These are the key topics covered in this guide:
- What ISO/IEC 27701 is and why it matters
- The change to a standalone standard
- ISO 27701:2019 vs 2025
- Route 1: transition from ISO 27701:2019
- Route 2: new ISO 27701:2025 implementation
- Transition timeline and deadline
- Common transition mistakes
- How PrivaLex can help
- Frequently asked questions
- Next step
| Current version | ISO/IEC 27701:2025 |
| Previous version | ISO/IEC 27701:2019, withdrawn |
| Publication date | 14 October 2025 |
| Transition | Confirm the applicable milestones with your certification body and accreditation scheme |
ISO/IEC 27701:2025 was published on 14 October 2025 and it represents the most significant update to privacy information management standards in years. The change that matters most is not a tweak to a control list: the standard is now a fully standalone framework. Organisations can certify a Privacy Information Management System (PIMS) without first holding ISO 27001 certification. That changes the conversation considerably, both for organisations already certified under the 2019 version and for those considering certification for the first time.
If your organisation is already certified under ISO/IEC 27701:2019, plan the transition now and confirm the applicable milestones with your certification body and accreditation scheme. If you are planning a new implementation, the 2025 version is the version to build against. This guide explains what has changed, what it means in practice, and how to prepare. You can find the complete overview in our detailed guide on ISO IEC 27701 changes.
What Is ISO/IEC 27701 and Why Does It Matter?
ISO/IEC 27701 is the international standard for Privacy Information Management Systems (PIMS). It provides a structured, internationally recognised framework that helps organisations establish, implement, maintain and continually improve the way they handle personally identifiable information (PII). The standard applies to both PII controllers and PII processors, terms that map directly onto the concepts of data controllers and data processors under the GDPR.
In the 2019 edition, ISO/IEC 27701 was designed as an extension of ISO/IEC 27001. To implement or certify it, an organisation first needed a functioning Information Security Management System (ISMS) under ISO 27001. That dependency is now removed. The 2025 edition stands on its own.
For EU organisations, the relevance is clear. The GDPR requires organisations to demonstrate accountability, to show, not just claim, that personal data is processed lawfully, fairly and securely. ISO/IEC 27701 certification provides exactly that evidence base. It demonstrates to clients, partners and regulators that your privacy governance is systematic, documented and independently verified.
Five practical benefits of ISO/IEC 27701:
- Strengthen customer, partner and regulator trust.
- Manage privacy risks through a repeatable management system.
- Generate auditable evidence of PII processing and accountability.
- Apply consistent privacy practices across teams and locations.
- Clarify controller, processor and internal responsibilities.
The Most Important Change: A Fully Standalone Standard
The single most significant change in ISO/IEC 27701:2025 is structural. The standard is no longer an extension of ISO/IEC 27001. It is now an independent management system standard, following the ISO harmonised high-level structure (Clauses 4–10) in its own right. Organisations can implement and certify a PIMS without holding or pursuing ISO 27001 certification.
This matters for several groups of organisations:
- Organisations that process large volumes of personal data but do not need or want a full Information Security Management System under ISO 27001 can now pursue privacy certification directly.
- SaaS companies and data-driven businesses that already hold SOC 2 for security can now add ISO/IEC 27701:2025 to address privacy, without duplicating information security audit work.
- Public sector and non-profit entities where privacy obligations are significant but resources for a full ISO 27001 programme are limited now have a proportionate path to certification.
- Organisations already certified under the 2019 edition can maintain an integrated PIMS and ISMS if they wish, the integration path remains available and continues to make sense for many.
Standalone or Integrated PIMS?
| Route | Best suited to | Main advantage |
|---|---|---|
| Standalone ISO 27701 | Organisations focused on privacy that do not need ISO 27001 certification, or that already use another security assurance framework | A direct and proportionate route to a certifiable PIMS |
| Integrated ISO 27701 + ISO 27001 | Organisations that already operate an ISMS or need to demonstrate privacy and information security together | Shared governance, documentation, risk processes and audit cycles |
The 2025 edition also introduces a new companion standard, ISO/IEC 27706:2025, which provides guidance specifically for certification bodies auditing PIMS under the new framework. This replaces ISO TS 27006-2:2021 and brings the certification infrastructure for ISO 27701 up to date.
ISO/IEC 27701:2019 vs 2025
The 2025 edition replaces the 2019 edition. The core purpose remains privacy information management, but the certification architecture and structure have changed:
| Area | ISO/IEC 27701:2019 | ISO/IEC 27701:2025 |
|---|---|---|
| Status | Withdrawn | Current edition |
| Type | Extension to ISO/IEC 27001 and 27002 | Standalone management system standard |
| ISO 27001 prerequisite | Required as the management-system foundation | Not required; integration remains possible |
| Structure | Extension clauses and privacy-specific annexes | Own harmonised Clauses 4–10 |
| Controller and processor controls | Separated across the extension annexes | Restructured and clarified in the revised annexes |
| Certification route | Integrated with an ISMS | Standalone PIMS or integrated PIMS and ISMS |
Beyond the standalone structure, the 2025 edition introduces several substantive updates across the standard’s clauses and annexes.
