ISO 27701 Explained: Extending ISO 27001 to Privacy Management (2026 Update)

ISO 27701 Explained: Extending ISO 27001 to Privacy Management

If you’ve already gone through ISO 27001, you know the drill: policies, risk assessments, an internal audit, a Statement of Applicability that never seems finished. So when someone mentions ISO 27701, the instinct is to groan a little — “another framework, another audit, another binder of documents.” The good news is that it’s smaller than it sounds. ISO 27701 doesn’t ask you to rebuild your security program; it asks you to point the one you already have at a new question: not just “is this data secure,” but “are we handling people’s personal information the way we said we would.” This guide walks through what ISO 27701 actually is, how it sits alongside ISO 27001, and a genuinely important change to how it works that most articles on this topic haven’t caught up to yet.

Quick idea: – ISO 27701 is the international standard for a Privacy Information Management System (PIMS) — a structured way to manage personal data (PII) alongside your existing information security work. It was originally built as an add-on to ISO 27001, but as of October 2025 it can also be certified entirely on its own.

  • Not a rebuild: If you already run ISO 27001, most of the groundwork — risk management, internal audits, document control — already exists. ISO 27701 adds privacy-specific requirements on top.
  • Built for GDPR-era scrutiny: It gives you a structured, auditable way to show regulators, customers, and partners that personal data is handled responsibly — not just secured.
  • No longer locked to ISO 27001: The 2025 edition removed the old prerequisite. You can now pursue it as a standalone privacy certification if that fits your business better.

Important context: – B4Q Assurance works with SaaS companies and data processors building out privacy programs — from initial gap assessments through ISO 27701 certification, whether that’s layered on an existing ISO 27001 program or pursued as a standalone effort under the 2025 edition.

iso 27701 explained

What Is ISO 27701, Really?

Strip away the acronyms and ISO 27701 is asking a fairly human question: when you collect someone’s name, email, health record, or payment details, do you actually know where it goes, who touches it, and how long you keep it? The standard formalizes that into a Privacy Information Management System, or PIMS — a set of requirements and controls for identifying privacy risk, assigning ownership for it, and proving — with evidence, not just a policy PDF — that personal data is handled the way your privacy notice says it is.

It was published in 2019, and for years it only existed as an extension: you needed ISO 27001 in place first, and 27701 bolted privacy controls on top of it. That’s still a completely valid path, and it’s still how most organizations implement it today. What changed is that it’s no longer the only path.

How It Relates to ISO 27001

Think of ISO 27001 as the foundation and ISO 27701 as a room built on top of it. ISO 27001 is about protecting information generally — whatever it is, wherever it lives. ISO 27701 narrows the focus specifically to personal data, and adds the extra governance layer that privacy laws like GDPR actually expect: things like data subject rights, retention limits, and clarity about whether you’re a controller or a processor for a given dataset.

ISO 27001 vs ISO 27701
ISO 27001 ISO 27701
Covers Information security broadly — all data, all assets Personal data (PII) specifically
Core question Is this information secure? Is this personal data handled the way we said it would be?
Output Information Security Management System (ISMS) Privacy Information Management System (PIMS)
Helps demonstrate General security posture to customers, partners, auditors GDPR-style privacy accountability to regulators and data subjects
Certification path (2025) Standalone, as always Standalone — or integrated with an existing ISMS

The Update Most Articles Haven't Caught Up To Yet

Important context: – B4Q Assurance works with SaaS companies and data processors building out privacy programs — from initial gap assessments through ISO 27701 certification, whether that’s layered on an existing ISO 27001 program or pursued as a standalone effort under the 2025 edition.

A few things came with that shift. The clause structure was rebuilt around ISO’s newer “harmonized” format (Clauses 4–10), the same shape used by ISO 42001 and other recent management-system standards, which makes it easier to run alongside other certifications. The Annex A controls were also consolidated and reorganized around controller and processor responsibilities specifically, rather than being scattered across several clauses the way the 2019 version had them.

If you’re already certified under the 2019 edition, nothing changes overnight — there’s a three-year transition window from the October 2025 publication date, so existing certificates remain valid while certification bodies roll out audits against the new edition. If you’re starting from scratch, though, it’s worth going straight to the 2025 edition rather than building toward a version of the standard that’s already being phased out.

The practical upshot for planning purposes: “do we need ISO 27001 first” is no longer automatically yes. It depends on your situation — which the next section walks through.

