← ISO and SOC Certifications

ISO/IEC 27701

Privacy information management system — an extension to ISO/IEC 27001. Updated: September 29, 2026.

ISO/IEC 27701 is the privacy counterpart to ISO/IEC 27001: a privacy information management system, with requirements for organisations acting as controllers of personal data, as processors, or as both. It is the nearest thing to a certifiable privacy standard, which is why it gets asked about.

What It Adds to 27001

Security asks whether data is protected. Privacy asks a different set of questions, and 27701 adds them:

How It Is Certified

27701 was published as an extension requiring an ISO/IEC 27001 management system underneath it — you cannot certify to it in isolation on that basis, and the two are typically audited together. The standard has since been revised, and editions differ in how standalone use is treated, so check which edition a certificate cites and what your certification body currently offers. That check matters both when you certify and when you evaluate somebody else's certificate.

Its Relationship With the GDPR

27701 includes mappings to data protection regimes including the GDPR, and those mappings are genuinely useful as an implementation guide. But certification to 27701 is not certification of GDPR compliance, and no certification body can issue the latter — only a supervisory authority interprets the law. What the certificate demonstrates is a systematic, independently audited approach to privacy management, which is a real and defensible claim to make to a customer or in a tender.

Who Needs It

Organisations processing significant volumes of personal data, particularly processors whose customers are themselves under regulatory pressure, and any business where privacy is part of what is being sold. For a small organisation with limited personal data, the controls are worth implementing and the certificate frequently is not.

Written from an infrastructure perspective. We are not a certification body, an audit firm or a legal adviser, and this is not legal advice. Standards are revised on a cycle — confirm the current edition before you commit.