Privacy management, extending your ISMS.
ISO/IEC 27701 turns an information security management system into a privacy one. It extends ISO 27001 and 27002 with the requirements and guidance a Privacy Information Management System needs — separately for organizations acting as controllers and as processors — and it cannot be certified on its own. You certify to 27701 as an extension of an existing 27001 certificate, or pursue both together. The privacy system sits on top of the security system; it does not replace it.
That dependency is the whole point and also the trap. The security controls you already operate — access, logging, encryption, supplier management — are most of what protects personal data. What 27701 adds is the privacy-specific layer: lawful basis, purpose limitation, data subject rights, records of processing, transfers. Run as a separate project by a separate team, that layer duplicates the controls underneath it and disagrees with them by the second audit.
Who it applies to
Organizations that already hold, or are pursuing, a 27001 certificate and process personal data at a scale where someone wants assurance about it — customers, regulators, or a group privacy function. The standard distinguishes controller and processor obligations, so a SaaS provider and its enterprise customer can both certify to it while carrying different control sets.
27701 and the GDPR
27701 is not a GDPR certificate and no auditor will tell you otherwise. What it does is give the GDPR's accountability principle a management system to live in: the record of processing activities, the data protection impact assessments, the data subject request handling and the processor contracts all have a home, an owner and a review date. Annex D of the standard maps its controls to GDPR articles for exactly this reason. Because the PIMS runs on the same control library as the ISMS, the 72-hour breach notification under Article 33 and the incident process 27001 already requires are one workflow with two clocks — not two teams discovering the same event separately.
What it asks, in operating terms
Read as an operating requirement rather than an extension document, 27701 reduces to a handful of standing asks layered on top of the ISMS you already run.
| What the standard asks | Where it is answered |
|---|---|
| Extend the ISMS, do not duplicate it | Shared control library · privacy controls layered on the same entries |
| Know whether you are controller or processor, per activity | Processing register · role recorded per processing activity |
| Hold records of processing that stay current | Processing register · owner and review date per entry |
| Handle data subject requests, with the clock running | Request workflow · clocked, sealed record |
| Show the GDPR mapping an auditor or regulator asks for | Per-regime exports · Annex D view of the same controls |
What you'd actually look at
In the dashboard, every figure opens on click to the activity, the control and the person behind it. This excerpt is what a PIMS file is made of:
- Processing activities
- 34 · 21 as controller, 13 as processor
- Privacy controls
- layered on the ISMS · no duplicate set
- Data subject requests
- 7 this quarter · all clocks met
- GDPR mapping
- Annex D · generated from live control state
- Auditor export
- sealed · sha256:c4e6...38b9
Where teams usually start
With a demo walked through by TruSecure — your processing activities in one register, a single privacy control opened to show it sits on an ISMS control you already evidence, the GDPR mapping generated rather than maintained. The certificate itself comes from an accredited certification body; TruSecure prepares and maintains the evidence, and holds no certification of its own yet. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
ISO/IEC 27701 extends ISO 27001 into a certifiable Privacy Information Management System, and cannot be certified independently of 27001. It supports GDPR compliance.