Management system
ISO/IEC 27701 — Privacy Information Management
Privacy obligations arrive from several directions at once — India's DPDP Act, the GDPR where you touch EU data, and customer contracts that impose their own terms. ISO/IEC 27701 gives you one system to satisfy them rather than a separate response to each.
- Standard
- ISO/IEC 27701:2025
- Standalone since
- Oct 2025
- Roles covered
- Controller + processor
- Maps to
- DPDP · GDPR
What changed, and why it matters
ISO/IEC 27701 specifies a privacy information management system — a PIMS — covering how you act as a controller of personal data, as a processor, or as both.
The 2025 edition, published on 14 October 2025, replaced the 2019 edition and made a structural change worth knowing about: ISO/IEC 27701 is now a standalone standard. Previously it was an extension that could only be implemented and certified on top of ISO/IEC 27001. It can now be adopted on its own, which opens it to organisations that have not certified an ISMS and do not intend to.
That said, the two remain natural companions. Where an ISMS already exists, the privacy system builds on the same risk method, the same document control and the same audit cycle — and most of the effort is in the privacy-specific requirements rather than in management-system scaffolding you have already built.
What it will ask of you
Privacy work fails when it is written as policy and never becomes process. These are the four places that difference shows.
Role determination, per activity
Where you act as controller, where as processor, and where as both. Everything downstream — obligations, contracts, who answers a data subject — depends on getting this right first.
Records of processing
What personal data you hold, where it came from, where it flows including outside India, who it is shared with and how long it is kept.
A privacy risk process, not a one-off
Risk to data subjects rather than only to the organisation, with impact assessments applied where processing is high risk and the records kept.
Rights handling that actually runs
Notice, consent, retention, disposal and data subject rights as working processes with owners and timelines — plus processor contracts and a breach notification procedure.
Why organisations implement it
- It demonstrates privacy accountability to enterprise customers with a recognised certificate instead of a self-assessment.
- It maps cleanly onto obligations under the DPDP Act and the GDPR, so one system serves several regimes.
- It clarifies your controller and processor roles per data flow — the question that decides who is responsible when something goes wrong.
- It produces the records of processing, retention decisions and data subject rights handling that a regulator asks for first.
Where we come in, and where we stop
Certification, where you want it, is performed by an independent accredited certification body. And one thing we will not do at all: tell you whether you comply with a law. That is a legal question decided against that law, and it wants a lawyer.
Ours
- Scope and role determination per processing activity
- Data mapping, flow maps and records of processing
- Privacy risk assessment, integrated with your security risk method
- Notices, consent mechanics, retention schedules and rights processes
- Processor and sub-processor contract terms, and breach notification
- Training, internal audit and certification readiness
Not ours
- Stage 1 and Stage 2 assessment, by an accredited certification body
- A legal opinion on whether you comply with the DPDP Act or the GDPR
How we build it
Certification, where you want it, is performed by an independent accredited certification body.
- 01Scope and role determinationWhich processing the PIMS covers, and where you act as controller, as processor, or as both. Everything downstream depends on getting this right.
- 02Data mapping and records of processingWhat personal data you hold, where it came from, where it flows including outside India, who it is shared with, and how long it is kept.
- 03Privacy risk assessmentRisk to data subjects, not only to the organisation, assessed alongside your information security risk work rather than in a separate register.
- 04Controls and proceduresNotice and consent, purpose limitation, retention and disposal, data subject rights handling, processor contracts and breach notification — implemented as working processes with owners.
- 05Training and internal auditRole-specific training for the people who handle personal data, then an internal audit against the standard with findings tracked to closure.
- 06Certification readinessManagement review, the evidence pack, and support through Stage 1 and Stage 2 where certification is the goal.
What you get from us
- Controller and processor role determination per processing activity
- Data inventory, flow maps and records of processing
- Privacy risk assessment integrated with your security risk method
- Privacy notices, consent mechanics and retention schedules
- A working data subject rights process with defined timelines
- Processor and sub-processor contract terms, and a breach notification procedure
Common questions
Do we need ISO/IEC 27001 first?
Not since the 2025 edition, which made ISO/IEC 27701 standalone. Under the 2019 edition it could only be certified as an extension to a certified ISMS. If you already hold ISO/IEC 27001 it remains the cheaper starting point, because the management system requirements are shared.
Does certification make us DPDP Act or GDPR compliant?
No, and be sceptical of anyone who says otherwise. Compliance with a law is a legal question decided against that law. ISO/IEC 27701 gives you the management system, records and evidence that make demonstrating compliance far more straightforward — it does not substitute for legal advice on your obligations.
We are a processor, not a controller. Is it still relevant?
Particularly so. The standard addresses processors directly, and processors are the ones whose customers demand evidence contractually. It is often easier to sell internally for exactly that reason.
How does this relate to a DPIA?
A privacy impact assessment is one process within the system. ISO/IEC 27701 requires you to have the assessment process, apply it where processing is high risk, and keep the records — rather than run a one-off assessment and file it.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
Related insights
Regulation · India
Is the DPDP Act in force? What applies today, and the deadline that matters
The Act is law today and its obligations bite on 13 May 2027. Penalties reach ₹250 crore, and the work that takes longest is the work nobody has started.
Regulation · EU
Does the GDPR apply to an Indian company? Scope, roles and the EU representative question
Most Indian firms are caught through a contract rather than by a regulator — and most do not need the EU representative they are being sold.
Regulation
Breach notification: the clock starts before you know what happened
Both regimes start counting when you become aware — and India’s rules have no risk threshold for telling the people affected.