ISO/IEC 27701:2025 is the current edition of the international privacy information management standard. Published on 14 October 2025, it replaces ISO/IEC 27701:2019 and can now be implemented as a standalone Privacy Information Management System (PIMS), without ISO/IEC 27001 being a prerequisite.

Organisations certified against the 2019 edition should begin planning their transition with their certification body. The deadline depends on the applicable accreditation and certification scheme. For example, the UKAS transition plan requires certification bodies to transition their certified clients by 31 October 2028.

This article explains what changed, who should use the 2025 standard, how certification works, and what organisations should do next.

What ISO/IEC 27701 is and why it matters

ISO/IEC 27701 is an international standard for establishing, implementing, maintaining and continually improving a Privacy Information Management System.

It helps organisations manage personal data in a structured and demonstrable way. The standard addresses privacy responsibilities across the personal information lifecycle, including:

  • Identifying personal information processing activities;
  • Defining privacy roles and responsibilities;
  • Managing controller and processor obligations;
  • Assessing privacy risks;
  • Selecting appropriate privacy controls;
  • Managing suppliers and third parties;
  • Maintaining documented information and evidence;
  • Monitoring performance and compliance;
  • Preparing for audits and continual improvement.

The ISO/IEC 27701:2025 standard is particularly relevant to organisations that process personal information at scale, act as data controllers or processors, provide privacy-related services, or need to demonstrate stronger privacy governance to customers and business partners.

ISO/IEC 27701 does not replace the GDPR or other privacy legislation. Certification can provide evidence that an organisation operates a structured privacy management system, but it does not automatically prove compliance with every legal obligation.

However, if you want a broader overview, you can check ISO 27701:2025.

Who should use ISO/IEC 27701:2025?

ISO/IEC 27701:2025 can benefit organisations that need a consistent way to govern personal information and demonstrate accountability.

It may be especially useful for:

  • technology companies and SaaS providers;
  • cloud service providers;
  • software and artificial intelligence companies;
  • healthcare and financial organisations;
  • marketing and analytics providers;
  • outsourcing and business process providers;
  • organisations processing employee, customer or user data;
  • companies responding to customer security and privacy questionnaires;
  • businesses preparing for an external privacy or information security audit.

The standard can also support organisations that already operate an information security management system. If your organisation is evaluating both frameworks, our article on ISO 27001 certification explains how an information security certification project can be structured.

ISO/IEC 27701:2025 is now a standalone standard

One of the most important changes in the 2025 edition is that ISO/IEC 27701 is now a standalone management system standard.

Under the 2019 edition, ISO/IEC 27701 was designed to extend ISO/IEC 27001 and ISO/IEC 27002, so organisations generally implemented it alongside ISO/IEC 27001. Our previous analysis of the changes to ISO/IEC 27701 provides additional context on this transition.

The 2025 edition can still be integrated with ISO/IEC 27001, but ISO/IEC 27001 is no longer a prerequisite. Organisations can now choose the implementation route that best matches their objectives, existing systems and customer requirements.

This makes ISO/IEC 27701:2025 more accessible to privacy-focused organisations that want to strengthen their privacy governance without undertaking a complete information security certification project.

Standalone implementation

A standalone implementation focuses directly on privacy information management. It can be suitable where:

  • privacy governance is the primary objective;
  • the organisation does not have ISO/IEC 27001 certification;
  • customers are requesting privacy certification specifically;
  • the organisation wants to demonstrate accountability for personal information;
  • the existing information security management system is limited or handled separately.

Integrated implementation

An integrated implementation combines ISO/IEC 27701:2025 with ISO/IEC 27001.

This can be efficient where an organisation already has:

  • an ISO/IEC 27001 management system;
  • established risk management processes;
  • information security policies and procedures;
  • internal audit and management review processes;
  • existing relationships with a certification body.
Implementation routeBest suited toMain consideration
Standalone ISO/IEC 27701:2025Privacy-led organisations without ISO/IEC 27001Requires a complete PIMS structure
Integrated ISO/IEC 27701:2025 and ISO/IEC 27001Organisations with an existing ISMSRequires coordination between security and privacy controls

Standalone does not mean simpler in every case. The complexity depends on the organisation’s processing activities, geographic scope, number of systems, suppliers, jurisdictions and level of existing documentation.

