ISAO — International Standards Accreditation Organization home pageVerify a certificate

Menu

Information and technology

ISO/IEC 27701:2025

Privacy information management systems

ISO/IEC 27701 sets out requirements for a privacy information management system.

Key facts

Edition
Current edition (2025)

A certified organisation manages the personal data it handles through defined responsibilities, privacy risk assessment and a set of privacy controls, whether it acts as a controller (deciding why and how data is processed), as a processor acting for others, or as both. Since the 2025 edition it is a stand-alone standard: it no longer has to be built on an ISO/IEC 27001 information security management system, although the two can be run together.

Who it suits

Organisations that process personal data at scale or on behalf of others: cloud and software providers, payroll, HR and marketing services, contact centres, healthcare and financial services, and public bodies. It helps where contracts ask a processor to show how it protects personal data, or where a controller wants an independent check on its privacy management.

What certification involves

ISAO, or a certification body accredited for ISO/IEC 27701, audits the system in two stages: first the scope, the roles the organisation takes, its privacy risk assessment and the controls it has chosen; then how those controls work in practice, for example handling requests from individuals, keeping records of processing, managing processors and responding to breaches. The certificate states the scope and the roles covered. Certification does not show that an organisation complies with data protection law; it shows that it runs an audited system for managing privacy. Certificates are normally valid for three years, with surveillance audits at least once a year and a recertification audit before expiry. ISAO carries out this certification itself, and also accredits certification bodies to do it. Every certificate ISAO issues, and every certificate issued under ISAO accreditation, is recorded on the public register.

Key themes

  • Deciding, for each kind of processing, whether the organisation acts as a controller, a processor or both
  • Assessing privacy risks to individuals as well as to the organisation
  • Privacy controls for controllers and for processors, set out in the standard's annexes
  • Knowing the legal grounds and purposes for processing, and keeping records of it
  • Responding to individuals who exercise their rights over their data
  • Privacy by design and by default, retention and secure disposal
  • Managing sub-processors, transfers and personal data breaches

Edition

Current edition
ISO/IEC 27701:2025

ISO/IEC 27701:2025, the second edition, was published in October 2025. It replaced ISO/IEC 27701:2019, which could only be used as an extension to ISO/IEC 27001 and ISO/IEC 27002. The 2025 edition can be used on its own, without an information security management system beneath it. It includes mappings to the EU General Data Protection Regulation and to other privacy standards, which help organisations relate its controls to their legal obligations.

Check a certificate for ISO/IEC 27701:2025

  • Enter the certificate number or verification code at Verify a certificate, or scan the QR code on the certificate. The record shows the certificate's status today, for example valid, suspended, withdrawn or expired.
  • Compare the organisation name, scope and sites on the record with the copy you were given. Check the roles covered (controller, processor or both) and that the processing you are concerned with is inside the scope.
  • Check who issued the certificate, as named on the record. Where a certification body accredited by ISAO issued it, the record shows the status of that accreditation and its accreditation number, and says so if the accreditation did not cover ISO/IEC 27701:2025 when the certificate was issued.
  • A certificate that still names ISO/IEC 27701:2019 refers to a withdrawn edition and was issued as an extension of an ISO/IEC 27001 certificate: ask the issuing body about it. A certificate to the 2025 edition can stand on its own.
  • If the certificate is not on the register, ISAO cannot confirm it: it may have been issued under another accreditation, or a detail may be wrong. Ask the issuing body, and report a concern if something does not look right.

This is ISAO’s own summary, not the text of the standard. Copies of ISO/IEC 27701:2025 can be bought from ISO or from national standards bodies.