Privacy
ISO/IEC 27701
Privacy Information Management System
Formal standard
Global
ISO/IEC JTC 1/SC 27
Since 2019
Extends an information security management system into a privacy information management system, with separate requirements for controllers and processors and a mapping annex to GDPR articles.
The GDPR mapping is the reason it matters: it turns "we comply with GDPR" into a set of auditable management-system requirements a certification body can actually test.
At a glance
- Category
- Privacy
- Jurisdiction
- Global
- Governance
- ISO/IEC JTC 1/SC 27
- Status
- 27701:2019 as a 27001 extension; 2025 revision makes it standalone
- First released
- 2019
Links
Related frameworks
Other entries under Privacy.
- ISO/IEC 27018: Protection of PII in Public Clouds
- NIST Privacy Framework
- ISO/IEC 29100: Privacy Framework
See ISO/IEC 27701 in context
Open the interactive Data Landscape for Regulation to compare ISO/IEC 27701 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.