ISO 27701 is an international standard published by the International Organization for Standardization (ISO) that establishes requirements and guidance for a Privacy Information Management System (PIMS). The 2025 edition, known as ISO 27001:2025, published October 14, 2025, made ISO 27701 a standalone standard—organizations can now certify to it without first implementing ISO 27001.
Key takeaways
- ISO 27701:2025 is a standalone standard—organizations no longer need ISO 27001 certification to pursue or hold it.
- The 2019 edition, which required ISO 27001 as a foundation, has been withdrawn. Organizations certified under it have until October 2028 to transition.
- ISO 27701 maps to other regulations, making certification structured evidence for accountability and third-party due diligence, not a compliance certificate in itself.
- ISO 27701 certification produces a publicly shareable certificate—unlike SOC 2, which requires NDA—making it a common credential for demonstrating privacy governance in international markets.
- Managed service providers and data processors that process customer personal information on behalf of clients are among the most common ISO 27701 certification candidates.
ISO 27701 addresses a gap that information security programs may leave open. Information security controls don’t necessarily satisfy applicable privacy requirements. Organizations can have a robust information security program and still lack the specific controls, documentation, and governance structures that privacy compliance may require.
ISO 27701 closes that gap with privacy-specific requirements for how organizations collect, use, store, and share personal information, whether as data controllers who determine the purpose of processing, or as data processors who handle personal information on behalf of others.
What does ISO 27701 require?
ISO 27701:2025 establishes requirements for a Privacy Information Management System (PIMS) through its own full set of management system clauses (Clauses 4–10), following the same high-level structure used by ISO 27001:2022 and other modern ISO management system standards. The standard is organized around two roles:
- Controllers (who determine the purposes and means of processing personal information)
- Processors (who process personal information on behalf of controllers)
For both roles, ISO 27701 requires organizations to define the scope of their PIMS, conduct privacy risk assessments identifying risks to data subjects’ rights and freedoms, and implement privacy controls from a consolidated Annex A—organized into three tables covering controller-specific controls, processor-specific controls, and shared controls—with matching implementation guidance in Annex B. Organizations must also maintain documentation including records of processing activities, privacy notices, data subject request procedures, and personal data breach response procedures.
ISO 27701 vs. ISO 27001: What’s the difference?
ISO 27001 establishes requirements for an Information Security Management System (ISMS), which is a systematic approach to managing information security risks. As of the 2025 edition, ISO 27701 is a separate, standalone management system standard for privacy, not an add-on to ISO 27001.
That’s a change from the 2019 edition, which could only be certified alongside ISO 27001. Under ISO 27701:2025, organizations can implement and certify a PIMS on its own, which is useful for teams that need to demonstrate privacy governance without taking on a full ISMS. Organizations that already hold ISO 27001 can still integrate the two. The standards share compatible terminology and structure, so governance, risk assessment, and audit cycles can run in parallel.
The practical difference still comes down to perspective. ISO 27001 asks, how do we protect information from security risks? ISO 27701 asks, how do we protect individuals from privacy risks arising from our processing of their personal information? The unit of risk shifts from information assets to data subjects, or the people whose personal information is being processed.
ISO 27701 certification—how it works
ISO 27701 certification follows the same audit structure as ISO 27001, whether pursued standalone or alongside it. An organization implements the requirements, then engages an accredited certification body to conduct an independent audit.
The audit has two stages:
- Stage 1 (documentation review): The certification body reviews the organization’s PIMS documentation, including scope definition, privacy risk assessment, processing activity records, policies, procedures, and control implementation. The goal is to confirm the PIMS is designed to meet the standard’s requirements before the on-site assessment.
- Stage 2 (implementation audit): The certification body audits actual implementation of PIMS controls, interviews staff, and tests whether documented procedures are being followed in practice.
Successful completion results in an ISO 27701 certificate covering the defined scope. Certificates require annual surveillance audits and full recertification every three years. Unlike SOC 2 Type 2, which produces a detailed audit report, ISO 27701 produces a publicly verifiable certificate that can be shared without NDA restriction.
Who should pursue ISO 27701?
ISO 27701 is most commonly pursued by organizations that process personal information as a service provider or data processor, including managed service providers, cloud platforms, SaaS vendors, and other organizations that handle customer personal information on behalf of clients. For these organizations, ISO 27701 processor certification gives customers structured evidence of privacy controls without requiring individual audits of each vendor.
Other strong candidates include organizations in regulated industries with privacy obligations (healthcare, financial services, and HR technology, for example), and organizations that want to demonstrate privacy governance to enterprise customers in procurement or vendor risk processes.
Because ISO 27701:2025 is standalone, organizations no longer need ISO 27001 as a prerequisite. It’s a shift that opens certification to privacy-first companies and smaller organizations that previously found the combined cost of two standards prohibitive. Organizations that already hold ISO 27001 can still integrate both systems and share governance and audit cycles where it makes sense.
How does Expel support ISO 27701?
Expel holds ISO 27701:2019 certification as a processor. This means Expel’s Privacy Information Management System has been independently assessed and certified as meeting the standard’s requirements for organizations that process personal information on behalf of customers. Expel will transition its certification to ISO 27701:2025 ahead of the October 2028 industry deadline.
For organizations that use Expel’s MDR service, Expel processes security event data and related telemetry that may contain personal information. Expel’s ISO 27701 processor certification provides structured, auditor-verified evidence of the privacy controls governing that processing.
Frequently asked questions
What is ISO 27701?
ISO 27701 is an international standard that establishes requirements for a Privacy Information Management System (PIMS) for organizations acting as personal information controllers or processors. The current edition, ISO 27701:2025, published October 2025, is a standalone standard that no longer requires ISO 27001 certification as a prerequisite.
What is the difference between ISO 27001 and ISO 27701?
ISO 27001 establishes requirements for an Information Security Management System (ISMS) focused on protecting information assets from security risks. ISO 27701 is a separate standard focused on protecting data subjects’ rights and managing personal information responsibly. As of the 2025 edition, ISO 27701 is standalone, so organizations can implement it without ISO 27001, though the two remain compatible for organizations that want to run both.
How does ISO 27701 certification work?
ISO 27701 certification follows the same two-stage audit process as ISO 27001: a documentation review (Stage 1), followed by an implementation audit (Stage 2) conducted by an accredited certification body. Successful completion results in a certificate requiring annual surveillance audits and full recertification every three years. Unlike SOC 2, ISO 27701 produces a publicly shareable certificate rather than a detailed audit report.
Who needs ISO 27701?
ISO 27701 is most relevant for organizations that process personal information as a service provider or data processor, or need to demonstrate privacy governance to enterprise customers in procurement or vendor risk processes. Because the 2025 edition is standalone, organizations no longer need ISO 27001 in place first to pursue it.
What happened to ISO 27701:2019?
ISO 27701:2019 has been withdrawn and replaced by ISO 27701:2025. Organizations currently certified under the 2019 edition have until October 2028 to transition to the 2025 edition.

