ISO/IEC 27701 extends ISO 27001 into a Privacy Information Management System (PIMS), adding controls specific to handling personal data as either a controller or a processor.
It doesn't replace ISO 27001 — it's a companion certification built on top of an existing ISMS — and it explicitly maps to GDPR requirements, which makes it a practical way to demonstrate accountability to EU regulators and enterprise customers without building a separate privacy program from scratch.
Privacy extension to 27001
ISO/IEC
ISO/IEC 27701:2019