← ALL FRAMEWORKS

ISO/IEC 27701

Data Privacy

Issued by ISO/IEC

ISO/IEC 27701:2025 specifies requirements for a Privacy Information Management System (PIMS), extending the security controls of ISO/IEC 27001/27002 with controls specific to processing personally identifiable information (PII) as either a PII controller or PII processor. Its controls map to major privacy regimes like GDPR, letting multinational companies run one auditable privacy program instead of separate compliance efforts per jurisdiction. The 2025 edition made PIMS certifiable on a standalone basis for the first time — previous editions required an existing ISO/IEC 27001 ISMS certification before an organization could pursue 27701 at all. It's pursued mainly by SaaS providers, cloud platforms, and data processors in privacy-heavy sectors like fintech, healthtech, and ad-tech.

Get notified the moment ISO/IEC 27701 actually changes — reviewed by a human before it ever reaches you.

Get started free

Most recent update

No published updates yet

This framework hasn't had a confirmed update yet — check back after the next monitoring run.