ISO/IEC 27701:2019 vs ISO/IEC 27701:2025

The following table summarises the main differences between the two editions.

AreaISO/IEC 27701:2019ISO/IEC 27701:2025
Relationship with ISO/IEC 27001Designed as an extension to ISO/IEC 27001Can be implemented independently or integrated with ISO/IEC 27001
Management systemPrivacy controls connected to an ISMSStandalone PIMS requirements and privacy management structure
Certification routeGenerally assessed with ISO/IEC 27001Standalone or integrated certification routes
Organisational scopeFocused on privacy within an information security frameworkBroader privacy management applicability
TransitionExisting certificates must move to the new editionCurrent edition for new implementations
DocumentationOften structured around ISO/IEC 27001 documentationRequires documentation and evidence aligned with the 2025 PIMS requirements

The transition is more than a terminology update. Organisations should treat it as a full transition to ISO/IEC 27701:2025 and assess their existing scope, policies, risk assessments, controls, records and audit evidence against the new requirements. 

Route 1: Transition from ISO/IEC 27701:2019

Organisations already certified against ISO/IEC 27701:2019 should treat the change as a structured transition rather than a simple document update. The transition considerations described in our earlier analysis of the ISO/IEC 27701 changes provide useful context, but each organisation must assess how the 2025 requirements affect its own PIMS.

Review the 2025 requirements

Compare the existing PIMS documentation and controls with ISO/IEC 27701:2025. Identify changes affecting the management system structure, privacy roles, processing activities, risk assessment, supplier management, monitoring, internal audits and continual improvement.

Confirm the certification scope

Review whether the existing scope still reflects the organisation’s actual processing activities. Consider new products, services, offices, systems, business units, suppliers, categories of personal information and jurisdictions.

An outdated or unclear scope can create problems during the audit and reduce the commercial value of the certificate.

Update the PIMS documentation

Revise the documents affected by the new requirements. These may include privacy policies, PIMS procedures, processing inventories, privacy risk assessments, controller and processor records, supplier reviews, contractual templates, incident procedures and data subject rights processes.

Implement the required changes

Updated documentation alone is not enough. The organisation must implement the revised processes and collect evidence showing that they operate in practice.

Useful evidence may include completed risk assessments, supplier reviews, employee training records, privacy impact assessments, incident records, retention reviews, monitoring results and corrective action records.

Complete the transition audit

The certification body will assess whether the organisation meets the 2025 requirements and whether the PIMS is effectively implemented.

Before the audit, complete an internal audit and management review. This gives the organisation time to address potential findings before the transition deadline.

Route 2: New ISO/IEC 27701:2025 implementation

Organisations starting from zero can implement ISO/IEC 27701:2025 as a standalone Privacy Information Management System or integrate it with an existing ISO/IEC 27001 management system. The practical implications of the ISO/IEC 27701:2025 update should be considered when defining the project scope and certification route.

Define the organisation and PIMS scope

Document the legal entities, locations, systems, business processes and personal information processing activities covered by the PIMS.

The scope should be specific enough to support a meaningful audit and certificate. Avoid including the entire organisation unless all departments and processing activities are genuinely managed within the system.

Identify privacy roles

Clarify whether the organisation acts as a personal information controller, processor, service provider or a combination of these roles.

Responsibilities should be assigned across privacy, legal, security, IT, procurement, HR, product and operational teams.

Create a processing and information inventory

Identify the personal information the organisation collects, uses, stores, shares and deletes.

The inventory should cover the individuals whose data is processed, categories of personal information, processing purposes, systems, locations, transfers, retention periods, recipients, suppliers and applicable legal or contractual requirements.

Assess privacy risks

Assess how personal information could be misused, exposed, retained unnecessarily or processed outside its intended purpose.

The risk assessment should connect each identified risk to an owner, treatment decision, control and follow-up record. Generic risks without evidence of action are unlikely to demonstrate an effective PIMS.

