ISO 27701 certification: the 2025 stand-alone edition, and how it sits with ISO 27001
ISO/IEC 27701:2025, foreword: “the document has been redrafted as a stand-alone management system standard.” Its only normative reference is ISO/IEC 29100, the privacy framework — not ISO/IEC 27001.
ISO 27701 used to be discussed as an add-on to ISO 27001. The 2025 edition changed its shape: it is now a complete management system standard of its own, for organisations that control or process personal data. This page sets out what it certifies, what changed, who audits it, and where ISO 27001 and UK GDPR fit, quoting the standards rather than summarising them.
ISO 27701 and ISO 27001, side by side
| ISO/IEC 27701:2025 | ISO/IEC 27001 | |
|---|---|---|
| What it certifies | A privacy information management system (PIMS) | An information security management system (ISMS) |
| Scope, in its own words | “This document specifies requirements for establishing, implementing, maintaining and continually improving a privacy information management system (PIMS).” | Requirements for an information security management system |
| Who it is for | PII controllers and PII processors | Any organisation |
| Edition | ISO/IEC 27701:2025 (second edition) | ISO/IEC 27001:2022 |
| Stand-alone? | Yes — “redrafted as a stand-alone management system standard” | Yes |
| Normative reference | ISO/IEC 29100 (privacy framework) | ISO/IEC 27000 |
| Risk | Privacy risk assessment and treatment (6.1.2, 6.1.3, 8.2, 8.3) | Information security risk assessment and treatment (6.1.2, 6.1.3, 8.2, 8.3) |
| Controls | Annex A: PIMS reference controls for controllers and processors | Annex A: 93 information security controls |
| Rules for certification bodies | ISO/IEC 27706:2025 | ISO/IEC 27006 |
What ISO 27701:2025 is
“This document specifies requirements for establishing, implementing, maintaining and continually improving a privacy information management system (PIMS).” And for whom: “This document is intended for personally identifiable information (PII) controllers and PII processors holding responsibility and accountability for PII processing.”
“This second edition cancels and replaces the first edition (ISO/IEC 27701:2019), which has been technically revised.” The foreword lists one main change — the redraft as a stand-alone management system standard — and the contents show what that means: clauses 4 to 10 with the same headings as every other harmonized-structure standard, including its own risk process.
| Clause | Title |
|---|---|
| 6.1.2 | Privacy risk assessment |
| 6.1.3 | Privacy risk treatment |
| 8.2 | Privacy risk assessment |
| 8.3 | Privacy risk treatment |
The annexes
| Annex | Title |
|---|---|
| A (normative) | PIMS reference control objectives and controls for PII controllers and PII processors |
| B (normative) | Implementation guidance for PII controllers and PII processors |
| C (informative) | Mapping to ISO/IEC 29100 |
| D (informative) | Mapping to the General Data Protection Regulation |
| E (informative) | Mapping to ISO/IEC 27018 and ISO/IEC 29151 |
| F (informative) | Correspondence with ISO/IEC 27701:2019 |
Annex A is normative — the reference control objectives and controls you are audited against, set separately for controllers and processors — and Annex B gives implementation guidance. The mappings in Annexes C to E are informative.
The mappings, including GDPR
The introduction says the document includes mapping to:
- the privacy framework and principles defined in ISO/IEC 29100
- ISO/IEC 27018
- ISO/IEC 29151
- the EU General Data Protection Regulation
“These mappings can be interpreted to take into account local legal requirements.” The mapping is to the EU regulation; for a UK organisation the law that applies is UK GDPR, and the note is the standard's own reminder to read the mapping with that in mind.
How ISO 27701 is certified
The rules for certification bodies have a new home. “This first edition of ISO/IEC 27706 cancels and replaces ISO/IEC TS 27006-2:2021, which has been technically revised.” Its foreword lists the main changes:
- the title has been modified
- the clause numbering has been aligned to ISO/IEC 17021 rather than ISO/IEC 27006-1, in accordance with ISO/IEC 27701
- Annexes A, B and C have been added
So ISO/IEC 27706's clauses are numbered like ISO/IEC 17021-1's, the standard every management system certification body works to. ISO/IEC 27706 has its own clauses on PIMS certification documents (8.2.2) and on determining audit time (9.1.4); we have seen the clause titles, not their text, so we do not quote audit-day figures for 27701.
