What Is ISO 27701 Certification?

ISO 27701 · PRIVACY MANAGEMENT

For six years ISO 27701 was an add-on. No ISO 27001 certificate meant no ISO 27701 certificate. The 2025 edition ended that rule. It changes who can get the badge, and where the work starts.

TL;DR

ISO 27701 certifies your privacy information management system, or PIMS. An accredited body audits it and issues the certificate. Since the second edition landed on 14 October 2025, a PIMS stands on its own. You no longer need ISO 27001 first.

2025Second edition, published 14 October
4 to 10Its own management system clauses
2028When 2019 certificates stop counting
27706New rulebook for certification bodies

Sources: ISO/IEC 27701:2025 · ISO/IEC 27706:2025

What ISO 27701 is #

ISO/IEC 27701 is the world standard for a privacy information management system, or PIMS. A PIMS runs privacy as a system instead of a set of promises. It asks what personal data you hold. It asks who owns it, what risks you accept, and how you prove all of that a year later.

ISO and IEC publish it through JTC 1/SC 27. That is the same committee behind ISO 27001 and ISO 42001. It borrows the words of data protection law without belonging to any one law. It names PII controllers and PII processors. Those map onto the controller and processor roles your lawyer already uses.

The certificate is a separate step. The standard describes a system. A certificate says an accredited body audited your system and found it conforming. You cannot certify yourself. No vendor can certify you by selling you software.

What changed in 2025 #

The 2019 edition said what it was in its own title. It read Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management. An extension needs something to extend. So the rule had teeth. No ISO 27001 certificate, no ISO 27701 certificate.

The second edition dropped that framing. It landed on 14 October 2025. The title now reads Privacy information management systems. Requirements and guidance. Clauses 4 to 10 belong to the standard itself. You can build, audit and certify a PIMS on its own.

That opens a door. Say your buyers ask about personal data more than security. You now have a route that does not start with an ISMS. Health tech, HR tech and marketing platforms all sit in that group. So does anyone handling customer records for a client.

Standalone does not mean lighter

Clauses 4 to 10 ask for the same machinery ISO 27001 asks for. Context, leadership, risk treatment, objectives, skills, internal audit, management review. Skip the ISMS and you build all of it for privacy. You do not inherit it. What you save is the security control set, not the system around it.

What the certificate covers #

Annex A carries the control objectives in three groups. A.1, A.2 and A.3. One group covers PII controllers. One covers PII processors. One covers the parts that apply to both. Annex B holds the guidance for putting those controls in place.

Your role decides which groups apply. Most software firms land in two of them. You are a processor for the customer data your product holds. You are a controller for staff records, job applicants and your marketing list. Work out which hat you wear for each data set. An auditor will expect that done before fieldwork.

Where scope gets decided #

Scope is the first place a PIMS goes wrong. The trap that catches ISO 27001 teams catches privacy teams too. Draw the system too wide and you pull in data flows you have never mapped. Draw it too tight and the certificate answers a question nobody asked. Our guide to building a management system covers the mechanics. They carry over.

What ISO 27701 certification is not #

This is where most articles on the subject get loose, so it is worth being blunt.

It is not a GDPR certification. Article 42 certification applies to processing operations. It runs through schemes approved under Article 43, by a supervisory authority or the European Data Protection Board. An ISO standard is not that. Irene Kamara put it plainly in the IAPP.

“Technical and management standards … including the well-known information security standard ISO/IEC 27001 or the new ISO/IEC 27701 … are not necessarily part of a GDPR certification mechanism.”

Irene KamaraWriting for the IAPP on GDPR certification

No North American statute treats it as proof either. PIPEDA, Quebec Law 25, Alberta and B.C. PIPA, HIPAA and the US state privacy laws do not name ISO 27701. None of them accept a certificate as proof. A regulator reads what you do, not what you hold.

So what is it worth? It answers what a buyer’s vendor risk team actually wants to know. Not “are you legal”, which they cannot check. Rather, “does this firm run privacy as a system, or improvise”. An accredited certificate answers that in one page. It shortens the questionnaire behind it.

How you get certified #

The chain works the way it does for ISO 27001. An accreditation body assesses certification bodies. Those bodies audit you and issue the certificate. The accreditation is what makes it mean anything outside your own website.

In Canada that body is the Standards Council of Canada. It runs a PIMS programme. In the United States it is ANAB. Either badge travels across the border, for the same reason an ISO 27001 badge does.

“ANAB accredits certification bodies that issue certifications to ISO/IEC 27701 privacy information management systems, instilling confidence.”

