All resources
Blog 5 min read

You have ISO 27001. ISO 27701 is closer than you think.

C1The Compliance One team28 August 2026

If you hold ISO 27001 and your customers have started asking about privacy, there is good news: 27701 was designed to sit right next to 27001, and a large chunk of it is work you have already done. This is not a fresh programme. It is your security programme, pointed at personal data.

What transfers almost for free

The management-system spine is shared. Clauses 4 to 10, context, leadership, planning, support, evaluation and improvement, are the same Annex SL structure in both standards, so your policy framework, internal audit programme, management reviews and corrective-action process carry across with light editing.

On the controls side, ISO 27701's security controls (Annex A.3) map almost one-to-one to ISO 27001:2022 Annex A. If you have implemented access control, encryption, logging, incident management and the rest for 27001, you have already implemented most of A.3. The evidence you collected counts twice.

27701 is not 27001's rival or its replacement. It is 27001 asked a second question: not just 'is the data secure?' but 'are we handling personal data properly?'

What is genuinely new

  • The privacy risk assessment, which weighs impact on individuals, not just the business.
  • The controller and processor privacy controls (Annex A.1 and A.2): lawful basis, consent, data-subject rights, records of processing, transfers, subprocessors.
  • The privacy-specific documents: privacy notice, DPIA, data processing agreements, retention schedules, cross-border transfer records.

The efficient way to do it

Compliance One cross-maps 27701 to your existing 27001 controls automatically, so the shared spine and the A.3 security controls arrive pre-satisfied with the evidence you already hold. What is left is the genuinely new privacy work, and the mandatory documents for that come pre-filled. Most teams find adding 27701 is a fraction of the effort the first certification took, which is a much better sentence to bring to your customer than 'give us another year'.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map Compliance One to your environment.