What a certificate is evidence of
The standard puts it modestly: “By complying with the requirements in this document, an organization can generate evidence of how it handles the processing of PII.” That evidence can support agreements with customers and partners who need to know how you handle personal data. It is not a legal finding.
ISO 27701 and ISO 27001 together
“This document enables an organization to align or integrate its privacy information management system (PIMS) with the requirements of other management system standards, and in particular with the information security management system specified in ISO/IEC 27001.” Both follow the harmonized structure, so a combined management system — one policy framework, one internal audit programme, one management review, two sets of risk and controls — is the natural design for an organisation that needs both.
The audit-time rule for integrated audits applies here too: each standard's time is calculated separately and added up, and any reduction for integration “shall not exceed 20% from the starting point”. See integrated management systems.
ISO 27701 and UK GDPR
UK GDPR Article 32(3) names “an approved certification mechanism as referred to in Article 42” as a means of demonstrating compliance with the security requirement. Article 42 certification is issued “on the basis of criteria approved by” the Information Commissioner, and “A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation”.
ISO/IEC 27701 is an international standard; whether a particular certification scheme is an ICO-approved Article 42 mechanism is a matter for the ICO's register. The ICO's own advice: “It is important that you check carefully that the code or certification scheme has been approved by the ICO.” The full picture for ISO 27001 is on ISO 27001 and UK GDPR.
Not stated here, because we have not found it
How and by when ISO/IEC 27701:2019 certificates move to the 2025 edition. Transition arrangements are set by the accreditation system; ask your certification body.
We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever certification body or consultancy you use. The standards are sold by ISO; everything quoted above is from their official previews.
Where this fits
Common questions
What is ISO 27701 certification?
Certification of a privacy information management system against ISO/IEC 27701 by a certification body. The standard “specifies requirements for establishing, implementing, maintaining and continually improving a privacy information management system (PIMS).” It is written for organisations that act as PII controllers or PII processors.
Do you need ISO 27001 to get ISO 27701 certified?
Under the 2025 edition, the standard itself no longer depends on ISO 27001: its foreword says it “the document has been redrafted as a stand-alone management system standard”, and its only normative reference is ISO/IEC 29100. That is our reading of the text; how a particular certification body scopes a 27701 audit is a question to put to it.
What changed in ISO 27701:2025?
“This second edition cancels and replaces the first edition (ISO/IEC 27701:2019), which has been technically revised.” The one main change it lists is that the document was redrafted as a stand-alone management system standard. It now has the familiar clause 4–10 structure, with its own privacy risk assessment and treatment.
Does ISO 27701 certification mean we comply with GDPR?
No certificate does that on its own. ISO/IEC 27701:2025 includes a mapping to the EU General Data Protection Regulation and notes that the mappings “can be interpreted to take into account local legal requirements”. Under UK GDPR, only a certification mechanism approved under Article 42 is named as a means of demonstrating compliance with the security requirement, and even that “does not reduce the responsibility of the controller or the processor”.
Who audits ISO 27701?
An accredited certification body, working to ISO/IEC 27706:2025 — a new standard that “cancels and replaces ISO/IEC TS 27006-2:2021”, with clause numbering aligned to ISO/IEC 17021.
Can ISO 27701 be integrated with ISO 27001?
Yes, and the standard is written for it: “This document enables an organization to align or integrate its privacy information management system (PIMS) with the requirements of other management system standards, and in particular with the information security management system specified in ISO/IEC 27001.”
What happens to certificates issued against ISO 27701:2019?
The transition arrangements are set by the accreditation system, and we have not found them published, so we do not state a date. Ask your certification body.
Sources cited on this page
- ISO/IEC 27701:2025, Privacy information management systems — Requirements and guidance, official preview (foreword, introduction, clauses 1–3, contents), read first-hand
- ISO/IEC 27706:2025, requirements for bodies certifying privacy information management systems, official preview (foreword, contents), read first-hand
- ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
- UK GDPR (Regulation (EU) 2016/679 as retained), legislation.gov.uk, Articles 32 and 42
- IAF MD 11:2023, Application of ISO/IEC 17021-1 for Audits of Integrated Management Systems (Issue 3)
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Considering ISO 27701?
Say whether you already hold ISO 27001, and whether you act as a controller, a processor or both.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.