ISO 27701 Explained: Extending ISO 27001 to Privacy Management
If you’ve already gone through ISO 27001, you know the drill: policies, risk assessments, an internal audit, a Statement of Applicability that never seems finished. So when someone mentions ISO 27701, the instinct is to groan a little — “another framework, another audit, another binder of documents.” The good news is that it’s smaller than it sounds. ISO 27701 doesn’t ask you to rebuild your security program; it asks you to point the one you already have at a new question: not just “is this data secure,” but “are we handling people’s personal information the way we said we would.” This guide walks through what ISO 27701 actually is, how it sits alongside ISO 27001, and a genuinely important change to how it works that most articles on this topic haven’t caught up to yet.
Quick idea: – ISO 27701 is the international standard for a Privacy Information Management System (PIMS) — a structured way to manage personal data (PII) alongside your existing information security work. It was originally built as an add-on to ISO 27001, but as of October 2025 it can also be certified entirely on its own.
- Not a rebuild: If you already run ISO 27001, most of the groundwork — risk management, internal audits, document control — already exists. ISO 27701 adds privacy-specific requirements on top.
- Built for GDPR-era scrutiny: It gives you a structured, auditable way to show regulators, customers, and partners that personal data is handled responsibly — not just secured.
- No longer locked to ISO 27001: The 2025 edition removed the old prerequisite. You can now pursue it as a standalone privacy certification if that fits your business better.
Important context: – B4Q Assurance works with SaaS companies and data processors building out privacy programs — from initial gap assessments through ISO 27701 certification, whether that’s layered on an existing ISO 27001 program or pursued as a standalone effort under the 2025 edition.
What Is ISO 27701, Really?
Strip away the acronyms and ISO 27701 is asking a fairly human question: when you collect someone’s name, email, health record, or payment details, do you actually know where it goes, who touches it, and how long you keep it? The standard formalizes that into a Privacy Information Management System, or PIMS — a set of requirements and controls for identifying privacy risk, assigning ownership for it, and proving — with evidence, not just a policy PDF — that personal data is handled the way your privacy notice says it is.
It was published in 2019, and for years it only existed as an extension: you needed ISO 27001 in place first, and 27701 bolted privacy controls on top of it. That’s still a completely valid path, and it’s still how most organizations implement it today. What changed is that it’s no longer the only path.
How It Relates to ISO 27001
Think of ISO 27001 as the foundation and ISO 27701 as a room built on top of it. ISO 27001 is about protecting information generally — whatever it is, wherever it lives. ISO 27701 narrows the focus specifically to personal data, and adds the extra governance layer that privacy laws like GDPR actually expect: things like data subject rights, retention limits, and clarity about whether you’re a controller or a processor for a given dataset.
| ISO 27001 | ISO 27701 | |
|---|---|---|
| Covers | Information security broadly — all data, all assets | Personal data (PII) specifically |
| Core question | Is this information secure? | Is this personal data handled the way we said it would be? |
| Output | Information Security Management System (ISMS) | Privacy Information Management System (PIMS) |
| Helps demonstrate | General security posture to customers, partners, auditors | GDPR-style privacy accountability to regulators and data subjects |
| Certification path (2025) | Standalone, as always | Standalone — or integrated with an existing ISMS |
The Update Most Articles Haven't Caught Up To Yet
Important context: – B4Q Assurance works with SaaS companies and data processors building out privacy programs — from initial gap assessments through ISO 27701 certification, whether that’s layered on an existing ISO 27001 program or pursued as a standalone effort under the 2025 edition.
A few things came with that shift. The clause structure was rebuilt around ISO’s newer “harmonized” format (Clauses 4–10), the same shape used by ISO 42001 and other recent management-system standards, which makes it easier to run alongside other certifications. The Annex A controls were also consolidated and reorganized around controller and processor responsibilities specifically, rather than being scattered across several clauses the way the 2019 version had them.
If you’re already certified under the 2019 edition, nothing changes overnight — there’s a three-year transition window from the October 2025 publication date, so existing certificates remain valid while certification bodies roll out audits against the new edition. If you’re starting from scratch, though, it’s worth going straight to the 2025 edition rather than building toward a version of the standard that’s already being phased out.
The practical upshot for planning purposes: “do we need ISO 27001 first” is no longer automatically yes. It depends on your situation — which the next section walks through.
