GRC Oversight

ISO/IEC 27701

ISO/IEC 27701 extends ISO/IEC 27001 and ISO/IEC 27002 with requirements and guidance for a Privacy Information Management System (PIMS), covering the processing of personally identifiable information (PII).

Governed by ISO and IEC (ISO/IEC 27701:2019)
What it is

What ISO/IEC 27701 is, in plain terms

ISO/IEC 27701 is the privacy extension to ISO/IEC 27001 and 27002. It turns an existing information security management system into a Privacy Information Management System (PIMS) by adding requirements and controls specific to handling personally identifiable information (PII), distinguishing the roles of PII controller and PII processor. It is widely used to demonstrate accountability against regulations such as the GDPR.

Typical effort & timeline

Because it builds on ISO 27001, an established ISMS is a prerequisite. The incremental effort focuses on the privacy-specific controls and documentation rather than rebuilding a management system from scratch.

Who needs it

Is this framework for you?

  • Organizations already certified to ISO 27001 that want a certifiable privacy program on top of it.
  • Processors who need to show enterprise customers a structured approach to handling PII.
  • Companies that want a recognized way to evidence GDPR-aligned accountability.
About the framework

Key facts about ISO/IEC 27701

  • Is an extension of ISO 27001; an established ISMS is a prerequisite.
  • Defines additional requirements and controls for PII controllers and PII processors.
  • Maps to privacy regulations such as the GDPR to support demonstrable accountability.
  • Certification is issued by accredited certification bodies, building on an ISO 27001 certification.

Public information about the framework itself. We don't claim certifications, assessment status, or authorizations for our own product.

With this platform

How we help with ISO/IEC 27701

  • Extend an existing ISO 27001 control set with the PIMS-specific controls.
  • Map controller/processor controls to tests and evidence.
  • Reuse ISO 27001 evidence to reduce duplicate work for the privacy extension.
  • Track PII processing activities and accountability documentation over time.
Step by step

Get and stay compliant

How the platform supports your ISO/IEC 27701 program, from first scope to ongoing monitoring.

Confirm your ISMS base

Ensure an ISO 27001 ISMS is in place, since 27701 extends it.

Classify your role

Determine where you act as PII controller, processor, or both, and apply the matching controls.

Map privacy controls

Connect controller/processor controls to tests and evidence, reusing ISO 27001 work.

Maintain records

Keep records of processing and accountability documentation current over time.

Representative areas

What ISO/IEC 27701 covers

Public, high-level control or requirement areas, for orientation, not a complete control list.

PIMS-specific requirements
PII controller controls
PII processor controls
Privacy by design & by default
Records of processing
Do it once

Reuse evidence across frameworks

ISO/IEC 27701 shares controls with frameworks you may already run. A passing test can satisfy requirements in more than one place, so adding the next framework means reusing work, not repeating it.

FAQ

Common questions about ISO/IEC 27701

No. ISO 27701 is an extension, so a working ISO 27001 ISMS (certified or being certified) is a prerequisite.

It does not grant legal compliance, but it provides a recognized framework that maps to GDPR obligations and supports demonstrable accountability.

27701 defines separate control sets for organizations acting as PII controllers and as PII processors; you apply whichever roles you hold.

Get audit-ready for ISO/IEC 27701

Get a guided demo, or start by scanning any domain for free.