ISO 27701

ISO 27701:2025:
the privacy management standard, now standalone.

What ISO/IEC 27701 requires, what changed in the 2025 edition, the controller and processor controls, how it maps to the GDPR and the DPDP Act, and how it relates to ISO 27001 now that you no longer need one to hold the other.

ISO/IEC 27701:2025Standalone PIMSController · processorGDPR · DPDP

Last updated Published by TryTrustableNot legal advice

01

What is ISO 27701?

ISO 27701, formally ISO/IEC 27701:2025, is the international standard for a privacy information management system (PIMS): the policies, roles, risk process and controls an organisation uses to handle personally identifiable information as a controller, a processor or both. Since the 2025 edition it can be certified on its own, without ISO 27001.

The standard is ISO/IEC 27701:2025, published in October 2025. It uses the same vocabulary as ISO privacy standards generally: PII rather than personal data, PII principal rather than data subject or Data Principal. The mapping is direct, and an organisation can use the standard without renaming anything internally.

As with any ISO management system standard, what it certifies is the organisation's process, not a product or a legal status: that privacy is governed, risks are assessed, controls are chosen and operated, and the whole system is audited and reviewed.

02

What changed in ISO 27701:2025?

ISO 27701:2025 turned the standard from an extension of ISO 27001 into a standalone management system standard. It now has its own clauses 4 to 10 in the harmonized structure and an Annex A with controller controls, processor controls and information security controls. Certificates to the 2019 edition must transition by October 2028.

ISO/IEC 27701:2019ISO/IEC 27701:2025
StatusExtension to ISO 27001 and ISO 27002Standalone management system standard
CertificationOnly together with ISO 27001On its own, or integrated with ISO 27001
Management system clausesAdditions to ISO 27001's clausesIts own clauses 4–10, harmonized structure
Annex AController (Annex A) and processor (Annex B) controlsA.1 controller, A.2 processor, A.3 information security controls
Security controlsTaken from ISO 27001's Annex AIncluded in the standard itself
TransitionCertificates valid until the transition endsTransition by October 2028

Checked September 2026. The 2025 edition introduced no net-new privacy controls; it reorganised existing ones and brought the security controls inside the standard.

03

What controls does ISO 27701 contain?

ISO 27701:2025 Annex A has three parts: controls for PII controllers, controls for PII processors, and information security controls carried over from ISO 27002 and the 2019 edition. An organisation selects the parts that match its role; a SaaS company is often a controller for its own users and a processor for its customers' data.

Role matters more here than in ISO 27001, because the obligations of a controller and a processor are different in law and the standard mirrors that. What each part covers:

PartWho it is forWhat it covers
A.1 ControllerOrganisations deciding why and how PII is processedConditions for collection and processing, lawful basis and consent records, obligations to PII principals (notice, access, correction, erasure, objection), privacy by design and by default, sharing, transfer and disclosure
A.2 ProcessorOrganisations processing PII on a customer's instructionsCustomer agreements, processing only on instruction, assisting the customer with rights and breaches, return and deletion at end of contract, sub-processor engagement, transfer and disclosure records
A.3 Information securityEveryone in scopeSecurity controls drawn from ISO 27002 that protect PII: access, cryptography, logging, supplier security, incident management

Paraphrased from the published structure; buy the standard for the control text.

04

How ISO 27701 maps to the GDPR and the DPDP Act

ISO 27701 maps to the GDPR and the DPDP Act at the level of controls: consent records, notices, rights handling, processor contracts, retention and breach handling appear in all three. The standard supplies the management system around them; the laws supply the legal tests and the deadlines, which a certificate does not replace.

PracticeISO 27701:2025GDPRDPDP Act 2023 and Rules 2025
Lawful basis and consent recordsA.1 controller controlsArticles 6, 7Sections 4, 6, 7
NoticeA.1Articles 13, 14Section 5; Rule 3
Rights of individualsA.1Articles 15–22Sections 11–14
Processor contracts and instructionsA.2 processor controlsArticle 28Section 8(2)
Security of processingA.3Article 32Section 8(5); Rule 6
Breach handlingA.2, A.3Articles 33, 34Section 8(6); Rule 7
Retention and erasureA.1, A.2Articles 5(1)(e), 17Section 8(7); Rule 8
Impact assessmentClause 6 risk process; A.1Article 35Section 10 (Significant Data Fiduciaries)

Common readings, not an ISO or regulator mapping. The fuller map is on ISO 27701 to DPDP.

