Overview
ISO/IEC 27701 specifies requirements and guidance for a privacy information management system, or PIMS. The second edition was published on October 14, 2025 and replaced the 2019 edition. The biggest change is structural. The 2019 edition was written as an extension of ISO/IEC 27001 and ISO/IEC 27002, so a PIMS could only be certified on top of an information security management system, while the 2025 edition is an independent management system standard that ISO says can be used on its own.
The 2025 text follows the harmonized structure used by other ISO management system standards, with clauses 4 to 10 covering context, leadership, planning, support, operation, evaluation, and improvement. According to UKAS, it also strengthens leadership and performance evaluation, adds climate change considerations, builds privacy risk management into the management system, and restructures the controls for controllers and processors. Auditors have new rules too. A companion standard, ISO/IEC 27706:2025, sets out requirements for the bodies that audit and certify a PIMS.
The move to a standalone standard means certification bodies needed new accreditation, so the transition is longer than usual. UKAS, which reflects the timeline agreed through the international accreditation working group, gives October 31, 2027 for accredited certification bodies to transition and October 31, 2028 for certified organizations to move from the 2019 edition. Canadian organizations certified through an SCC-accredited body should confirm the SCC's own transition arrangements with their certification body. A certificate supports privacy accountability. It doesn't replace legal compliance with PIPEDA or Law 25.
Who it applies to in Canada
Any organization that acts as a controller or processor of personally identifiable information (PII), in the public, private, or not-for-profit sector. It suits organizations that want a structured, certifiable privacy program.
Canadian organizations use ISO/IEC 27701 to show accountability for personal information under PIPEDA, Quebec's Law 25, and provincial privacy laws, and to answer privacy questions from international customers. The Standards Council of Canada runs an accreditation program for privacy information management systems certification bodies.
Controls at a glance
Clauses 4 to 10 set the management system requirements, and Annex A lists reference controls for PII controllers and PII processors.
Context and leadership (clauses 4 and 5)
- Identify privacy-related issues, laws, and contracts
- Determine whether the organization is controller, processor, or both
- Define the PIMS scope
- Top management sets a privacy policy and roles
Planning (clause 6)
- Assess privacy risks to individuals and to the organization
- Plan risk treatment and select controls
- Record control decisions in a Statement of Applicability
- Set privacy objectives and plan changes
Support and operation (clauses 7 and 8)
- Provide resources, competence, and awareness for privacy
- Control documented information about processing
- Run privacy risk assessments and treatment plans
- Control outsourced processing
Evaluation and improvement (clauses 9 and 10)
- Monitor and measure privacy performance
- Run internal audits and management reviews
- Correct nonconformities and improve the PIMS
Controls for PII controllers (Annex A)
- Identify and document lawful purposes for processing
- Obtain and record consent where needed
- Carry out privacy impact assessments
- Give individuals notice and handle their rights requests
- Limit collection, use, and retention by design and default
- Manage transfers and disclosures to third parties
Controls for PII processors (Annex A)
- Process PII only under customer agreements and instructions
- Help customers meet their obligations to individuals
- Return or dispose of PII when services end
- Disclose subprocessors and processing locations
- Notify customers of legally binding disclosure requests
Security controls for PII
- Apply information security controls to PII processing
- Handle privacy breaches and notification duties
- Protect PII in systems, backups, and test data
Security controls draw on ISO/IEC 27002:2022.
Certification and assessment
A certification body audits the PIMS in stage 1 and stage 2 audits and issues a certificate that names the scope and the PII roles covered. Under the 2025 edition, the PIMS can be certified on its own or together with ISO/IEC 27001. Certification bodies follow ISO/IEC 17021-1 and the PIMS-specific rules in ISO/IEC 27706:2025.
Dates to know
- 2025-10-14
- ISO/IEC 27701:2025 published as a standalone standard, replacing the 2019 edition
- 2026-05-01
- UKAS begins assessing certification bodies to the 2025 edition
- 2027-10-31
- Accredited certification bodies must complete their transition (UKAS timeline)
- 2028-10-31
- Certified organizations must complete their transition from the 2019 edition (UKAS timeline)
Resources
Official texts and free tools for ISO 27701. Links open the publisher’s site.
- ISO/IEC 27701:2025 Privacy information management systems, ISO
- Privacy information management systems accreditation, Standards Council of Canada
- Transition arrangements for privacy information management systems, UKAS
- PIPEDA fair information principles, Office of the Privacy Commissioner of Canada
- Commission d'accès à l'information du Québec, Commission d'accès à l'information du Québec
- IAF CertSearch, International Accreditation Forumtool
Need help? Browse the directory or read the guides.
References
- ISO/IEC 27701:2025 Privacy information management systems, ISO
- Transition arrangements for privacy information management systems, UKAS
- Privacy information management systems accreditation, Standards Council of Canada
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.