Harmonised High-Level Structure
ISO/IEC 27701:2025 now follows the same Clauses 4–10 structure as other ISO management system standards, including ISO 27001 and ISO 42001. This makes multi-standard environments significantly easier to manage. Organisations holding multiple certifications can align audit cycles, share documentation and reduce duplication across their compliance programmes.
Restructured Annexes for Controllers and Processors
The control annexes have been reorganised. Annex A now consolidates controls for PII controllers and processors into a clearer structure (A.1, A.2 and A.3). The distinction between controller and processor obligations is more explicitly defined throughout, in alignment with the GDPR’s treatment of these roles.
Privacy Risks in AI and Digital Environments
AI, automated decision-making, profiling, cloud processing and other digital environments must be addressed when they fall within the PIMS scope and create privacy risks. The relevant requirement is to identify, assess, treat and evidence those risks through the ISO/IEC 27701:2025 management system. Organisations that also use ISO/IEC 42001 can align governance and risk processes, but ISO 42001 is not a prerequisite for ISO 27701 certification.
Stronger Governance and Leadership Requirements
Clause 7 now includes broader requirements for resource allocation, competence in privacy support roles and privacy awareness across all levels of the organisation. The standard strengthens the expectation that privacy governance is embedded in leadership and organisational strategy, not delegated entirely to a compliance team.
PII Lifecycle and Operational Controls
Clause 8 introduces a more streamlined approach to operational control across the full PII lifecycle, from collection and processing through to deletion. It references Annexes A and B for the detailed controls and ensures that privacy requirements are applied consistently in day-to-day operations.
Shorter Normative References List
Because the standard now stands alone, Clause 2 (normative references) contains a shorter list. The 2025 edition references ISO/IEC 29100 (Privacy Framework) as its primary normative reference, rather than ISO 27001 and ISO 27002 as in the 2019 version. This reflects the standard’s independence while maintaining alignment with the broader ISO privacy framework.
Route 1: Transition from ISO/IEC 27701:2019
If your organisation is currently certified under ISO/IEC 27701:2019, the transition does not mean starting over. The foundation of your PIMS remains valid. What changes is the structure you align it to and the evidence you need to demonstrate under the new clauses and controls.
The practical transition steps are:
- Confirm the transition arrangements, audit milestones and evidence expected by your certification body and accreditation scheme.
- Perform a clause-by-clause gap assessment against the ISO/IEC 27701:2025 PIMS requirements and revised controls.
- Remap controller and processor controls and update applicability decisions and supporting justification.
- Review the privacy risk methodology, risk assessment and treatment plan across the PII lifecycle.
- Update policies, procedures, records and other documented information to match the new structure.
- Train relevant privacy, legal, security, technology and operational roles.
- Complete an internal audit and management review against the revised PIMS before the external audit.
- Agree and schedule the transition audit with the certification body within the applicable timetable.
Organisations that are already certified to ISO 27001:2022 and hold the 2019 version of ISO 27701 as an extension should find the transition relatively straightforward, since many of the structural changes in ISO 27701:2025 draw on elements already present in ISO 27001:2022 and ISO 27002:2022.
Route 2: New ISO/IEC 27701:2025 Implementation
Organisations starting now should build directly against the 2025 edition. A practical implementation sequence is:
- Define the PIMS scope, organisational context, interested parties and certification objectives.
- Identify whether each in-scope activity is performed as a PII controller, processor or both.
- Establish privacy governance, responsibilities, competence and reporting arrangements.
- Assess privacy risks and opportunities across the PII lifecycle.
- Select applicable controls, justify applicability decisions and prepare the required PIMS documentation.
- Implement the processes and retain evidence that controls operate in practice.
- Complete the internal audit, corrective actions and management review.
- Select an accredited certification body and complete the certification audit.
Transition Timeline and Deadline
ISO/IEC 27701:2025 was published on 14 October 2025. Transition arrangements are implemented through accreditation schemes and certification bodies. For example, the UKAS transition plan sets 31 October 2028 as the date by which its certification bodies are to have transitioned all certified clients. Treat that date as a planning reference, not as a universal deadline for every certificate.
Your applicable milestones may depend on the accreditation body, certification body, audit cycle and certificate status. Obtain the transition plan in writing and schedule the required gap assessment, internal audit and external audit early enough to address findings.
For organisations planning new implementations, the 2025 edition is the current version and should be used as the basis for any new PIMS design. There is no reason to build against the 2019 version.
4 Common Mistakes When Preparing for the Transition
1. Waiting until the deadline is close
Three years feels like a long time, but transition audits need to be scheduled with certification bodies, and good slots fill up. Organisations that start early can also integrate the transition into their regular surveillance audit cycle, which reduces disruption and cost.