Establish privacy controls

Select and implement controls appropriate to the organisation’s risks and processing activities. These may cover privacy by design, transparency, data minimisation, consent, individual rights, retention and deletion, information security, supplier management, incident response and international transfers.

Operate the system

The PIMS must operate over time, not only during the certification audit. Assign process owners, train relevant staff, monitor performance and retain evidence that the procedures are being followed.

Audit and improve

Before certification, complete an internal audit and management review. Record findings, corrective actions and improvement decisions.

The organisation can then select an independent certification body and proceed with the certification audit.

Is ISO/IEC 27701:2025 certification mandatory?

ISO/IEC 27701:2025 certification is generally voluntary. Privacy laws such as the GDPR do not automatically require every organisation to obtain an ISO/IEC 27701 certificate.

However, certification may become commercially or contractually important. Customers, regulators, procurement teams or business partners may ask for evidence of a formal privacy management system.

Certification can help an organisation demonstrate that it has:

  • defined privacy responsibilities;
  • assessed privacy risks;
  • implemented relevant controls;
  • established monitoring and improvement processes;
  • created repeatable privacy governance practices.

Certification should not be presented as a guarantee of GDPR compliance. The organisation remains responsible for meeting the specific legal requirements that apply to its processing activities.

How PrivaLex Can Help With Your Privacy Standard Version

PrivaLex can support both organisations transitioning from ISO/IEC 27701:2019 and those implementing ISO/IEC 27701:2025 for the first time. The appropriate approach depends on the organisation’s current certification status, existing management systems, processing activities, customer requirements and target audit date.

For a transition project, PrivaLex can review the existing PIMS and map its policies, procedures, controls and records against the 2025 requirements. This helps identify where the organisation needs to update its scope, clarify privacy responsibilities, revise risk assessments, strengthen supplier oversight or produce additional evidence before the transition audit.

For a new implementation, PrivaLex can help define a practical certification scope and establish the core elements of the PIMS. This may include documenting processing activities, identifying controller and processor responsibilities, assessing privacy risks, developing policies and procedures, selecting appropriate controls and assigning ownership across the organisation.

PrivaLex can also help connect privacy management with information security where both standards are being implemented together. Organisations considering an integrated approach may benefit from reviewing the requirements involved in ISO/IEC 27001 certification, particularly where existing security controls, internal audits and management reviews can support the privacy certification process.

The final stage is audit preparation. PrivaLex can help review objective evidence, test whether documented procedures are being followed, identify potential nonconformities and prepare teams for questions from the certification body. This gives the organisation a clearer view of its readiness before the formal audit begins.

PrivaLex does not issue the certificate. Certification must be completed by an independent certification body. If you need support with the transition, implementation scope or audit preparation, you can contact PrivaLex. 

How does ISO/IEC 27701:2025 certification work?

Certification normally follows a structured audit process:

  1. Define the PIMS scope and applicable processing activities.
  2. Perform a gap assessment against ISO/IEC 27701:2025.
  3. Establish policies, procedures and privacy controls.
  4. Operate the PIMS and collect objective evidence.
  5. Complete an internal audit.
  6. Conduct a management review.
  7. Select an independent certification body.
  8. Complete the certification audit.
  9. Address any nonconformities.
  10. Maintain and continually improve the PIMS through surveillance and recertification audits.

The consultant supporting implementation cannot issue the certificate. Certification is performed by an independent certification body operating under the relevant accreditation arrangements.

Implementation time varies considerably. A small organisation with mature governance may complete the implementation work in a few months. More complex organisations may require six to twelve months or longer, particularly where there are multiple entities, systems, suppliers, jurisdictions or high-risk processing activities.

Transition timeline and deadline

There is no single deadline that applies identically to every organisation worldwide. The applicable date depends on the certification scheme, accreditation body and certification body.

The UKAS transition plan provides one important example. Under that arrangement, certification bodies must transition existing ISO/IEC 27701:2019 certificates by 31 October 2028.

