Skip to content
Oluma Cyber Security Awareness
Standard · Certifiable Privacy

ISO/IEC 27701

The privacy sibling of ISO 27001 — and as of 2025, a standalone, certifiable privacy management system you can earn on its own. The way to prove you manage personal data, not just secure it.

2025 editionStandalone PIMSAnnex A/B controlsGDPR aligned
01 The Problem

Securing data isn’t the same as managing privacy

ISO 27001 proves you protect information. But regulators, customers, and individuals increasingly ask a different question: not “is my data secure?” but “do you handle my personal data lawfully and responsibly?” Security and privacy overlap, but they aren’t the same discipline.

Organizations had a certifiable way to prove security — and nothing equivalent for privacy management. “We comply with GDPR” was a claim, not a certificate.

03 The Story Behind It

From ISO 27001 extension to standalone standard

2019
Born as an extension
The first edition arrived as an add-on to ISO 27001 — you could only implement it if you already had (or were building) an ISMS.
Adoption
The privacy proof of choice
It became the go-to way to demonstrate GDPR-aligned privacy management to global customers and regulators.
2025 · standalone
Freed from 27001
Published 14 October 2025, the second edition became a fully standalone, independently certifiable standard — no longer requiring ISO 27001 first. It also expanded to cover biometric data, health data, IoT, and AI-related privacy risks.
04 How It Works

Management clauses plus privacy controls

Like 27001, it has two halves. Clauses 4–10 are the mandatory management-system requirements — now written to stand on their own for privacy. The annexes provide the reference privacy controls, split by the role you play with personal data.

PII ControllersPII ProcessorsInformation Security

Whether you decide how personal data is used (a controller) or merely process it for someone else (a processor) determines which controls apply. The standalone management clauses:

4 Context & scope of the PIMS
5 Leadership & accountability
6 Planning & privacy risk
7 Support & competence
8 Operation across the PII lifecycle
9 Performance evaluation
10 Improvement
A/B Controller & processor controls
27701 vs. GDPR

GDPR is the law that says what you must do with EU personal data. 27701 is the certifiable system for actually doing it — and unlike GDPR, it hands you a certificate customers recognize worldwide.

06 Who Uses It

Anyone accountable for personal data

☁️
SaaS & processors
Vendors handling customers’ personal data who must prove disciplined privacy management.
🌍
Global enterprises
Organizations facing GDPR and a growing web of privacy laws that want one certifiable system.
🏥
Regulated sectors
Health, finance, and others where personal-data accountability is under the most scrutiny.

Because it’s built to map outward, one PIMS supports many privacy regimes at once.

maps to GDPRCCPA / CPRAbuilds on ISO 27001pairs with ISO 27018
07 Career Relevance

The credential bridging security and privacy

As privacy and security roles converge, 27701 fluency is a genuine differentiator. It’s the skill that lets a GRC professional operationalize privacy law instead of just citing it.

Privacy manager
Build the PIMS
Stand up scope, privacy risk assessment, and controls that turn GDPR into a running system.
Lead auditor
Assess privacy
Evaluate whether a PIMS genuinely meets the standard — a fast-growing assessment niche.
GRC / DPO support
Bridge the disciplines
Connect the ISMS and PIMS so security and privacy evidence reinforce each other instead of duplicating work.

Pair it with your ISO 27001 knowledge and you cover the full security-and-privacy certification story.

09 Final Takeaway

If 27001 proves you keep data safe, 27701 proves you keep it private.

Its 2025 leap to a standalone standard is the news: privacy management is now certifiable in its own right, no ISMS required. For anyone answerable to GDPR and the widening world of privacy law, that single certificate turns “we respect privacy” into something an auditor will sign.