ISO/IEC 27701:2025 — Privacy Information Management

The privacy information management standard. Since the 2025 edition it certifies on its own, with no ISO 27001 certificate required first.

ISO and IEC. Certification is issued by accredited certification bodies.

What it is

ISO/IEC 27701 is the international standard for a Privacy Information Management System — a PIMS. It governs how an organisation collects, uses, discloses, retains and disposes of personal information, and how it meets the obligations it owes to the people that information describes.

The 2025 edition, published in October 2025, is a structural break from its predecessor rather than a routine update. The 2019 version was an extension of ISO/IEC 27001 and could only be certified alongside it. The 2025 edition is a complete, self-contained management system standard with its own Clauses 4 to 10, so a PIMS can be implemented and certified on its own merits with no ISO 27001 certificate in place.

The control set was rebuilt around the role an organisation plays rather than mapped one-to-one onto ISO/IEC 27002. Annex A holds 78 privacy controls in three groups: controls for PII controllers, controls for PII processors, and shared controls applying to both. Controls are justified by role, which changes how the Statement of Applicability is built and how evidence is presented. Mapping annexes connect the standard to GDPR and ISO/IEC 29100.

Organisations certified to the 2019 edition must transition by October 2028, when those certificates expire. Organisations new to the standard certify directly against 2025 and have no transition obligation.

Who it's for

Organisations whose exposure sits in personal information rather than infrastructure security.

Organisations handling personal information at scale

Health, education, financial services, recruitment, marketing, and any platform holding substantial customer records. Where a breach would be reportable and newsworthy, this is the standard that addresses it directly.

Processors acting on behalf of others

If you handle personal information for a client, their obligations reach you by contract. Increasingly they want independent evidence rather than a contractual warranty, and this is the recognised form of that evidence.

Organisations selling into the EU or UK

The GDPR mapping annexes make a certified PIMS a practical way to demonstrate accountability to European counterparties without arguing the point from first principles.

Organisations without an ISMS

This is the group the 2025 edition opened up. If your risk is privacy rather than security, you no longer have to build an information security management system first in order to certify.

Why implement it

  • It answers the privacy half of due diligence. Enterprise questionnaires ask where personal information goes, who it is shared with and how long it is kept. A certified PIMS answers all three from documents you already hold.
  • It is now reachable without an ISMS. Certification is open to organisations that could not previously pursue it, and while adoption of the standalone edition is still building, that is an advantage rather than a drawback.
  • It maps onto Australian obligations. The controls align closely with the Australian Privacy Principles and the Notifiable Data Breaches scheme, so one control set serves certification and regulatory defensibility together.
  • It travels. The GDPR and ISO/IEC 29100 mapping annexes make the same system legible to international counterparties.
  • It forces the inventory nobody has. Most organisations cannot produce a complete record of their personal information holdings on request. Building one is the single most useful output of the engagement, certificate or not.

How implementation works

Five to eight months standalone, materially less where an ISO 27001 ISMS already exists.

1. Determine your role

Establish where the organisation acts as PII controller, where as processor, and where both. Because the 2025 control set is organised by role, this drives everything downstream and is expensive to unwind if it is wrong.

2. Build the personal information inventory

What personal information is held, why, where it sits, who it is disclosed to, and when it is destroyed. Nearly every organisation discovers holdings it had forgotten — old exports, backups, a spreadsheet on someone's drive.

3. Assess privacy risk and build the Statement of Applicability

Assess risk to individuals, not only to the organisation. This is the distinction people find hardest and the one auditors probe. Then select from the 78 Annex A controls according to role.

4. Build the controls

Privacy policy and collection notices, lawful basis and consent records, individual rights handling, retention and disposal schedules, a privacy impact assessment procedure, and breach response wired to the OAIC notification pathway.

5. Operate the system

The PIMS must produce records — completed rights requests, executed retention actions, assessments performed — before an auditor can verify anything.

6. Internal audit and management review

Both mandatory before Stage 2. The internal audit must be impartial.

7. Stage 1 and Stage 2 certification audit

How Soveriq helps

Soveriq builds the PIMS inside your existing environment, so the inventory, rights register and retention schedules live in systems your team already uses rather than a compliance subscription you rent indefinitely.

Where ISO 27001 is also in scope, both run on one governance layer, one risk register and one audit programme.

On internal audit. Where Soveriq has built your management system, we do not then audit it and present that as an independent internal audit. What we provide is readiness validation — labelled as such, and not a substitute for the impartial audit Clause 9.2 requires. Where an independent internal audit is needed after a Soveriq build, it is performed by someone independent of that build and disclosed to you in writing. The same applies to any retainer including an audit component.

What we will not do. Soveriq does not issue certificates, is not a certification body, and does not promise a certification outcome.

What the engagement looks like

  • Module 01 — Gap analysis. Role determination, data mapping and a clause-by-clause review against the 2025 edition.
  • Module 02 — Build. Inventory, privacy risk assessment, Statement of Applicability by role, notices, rights handling, retention schedules and breach response.
  • Module 03 — Internal audit, subject to the impartiality position above.
  • Module 04 — Audit representation through Stage 1 and Stage 2.
  • Module 05 — Continuous compliance. Rights request handling, retention actions and surveillance readiness.

Price floors are published on the pricing page. Certification body fees are separate and paid directly to that body.

Where ISO 27001 is in scope at the same time, the shared Annex SL clauses mean the second certificate costs a fraction of the first.

Common questions

Do we still need ISO 27001 first?

No. That was true of the 2019 edition and is the single biggest change in the 2025 revision. A PIMS can now be scoped and certified entirely on its own. Many organisations still choose both, because the same customers usually ask for both.

We are certified to the 2019 edition. What happens?

Your certificate remains valid until October 2028, at which point 2019 certificates expire. Transition audits can usually be combined with a scheduled surveillance or recertification audit rather than run separately, which is the cheaper path.

Does this make us GDPR compliant?

No, and be wary of anyone who says otherwise. The standard includes annexes mapping its controls to GDPR, so a certified PIMS is strong evidence of accountability and covers much of the ground. Certification is not a finding of legal compliance, and no certificate can be.

How does it relate to the Australian Privacy Act?

The control set aligns closely with the Australian Privacy Principles and supports the record-keeping and breach response the Notifiable Data Breaches scheme assumes. It is a practical way to operationalise APP obligations, though the Act applies regardless of whether you certify.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope