News

ISO/IEC 27701: extending ISO 27001 to privacy management

Cybersecurity padlock on keyboard
In short: ISO/IEC 27701:2019 is an extension to ISO/IEC 27001 and 27002 for privacy information management. It helps organizations acting as controllers or processors of personal data manage privacy risks and demonstrate accountability.

What is ISO/IEC 27701?

ISO/IEC 27701 specifies requirements and guidance for a Privacy Information Management System (PIMS) built on an existing information security management system.

What does it add to ISO/IEC 27001?

  • Privacy-specific requirements for PII controllers and PII processors
  • Additional controls for consent, data subject rights and privacy by design
  • Mapping to privacy frameworks such as the GDPR

Who should use it?

Any organization that processes personal data and already operates — or plans to operate — an ISO/IEC 27001 system.

Key takeaways

  • ISO/IEC 27701 builds privacy management on top of ISO/IEC 27001.
  • It covers both data controllers and data processors.
  • It helps demonstrate accountability under privacy laws.

Frequently asked questions

Can you certify to ISO/IEC 27701 alone?

No. It is an extension and is certified together with ISO/IEC 27001.

Does ISO/IEC 27701 guarantee GDPR compliance?

No standard guarantees legal compliance, but ISO/IEC 27701 provides a structured way to meet many GDPR accountability expectations.

What is PII?

Personally identifiable information — any information that can identify a person.