ISO/IEC 27701

How to scope a privacy information management system under the current standalone edition and connect it with security controls.

Confirm the edition and assessment goal

ISO/IEC 27701:2025 replaced the 2019 edition and is described by ISO as an independent management system standard. That matters for scoping and for organizations that previously treated it only as an extension to ISO/IEC 27001. Confirm which edition a customer or certification body expects before reusing an older checklist.

Define why the organization wants a PIMS: governing privacy operations, answering customer due diligence, preparing for independent assessment, or improving control over personal information.

Map controller and processor activities

Identify the personal information handled, purposes, systems, suppliers, data flows, individuals affected, and jurisdictions. Record where the organization acts as a controller, processor, or both for different activities. Those roles shape obligations and evidence, so a single organization-wide label is rarely sufficient.

Set the PIMS boundary around real processing and the people who can change it. Include business, legal, product, security, and supplier owners in the operating model.

Make privacy decisions operable

Establish policy, objectives, risk assessment, data handling rules, request and incident processes, supplier controls, and review. Connect these to normal workflows: product intake, contracts, system changes, retention decisions, and incident triage. A privacy notice alone does not demonstrate that the underlying processing is governed.

ISO/IEC 27001 controls for access, logging, suppliers, and incidents may be reused where the scope overlaps. Privacy-specific decisions about lawful processing, transparency, rights, retention, and transfers still need their own owners and legal analysis.

Test the management cycle

Sample actual processing activities and trace their records through approval, operation, request handling, changes, and review. Use internal audit and management review to identify weak controls and unresolved risk. If certification is pursued, an independent body determines conformity within its assessed scope.

A PIMS can support accountability but does not itself prove compliance with GDPR or any other privacy law.

Put it into practice

  • Confirm the current 2025 edition with buyers and assessors.
  • Map processing activities and controller or processor roles.
  • Link privacy decisions to routine product, supplier, and incident workflows.
  • Assess legal obligations separately from PIMS conformity.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources