home / frameworks / iso-27701

// International standards

ISO/IEC 27701:2025

ISO/IEC 27701 sets requirements for a privacy information management system (PIMS) for PII controllers and processors. The 2025 edition is a standalone standard, so it no longer has to be certified as an extension of ISO/IEC 27001.

International

Overview

ISO/IEC 27701 specifies requirements and guidance for a privacy information management system, or PIMS. The second edition was published on October 14, 2025 and replaced the 2019 edition. The biggest change is structural. The 2019 edition was written as an extension of ISO/IEC 27001 and ISO/IEC 27002, so a PIMS could only be certified on top of an information security management system, while the 2025 edition is an independent management system standard that ISO says can be used on its own.

The 2025 text follows the harmonized structure used by other ISO management system standards, with clauses 4 to 10 covering context, leadership, planning, support, operation, evaluation, and improvement. According to UKAS, it also strengthens leadership and performance evaluation, adds climate change considerations, builds privacy risk management into the management system, and restructures the controls for controllers and processors. Auditors have new rules too. A companion standard, ISO/IEC 27706:2025, sets out requirements for the bodies that audit and certify a PIMS.

The move to a standalone standard means certification bodies needed new accreditation, so the transition is longer than usual. UKAS, which reflects the timeline agreed through the international accreditation working group, gives October 31, 2027 for accredited certification bodies to transition and October 31, 2028 for certified organizations to move from the 2019 edition. Canadian organizations certified through an SCC-accredited body should confirm the SCC's own transition arrangements with their certification body. A certificate supports privacy accountability. It doesn't replace legal compliance with PIPEDA or Law 25.

Who it applies to in Canada

Any organization that acts as a controller or processor of personally identifiable information (PII), in the public, private, or not-for-profit sector. It suits organizations that want a structured, certifiable privacy program.

Canadian organizations use ISO/IEC 27701 to show accountability for personal information under PIPEDA, Quebec's Law 25, and provincial privacy laws, and to answer privacy questions from international customers. The Standards Council of Canada runs an accreditation program for privacy information management systems certification bodies.

Controls at a glance

Clauses 4 to 10 set the management system requirements, and Annex A lists reference controls for PII controllers and PII processors.

Context and leadership (clauses 4 and 5)

  • Identify privacy-related issues, laws, and contracts
  • Determine whether the organization is controller, processor, or both
  • Define the PIMS scope
  • Top management sets a privacy policy and roles

Planning (clause 6)

  • Assess privacy risks to individuals and to the organization
  • Plan risk treatment and select controls
  • Record control decisions in a Statement of Applicability
  • Set privacy objectives and plan changes

Support and operation (clauses 7 and 8)

  • Provide resources, competence, and awareness for privacy
  • Control documented information about processing
  • Run privacy risk assessments and treatment plans
  • Control outsourced processing

Evaluation and improvement (clauses 9 and 10)

  • Monitor and measure privacy performance
  • Run internal audits and management reviews
  • Correct nonconformities and improve the PIMS

Controls for PII controllers (Annex A)

  • Identify and document lawful purposes for processing
  • Obtain and record consent where needed
  • Carry out privacy impact assessments
  • Give individuals notice and handle their rights requests
  • Limit collection, use, and retention by design and default
  • Manage transfers and disclosures to third parties

Controls for PII processors (Annex A)

  • Process PII only under customer agreements and instructions
  • Help customers meet their obligations to individuals
  • Return or dispose of PII when services end
  • Disclose subprocessors and processing locations
  • Notify customers of legally binding disclosure requests

Security controls for PII

  • Apply information security controls to PII processing
  • Handle privacy breaches and notification duties
  • Protect PII in systems, backups, and test data

Security controls draw on ISO/IEC 27002:2022.

Certification and assessment

A certification body audits the PIMS in stage 1 and stage 2 audits and issues a certificate that names the scope and the PII roles covered. Under the 2025 edition, the PIMS can be certified on its own or together with ISO/IEC 27001. Certification bodies follow ISO/IEC 17021-1 and the PIMS-specific rules in ISO/IEC 27706:2025.

Dates to know

2025-10-14
ISO/IEC 27701:2025 published as a standalone standard, replacing the 2019 edition
2026-05-01
UKAS begins assessing certification bodies to the 2025 edition
2027-10-31
Accredited certification bodies must complete their transition (UKAS timeline)
2028-10-31
Certified organizations must complete their transition from the 2019 edition (UKAS timeline)

Resources

Official texts and free tools for ISO 27701. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. ISO/IEC 27701:2025 Privacy information management systems, ISO
  2. Transition arrangements for privacy information management systems, UKAS
  3. Privacy information management systems accreditation, Standards Council of Canada