What the standard does not carry: India's Consent Manager regime, the Eighth Schedule language rule, the DPDP Act's dates, and the GDPR's representative and transfer mechanics. The DPDP Act guide and the GDPR guide for Indian companies cover those.

05

How does ISO 27701 relate to ISO 27001?

ISO 27701 and ISO 27001 are now separate certifiable standards that share the harmonized clause structure. An organisation with ISO 27001 reuses its internal audit, management review, document control and many security controls, and adds the privacy risk process and the controller or processor controls. The two can be audited together.

For an Indian company the practical choice is usually between ISO 27001 plus ISO 27701 as one integrated system, and ISO 27701 alone where the buyer's question is only about privacy. The ISO 27001 build order is on ISO 27001 compliance software.

06

Where the platform fits

ISO 27701 is on the coverage list with ISO 27001, the GDPR and the DPDP Act, on one control set. Cross-framework mapping shows which ISO 27701 requirements your existing controls already satisfy before you enable it; the consent platform and DSAR workflow produce the controller-side records; the evidence ledger keeps them dated for the auditor. Only an accredited certification body issues the certificate. TryTrustable does not hold SOC 2 or ISO 27001 itself yet: both are in progress, as the trust page says.

Questions

The things people ask us

What is ISO 27701?

ISO 27701, formally ISO/IEC 27701:2025, is the international standard for a privacy information management system (PIMS): the policies, roles, risk process and controls an organisation uses to handle personally identifiable information as a controller, a processor or both. Since the 2025 edition it can be certified on its own, without ISO 27001.

Do I need ISO 27001 before ISO 27701?

Not any more. Under the 2019 edition, ISO 27701 extended ISO 27001 and could only be certified alongside it. The 2025 edition is standalone, with its own management system clauses and security controls. Many organisations still run the two together, because the clause structure is shared and one audit programme is cheaper than two.

What changed in ISO 27701:2025?

ISO 27701:2025 turned the standard from an extension of ISO 27001 into a standalone management system standard. It now has its own clauses 4 to 10 in the harmonized structure and an Annex A with controller controls, processor controls and information security controls. Certificates to the 2019 edition must transition by October 2028.

When do ISO 27701:2019 certificates expire?

Organisations certified to the 2019 edition have until October 2028 to transition to ISO/IEC 27701:2025, under the transition arrangements accreditation bodies have set. After that a 2019 certificate is no longer valid. Most organisations move at a surveillance or recertification audit rather than holding a separate transition audit.

Does ISO 27701 certification mean GDPR compliance?

No. ISO 27701 certifies a management system; it does not certify compliance with any law, and no regulator treats it as proof of GDPR or DPDP compliance. It is good evidence that your privacy programme is organised and runs, and its controls map to many GDPR and DPDP obligations, but the legal duties still have to be met as the law states them.

Is ISO 27701 useful for the DPDP Act?

Yes, as structure. The controller controls map to DPDP notice, consent, purpose limitation, retention and rights; the processor controls map to what a Data Fiduciary must require of its Data Processors; the security controls support Section 8(5) safeguards. It does not cover India-specific mechanics such as Consent Managers or Eighth Schedule languages.

Who issues ISO 27701 certificates?

Certification bodies accredited for ISO/IEC 27701 by a national accreditation body, auditing under ISO/IEC 17021-1 and the privacy-specific requirements for bodies certifying a PIMS. Check the accreditation covers the 2025 edition before you book, and that the certificate names your legal entity and scope.

Book a walkthrough

See ISO 27701 evidenced from privacy records.

We show consent receipts and rights requests mapped to ISO 27701 controller controls and the DPDP Act from the same record.