ISO 27701

ISO 27701 Privacy Information Management in 2026: The Complete Guide

A senior-practitioner's guide to ISO/IEC 27701 — the privacy extension to ISO 27001 — covering PIMS scope, controller vs processor roles, GDPR alignment, and how to certify without duplicating your 27001 program.

February 22, 202613 min readBy GRC XL Advisory

Quick Answer

ISO/IEC 27701 is an international standard that extends ISO/IEC 27001 with privacy-specific requirements to establish, implement, maintain, and continually improve a Privacy Information Management System (PIMS). It maps directly to GDPR and other privacy regulations, and certification is only available to organizations that already hold — or are simultaneously certifying — ISO/IEC 27001.

Key Takeaways

  • ISO 27701 is not standalone — it is an extension of ISO 27001 and cannot be certified without a 27001 certificate.
  • The PIMS defines separate controls for PII Controllers (Annex A) and PII Processors (Annex B); many organizations act as both and implement both annexes.
  • ISO 27701 maps cleanly to GDPR Articles 5–39, and certification is now the most common way for B2B vendors to answer GDPR due-diligence questionnaires at scale.
  • Typical incremental effort over an existing ISO 27001 program is 3–6 months and 20–30% additional evidence workload.
  • Certification bodies audit ISO 27701 as an extension of the 27001 audit — one Stage 1, one Stage 2, one integrated certificate scope.

What is ISO 27701?

ISO/IEC 27701:2019 — Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management — is the international standard for a Privacy Information Management System (PIMS). It was published in August 2019 and is now the most widely adopted certifiable privacy framework globally.

27701 does not replace GDPR, CCPA, or any privacy law. It provides the management-system scaffolding — governance, roles, controls, evidence, continuous improvement — to implement those laws systematically and prove it to third parties.

Standard structure and PIMS

27701 layers privacy requirements on top of the ISO 27001 clauses (4–10) and ISO 27002 controls. In practice, an implementer works through:

ISO 27701 building blocks

  • Clauses 5–8: PIMS-specific requirements added to the 27001 management-system clauses (context, leadership, planning, support, operation).
  • Annex A: Additional controls for PII Controllers — the organization that determines purposes and means of processing.
  • Annex B: Additional controls for PII Processors — the organization that processes PII on behalf of a controller.
  • Annex C–F: Mappings to GDPR, ISO 29100, ISO 27018, and ISO 29151 for cross-framework reuse.

Controller vs processor — get the role right

27701 explicitly recognizes that an organization can be a controller, a processor, or both, and requires you to declare which. This is the same distinction GDPR uses:

RoleDefinitionExample
PII ControllerDetermines purposes and means of processingSaaS company processing its own employee HR data; a marketing platform deciding what to do with signup data
PII ProcessorProcesses PII on behalf of a controllerA cloud provider hosting a customer's tenant; an analytics SaaS operating under customer instructions
BothActs as controller for some data, processor for other dataMost B2B SaaS: controller for its own employees and prospects, processor for customer end-user data

GDPR and privacy-law alignment

Annex D of ISO 27701 provides the official mapping from PIMS controls to GDPR Articles 5–39, including data subject rights, lawful basis, DPIA, records of processing, breach notification, and international transfers. This mapping is the single largest reason 27701 has become the default enterprise vendor answer to GDPR due diligence.

27701 also maps well to other regimes: LGPD (Brazil), PIPEDA (Canada), the UK GDPR post-Brexit, and increasingly U.S. state privacy laws (CPRA, VCDPA, CPA, CTDPA, UCPA). It does not automatically make you compliant with any single law, but it produces most of the evidence those laws expect.

ISO 27701 certification does not equal GDPR compliance — but it is the fastest way to answer 90% of vendor privacy questionnaires and short-circuit repetitive DPIA reviews from enterprise buyers.

Certification path

27701 is only certifiable in combination with 27001. There are two viable paths:

Path A — Sequential. Certify 27001 first, then add 27701 at the next surveillance or recertification audit. Lowest risk, most common.

Path B — Integrated. Certify 27001 and 27701 together in a single Stage 1 + Stage 2 audit. Higher intensity but faster to a combined certificate.

Either way, the certification body issues a single certificate with the 27701 scope explicit. Surveillance audits are integrated with 27001.

Cost, timeline, and effort

Realistic 2026 figures for a mid-size B2B SaaS with an existing 27001 program adding 27701:

ISO 27701 incremental cost and effort

  • Certification body incremental audit fee: typically 20–35% of the 27001 audit fee.
  • Advisory/readiness support: $25K–$75K for a first-time PIMS.
  • Internal effort: 300–700 hours across privacy, legal, security, and product.
  • Timeline from kick-off to certificate: 3–6 months for organizations with mature 27001.
  • GRC tooling: minimal incremental cost — most 27001 platforms include 27701 out of the box.

Common implementation mistakes

1. Declaring only one role. Almost every B2B SaaS is both controller and processor. Picking only one role narrows scope but misleads customers and creates GDPR risk.

2. Treating 27701 as GDPR-in-a-box. GDPR obligations (DPO appointment, records of processing, cross-border transfer mechanisms, DPIA thresholds) still require legal analysis — 27701 organizes them, it does not decide them.

3. Copy-pasting the 27001 ISMS scope. The PIMS scope must explicitly cover the PII processing activities — usually broader (marketing, HR, support) than the 27001 ISMS scope.

4. Ignoring supplier obligations. Annex B processor controls include specific requirements for how you use sub-processors — these must flow down through contracts.

5. No records of processing (ROPA). Article 30 ROPA is table stakes; 27701 assumes you maintain it and updates it via the PIMS.

Build Trust. Reduce Risk. Achieve Compliance.

Talk to a senior GRC advisor

Free scoping call. Executive-grade guidance on your compliance roadmap.

Book a consultation

Frequently Asked Questions

Can we certify ISO 27701 without ISO 27001?

No — 27701 is an extension standard. Certification bodies will not issue a 27701 certificate unless a 27001 certificate is held or being issued in the same audit cycle.

Does ISO 27701 replace a DPO?

No. GDPR Article 37 obligations to appoint a Data Protection Officer are independent of ISO 27701. However, 27701 requires an appointed person with accountability for the PIMS, which is often the DPO in practice.

How is ISO 27701 different from ISO 27018?

27018 is a code of practice for cloud PII processors — narrower and non-certifiable on its own. 27701 is a certifiable management-system standard covering both controllers and processors across all environments. Most cloud SaaS pursue 27701 rather than 27018 today.

How long does an ISO 27701 certificate last?

Three years, aligned with the 27001 certification cycle, with annual surveillance audits.

Is ISO 27701 recognized in the U.S.?

Yes — U.S. enterprise buyers increasingly request 27701 alongside SOC 2 for privacy assurance, particularly for vendors handling employee data or B2C personal information. It also supports evidence for CPRA and other state privacy laws.

Related Topics

ISO 27701ISO/IEC 27701Privacy Information Management SystemPIMS certificationISO 27701 GDPRISO 27701 vs ISO 27001ISO 27701 controller processorISO 27701 certification

Build Trust. Reduce Risk. Achieve Compliance.