ISO 27701: Privacy Information Management That
Most organisations can produce a privacy policy, a data protection impact assessment template, and a register of processing activities. Fewer can demonstrate that privacy is actually *managed* — with clear ownership, ongoing monitoring, and evidence that controls work in practice rather than existing only on paper. ISO 27701 is the standard built to close that gap, extending an organisation's information security management system to cover privacy specifically.
In this article:
- What ISO 27701 actually is
- How it relates to GDPR and ISO 27001
- The core requirements explained
- Who should be considering it
- Practical steps to get started
What ISO 27701 Actually Is
ISO 27701 is a privacy information management system (PIMS) extension standard — it doesn't stand alone but builds directly on top of ISO 27001, adding specific requirements and controls for managing personal data as both a data controller and/or data processor. Because it's an extension rather than a separate management system, organisations already certified to ISO 27001 typically find it a natural next step rather than starting from zero.
How It Relates to GDPR and ISO 27001
This is where the standard earns its value, so it's worth separating the pieces clearly:
- GDPR is UK/EU law — a legal obligation with specific requirements around lawful basis, data subject rights, breach notification, and more. It's not a certifiable management system; it's the regulation you must comply with regardless.
- ISO 27001 is the information security management system standard, covering the confidentiality, integrity, and availability of information broadly — not personal data specifically.
- ISO 27701 sits on top of ISO 27001 and translates privacy law obligations, including much of what GDPR requires, into concrete management system controls: roles, processes, documentation, and continual improvement specific to personal data.
In practice, ISO 27701 certification gives an organisation (and its customers, regulators, and partners) credible, externally audited evidence that GDPR-type obligations are being actively managed, not just described in a policy document that hasn't been reviewed since it was written.
The Core Requirements Explained
- PIMS-specific roles and responsibilities — clear ownership of privacy obligations, distinct from general information security roles, so accountability doesn't get lost between teams.
- Controller and processor-specific controls — the standard explicitly separates requirements depending on whether you're determining the purposes of processing (controller) or processing on someone else's behalf (processor).
- Privacy risk assessment — extending standard information security risk assessment to explicitly consider risks to data subjects, not just to the organisation.
- Data subject rights processes — documented, tested procedures for handling access requests, corrections, deletions, and objections, rather than improvising when a request actually arrives.
- Third-party and processor management — formal controls over how personal data is shared with and handled by suppliers and partners.
- Continual improvement and monitoring — ongoing review of privacy controls against evolving risk and regulatory expectations, not a one-off implementation exercise.
Who Should Be Considering It
- Organisations already certified to ISO 27001 looking for the most efficient way to formalise privacy management on top of existing infrastructure.
- Data processors handling personal data on behalf of clients, where certification provides strong contractual reassurance without clients needing to audit privacy controls themselves.
- Organisations operating across multiple jurisdictions, where a recognised international standard helps demonstrate consistent privacy practice regardless of local law variations.
- Businesses that have had a near-miss or actual data incident, where certification provides credible evidence of strengthened practice going forward.
- Any organisation for whom "we comply with GDPR" is currently more of a claim than something they can evidence under scrutiny.
Practical Steps to Get Started
- Confirm your ISO 27001 foundation is solid first. ISO 27701 extends that system — gaps in the base ISMS will surface as gaps in the PIMS too.
- Clarify whether you're acting as controller, processor, or both, for each relevant data flow. This shapes which specific controls apply and is often more nuanced than assumed.
- Audit your data subject rights process by actually testing it. Submit an internal test access request and time how smoothly it's handled end-to-end.
- Map personal data flows to third parties explicitly, including sub-processors, and check contracts reflect current practice rather than a template signed years ago.
- Assign clear privacy ownership, separate from general IT security roles, even if it's the same person wearing two hats — the accountability needs to be explicit.
- Build privacy risk review into existing management review cycles, rather than treating it as a separate, occasional exercise disconnected from the main ISMS.
The Bottom Line
ISO 27701 turns "we comply with GDPR" from an assertion into something an organisation can actually demonstrate — with clear ownership, tested processes, and evidence that privacy is managed as a living system, not a policy document gathering dust.
If you'd like support building a privacy information management system that goes beyond paperwork, CAW Consultancy can help.
