ISO/IEC 27701 extends an ISO 27001 information security management system into a Privacy Information Management System (PIMS). It is the answer to a specific problem: privacy law tells you what outcomes to achieve, but not how to run a management system that reliably achieves them - and no privacy law is certifiable.
It is an extension, not a standalone
You cannot certify to ISO 27701 on its own. It sits on top of ISO 27001, either certified together or added to an existing certificate. That dependency is deliberate: privacy protection without information security is not achievable, so the security management system is the foundation.
Practically, if you already hold ISO 27001, adding 27701 is an extension exercise rather than a new programme.
What it adds
- Privacy-specific extensions to the ISO 27001 clauses and Annex A controls - reinterpreting them through a privacy lens.
- Controller-specific controls - lawful basis, purpose determination, consent handling, transparency, data subject rights, privacy by design, records of processing, and transfers.
- Processor-specific controls - acting only on documented instructions, supporting the controller's obligations, subprocessor management, and return or deletion at the end of the relationship.
- Role clarity. You declare whether you act as controller, processor, or both - and the applicable control set follows.
The controller/processor split is the most useful part in practice. Many organisations are both, in different processing activities - and 27701 forces you to be explicit about which, per activity, rather than leaving it ambiguous in contracts.
Extend your ISMS into privacy
GRC Copilot maps ISO 27701 alongside your ISO 27001 controls and your GDPR and PDPL obligations - reusing the security evidence you already hold and showing only the privacy delta.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Why organisations pursue it
- It answers privacy due diligence. Enterprise buyers increasingly ask how you manage privacy, not just security. A certificate answers that in one artefact.
- It is jurisdiction-flexible. The same PIMS supports GDPR, the Saudi PDPL and other regimes, because it structures the management system rather than encoding one law.
- It demonstrates accountability - which most privacy regimes require you to be able to evidence, not merely assert.
- It reduces duplicated effort where security and privacy teams were maintaining parallel documentation.
What it does not do
Certification does not make you compliant with any privacy law. Regulators do not recognise it as a compliance determination. What it provides is a well-evidenced management system that makes demonstrating compliance far more straightforward - and that distinction matters when a customer asks whether ISO 27701 means you are "GDPR certified". It does not, and no such certification exists.
Practical path
- Confirm your ISO 27001 scope - the PIMS scope sits within or alongside it.
- Determine your roles per processing activity: controller, processor, or both.
- Build or extend your records of processing - this is the backbone artefact for both 27701 and privacy law.
- Map the additional controls for your declared roles onto your existing control library.
- Close the privacy delta - typically rights handling, transfers, retention enforcement and subprocessor management.
- Run the internal audit and management review covering the privacy extension.
- Certify alongside your ISO 27001 surveillance or recertification to reduce audit overhead.
Frequently asked questions
Can we certify to ISO 27701 without ISO 27001?
No. It is an extension and requires the ISO 27001 management system, either certified simultaneously or already in place.
Does ISO 27701 mean we are GDPR compliant?
No. There is no GDPR certification. It demonstrates a managed, evidenced privacy system, which supports your accountability obligations but is not a legal determination.
How much extra work is it over ISO 27001?
For organisations with mature privacy practices, moderate - mostly documentation and role clarity. For those with an ISMS but little privacy structure, the records of processing and rights handling are usually the largest gaps.
Does it help with the Saudi PDPL?
Yes. Because it structures a privacy management system rather than encoding one jurisdiction, the same PIMS supports PDPL obligations - though transfer rules must still be addressed specifically.
Key takeaways
- ISO 27701 extends ISO 27001; it cannot be certified alone.
- Controller and processor roles determine which controls apply - declare them per activity.
- It supports GDPR and PDPL accountability without being a legal compliance determination.
- Records of processing and rights handling are the usual gaps.