It answers the GDPR question
'Are you GDPR compliant?' has no certificate of its own. ISO 27701 is the recognised, auditable way to demonstrate a privacy programme that meets it.
Prove you handle personal data properly.
ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS): how an organisation manages the personal data it holds, whether as a controller, a processor, or both. The 2025 second edition was redrafted as a stand-alone management system, and it maps directly to GDPR, so it is the closest thing there is to a certifiable, globally recognised way to prove your privacy programme actually works.
The standard
ISO/IEC 27701:2025 — Privacy Information Management System
Who needs it
Any organisation that processes personal data and wants to prove it does so responsibly: SaaS vendors whose customers ask 'are you GDPR compliant?', anyone already holding ISO 27001 who wants a privacy credential to match, and businesses operating across multiple privacy regimes who want one recognised standard to anchor them.
GDPR
mapped article-by-article
The basics
A management system for privacy, built on the same clause 4 to 10 spine as ISO 27001, plus a normative Annex A of privacy controls: A.1 for PII controllers (31), A.2 for PII processors (18), and A.3 security controls for both (29).
Role-aware by design: you first determine whether you are a controller (you decide why and how personal data is used) or a processor (you handle it on a customer's instructions), and that decides which controls apply. Most organisations are controllers of their own data; many SaaS vendors are also processors.
Certifiable by an accredited body, and mapped article-by-article to the GDPR, so a certificate is credible evidence to customers and regulators alike.
Why it matters
'Are you GDPR compliant?' has no certificate of its own. ISO 27701 is the recognised, auditable way to demonstrate a privacy programme that meets it.
The security controls (Annex A.3) map almost one-to-one to ISO 27001:2022, so if you hold 27001 you are already a long way in.
An independent privacy certification carries weight in procurement that a self-declared privacy policy never will.
Determine whether you are a PII controller, processor or both, per processing activity. It drives everything else.
A privacy risk assessment that weighs the impact on individuals, not just the business, feeding your Statement of Applicability.
Lawful basis, consent, data-subject rights, minimisation, transfers, and the security of personal data.
Records of processing, DPIAs, DPAs, monitoring, audit and management review keep the PIMS living.
Privacy is a maze of overlapping obligations: lawful basis, consent, data-subject requests, records of processing, cross-border transfers, processor contracts, breach notification. Standing all of that up by hand, and keeping it evidenced, while also proving it to auditors and customers, is where most privacy programmes stall.
Do it once, reuse it everywhere. Evidence you collect for ISO 27701is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps ISO 27701 to your environment in a 30-minute walkthrough — and how much of it we handle for you.