[email protected]
Accredited Certification Body · IAS & IAF Member · Certificates Verifiable Online
HomeStandardsISO/IEC 27701

Get Your ISO/IEC 27701 Quote

Takes 30 seconds · a specialist responds within 2 business hours
Step 1 of 2
CertificationTrainingCompliance Audits
Not sure - guide me
ISO/IEC 27701
No spam. No obligation. A clear quote.
15,000+Certified Clients
30+Countries Served
IAS · IAFAccredited
ISO/IEC 27701:2019 / 2025 · Privacy Information Management

Proof that personal data is governed, not just secured when the data clause bites

ISO/IEC 27701 certifies a privacy information management system: what personal data you hold, on whose instructions, under what lawful basis, for how long, and how a data subject request or a breach is handled. It is what controllers ask processors for when a data processing agreement is on the table.

You need ISO/IEC 27701 if…

  • !A customer’s data processing agreement requires certified privacy controls, not a signed policy.
  • !A data subject access request arrived and it took three weeks to find every copy of the record.
  • !You already hold ISO/IEC 27001 and buyers are now asking specifically about personal data handling.
  • !Cross-border transfers are happening and nobody can state the mechanism relied on for each one.
  • !Retention periods are documented but never enforced, so nothing is ever actually deleted.
  • !You act as a processor for some clients and a controller for others without distinguishing the two.
What it is

A privacy management standard built on information security. It adds the duties of controllers and processors - lawful basis, purpose limitation, retention, transfers, consent and data subject rights - to the way security is already managed.

Who issues it

The 2019 edition is certified only as an extension to an ISO/IEC 27001 ISMS; the 2025 edition stands alone, with a transition period for existing certificates.

Validity

Three-year cycle with annual surveillance, normally aligned to the ISMS certificate where the two are audited together.

Who gets asked for it

Processors handling customer personal data, software and outsourcing providers, health, telecom and financial organisations, and anyone signing data processing agreements.

8of 25 industries

Where this certification is demanded

ISO/IEC 27701 is applicable across 8 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.

Defence IndustryHospitality IndustryPublic SectorTelecommunication IndustryEducation IndustryInformation Technology Industry+2 more

What ISO/IEC 27701 Actually Requires

The backbone an implementer has to build, in the order it usually gets built.

1
Controller or processor role

Decide, for each processing activity, whether you act as controller, joint controller or processor, because different obligations and different annex controls follow.

2
Records of processing

Record what personal data you process, why, on whose instruction and under what lawful basis, with the retention period stated for each purpose.

3
Privacy risk & impact

Extend the security risk assessment to risk borne by the individual, and run impact assessments where processing is large-scale, sensitive or intrusive.

4
Notice, consent & rights

Give clear privacy information, capture and honour withdrawal of consent where that is the basis, and answer access, correction, erasure and objection requests within statutory deadlines.

5
Transfers & subprocessors

Control cross-border transfers and record the mechanism used, approve subprocessors contractually, and pass down the obligations you accepted from your own customer.

6
Breach handling & evidence

Detect, assess and notify personal data breaches inside the windows regulators and customer contracts impose, and keep records proving the system operates.

How ISO/IEC 27701 Certification Works

No black box. A defined, time-bound route from first call to certificate in hand.

Application & Proposal

Scoping turns on the processing activities covered, whether you are controller or processor for each, the systems and countries involved, and whether an ISO/IEC 27001 certificate already exists.

1–2 days

Gap Review & Readiness

Someone asks for a copy of their data. Marketing has it in one tool, support in another, and a subprocessor dropped from the list two years ago still holds a backup.

1–2 weeks

Stage 1 + Stage 2 Audit

Stage 1 checks the security foundation, role determination and records of processing. Stage 2 traces a request end to end, tests deletion against retention rules, and samples transfer and subprocessor controls.

Scheduled around operations

Certificate Issued

The certificate states the privacy scope and the role you were assessed in. At surveillance, expect a real data subject request to be timed rather than the procedure read.

Valid 3 years
Where an ISO/IEC 27001 system is already certified, most organisations add the privacy extension in four to eight weeks; building both together takes ten to sixteen, and SIS can combine the audits either way.

Industries That Need ISO/IEC 27701

🛡️
Defence Industry
Open full page →
Why it applies hereDefence organisations hold service records, biometric data, medical files and vendor personnel information. ISO/IEC 27701 extends an existing ISMS into a privacy management system, mapping controls to the data protection law of each jurisdiction you operate in for personnel and veteran data. It matters most for contractors running payroll, recruitment, health or welfare systems on behalf of armed forces clients.Typical trigger: Personnel and welfare systems
🏨
Hospitality Industry
Open full page →
Why it applies hereHotels hold passport scans, card data, loyalty profiles and stay histories across PMS, booking engine and CRM systems. ISO/IEC 27701 extends information security into privacy governance with lawful basis, retention and data subject request handling, which is what corporate clients and international guests expect a global property to demonstrate.Typical trigger: Guest data; corporate client audits
🏛️
Public Sector
Open full page →
Why it applies herePublic bodies are among the largest processors of personal data and operate under the strictest expectations. ISO/IEC 27701 adds lawful basis, purpose limitation, retention and data subject rights handling onto the ISMS, evidencing national data protection obligations across citizen databases, welfare programmes and identity systems.Typical trigger: Citizen data; data protection duties
📡
Telecommunication Industry
Open full page →
Why it applies hereSubscriber data, call detail records and location history are among the most sensitive personal data any business holds. ISO/IEC 27701 adds lawful basis, retention limits, consent management and data subject rights handling to the ISMS, evidencing obligations under GDPR and the equivalent law in every market you serve, across billing, CRM and analytics platforms.Typical trigger: Subscriber privacy; cross-border duties
🎓
Education Industry
Open full page →
Why it applies hereStudent data includes minors, health information and assessment history, attracting the strictest privacy expectations. ISO/IEC 27701 adds lawful basis, consent handling for children, retention limits and data subject rights to the ISMS, covering learning platforms, admissions systems and third-party edtech vendors.Typical trigger: Children's data; edtech vendors
💻
Information Technology Industry
Open full page →
Why it applies hereTechnology firms process personal data on behalf of customers as processors and for their own purposes as controllers. ISO/IEC 27701 clarifies those roles and evidences lawful basis, retention, subprocessor control and data subject request handling, directly supporting the privacy obligations written into customer contracts in every market you sell into.Typical trigger: Processor obligations; contract clauses
🏦
Banking and Finance
Open full page →
Why it applies hereBanks hold identity documents, transaction history, credit data and biometrics across core banking, lending and marketing systems. ISO/IEC 27701 extends the ISMS into privacy governance with lawful basis, retention and data subject rights handling, evidencing data protection obligations including for outsourced processing.Typical trigger: Customer data; outsourced processing
🧳
Tourism Industries
Open full page →
Why it applies hereTraveller data includes passports, visas, health information and movement history, shared across many partners and systems. ISO/IEC 27701 adds lawful basis, retention limits, transfer controls and data subject rights handling onto the ISMS, which European partners require before exchanging traveller records.Typical trigger: European partner requirements; passport data

