What changed with ISO/IEC 27701:2025?
The 2019 edition was structurally dependent: a PIMS could only be certified as an extension of an ISO/IEC 27001 ISMS, because 27701:2019 worked by amending 27001 and 27002 clauses. The 2025 revision rebuilt the standard on the harmonized management-system structure so it can be implemented and certified standalone, aligned it with ISO/IEC 27001:2022's updated control set, and clarified the controller and processor guidance. Practical consequences: organizations without 27001 can now pursue 27701 directly (though in practice a PIMS still needs the security substrate, and most certifiers expect equivalent security controls); organizations holding extension-model certificates transition at surveillance or recertification audits per their certification body's transition arrangements; and integrated audits covering 27001 plus 27701 remain the efficient path for companies wanting both. When referencing the standard in contracts or RFPs, cite the edition, security questionnaires written for the 2019 extension model ask structurally different questions than the standalone standard answers.
How does implementation actually sequence?
Six phases. Scoping and role determination: define the PIMS boundary (entities, systems, processing activities) and determine for each processing activity whether you act as PII controller, PII processor, or both, this drives which control set applies, and multi-product companies usually hold both roles. PII inventory and mapping: what PII, from whom, for what purposes, stored where, flowing to whom, retained how long; if you maintain GDPR Article 30 records, they seed this. Privacy risk assessment: extend the security risk methodology to privacy-specific harms (unlawful processing, purpose creep, re-identification, transfer risk), assessing impact on PII principals rather than only on the organization, the analytical shift security teams find hardest. Control selection and implementation: the applicable controller controls (notice, consent, purpose limitation, DSAR handling, disclosure records, transfer safeguards) and processor controls (instructions, subprocessor management, assistance duties, return/deletion), documented in the statement of applicability. Management-system integration: privacy objectives, roles (a privacy lead with real authority), competence and awareness, internal audit, and management review. Certification readiness: an internal audit cycle and a mock DSAR or incident drill before stage 1. With a functioning ISMS, six to twelve months; without one, the security foundation adds most of a year.
What do the controller controls require that security programs miss?
The controls that require legal-basis machinery, not security machinery. Purpose specification and limitation: documented purposes per processing activity and mechanisms preventing use beyond them, security controls do not care why data is processed; privacy controls turn on it. Lawful basis and consent: records of the basis for each purpose, and where consent is the basis, collection mechanisms meeting validity conditions with withdrawal as easy as grant. Notice: privacy information provided at collection, kept current, covering purposes, recipients, retention, and rights. PII principal rights: operational processes for access, correction, deletion, restriction, and portability requests with identity verification and deadlines, the control that most often fails audits, because it requires cross-system data location capability. Disclosure and transfer records: logs of what was disclosed to whom, including law-enforcement requests, and safeguards for cross-border transfers. Retention and disposal: schedules per purpose and evidence deletion actually executes, including in backups within defensible windows. Privacy by design: privacy requirements entering system development. Teams treating 27701 as '27001 plus a few clauses' stall exactly here; the controller set is where a PIMS becomes a privacy program.
How does 27701 certification interact with GDPR and other laws?
It is evidence, not compliance. No certification satisfies GDPR by itself, and 27701 certification is not (yet) an approved GDPR Article 42 certification mechanism, the approved EU schemes are separate, though EDPB and national DPAs have acknowledged management-system certifications as accountability indicators. What it does deliver: documented, audited evidence of the accountability principle (Article 5(2)), organized artifacts for regulator inquiries (records, risk assessments, DSAR logs, processor contracts), a credible answer to enterprise-customer diligence (frequently accepted in lieu of bespoke privacy questionnaires), and for processors, a differentiator in procurement where Article 28 diligence is mandatory. The mapping annexes correlate 27701 controls to GDPR articles, so an implemented PIMS covers most operational GDPR duties by construction; gaps that remain legal rather than operational: DPIA thresholds, DPO appointment triggers, breach notification deadlines, and lawful-basis judgment calls still need counsel. The same logic extends to other regimes: the PIMS gives one operational chassis, and jurisdiction-specific requirements (CCPA opt-outs, LGPD bases, PIPL localization) bolt onto it as control variants rather than parallel programs.
What does certification cost and involve, audit by audit?
Stage 1: the certification body reviews PIMS documentation (scope, statement of applicability, risk assessment, mandatory policies and records) and confirms readiness; findings here are usually documentation gaps. Stage 2: the implementation audit, interviews, records sampling, control testing across the scope; auditors reliably probe DSAR handling end-to-end, consent records, processor contracts and subprocessor lists, retention execution, and the privacy risk assessment's treatment of principal harms. Certificate issues on closure of nonconformities, valid three years. Surveillance audits annually, narrower in scope but always touching management review, internal audit, corrective actions, and a control sample. Recertification in year three repeats a full-scope audit. Costs scale with organization size and scope complexity: certification-body fees for a mid-size single-site scope typically run in the tens of thousands over a three-year cycle, with integrated 27001+27701 audits costing meaningfully less than separate ones; internal effort is the larger cost, commonly a part-time privacy lead plus control-owner time across the first year. Choose an accredited body (check accreditation for 27701 specifically) and confirm auditor privacy competence, the standard is young enough that auditor quality varies.