Skip to content
SecuriFii

Management system

ISO/IEC 27701 — Privacy Information Management

Privacy obligations arrive from several directions at once — India's DPDP Act, the GDPR where you touch EU data, and customer contracts that impose their own terms. ISO/IEC 27701 gives you one system to satisfy them rather than a separate response to each.

Standard
ISO/IEC 27701:2025
Standalone since
Oct 2025
Roles covered
Controller + processor
Maps to
DPDP · GDPR

What changed, and why it matters

ISO/IEC 27701 specifies a privacy information management system — a PIMS — covering how you act as a controller of personal data, as a processor, or as both.

The 2025 edition, published on 14 October 2025, replaced the 2019 edition and made a structural change worth knowing about: ISO/IEC 27701 is now a standalone standard. Previously it was an extension that could only be implemented and certified on top of ISO/IEC 27001. It can now be adopted on its own, which opens it to organisations that have not certified an ISMS and do not intend to.

That said, the two remain natural companions. Where an ISMS already exists, the privacy system builds on the same risk method, the same document control and the same audit cycle — and most of the effort is in the privacy-specific requirements rather than in management-system scaffolding you have already built.

What it will ask of you

Privacy work fails when it is written as policy and never becomes process. These are the four places that difference shows.

  • Role determination, per activity

    Where you act as controller, where as processor, and where as both. Everything downstream — obligations, contracts, who answers a data subject — depends on getting this right first.

  • Records of processing

    What personal data you hold, where it came from, where it flows including outside India, who it is shared with and how long it is kept.

  • A privacy risk process, not a one-off

    Risk to data subjects rather than only to the organisation, with impact assessments applied where processing is high risk and the records kept.

  • Rights handling that actually runs

    Notice, consent, retention, disposal and data subject rights as working processes with owners and timelines — plus processor contracts and a breach notification procedure.

Why organisations implement it

  • It demonstrates privacy accountability to enterprise customers with a recognised certificate instead of a self-assessment.
  • It maps cleanly onto obligations under the DPDP Act and the GDPR, so one system serves several regimes.
  • It clarifies your controller and processor roles per data flow — the question that decides who is responsible when something goes wrong.
  • It produces the records of processing, retention decisions and data subject rights handling that a regulator asks for first.

Where we come in, and where we stop

Certification, where you want it, is performed by an independent accredited certification body. And one thing we will not do at all: tell you whether you comply with a law. That is a legal question decided against that law, and it wants a lawyer.

Ours

  • Scope and role determination per processing activity
  • Data mapping, flow maps and records of processing
  • Privacy risk assessment, integrated with your security risk method
  • Notices, consent mechanics, retention schedules and rights processes
  • Processor and sub-processor contract terms, and breach notification
  • Training, internal audit and certification readiness

Not ours

  • Stage 1 and Stage 2 assessment, by an accredited certification body
  • A legal opinion on whether you comply with the DPDP Act or the GDPR

How we build it

Certification, where you want it, is performed by an independent accredited certification body.

  1. 01Scope and role determinationWhich processing the PIMS covers, and where you act as controller, as processor, or as both. Everything downstream depends on getting this right.
  2. 02Data mapping and records of processingWhat personal data you hold, where it came from, where it flows including outside India, who it is shared with, and how long it is kept.
  3. 03Privacy risk assessmentRisk to data subjects, not only to the organisation, assessed alongside your information security risk work rather than in a separate register.
  4. 04Controls and proceduresNotice and consent, purpose limitation, retention and disposal, data subject rights handling, processor contracts and breach notification — implemented as working processes with owners.
  5. 05Training and internal auditRole-specific training for the people who handle personal data, then an internal audit against the standard with findings tracked to closure.
  6. 06Certification readinessManagement review, the evidence pack, and support through Stage 1 and Stage 2 where certification is the goal.

What you get from us

  • Controller and processor role determination per processing activity
  • Data inventory, flow maps and records of processing
  • Privacy risk assessment integrated with your security risk method
  • Privacy notices, consent mechanics and retention schedules
  • A working data subject rights process with defined timelines
  • Processor and sub-processor contract terms, and a breach notification procedure

Common questions

Do we need ISO/IEC 27001 first?

Not since the 2025 edition, which made ISO/IEC 27701 standalone. Under the 2019 edition it could only be certified as an extension to a certified ISMS. If you already hold ISO/IEC 27001 it remains the cheaper starting point, because the management system requirements are shared.

Does certification make us DPDP Act or GDPR compliant?

No, and be sceptical of anyone who says otherwise. Compliance with a law is a legal question decided against that law. ISO/IEC 27701 gives you the management system, records and evidence that make demonstrating compliance far more straightforward — it does not substitute for legal advice on your obligations.

We are a processor, not a controller. Is it still relevant?

Particularly so. The standard addresses processors directly, and processors are the ones whose customers demand evidence contractually. It is often easier to sell internally for exactly that reason.

How does this relate to a DPIA?

A privacy impact assessment is one process within the system. ISO/IEC 27701 requires you to have the assessment process, apply it where processing is high risk, and keep the records — rather than run a one-off assessment and file it.

Related insights