Privacy

ISO/IEC 27701

Privacy Information Management System

Formal standard Global ISO/IEC JTC 1/SC 27 Since 2019

Extends an information security management system into a privacy information management system, with separate requirements for controllers and processors and a mapping annex to GDPR articles.

The GDPR mapping is the reason it matters: it turns "we comply with GDPR" into a set of auditable management-system requirements a certification body can actually test.

At a glance

Category
Privacy
Jurisdiction
Global
Governance
ISO/IEC JTC 1/SC 27
Status
27701:2019 as a 27001 extension; 2025 revision makes it standalone
First released
2019

Links

Related frameworks

Other entries under Privacy.

See ISO/IEC 27701 in context

Open the interactive Data Landscape for Regulation to compare ISO/IEC 27701 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.