ISO 27701
ISO/IEC 27701 extends ISO 27001 into privacy. It certifies that a company has a Privacy Information Management System (PIMS) governing how it handles personal data as a controller or processor, adding specific controls for consent, retention, and data subject rights on top of its information security baseline.
Information security and data privacy overlap, but they're not the same discipline. A company can encrypt every database it owns and still mishandle consent, retention, or a data subject's deletion request. ISO 27701 closes that gap.
What is ISO 27701?
ISO/IEC 27701 is an extension to ISO 27001 that adds requirements for a Privacy Information Management System, or PIMS. A company must already have, or simultaneously implement, ISO 27001 as the security foundation; ISO 27701 then layers on privacy-specific controls covering how personal data is collected, used, retained, and eventually deleted.
The standard adds roughly 18 additional controls on top of the ISO 27001 Annex A baseline, split between controls that apply when the company acts as a data controller and controls that apply when it acts as a processor on a customer's behalf.
Why ISO 27701 Matters
Privacy regulations like GDPR and CCPA describe legal obligations; ISO 27701 describes an operational system for meeting them consistently. Holding the certification doesn't replace legal compliance, but it demonstrates the company runs privacy as a managed program rather than a policy document nobody revisits.
- Bridges security and privacy: extends an existing ISO 27001 program instead of starting from scratch
- Covers both controller and processor roles: relevant for vendors that both own account data and process customer data on a client's behalf
- Supports regulatory alignment: the control set maps closely to obligations found in GDPR and similar laws, even though it isn't a legal certification of compliance
How ISO 27701 Works
A company pursuing ISO 27701 defines the scope of its PIMS (which data flows and business units are covered), maps its role as controller and/or processor for each type of data, then implements and evidences the additional privacy controls. Certification follows the same audit structure as ISO 27001: an accredited body reviews the program, then conducts recurring surveillance audits.
One thing worth checking on any vendor's certificate: the stated scope. Some ISO 27701 certifications cover only a company's processor role, meaning the certification speaks to how it handles a customer's end-user data but not necessarily its own account-holder data as a controller. Always read the certificate scope rather than assuming full coverage from a badge alone.
Frequently Asked Questions
Does ISO 27701 mean a company is GDPR compliant?
Not automatically. ISO 27701 demonstrates a structured privacy management program that supports compliance, but GDPR compliance is a legal determination, not a certification outcome.
Can a company get ISO 27701 without ISO 27001?
No. ISO 27701 is structured as an extension, so the underlying ISO 27001 certification (or simultaneous implementation) is a prerequisite.