Get in touch with CAW Consultancy today for a free, no-obligation consultation — visit www.cawconsultancy.co.uk to find out how we can help you stay compliant and confident.
In this article:
- What ISO 27701 actually is
- How it relates to GDPR and ISO 27001
- The core requirements explained
- Who should be considering it
- Practical steps to get started
What ISO 27701 Actually Is
ISO 27701 is a privacy information management system (PIMS) extension standard — it doesn't stand alone but builds directly on top of ISO 27001, adding specific requirements and controls for managing personal data as both a data controller and/or data processor. Because it's an extension rather than a separate management system, organisations already certified to ISO 27001 typically find it a natural next step rather than starting from zero.
How It Relates to GDPR and ISO 27001
This is where the standard earns its value, so it's worth separating the pieces clearly:
- GDPR is UK/EU law — a legal obligation with specific requirements around lawful basis, data subject rights, breach notification, and more. It's not a certifiable management system; it's the regulation you must comply with regardless.
- ISO 27001 is the information security management system standard, covering the confidentiality, integrity, and availability of information broadly — not personal data specifically.
- ISO 27701 sits on top of ISO 27001 and translates privacy law obligations, including much of what GDPR requires, into concrete management system controls: roles, processes, documentation, and continual improvement specific to personal data.
In practice, ISO 27701 certification gives an organisation (and its customers, regulators, and partners) credible, externally audited evidence that GDPR-type obligations are being actively managed, not just described in a policy document that hasn't been reviewed since it was written.
The Core Requirements Explained
- PIMS-specific roles and responsibilities — clear ownership of privacy obligations, distinct from general information security roles, so accountability doesn't get lost between teams.
- Controller and processor-specific controls — the standard explicitly separates requirements depending on whether you're determining the purposes of processing (controller) or processing on someone else's behalf (processor).
- Privacy risk assessment — extending standard information security risk assessment to explicitly consider risks to data subjects, not just to the organisation.
- Data subject rights processes — documented, tested procedures for handling access requests, corrections, deletions, and objections, rather than improvising when a request actually arrives.
- Third-party and processor management — formal controls over how personal data is shared with and handled by suppliers and partners.
- Continual improvement and monitoring — ongoing review of privacy controls against evolving risk and regulatory expectations, not a one-off implementation exercise.
Who Should Be Considering It
- Organisations already certified to ISO 27001 looking for the most efficient way to formalise privacy management on top of existing infrastructure.
- Data processors handling personal data on behalf of clients, where certification provides strong contractual reassurance without clients needing to audit privacy controls themselves.
- Organisations operating across multiple jurisdictions, where a recognised international standard helps demonstrate consistent privacy practice regardless of local law variations.
- Businesses that have had a near-miss or actual data incident, where certification provides credible evidence of strengthened practice going forward.
- Any organisation for whom "we comply with GDPR" is currently more of a claim than something they can evidence under scrutiny.
Practical Steps to Get Started
- Confirm your ISO 27001 foundation is solid first. ISO 27701 extends that system — gaps in the base ISMS will surface as gaps in the PIMS too.
- Clarify whether you're acting as controller, processor, or both, for each relevant data flow. This shapes which specific controls apply and is often more nuanced than assumed.
- Audit your data subject rights process by actually testing it. Submit an internal test access request and time how smoothly it's handled end-to-end.
- Map personal data flows to third parties explicitly, including sub-processors, and check contracts reflect current practice rather than a template signed years ago.
- Assign clear privacy ownership, separate from general IT security roles, even if it's the same person wearing two hats — the accountability needs to be explicit.
- Build privacy risk review into existing management review cycles, rather than treating it as a separate, occasional exercise disconnected from the main ISMS.
The Bottom Line
ISO 27701 turns "we comply with GDPR" from an assertion into something an organisation can actually demonstrate — with clear ownership, tested processes, and evidence that privacy is managed as a living system, not a policy document gathering dust.
If you'd like support building a privacy information management system that goes beyond paperwork, CAW Consultancy can help.
Get in touch with CAW Consultancy today for a free, no-obligation consultation — visit www.cawconsultancy.co.uk to find out how we can help you stay compliant and confident.