ISO 27701
Definition
ISO 27701
ISO 27701 is the standard for privacy information management, setting out how an organisation governs personal data it holds or processes. The 2025 edition made it a standalone standard, so a provider no longer needs ISO 27001 certification underneath it.
That change is larger than it sounds.
Until 2025 this was an extension. You could not hold it without holding the security standard first — which limited it to organisations already carrying that certification and its cost.
As a standalone standard it becomes reachable for providers that manage personal data carefully but never needed a full security management system. Whether that is good news depends on what you were using the pairing to prove.
Key takeaways
- ISO/IEC 27701:2025 was published in October 2025, replacing the 2019 edition.
- It is now a standalone standard rather than an extension of ISO/IEC 27001 and 27002.
- It covers organisations acting as PII controllers and as PII processors.
- Buyers who relied on the old pairing should check whether security certification still sits underneath.
How it works
ISO 27701 specifies a privacy information management system. DNV records that the 2025 edition becomes a stand-alone standard aimed at further strengthening privacy information management systems (PIMS) rather than remaining an extension of ISO/IEC 27001.
The previous edition was published in 2019 and worked only as an add-on. An organisation certified its security management system, then extended the scope to cover privacy.
The new edition also broadens the control set. DNV notes it includes more comprehensive privacy controls for both Personally Identifiable Information (PII) controllers and processors, with better alignment to regulations such as the GDPR.
That alignment is the reason buyers ask for it. European law makes a controller responsible for using only processors that provide sufficient guarantees to implement appropriate technical and organisational measures.
A certificate is one way of evidencing that judgement.
It is evidence — not proof. Certification demonstrates a managed system exists; it does not establish that any particular processing operation is lawful.
| ISO 27701:2019 | ISO 27701:2025 | |
|---|---|---|
| Status | Extension to ISO/IEC 27001 | Standalone standard |
| Prerequisite | ISO/IEC 27001 certification | None required |
| Title framing | Extension for privacy information management | Privacy information management systems |
| Control coverage | Controllers and processors | Broader controls for both |
| Buyer implication | Security certification implied | Security must be checked separately |
The bottom-right cell is the practical one. A 2025 certificate no longer tells you the provider holds ISO 27001 — so ask.
Examples
Privacy certification is requested far more often than it is read, and the 2025 change has made the difference between the two editions worth noticing. Every arrangement below cost somebody money to get wrong at least once.
A European controller asks its offshore provider for evidence of privacy governance before signing. A PIMS certificate is a cleaner answer than a questionnaire, though it does not replace the contract.
A provider certified in 2023 under the old extension carries ISO 27001 by necessity. Its certificate implies a security system that a 2025 certificate would not.
A buyer discovers its provider holds only the 2025 standalone certificate. The privacy governance is certified and the security baseline is unverified, which pushes the checking back onto its own vendor management outsourcing team.
A healthcare client pairs the certificate with a data protection impact assessment, treating certification as one input among several rather than as the conclusion.
Related terms
Privacy standards, security standards and privacy law are three different things that buyers routinely request as though they were one. Each line below fixes a single meaning and marks where that meaning runs out.
- GDPR (General Data Protection Regulation): binding European law that this standard helps evidence but cannot satisfy.
- ISO 27001: the security management system that was formerly a prerequisite.
- Data Privacy Act Philippines: national privacy law in a major outsourcing destination.
- Compliance outsourcing: buying regulatory capability as a service.
- ISO certification: the general audit mechanism behind ISO management standards.
- ISO 42001: the artificial intelligence management standard, increasingly requested alongside this one.
- Cybersecurity outsourcing: buying security operations rather than certifying privacy governance.
FAQ
Does ISO 27701 still require ISO 27001?
Not in the 2025 edition. It became a standalone standard, so a provider can now certify privacy management without holding the security certification first.
When was the 2025 edition published?
In October 2025, replacing the 2019 edition that worked only as an extension to the security standard.
Does certification prove GDPR compliance?
No. It evidences a managed privacy system, which helps a controller justify its choice of processor, but lawfulness of processing is assessed separately.
Who is it for, controllers or processors?
Both. The standard sets controls for organisations acting as PII controllers and for those acting as PII processors on someone else’s behalf.
What should I check on a 2025 certificate?
Whether ISO 27001 sits underneath it. The pairing used to be automatic and now has to be confirmed.
How does it relate to ISO 27018?
ISO 27018 is a narrower code of practice for personal data in public clouds. ISO 27701 is a full management system standard.
Browse source partners in the Outsource Accelerator hubs directory and ask whether the privacy claim covers the work you are buying.







Independent