Commonly taken alongside

Privacy sits directly on top of information security and, increasingly, on top of AI governance, so certifying ISO/IEC 27701 with 27001 and 42001 lets SIS test the shared risk, supplier and incident processes once instead of three times.

Not Sure Which Certification You Need?

Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.

Question 1 of 3

Which sector best describes your organisation?

One audit for security and privacy, not two

Adding the privacy extension to a certified ISO/IEC 27001 system takes a fraction of the audit days a standalone privacy programme would. The risk method and supplier controls are already audited.

Get My Free Quote →

What ISO/IEC 27701 Changes for Your Business

Certification is not a certificate on the wall. It is a working system that pays for itself.

✍️

Data processing clauses get answered

Contract negotiations stop stalling on privacy annexes when the certificate and scope already evidence the controls the customer is trying to impose.

Requests answered within deadline

A tested process for locating, extracting and deleting a person’s data turns a statutory deadline from a scramble into a routine task.

🗑️

Retention actually happens

Retention rules get enforced in the systems that hold the data, which reduces both the breach exposure and the volume of any future request.

🌍

Transfers become defensible

Each cross-border flow gets a recorded mechanism and a documented assessment behind it. That is the first thing a regulator or a European customer will ask to see.

🧩

Builds on your existing system

The privacy system reuses the security risk method, asset register, supplier controls and incident process, so implementation is an extension rather than a rebuild.

🤝

Subprocessors properly controlled

Approval, contractual flow-down and ongoing monitoring of subprocessors close the gap that is most often exposed when a customer audits a processor.

Knowledge Base - Downloads

Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.

PDF GUIDE

ISO/IEC 27701 implementation guide for both editions

How the controller and processor annexes translate into working practice, and what changes under the standalone 2025 edition.

TEMPLATE

Records of processing activities register

Fields covering purpose, categories, lawful basis, recipients, transfers, retention and role, structured so an auditor can sample it.

CHECKLIST

Data subject request handling checklist

Identity verification, system-by-system search, backups, exemptions, redaction and the statutory clock, laid out as a procedure an auditor can follow.

WHITEPAPER

Certifying privacy when you are a processor

What customers actually test during processor audits, where processors most often fail them, and how a certified privacy system shortens those reviews.

🔒 Documents are locked. Fill the form once to unlock every download.

Frequently Asked Questions

Straight answers to what buyers ask before they commit to ISO/IEC 27701.

Do we need ISO/IEC 27001 before we can certify 27701?
Under the 2019 edition, yes: it is written as an extension and is certified alongside an ISO/IEC 27001 ISMS. The 2025 edition restructures the standard so a privacy management system can be implemented and certified on its own, with a transition period for existing certificates. Most organisations still run both, because privacy controls depend on security controls anyway.
Does ISO/IEC 27701 make us GDPR compliant?
It does not confer legal compliance, and no certification body can grant that. What it provides is the operational system the law assumes: records of processing, lawful basis, retention, transfer controls, rights handling and breach response, all independently audited. Certification is strong evidence of accountability, but specific legal questions remain for your legal advisers to answer.
How does the standard treat the controller and processor distinction?
It is the first thing determined, because the annexes differ. Controllers carry duties around lawful basis, notice, consent and rights. Processors carry duties around acting on documented instructions, assisting the controller, controlling subprocessors and returning or deleting data at the end. Many organisations are both, for different activities, and the system must state which is which.
What does the auditor test on data subject requests?
They will take a real request and follow it: how identity was verified, which systems were searched including backups and third parties, what was withheld and on what ground, when the response went out against the statutory clock, and what record remains. If no request has ever arrived, expect them to ask you to run the process as an exercise.
Can the privacy certificate be audited at the same time as security?
Yes, and it usually should be. The clauses on context, leadership, competence, internal audit and management review are common, and the asset, supplier and incident evidence overlaps heavily. SIS combines the audits into one visit with a single report structure, which is materially cheaper than commissioning the two assessments separately.
What does the certificate scope actually say?
It names the processing activities and services covered, the sites, and the role you hold for them. Precision matters here more than in most standards, because a customer reading the certificate wants to know whether their processing sits inside the boundary. SIS will not issue a scope that reads more broadly than what was audited.
Email Us
✉ EmailGet Quote