In short: ISO/IEC 27701:2019 is an extension to ISO/IEC 27001 and 27002 for privacy information management. It helps organizations acting as controllers or processors of personal data manage privacy risks and demonstrate accountability.
What is ISO/IEC 27701?
ISO/IEC 27701 specifies requirements and guidance for a Privacy Information Management System (PIMS) built on an existing information security management system.
What does it add to ISO/IEC 27001?
- Privacy-specific requirements for PII controllers and PII processors
- Additional controls for consent, data subject rights and privacy by design
- Mapping to privacy frameworks such as the GDPR
Who should use it?
Any organization that processes personal data and already operates — or plans to operate — an ISO/IEC 27001 system.
Key takeaways
- ISO/IEC 27701 builds privacy management on top of ISO/IEC 27001.
- It covers both data controllers and data processors.
- It helps demonstrate accountability under privacy laws.
Frequently asked questions
Can you certify to ISO/IEC 27701 alone?
No. It is an extension and is certified together with ISO/IEC 27001.
Does ISO/IEC 27701 guarantee GDPR compliance?
No standard guarantees legal compliance, but ISO/IEC 27701 provides a structured way to meet many GDPR accountability expectations.
What is PII?
Personally identifiable information — any information that can identify a person.