privacy Information Management System (PIMS) by adding requirements and controls specific to handling personally identifiable information (PII), distinguishing the roles of PII controller and PII processor. It is widely used to demonstrate accountability against regulations such as the GDPR.
Typical effort & timeline
Because it builds on ISO 27001, an established ISMS is a prerequisite. The incremental effort focuses on the privacy-specific controls and documentation rather than rebuilding a management system from scratch.
Is this framework for you?
- Organizations already certified to ISO 27001 that want a certifiable privacy program on top of it.
- Processors who need to show enterprise customers a structured approach to handling PII.
- Companies that want a recognized way to evidence GDPR-aligned accountability.
Key facts about ISO/IEC 27701
- Is an extension of ISO 27001; an established ISMS is a prerequisite.
- Defines additional requirements and controls for PII controllers and PII processors.
- Maps to privacy regulations such as the GDPR to support demonstrable accountability.
- Certification is issued by accredited certification bodies, building on an ISO 27001 certification.
Public information about the framework itself. We don't claim certifications, assessment status, or authorizations for our own product.
How we help with ISO/IEC 27701
- Extend an existing ISO 27001 control set with the PIMS-specific controls.
- Map controller/processor controls to tests and evidence.
- Reuse ISO 27001 evidence to reduce duplicate work for the privacy extension.
- Track PII processing activities and accountability documentation over time.
Get and stay compliant
How the platform supports your ISO/IEC 27701 program, from first scope to ongoing monitoring.
Confirm your ISMS base
Ensure an ISO 27001 ISMS is in place, since 27701 extends it.
Classify your role
Determine where you act as PII controller, processor, or both, and apply the matching controls.
Map privacy controls
Connect controller/processor controls to tests and evidence, reusing ISO 27001 work.
Maintain records
Keep records of processing and accountability documentation current over time.
What ISO/IEC 27701 covers
Public, high-level control or requirement areas, for orientation, not a complete control list.
Reuse evidence across frameworks
ISO/IEC 27701 shares controls with frameworks you may already run. A passing test can satisfy requirements in more than one place, so adding the next framework means reusing work, not repeating it.
Common questions about ISO/IEC 27701
No. ISO 27701 is an extension, so a working ISO 27001 ISMS (certified or being certified) is a prerequisite.
It does not grant legal compliance, but it provides a recognized framework that maps to GDPR obligations and supports demonstrable accountability.
27701 defines separate control sets for organizations acting as PII controllers and as PII processors; you apply whichever roles you hold.
Get audit-ready for ISO/IEC 27701
Get a guided demo, or start by scanning any domain for free.