iso27001partnersUK certification, costed Get a cost estimate

ISO 27701 certification: the 2025 stand-alone edition, and how it sits with ISO 27001

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 8 min read
5 primary sources cited on this page. How we check what is on this site
The change that matters A stand-alone standard since 2025

ISO/IEC 27701:2025, foreword: “the document has been redrafted as a stand-alone management system standard.” Its only normative reference is ISO/IEC 29100, the privacy framework — not ISO/IEC 27001.

ISO 27701 used to be discussed as an add-on to ISO 27001. The 2025 edition changed its shape: it is now a complete management system standard of its own, for organisations that control or process personal data. This page sets out what it certifies, what changed, who audits it, and where ISO 27001 and UK GDPR fit, quoting the standards rather than summarising them.

ISO 27701 and ISO 27001, side by side

ISO/IEC 27701:2025 and ISO/IEC 27001:2022 compared
ISO/IEC 27701:2025ISO/IEC 27001
What it certifiesA privacy information management system (PIMS)An information security management system (ISMS)
Scope, in its own words“This document specifies requirements for establishing, implementing, maintaining and continually improving a privacy information management system (PIMS).”Requirements for an information security management system
Who it is forPII controllers and PII processorsAny organisation
EditionISO/IEC 27701:2025 (second edition)ISO/IEC 27001:2022
Stand-alone?Yes — “redrafted as a stand-alone management system standard”Yes
Normative referenceISO/IEC 29100 (privacy framework)ISO/IEC 27000
RiskPrivacy risk assessment and treatment (6.1.2, 6.1.3, 8.2, 8.3)Information security risk assessment and treatment (6.1.2, 6.1.3, 8.2, 8.3)
ControlsAnnex A: PIMS reference controls for controllers and processorsAnnex A: 93 information security controls
Rules for certification bodiesISO/IEC 27706:2025ISO/IEC 27006

What ISO 27701:2025 is

“This document specifies requirements for establishing, implementing, maintaining and continually improving a privacy information management system (PIMS).” And for whom: “This document is intended for personally identifiable information (PII) controllers and PII processors holding responsibility and accountability for PII processing.”

“This second edition cancels and replaces the first edition (ISO/IEC 27701:2019), which has been technically revised.” The foreword lists one main change — the redraft as a stand-alone management system standard — and the contents show what that means: clauses 4 to 10 with the same headings as every other harmonized-structure standard, including its own risk process.

Privacy risk clauses in ISO/IEC 27701:2025 (from its contents)
ClauseTitle
6.1.2Privacy risk assessment
6.1.3Privacy risk treatment
8.2Privacy risk assessment
8.3Privacy risk treatment

The annexes

Annexes of ISO/IEC 27701:2025 (from its contents)
AnnexTitle
A (normative)PIMS reference control objectives and controls for PII controllers and PII processors
B (normative)Implementation guidance for PII controllers and PII processors
C (informative)Mapping to ISO/IEC 29100
D (informative)Mapping to the General Data Protection Regulation
E (informative)Mapping to ISO/IEC 27018 and ISO/IEC 29151
F (informative)Correspondence with ISO/IEC 27701:2019

Annex A is normative — the reference control objectives and controls you are audited against, set separately for controllers and processors — and Annex B gives implementation guidance. The mappings in Annexes C to E are informative.

The mappings, including GDPR

The introduction says the document includes mapping to:

  • the privacy framework and principles defined in ISO/IEC 29100
  • ISO/IEC 27018
  • ISO/IEC 29151
  • the EU General Data Protection Regulation

“These mappings can be interpreted to take into account local legal requirements.” The mapping is to the EU regulation; for a UK organisation the law that applies is UK GDPR, and the note is the standard's own reminder to read the mapping with that in mind.

How ISO 27701 is certified

The rules for certification bodies have a new home. “This first edition of ISO/IEC 27706 cancels and replaces ISO/IEC TS 27006-2:2021, which has been technically revised.” Its foreword lists the main changes:

  • the title has been modified
  • the clause numbering has been aligned to ISO/IEC 17021 rather than ISO/IEC 27006-1, in accordance with ISO/IEC 27701
  • Annexes A, B and C have been added

So ISO/IEC 27706's clauses are numbered like ISO/IEC 17021-1's, the standard every management system certification body works to. ISO/IEC 27706 has its own clauses on PIMS certification documents (8.2.2) and on determining audit time (9.1.4); we have seen the clause titles, not their text, so we do not quote audit-day figures for 27701.

