All resources
Guide 9 min read

ISO 27701 explained: the closest thing to a GDPR certificate

C1The Compliance One team28 August 2026

Here is an awkward fact about the world's most famous privacy law: you cannot get certified against the GDPR. There is no badge, no certificate, no auditor who stamps 'GDPR compliant' on your website. So when a customer asks the question, and they always ask the question, most companies reach for a privacy policy and a hopeful tone. ISO 27701 exists to give you a much better answer.

It is the international standard for a Privacy Information Management System, or PIMS. Think of it as a management system for personal data: the policies, roles, risk assessments and controls that govern how you handle the personal information people trust you with. And crucially, it maps directly to the GDPR, article by article. So an ISO 27701 certificate is about as close as you can get to a certifiable, independently audited 'yes' to the GDPR question.

You cannot certify to the GDPR. You can certify to ISO 27701, which maps to it. For a buyer's security team, that is the difference between a promise and proof.

The 2025 rewrite you need to know about

There are two versions in the wild, and picking the wrong one wastes months. The 2019 edition was a bolt-on: you had to already hold ISO 27001, and 27701 extended it. The 2025 second edition was completely redrafted as a stand-alone management system, so you can pursue it in its own right (though it still plays beautifully with 27001). Our content is on the 2025 text, so you are not building against last year's model.

The moving parts

27701 has the same clause 4 to 10 spine as other ISO management systems (context, leadership, planning, support, operation, evaluation, improvement), with privacy risk assessment and treatment at its heart. Then it adds a normative Annex A of privacy controls, split by role:

  • A.1, controller controls (31): lawful basis, consent, data-subject rights, minimisation, retention, and cross-border transfers.
  • A.2, processor controls (18): acting only on customer instructions, subprocessors, disclosures, and secure return or deletion of data.
  • A.3, security controls (29): the security of personal data, which map almost one-to-one to ISO 27001:2022.

How Compliance One makes it manageable

The platform ships the full 2025 clause library plus all 78 Annex A controls, enabled by default with a Statement of Applicability. It is role-aware out of the box: controller and security controls are on, processor controls are one click to promote, and a plain-English banner explains the difference so you pick the right set without a law degree. Every control cross-maps to ISO 27001 and to GDPR articles, and the mandatory documents (records of processing, privacy notice, DPAs, DPIA, and more) come pre-filled. The GDPR question stops being a nervous moment and becomes an attachment.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.