ISO/IEC 27701
Privacy information management system — an extension to ISO/IEC 27001. Updated: September 29, 2026.
ISO/IEC 27701 is the privacy counterpart to ISO/IEC 27001: a privacy information management system, with requirements for organisations acting as controllers of personal data, as processors, or as both. It is the nearest thing to a certifiable privacy standard, which is why it gets asked about.
What It Adds to 27001
Security asks whether data is protected. Privacy asks a different set of questions, and 27701 adds them:
- Lawful basis and purpose. Why you hold the data at all, and whether you are still using it for that reason.
- Individuals' rights — access, correction, deletion, portability, objection — as an operational process with a clock on it, not a policy statement.
- Data minimisation and retention. Collecting less, and deleting on a schedule rather than never.
- Privacy by design in new systems, and impact assessments where processing is high risk.
- Records of processing, and the controller/processor split written down for each flow.
- Transfers — where data goes, and on what basis it is allowed to go there. This intersects directly with the residency scope discussed under security and compliance needs.
How It Is Certified
27701 was published as an extension requiring an ISO/IEC 27001 management system underneath it — you cannot certify to it in isolation on that basis, and the two are typically audited together. The standard has since been revised, and editions differ in how standalone use is treated, so check which edition a certificate cites and what your certification body currently offers. That check matters both when you certify and when you evaluate somebody else's certificate.
Its Relationship With the GDPR
27701 includes mappings to data protection regimes including the GDPR, and those mappings are genuinely useful as an implementation guide. But certification to 27701 is not certification of GDPR compliance, and no certification body can issue the latter — only a supervisory authority interprets the law. What the certificate demonstrates is a systematic, independently audited approach to privacy management, which is a real and defensible claim to make to a customer or in a tender.
Who Needs It
Organisations processing significant volumes of personal data, particularly processors whose customers are themselves under regulatory pressure, and any business where privacy is part of what is being sold. For a small organisation with limited personal data, the controls are worth implementing and the certificate frequently is not.
Written from an infrastructure perspective. We are not a certification body, an audit firm or a legal adviser, and this is not legal advice. Standards are revised on a cycle — confirm the current edition before you commit.