What a certificate is evidence of

The standard puts it modestly: “By complying with the requirements in this document, an organization can generate evidence of how it handles the processing of PII.” That evidence can support agreements with customers and partners who need to know how you handle personal data. It is not a legal finding.

ISO 27701 and ISO 27001 together

“This document enables an organization to align or integrate its privacy information management system (PIMS) with the requirements of other management system standards, and in particular with the information security management system specified in ISO/IEC 27001.” Both follow the harmonized structure, so a combined management system — one policy framework, one internal audit programme, one management review, two sets of risk and controls — is the natural design for an organisation that needs both.

The audit-time rule for integrated audits applies here too: each standard's time is calculated separately and added up, and any reduction for integration “shall not exceed 20% from the starting point”. See integrated management systems.

ISO 27701 and UK GDPR

UK GDPR Article 32(3) names “an approved certification mechanism as referred to in Article 42” as a means of demonstrating compliance with the security requirement. Article 42 certification is issued “on the basis of criteria approved by” the Information Commissioner, and “A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation”.

ISO/IEC 27701 is an international standard; whether a particular certification scheme is an ICO-approved Article 42 mechanism is a matter for the ICO's register. The ICO's own advice: “It is important that you check carefully that the code or certification scheme has been approved by the ICO.” The full picture for ISO 27001 is on ISO 27001 and UK GDPR.

Not stated here, because we have not found it

How and by when ISO/IEC 27701:2019 certificates move to the 2025 edition. Transition arrangements are set by the accreditation system; ask your certification body.

We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever certification body or consultancy you use. The standards are sold by ISO; everything quoted above is from their official previews.

Where this fits

Common questions

What is ISO 27701 certification?

Certification of a privacy information management system against ISO/IEC 27701 by a certification body. The standard “specifies requirements for establishing, implementing, maintaining and continually improving a privacy information management system (PIMS).” It is written for organisations that act as PII controllers or PII processors.

Do you need ISO 27001 to get ISO 27701 certified?

Under the 2025 edition, the standard itself no longer depends on ISO 27001: its foreword says it “the document has been redrafted as a stand-alone management system standard”, and its only normative reference is ISO/IEC 29100. That is our reading of the text; how a particular certification body scopes a 27701 audit is a question to put to it.

What changed in ISO 27701:2025?

“This second edition cancels and replaces the first edition (ISO/IEC 27701:2019), which has been technically revised.” The one main change it lists is that the document was redrafted as a stand-alone management system standard. It now has the familiar clause 4–10 structure, with its own privacy risk assessment and treatment.

Does ISO 27701 certification mean we comply with GDPR?

No certificate does that on its own. ISO/IEC 27701:2025 includes a mapping to the EU General Data Protection Regulation and notes that the mappings “can be interpreted to take into account local legal requirements”. Under UK GDPR, only a certification mechanism approved under Article 42 is named as a means of demonstrating compliance with the security requirement, and even that “does not reduce the responsibility of the controller or the processor”.

Who audits ISO 27701?

An accredited certification body, working to ISO/IEC 27706:2025 — a new standard that “cancels and replaces ISO/IEC TS 27006-2:2021”, with clause numbering aligned to ISO/IEC 17021.

Can ISO 27701 be integrated with ISO 27001?

Yes, and the standard is written for it: “This document enables an organization to align or integrate its privacy information management system (PIMS) with the requirements of other management system standards, and in particular with the information security management system specified in ISO/IEC 27001.”

What happens to certificates issued against ISO 27701:2019?

The transition arrangements are set by the accreditation system, and we have not found them published, so we do not state a date. Ask your certification body.

Sources cited on this page

  1. ISO/IEC 27701:2025, Privacy information management systems — Requirements and guidance, official preview (foreword, introduction, clauses 1–3, contents), read first-hand
  2. ISO/IEC 27706:2025, requirements for bodies certifying privacy information management systems, official preview (foreword, contents), read first-hand
  3. ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
  4. UK GDPR (Regulation (EU) 2016/679 as retained), legislation.gov.uk, Articles 32 and 42
  5. IAF MD 11:2023, Application of ISO/IEC 17021-1 for Audits of Integrated Management Systems (Issue 3)

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Considering ISO 27701?

Say whether you already hold ISO 27001, and whether you act as a controller, a processor or both.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now