ISO 27001 and UK GDPR: Article 32, certification, and what a certificate does not prove
“A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation” — UK GDPR Article 42(4), about the certifications the law itself recognises.
ISO 27001 and UK GDPR are often mentioned in the same breath, and the relationship is simpler than it is often made to sound. UK GDPR requires security appropriate to the risk. ISO 27001 is a way of running that security as a managed system. Neither is a substitute for the other, and the law names its own kind of certification — which is not automatically the one on your wall.
What Article 32 requires, and where an ISMS fits
UK GDPR Article 32(1): “Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:”
| Article 32(1) | In an ISO 27001 ISMS (our reading) | |
|---|---|---|
| a | the pseudonymisation and encryption of personal data | Cryptography is an Annex A control; whether and where to use it is a risk-treatment decision |
| b | the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services | Confidentiality, integrity and availability are what the ISMS risk assessment is built on (6.1.2 c)); resilience is addressed through continuity controls |
| c | the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident | Backup and continuity controls in Annex A, and incident management |
| d | a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing | Internal audit, management review and monitoring (clauses 9.1–9.3) — the management system's own testing and evaluation cycle |
The right-hand column is our reading of the two texts, not something either says. What both do say is that the level of protection follows the risk: Article 32(2) — “In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.” — and ISO 27001 builds everything from a risk assessment covering “the loss of confidentiality, integrity and availability for information within the scope”.
Scope is the gap to check first
Article 32 applies to all processing of personal data. An ISO 27001 certificate covers the scope written on it. If personal data is processed outside that scope — a second product, a support function, a subsidiary — the certificate says nothing about it.
Certification under UK GDPR is a defined thing
Article 32(3): “Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as a means of demonstrating compliance with the requirements set out in paragraph 1 of this Article.” Those words were substituted by the Data (Use and Access) Act 2025 with effect from 20 August 2025.
Article 42 sets out what such a certification is. It is issued by accredited certification bodies or the Commissioner “on the basis of criteria approved by” the Commissioner, and:
- “Certification shall be issued to a controller or processor for a maximum period of three years and may be renewed, under the same conditions, provided that the relevant criteria continue to be met.”
- “A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation”
Is ISO 27001 one of them?
ISO/IEC 27001 certification is issued by accredited certification bodies against a standard written by ISO and IEC. An Article 42 mechanism is certification against criteria the ICO has approved and entered on its register. Those are different routes, and a certificate is not an Article 42 mechanism merely because it is accredited. The ICO says: “It is important that you check carefully that the code or certification scheme has been approved by the ICO.”
The register itself currently carries a notice: “Approval of the certification schemes in this register remain valid. However, due to the Data (Use and Access) Act coming into law on 19 June 2025, they are under review and may be subject to change.” We have not been able to read the register's entries in a form we could quote, so we do not say which schemes are on it. Check it directly before relying on any scheme under Article 32(3).
Cyber Essentials, ISO 27001 and the ICO
The ICO's security guidance names Cyber Essentials as the place to start: “A good starting point is to make sure that you’re in line with the requirements of Cyber Essentials – a government scheme that includes a set of basic technical controls you can put in place relatively easily.” It also warns that you may need to go further, depending on your processing.
ISO 27001 does not automatically include it. The government's procurement policy note is explicit: “The ISO27001 standard is widely used but companies that attain this standard will not automatically conform to Cyber Essentials. This is because it is not usual for all of the five technical controls in Cyber Essentials to be included in the scope for ISO27001 implementation. It is also unlikely that any of these controls will be tested for ISO27001. Therefore most businesses with ISO27001 will have to adopt Cyber Essentials in addition to ISO27001 or demonstrate equivalent controls are in place.” For a UK organisation handling personal data, the two are complementary: Cyber Essentials for a defined technical baseline, ISO 27001 for the management system around it. The comparison is set out on ISO 27001 vs Cyber Essentials.
Where ISO 27701 fits
For organisations whose main exposure is personal data, ISO/IEC 27701:2025 is the privacy management system standard, now stand-alone, and it includes a mapping to the EU GDPR. It is still an ISO standard, not an ICO-approved scheme by default, and the same Article 42 point applies. See ISO 27701 certification.
Answering a customer's data-protection questions
A certificate on its own does not answer them. The questions are about what personal data you process, where, under what security measures, with which sub-processors, and how you test those measures. An ISO 27001 management system produces most of that evidence as a by-product — for the processing inside its scope.
We do not audit, certify, consult or give legal advice, and are paid the same fixed fee per enquiry whichever firm you use. The legal text above is quoted from legislation.gov.uk; for advice on your own obligations, speak to a data protection professional.
Where this fits
Common questions
Does ISO 27001 make us GDPR compliant?
No certificate does that. UK GDPR Article 32 requires “appropriate technical and organisational measures to ensure a level of security appropriate to the risk”. An ISO 27001 management system is a structured way to decide on and run those measures, and a certificate is evidence that you do. But security is one part of UK GDPR, and a certificate does not transfer responsibility for any of it.
Is ISO 27001 an approved certification under UK GDPR?
Article 32(3) refers to “an approved certification mechanism as referred to in Article 42”, and Article 42 certification is issued on criteria approved by the Information Commissioner. Whether a given scheme is approved is on the ICO's register. The ICO's own advice: “It is important that you check carefully that the code or certification scheme has been approved by the ICO.”
What does Article 32 of UK GDPR require?
Security appropriate to the risk, taking into account the state of the art, costs, and the nature, scope, context and purposes of processing. It lists four measures “as appropriate”: pseudonymisation and encryption; ongoing confidentiality, integrity, availability and resilience; timely restoration after an incident; and a process for regularly testing and evaluating the measures.
How long does a UK GDPR certification last?
Under Article 42: “Certification shall be issued to a controller or processor for a maximum period of three years and may be renewed, under the same conditions, provided that the relevant criteria continue to be met.” ISO 27001 certificates run on their own three-year cycle under the certification-body rules, which is a separate thing.
Is Cyber Essentials enough for GDPR security?
The ICO calls it a starting point: “A good starting point is to make sure that you’re in line with the requirements of Cyber Essentials – a government scheme that includes a set of basic technical controls you can put in place relatively easily.” It adds that you may have to go beyond it depending on your processing.
Does ISO 27001 include Cyber Essentials?
Not automatically. The government's procurement policy note says ISO 27001 holders “will not automatically conform to Cyber Essentials”, because the five Cyber Essentials controls are not necessarily in an ISO 27001 scope or tested at an ISO 27001 audit.
What changed with the Data (Use and Access) Act 2025?
Among other things, the words of Article 32(3) were substituted with effect from 20 August 2025. The ICO's certification register also notes that approved schemes “are under review and may be subject to change” because of the Act.
Sources cited on this page
- UK GDPR (Regulation (EU) 2016/679 as retained), legislation.gov.uk, Articles 32 and 42
- ICO, A guide to data security
- ICO, Certification schemes register
- PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note)
- ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
- ISO/IEC 27701:2025, Privacy information management systems — Requirements and guidance, official preview (foreword, introduction, clauses 1–3, contents), read first-hand
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
A customer asked about GDPR security?
Say what they asked for and what is in your current ISO 27001 scope, if you have one.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.