Who Actually Needs This

ISO 27701 speaks in terms of two roles, and most organizations are more of one than the other:

PII Controller vs PII Processor
Role What it means Typical example
PII Controller You decide why and how personal data is collected and used A SaaS company collecting its own customers' account and usage data
PII Processor You handle personal data on someone else's instructions A vendor or subprocessor handling data on behalf of a SaaS client

Plenty of companies are honestly both, depending on the dataset — controller for their own employee and customer records, processor for whatever their customers route through their platform. ISO 27701 expects you to be clear about which hat you’re wearing for each category of data, because the obligations differ.

iso 27701 explained

Why This Usually Feels Bigger Than It Is

Most of the dread around a second certification isn’t really about ISO 27701 — it’s about how privacy work tends to get tracked before there’s a system for it: a spreadsheet of data flows here, a Slack thread about retention periods there, a policy doc nobody’s opened since it was written. None of that is wrong, exactly, it just doesn’t hold up well when an auditor asks you to show, not tell, how a data subject request actually gets handled.

 The fix isn’t more spreadsheets, it’s consolidating what you’re already doing into the structure ISO 27701 expects — which, in practice, is most of the reason a gap analysis is the right first step rather than jumping straight to writing new policy.

Two Paths to Get There

Because the 2025 edition removed the ISO 27001 prerequisite, there are genuinely two reasonable starting points now, depending on where your organization already stands.

Path A: You Already Have ISO 27001

This is still the most common route, and it’s a shorter one — you’re extending a system that already exists rather than starting from zero.

 Path B: You’re Starting Fresh Under the 2025 Edition

If you don’t have ISO 27001 yet — or you’d rather not take on two certifications at once — the standalone route follows a similar shape but stands on its own from day one.

 In both cases the heaviest lift is usually the gap analysis and the risk assessment — everything after that is mostly about turning what you find into documented, evidence-backed practice.

What Happens If Privacy Stays an Afterthought

Consequences of Getting Privacy Roles Wrong
Consequence What it looks like
Regulatory exposure GDPR and similar laws expect documented accountability — not having it is itself a finding, breach or not
Slower enterprise deals Privacy-mature customers increasingly ask for ISO 27701 or an equivalent alongside ISO 27001 or SOC 2
Duplicated effort Teams that treat privacy and security as separate projects often rebuild the same risk registers and evidence twice
Weaker incident response Without clear controller/processor ownership, a data subject request or breach takes longer to route correctly

Why This Is Worth Doing Properly

Beyond satisfying a customer questionnaire, a real PIMS gives you something genuinely useful day to day: a clear, current answer to “where does this data live and who’s responsible for it,” instead of having to reconstruct that answer under pressure the first time a regulator or a customer actually asks.

Common Mistakes We See

  • Assuming ISO 27001 is still a hard prerequisite, and ruling out ISO 27701 because of it
  • Writing privacy policies before finishing the gap analysis, so the paperwork doesn’t match reality
  • Never deciding clearly whether you’re a controller or processor for a given dataset
  • Treating certification as the finish line instead of year-round evidence collection
  • Building a brand-new 2019-style program instead of implementing directly against the 2025 edition
iso 27701 explained

How B4Q Assurance Helps

B4Q Assurance works with SaaS companies and data processors building privacy programs from the ground up — running the initial gap analysis, scoping controller and processor responsibilities, and preparing teams for ISO 27701 certification, whether that’s integrated with an existing ISMS or pursued standalone under the 2025 edition.

Resources

FAQs

Do I still need ISO 27001 before I can get ISO 27701 certified?

Not anymore. The 2025 edition made ISO 27701 a standalone standard, so you can certify against it without holding ISO 27001 first. Integrating it with an existing ISMS is still a valid — and common — approach.

Existing certificates remain valid through a three-year transition window from the October 2025 publication date, giving certification bodies time to roll out audits against the new edition.

 

No. It’s a structured way to demonstrate privacy accountability and can support GDPR compliance, but certification alone doesn’t satisfy every legal requirement under GDPR or other privacy laws.

For organizations already certified to ISO 27001, a few months is typical since most supporting processes already exist. Starting from scratch under the standalone route generally takes longer, closer to what a first ISO 27001 implementation takes.

Often both, depending on the dataset. You’re typically a controller for your own employee and customer records, and a processor for data your customers route through your platform on their own behalf.

What do you think?