Who Actually Needs This
ISO 27701 speaks in terms of two roles, and most organizations are more of one than the other:
| Role | What it means | Typical example |
|---|---|---|
| PII Controller | You decide why and how personal data is collected and used | A SaaS company collecting its own customers' account and usage data |
| PII Processor | You handle personal data on someone else's instructions | A vendor or subprocessor handling data on behalf of a SaaS client |
Plenty of companies are honestly both, depending on the dataset — controller for their own employee and customer records, processor for whatever their customers route through their platform. ISO 27701 expects you to be clear about which hat you’re wearing for each category of data, because the obligations differ.
Why This Usually Feels Bigger Than It Is
Most of the dread around a second certification isn’t really about ISO 27701 — it’s about how privacy work tends to get tracked before there’s a system for it: a spreadsheet of data flows here, a Slack thread about retention periods there, a policy doc nobody’s opened since it was written. None of that is wrong, exactly, it just doesn’t hold up well when an auditor asks you to show, not tell, how a data subject request actually gets handled.
The fix isn’t more spreadsheets, it’s consolidating what you’re already doing into the structure ISO 27701 expects — which, in practice, is most of the reason a gap analysis is the right first step rather than jumping straight to writing new policy.
Two Paths to Get There
Because the 2025 edition removed the ISO 27001 prerequisite, there are genuinely two reasonable starting points now, depending on where your organization already stands.
Path A: You Already Have ISO 27001
This is still the most common route, and it’s a shorter one — you’re extending a system that already exists rather than starting from zero.
Path B: You’re Starting Fresh Under the 2025 Edition
If you don’t have ISO 27001 yet — or you’d rather not take on two certifications at once — the standalone route follows a similar shape but stands on its own from day one.
In both cases the heaviest lift is usually the gap analysis and the risk assessment — everything after that is mostly about turning what you find into documented, evidence-backed practice.
What Happens If Privacy Stays an Afterthought
| Consequence | What it looks like |
|---|---|
| Regulatory exposure | GDPR and similar laws expect documented accountability — not having it is itself a finding, breach or not |
| Slower enterprise deals | Privacy-mature customers increasingly ask for ISO 27701 or an equivalent alongside ISO 27001 or SOC 2 |
| Duplicated effort | Teams that treat privacy and security as separate projects often rebuild the same risk registers and evidence twice |
| Weaker incident response | Without clear controller/processor ownership, a data subject request or breach takes longer to route correctly |
Why This Is Worth Doing Properly
Beyond satisfying a customer questionnaire, a real PIMS gives you something genuinely useful day to day: a clear, current answer to “where does this data live and who’s responsible for it,” instead of having to reconstruct that answer under pressure the first time a regulator or a customer actually asks.
Common Mistakes We See
- Assuming ISO 27001 is still a hard prerequisite, and ruling out ISO 27701 because of it
- Writing privacy policies before finishing the gap analysis, so the paperwork doesn’t match reality
- Never deciding clearly whether you’re a controller or processor for a given dataset
- Treating certification as the finish line instead of year-round evidence collection
- Building a brand-new 2019-style program instead of implementing directly against the 2025 edition
How B4Q Assurance Helps
B4Q Assurance works with SaaS companies and data processors building privacy programs from the ground up — running the initial gap analysis, scoping controller and processor responsibilities, and preparing teams for ISO 27701 certification, whether that’s integrated with an existing ISMS or pursued standalone under the 2025 edition.
Resources
FAQs
Do I still need ISO 27001 before I can get ISO 27701 certified?
Not anymore. The 2025 edition made ISO 27701 a standalone standard, so you can certify against it without holding ISO 27001 first. Integrating it with an existing ISMS is still a valid — and common — approach.
What happens to organizations already certified under the 2019 edition?
Existing certificates remain valid through a three-year transition window from the October 2025 publication date, giving certification bodies time to roll out audits against the new edition.
Is ISO 27701 the same as GDPR compliance?
No. It’s a structured way to demonstrate privacy accountability and can support GDPR compliance, but certification alone doesn’t satisfy every legal requirement under GDPR or other privacy laws.
How long does ISO 27701 implementation usually take?
For organizations already certified to ISO 27001, a few months is typical since most supporting processes already exist. Starting from scratch under the standalone route generally takes longer, closer to what a first ISO 27001 implementation takes.
Are we a controller or a processor?
Often both, depending on the dataset. You’re typically a controller for your own employee and customer records, and a processor for data your customers route through your platform on their own behalf.