All frameworks
ISOCertification · privacy

ISO 27701 compliance

Prove you handle personal data properly.

ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS): how an organisation manages the personal data it holds, whether as a controller, a processor, or both. The 2025 second edition was redrafted as a stand-alone management system, and it maps directly to GDPR, so it is the closest thing there is to a certifiable, globally recognised way to prove your privacy programme actually works.

Start from the basics

The standard

ISO/IEC 27701:2025 — Privacy Information Management System

Who needs it

Any organisation that processes personal data and wants to prove it does so responsibly: SaaS vendors whose customers ask 'are you GDPR compliant?', anyone already holding ISO 27001 who wants a privacy credential to match, and businesses operating across multiple privacy regimes who want one recognised standard to anchor them.

GDPR

mapped article-by-article

The basics

What is ISO 27701?

A management system for privacy, built on the same clause 4 to 10 spine as ISO 27001, plus a normative Annex A of privacy controls: A.1 for PII controllers (31), A.2 for PII processors (18), and A.3 security controls for both (29).

Role-aware by design: you first determine whether you are a controller (you decide why and how personal data is used) or a processor (you handle it on a customer's instructions), and that decides which controls apply. Most organisations are controllers of their own data; many SaaS vendors are also processors.

Certifiable by an accredited body, and mapped article-by-article to the GDPR, so a certificate is credible evidence to customers and regulators alike.

Why it matters

What ISO 27701 does for your business

It answers the GDPR question

'Are you GDPR compliant?' has no certificate of its own. ISO 27701 is the recognised, auditable way to demonstrate a privacy programme that meets it.

It rides on your ISO 27001

The security controls (Annex A.3) map almost one-to-one to ISO 27001:2022, so if you hold 27001 you are already a long way in.

It builds durable trust

An independent privacy certification carries weight in procurement that a self-declared privacy policy never will.

What it covers

Know your role

Determine whether you are a PII controller, processor or both, per processing activity. It drives everything else.

Assess privacy risk

A privacy risk assessment that weighs the impact on individuals, not just the business, feeding your Statement of Applicability.

Apply the controls

Lawful basis, consent, data-subject rights, minimisation, transfers, and the security of personal data.

Evidence & improve

Records of processing, DPIAs, DPAs, monitoring, audit and management review keep the PIMS living.

The hard way

Privacy is a maze of overlapping obligations: lawful basis, consent, data-subject requests, records of processing, cross-border transfers, processor contracts, breach notification. Standing all of that up by hand, and keeping it evidenced, while also proving it to auditors and customers, is where most privacy programmes stall.

The easier way, with Compliance One

  • Ships the full ISO 27701:2025 clause 4 to 10 library plus all 78 Annex A controls, enabled by default with a Statement of Applicability.
  • Is role-aware out of the box: controller (A.1) and security (A.3) controls are on by default, and processor (A.2) controls are one click to promote, with a clear in-app banner explaining the difference.
  • Pre-fills the mandatory documents: privacy policy, records of processing (controller and processor), privacy notice, consent and data-subject-request procedures, PIA/DPIA, data processing agreement, cross-border transfer register, retention schedule and more.
  • Cross-maps every control to ISO 27001 and to GDPR articles, so the evidence you already hold carries across and your privacy and security programmes share one source of truth.

Do it once, reuse it everywhere. Evidence you collect for ISO 27701is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Is this the 2019 or the 2025 version?
The 2025 second edition, which was redrafted as a stand-alone management system. The 2019 edition was an extension you bolted onto ISO 27001. Our content is on the current text.
We already have ISO 27001 — how much extra work is it?
Less than you would expect. Clauses 4 to 10 are the shared management-system spine, and the Annex A.3 security controls map almost one-to-one to 27001:2022. Compliance One cross-maps the overlap so you extend your programme rather than restart it.
What's the difference between a controller and a processor?
A controller decides why and how personal data is processed (your own employee and customer data). A processor handles personal data on a customer's instructions (a SaaS handling its customers' data). It decides which controls apply, and the platform makes picking the right set easy.
Does it prove GDPR compliance?
It is the closest recognised route. ISO 27701 maps directly to the GDPR, so certification is strong, independent evidence of a compliant privacy programme, though GDPR compliance ultimately rests with you and your legal counsel.

Ready to tackle ISO 27701?

See exactly how Compliance One maps ISO 27701 to your environment in a 30-minute walkthrough — and how much of it we handle for you.