ANABOn its privacy information management accreditation programme

One new piece sits behind all this. ISO/IEC 27706:2025 arrived on the same day as the revised standard. It sets the rules for bodies that audit and certify a PIMS. It replaces the older technical specification and sits beside ISO/IEC 17021-1. The effect lands on auditor skills. A body must now show its auditors know privacy, not just security.

Two questions worth asking your certification body

Which edition are you accredited to audit against? And does ISO/IEC 27706 cover you yet? Ask rather than assume. At the time of writing, the public programme pages at SCC and ANAB still carry 2019-era wording. That tells you how new this is.

If you hold a 2019 certificate #

Your certificate stays valid while the transition runs. You keep meeting the normal requirements, as before. The window is three years from publication. That puts the end in October 2028. Published sources differ on the exact day. Take that date from your certification body, not from an article.

Certification bodies move first. An accreditation body has to assess each of them against the new rules. Only then can they audit anyone to the 2025 edition. The accreditation community expects that work to finish during 2027.

Oct 2025

Published

27701 and 27706, same day

Through 2027

Bodies transition

Assessed under ISO/IEC 27706

Oct 2028

2019 expires

Old certificates stop counting

Segments scaled to the length of each phase, not to effort. Confirm the exact 2028 date with your certification body.

What a transition audit looks at #

The controls you already run carry over. The gap sits in the management system. The 2019 edition let you borrow most of it from ISO 27001. Now the auditor wants privacy objectives, a privacy risk treatment, a privacy internal audit and a management review that names privacy. Each has to stand on its own. Folding them into ISMS paperwork no longer counts. Think of an ISO 27001 risk assessment, pointed at personal data.

Frequently asked questions #

What is ISO 27701 certification?

An accredited body audits your privacy information management system against ISO/IEC 27701. If it conforms, you get the certificate. The standard covers how you govern personal data as a system. The certificate covers the scope you drew, and nothing outside it.

Do you need ISO 27001 before ISO 27701?

Not any more. The 2019 edition was an extension, so you needed ISO 27001 first. The 2025 edition carries its own clauses. You can certify a PIMS on its own. Holding ISO 27001 still saves real work, because the two systems share their machinery.

Is ISO 27701 a GDPR certification?

No. Article 42 covers processing operations, through a scheme approved under Article 43. A supervisory authority or the European Data Protection Board approves it. ISO 27701 is a management system standard. No ISO certificate meets Article 42 on its own. It is useful evidence, not a legal finding.

What changed in ISO 27701:2025?

The standard became standalone. Its title dropped the extension wording. Clauses 4 to 10 became its own. Annex A now splits into A.1, A.2 and A.3, for controllers, processors and the parts that apply to both. Annex B holds the guidance. ISO/IEC 27706:2025 arrived beside it to govern certification bodies.

When do ISO 27701:2019 certificates expire?

The transition runs three years from the October 2025 publication. It ends in October 2028. Existing certificates stay valid until then, as long as you keep meeting the usual requirements. Published sources disagree on the exact day. Confirm it with your certification body before you plan the audit.

Does ISO 27701 cover PIPEDA, Law 25 or US state privacy laws?

No statute names it. PIPEDA, Quebec Law 25, Alberta and B.C. PIPA, HIPAA and the US state privacy laws all judge what you do, not what you hold. A PIMS gives you the records, roles and reviews those laws expect. That makes a regulator conversation easier. It does not end one.

Key takeaways #

  • ISO 27701 certifies a privacy information management system, audited by an accredited body against a scope you define.
  • The second edition, published 14 October 2025, made the standard standalone. ISO 27001 is no longer a prerequisite.
  • Standalone does not mean lighter. Clauses 4 to 10 ask for a full management system, built for privacy rather than borrowed.
  • Annex A splits into A.1, A.2 and A.3, across controllers, processors and both. Most software firms need two of the three.
  • The certificate is not a GDPR Article 42 certification. No North American statute treats it as proof either.
  • SCC accredits in Canada and ANAB in the United States. ISO/IEC 27706:2025 now sets what those certification bodies must prove.
  • 2019 certificates run out in October 2028. Certification bodies transition first, during 2027.
HZ

Hunter Zhu Founder of Nank.ai, a firm that takes companies in Canada and the United States to SOC 2, ISO 27001, and ISO 42001. Connect on LinkedIn

Work out whether you need the certificate #

The answer turns on who is asking and what they will accept. Talk to us about ISO 27701 readiness, and about whether an ISMS, a PIMS, or both belong in your plan.

What are your feelings
Updated on September 21, 2026
Scroll to Top