Organisations should therefore establish their own timeline based on the earliest relevant date, including:

  • the date their certification body stops auditing against the 2019 edition;
  • the date existing certificates expire;
  • the next surveillance or recertification audit;
  • the time needed to update documentation;
  • the time needed to operate the revised PIMS;
  • the time needed to close audit findings.

What to prepare now

Start by:

  • contacting the certification body;
  • confirming the transition route;
  • reviewing the official 2025 requirements;
  • mapping the current PIMS to the new edition;
  • checking whether the scope remains accurate;
  • updating processing inventories and risk assessments;
  • identifying missing evidence;
  • scheduling internal audit and management review activities;
  • reserving an audit window before the applicable deadline.

6 Common transition mistakes

1. Treating the transition as a document-only exercise

Changing terminology in policies does not demonstrate that the PIMS has changed. Organisations must update the way privacy risks are identified, managed, monitored and evidenced.

2. Assuming ISO/IEC 27001 is still mandatory

ISO/IEC 27701:2025 can be implemented independently. Requiring ISO/IEC 27001 when the organisation only needs a standalone PIMS can increase the project scope unnecessarily.

3. Using an unclear scope

An incomplete scope may exclude important processing activities, suppliers or business units. A clear scope is essential for both audit accuracy and the commercial value of the certificate.

4. Relying on generic risk assessments

Privacy risks should reflect the organisation’s actual processing activities, systems, suppliers and affected individuals. Generic templates need to be adapted and supported by evidence.

5. Confusing certification with legal compliance

An ISO/IEC 27701 certificate supports accountability, but it does not replace legal analysis, records of processing, data protection impact assessments or other GDPR obligations.

6. Waiting until the final audit window

Late planning can limit the organisation’s choice of audit dates and leave insufficient time to address nonconformities.

Next step

Whether you are transitioning from ISO/IEC 27701:2019 or starting a new standalone PIMS, begin by confirming your scope, certification route and audit timeline.

A structured gap assessment can show which policies, records, controls and operational processes need attention before certification.

To discuss your transition or implementation plans, schedule a session with PrivaLex.

Frequently Asked Questions (FAQs) 

What is ISO/IEC 27701:2025?

ISO/IEC 27701:2025 is an international standard for establishing and improving a Privacy Information Management System. It helps organisations manage personal information, privacy risks, responsibilities and controls in a structured way.

Is ISO/IEC 27701:2025 a replacement for the GDPR?

No. The standard supports privacy governance and accountability, but it does not replace the GDPR or any other applicable privacy law.

Do I need ISO/IEC 27001 before implementing ISO/IEC 27701:2025?

No. ISO/IEC 27701:2025 can be implemented as a standalone standard. It can also be integrated with ISO/IEC 27001 where an organisation already operates an information security management system.

What happens to ISO/IEC 27701:2019 certificates?

Organisations certified against ISO/IEC 27701:2019 should contact their certification body and confirm the applicable transition arrangements. The certificate may remain valid during the permitted transition period, but the organisation will eventually need to be assessed against the 2025 edition.

Is ISO/IEC 27701:2025 certification mandatory?

Certification is generally voluntary. It may nevertheless be requested by customers, business partners, procurement teams or contractual arrangements.

How long does implementation take?

The timeline depends on the organisation’s size, scope, processing activities, existing management systems and audit readiness. Smaller organisations may complete implementation in a few months, while more complex organisations may need six to twelve months or longer.

Can ISO/IEC 27701:2025 be integrated with ISO/IEC 27001?

Yes. The 2025 edition can be implemented as a standalone PIMS or integrated with an existing ISMS.

Who issues the ISO/IEC 27701:2025 certificate?

An independent certification body issues the certificate after completing the required audit. Consultants can provide implementation support but cannot issue the certification.

What is the ISO/IEC 27701:2025 transition deadline?

There is no universal deadline for every certification scheme. The organisation should confirm the applicable deadline with its certification body. Under the UKAS transition plan, the stated deadline for transitioning certified clients is 31 October 2028.


Free checklist
Do you know what’s standing between you and ISO 27001 certification?
Download our readiness checklist and find out which controls you already have in place and where your real gaps lie, before you start the process.
Download Free Checklist