Back to Frameworks
Privacy

ISO 27701

ISO/IEC 27701 extends ISO 27001 into a Privacy Information Management System (PIMS), adding controls specific to handling personal data as either a controller or a processor.

It doesn't replace ISO 27001 — it's a companion certification built on top of an existing ISMS — and it explicitly maps to GDPR requirements, which makes it a practical way to demonstrate accountability to EU regulators and enterprise customers without building a separate privacy program from scratch.

See how LumiGRC handles ISO 27701

Get a Demo
PIMS

Privacy extension to 27001

0%
Typical certification profile
Audit Rigor71%
Time to Certify55%
Surveillance Burden49%
Issued & Enforced By

ISO/IEC

ISO/IEC 27701:2019

Key Points

  • Extends an existing ISO 27001 ISMS into privacy management
  • Distinguishes controller vs. processor obligations
  • Maps directly to GDPR requirements
  • Demonstrates privacy accountability to regulators and customers