Get Your ISO/IEC 27701 Quote
Proof that personal data is governed, not just secured when the data clause bites
ISO/IEC 27701 certifies a privacy information management system: what personal data you hold, on whose instructions, under what lawful basis, for how long, and how a data subject request or a breach is handled. It is what controllers ask processors for when a data processing agreement is on the table.
You need ISO/IEC 27701 if…
- !A customer’s data processing agreement requires certified privacy controls, not a signed policy.
- !A data subject access request arrived and it took three weeks to find every copy of the record.
- !You already hold ISO/IEC 27001 and buyers are now asking specifically about personal data handling.
- !Cross-border transfers are happening and nobody can state the mechanism relied on for each one.
- !Retention periods are documented but never enforced, so nothing is ever actually deleted.
- !You act as a processor for some clients and a controller for others without distinguishing the two.
A privacy management standard built on information security. It adds the duties of controllers and processors - lawful basis, purpose limitation, retention, transfers, consent and data subject rights - to the way security is already managed.
The 2019 edition is certified only as an extension to an ISO/IEC 27001 ISMS; the 2025 edition stands alone, with a transition period for existing certificates.
Three-year cycle with annual surveillance, normally aligned to the ISMS certificate where the two are audited together.
Processors handling customer personal data, software and outsourcing providers, health, telecom and financial organisations, and anyone signing data processing agreements.
Where this certification is demanded
ISO/IEC 27701 is applicable across 8 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What ISO/IEC 27701 Actually Requires
The backbone an implementer has to build, in the order it usually gets built.
Decide, for each processing activity, whether you act as controller, joint controller or processor, because different obligations and different annex controls follow.
Record what personal data you process, why, on whose instruction and under what lawful basis, with the retention period stated for each purpose.
Extend the security risk assessment to risk borne by the individual, and run impact assessments where processing is large-scale, sensitive or intrusive.
Give clear privacy information, capture and honour withdrawal of consent where that is the basis, and answer access, correction, erasure and objection requests within statutory deadlines.
Control cross-border transfers and record the mechanism used, approve subprocessors contractually, and pass down the obligations you accepted from your own customer.
Detect, assess and notify personal data breaches inside the windows regulators and customer contracts impose, and keep records proving the system operates.
How ISO/IEC 27701 Certification Works
No black box. A defined, time-bound route from first call to certificate in hand.
Application & Proposal
Scoping turns on the processing activities covered, whether you are controller or processor for each, the systems and countries involved, and whether an ISO/IEC 27001 certificate already exists.
1–2 daysGap Review & Readiness
Someone asks for a copy of their data. Marketing has it in one tool, support in another, and a subprocessor dropped from the list two years ago still holds a backup.
1–2 weeksStage 1 + Stage 2 Audit
Stage 1 checks the security foundation, role determination and records of processing. Stage 2 traces a request end to end, tests deletion against retention rules, and samples transfer and subprocessor controls.
Scheduled around operationsCertificate Issued
The certificate states the privacy scope and the role you were assessed in. At surveillance, expect a real data subject request to be timed rather than the procedure read.
Valid 3 yearsIndustries That Need ISO/IEC 27701
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
One audit for security and privacy, not two
Adding the privacy extension to a certified ISO/IEC 27001 system takes a fraction of the audit days a standalone privacy programme would. The risk method and supplier controls are already audited.
Get My Free Quote →What ISO/IEC 27701 Changes for Your Business
Certification is not a certificate on the wall. It is a working system that pays for itself.
Data processing clauses get answered
Contract negotiations stop stalling on privacy annexes when the certificate and scope already evidence the controls the customer is trying to impose.
Requests answered within deadline
A tested process for locating, extracting and deleting a person’s data turns a statutory deadline from a scramble into a routine task.
Retention actually happens
Retention rules get enforced in the systems that hold the data, which reduces both the breach exposure and the volume of any future request.
Transfers become defensible
Each cross-border flow gets a recorded mechanism and a documented assessment behind it. That is the first thing a regulator or a European customer will ask to see.
Builds on your existing system
The privacy system reuses the security risk method, asset register, supplier controls and incident process, so implementation is an extension rather than a rebuild.
Subprocessors properly controlled
Approval, contractual flow-down and ongoing monitoring of subprocessors close the gap that is most often exposed when a customer audits a processor.
Knowledge Base - Downloads
Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.
ISO/IEC 27701 implementation guide for both editions
How the controller and processor annexes translate into working practice, and what changes under the standalone 2025 edition.
Records of processing activities register
Fields covering purpose, categories, lawful basis, recipients, transfers, retention and role, structured so an auditor can sample it.
Data subject request handling checklist
Identity verification, system-by-system search, backups, exemptions, redaction and the statutory clock, laid out as a procedure an auditor can follow.
Certifying privacy when you are a processor
What customers actually test during processor audits, where processors most often fail them, and how a certified privacy system shortens those reviews.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to ISO/IEC 27701.
Do we need ISO/IEC 27001 before we can certify 27701?
Does ISO/IEC 27701 make us GDPR compliant?
How does the standard treat the controller and processor distinction?
What does the auditor test on data subject requests?
Can the privacy certificate be audited at the same time as security?
What does the certificate scope actually say?
Start ISO/IEC 27701 certification with an accredited body
Rights handling and retention get tested in the live systems, not in the procedure. That is the difference between a certificate a customer accepts and one they query.
Get My Free Quote → WhatsApp Us