2. Treating the standalone change as irrelevant if you already hold ISO 27001
Even if your organisation continues to operate an integrated PIMS and ISMS, the structural changes in the 2025 edition still require a gap assessment and documentation update. The standalone capability does not remove the transition requirement for currently certified organisations.
3. Updating documentation without updating practice
The most common gap in any management system transition is updating the SoA and policy documents without verifying that operational controls, training records and risk treatment decisions actually reflect the new requirements. Auditors assess evidence of implementation, not just documentation.
4. Overlooking in-scope AI and automated processing risks
If your organisation uses AI tools, automated decision-making or profiling involving personal data, determine whether those activities fall within the PIMS scope and assess their privacy risks. The audit issue is not the mere use of AI; it is failing to identify, treat and evidence relevant in-scope privacy risks.
How PrivaLex Can Help
At PrivaLex Partners we support organisations through the full ISO/IEC 27701 journey, from initial gap assessment through to certification and ongoing maintenance. Whether you are transitioning from the 2019 version or building a PIMS for the first time against the 2025 standard, we provide direct expert support adapted to your organisation’s size, sector and existing compliance posture.
Our support covers: gap analysis against ISO/IEC 27701:2025; SoA review and update; PIMS documentation aligned to the new clause structure; controller and processor obligation mapping; internal audit preparation; team training on revised requirements; and coordination with your certification body on transition audit planning.
Our ISO/IEC 27701 deliverables can include:
- A clause-by-clause gap assessment and prioritised implementation plan.
- A controller and processor control map with applicability decisions.
- PIMS policies, procedures, records and privacy risk methodology.
- Internal audit and management review preparation.
- Role-based training and evidence-readiness support.
- Coordination with the certification body for initial or transition audits.
We also help organisations decide whether to pursue an integrated PIMS and ISMS under ISO 27001 and ISO 27701, or to implement ISO 27701:2025 as a standalone certification. For many SaaS companies and data-driven organisations in the EU, the standalone path opens a more efficient route to demonstrating privacy accountability without the full overhead of ISO 27001.
For a complete overview of all the changes in the 2025 version and how to prepare for the transition, read our detailed guide: ISO 27701:2025 – What’s changing and how to prepare for the new privacy standard version.
Schedule a session with PrivaLex to assess your transition requirements and plan a practical path to ISO/IEC 27701:2025 compliance.
Frequently Asked Questions (FAQs)
Does ISO/IEC 27701:2025 still require ISO 27001 certification first?
No. This is the most important change in the 2025 edition. ISO/IEC 27701:2025 is now a fully standalone standard. Organisations can implement and certify a PIMS without holding ISO 27001 certification. If you already hold ISO 27001 and want to maintain an integrated system, that remains possible, but it is no longer a requirement.
When is the transition deadline for organisations certified under the 2019 version?
Transition milestones depend on the applicable accreditation scheme and certification body. For example, UKAS requires its certification bodies to have transitioned all certified clients by 31 October 2028. Confirm the date and audit arrangements that apply to your certificate directly with your certification body.
If we already have ISO 27001 and ISO 27701:2019, what do we actually need to do?
You need to conduct a gap assessment against the 2025 structure and controls, update your SoA and relevant documentation, review your risk treatment plan for PII, train your team on the revised requirements, and schedule a transition audit with your certification body. Organisations already aligned with ISO 27001:2022 should find the transition relatively manageable, since the 2025 edition draws on the same structural foundations.
Is ISO/IEC 27701:2025 relevant for GDPR compliance?
Yes, directly. ISO/IEC 27701 maps closely onto the GDPR’s accountability requirements. The standard’s framework for documentation, risk management, controller and processor obligations, data subject rights and breach response aligns with what the GDPR requires organisations to demonstrate. Certification does not constitute legal GDPR compliance in itself, that requires a legal analysis of your specific processing activities, but it provides strong, auditable evidence that your privacy governance is systematic and mature.
Can we certify ISO/IEC 27701:2025 alongside SOC 2 instead of ISO 27001?
Yes. Because ISO/IEC 27701:2025 is now standalone, organisations that hold SOC 2 for security can add ISO 27701 to cover privacy without needing to layer in a full ISO 27001 programme. This is particularly relevant for SaaS companies and technology organisations with primarily US-market security requirements who also need to demonstrate privacy compliance to EU buyers. The two frameworks address different domains, security and privacy, and complement each other without significant duplication.
How long does a new ISO/IEC 27701:2025 implementation take?
For a new standalone implementation, most organisations should expect three to six months from a structured gap assessment to certificate issuance, depending on organisational size, the volume and complexity of personal data processing, and whether existing privacy documentation and controls are already in place. For organisations transitioning from the 2019 version with a functioning PIMS, the timeline can be shorter. PrivaLex can provide a more precise estimate after an initial assessment of your current posture.
Next Step
Whether you are managing an existing ISO 27701 certification, considering the standalone path for the first time, or trying to understand how the 2025 update affects your broader compliance programme, the right starting point is a structured gap assessment.
Schedule a session with PrivaLex and we will help you understand exactly where you stand and what your transition or implementation plan should look like.
