All resources
Blog 6 min read

GDPR vs ISO 27701: certify the system, evidence the regulation

C1The Compliance One team16 September 2026

Here is a conversation that happens constantly. A buyer asks, 'Are you GDPR compliant? Can you send your certificate?' And you have to explain that there is no such certificate, which sounds evasive even though it is completely true. GDPR is a law you comply with, not a scheme you pass. There is no auditor who hands out a GDPR badge.

That gap is exactly what ISO 27701 fills. It is the recognised, certifiable way to prove a privacy programme that meets GDPR, and understanding the relationship between the two is the key to answering that buyer without going quiet.

The difference in one line

GDPR is the regulation you must obey. ISO 27701 is the management system, certifiable by an accredited body, that proves you obey it. One is the law, the other is the evidence.

Why 27701 is the right proof

ISO 27701 is a Privacy Information Management System (a PIMS). The 2025 second edition was redrafted to stand on its own, built on the same clause 4 to 10 spine as ISO 27001 plus a set of privacy controls for controllers and processors. Crucially, it is mapped to the GDPR article by article. So when you implement a 27701 control, you can point at the GDPR articles it satisfies, and when an auditor certifies your PIMS, that certificate becomes credible, independent evidence to customers and regulators alike.

It does not make GDPR compliance someone else's responsibility. Compliance still ultimately rests with you and your legal counsel. But it turns 'trust us, we are compliant' into 'here is our certified privacy management system and here is how it maps to every article you care about'.

You want both, and they share most of the work

The happy news is that these are not two separate projects. Because 27701's security controls ride almost one to one on ISO 27001:2022, and its privacy controls map straight to GDPR, doing the work once feeds all three. Compliance One models this as one control set: implement a control, attach the evidence, and it counts toward ISO 27001, ISO 27701 and the matching GDPR articles at the same time. Your Record of Processing, your DPIAs, your breach process and your data-subject-request workflow all live in one place and serve every framework that needs them.

So the next time a buyer asks for your GDPR certificate, you have a real answer: a certified ISO 27701 privacy management system, mapped article by article to the regulation, with the evidence to back it. That is a far better place to be than going quiet.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map Compliance One to your environment.