Skip to content
All articles
Standards update

ISO 27701:2025: The Complete Guide to the Standalone Privacy Standard

The 2025 revision made ISO 27701 a standalone standard, certifiable without ISO 27001. Here is what changed, what the standard covers, who needs it, and how certification works.

9 min read
Keyboard key marked with a padlock and the words Data Privacy
Share

ISO/IEC 27701:2025 is the current international standard for privacy information management, and its 2025 revision made one change that matters above all others. The standard is now standalone. An organisation can be certified against ISO 27701:2025 in its own right, without first holding ISO 27001. This is a significant shift from the earlier 2019 version, which existed only as an extension to an information security management system. This guide explains what ISO 27701:2025 is, what changed, what the standard covers, who needs it, and how certification works.

What ISO 27701:2025 is

ISO/IEC 27701 is the international standard for a Privacy Information Management System, usually shortened to PIMS. It was developed jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), which is why both appear in its full designation. Its purpose is to give organisations a structured, auditable way to manage the personal data they hold, and to demonstrate that management to customers, partners, and regulators.

A privacy information management system is the set of policies, roles, processes, and controls an organisation uses to protect personally identifiable information, usually shortened to PII. Rather than treating privacy as an occasional project or a legal box to tick, a PIMS makes privacy an ongoing, managed part of how the organisation runs. It covers how personal data is collected, used, stored, shared, and eventually disposed of, and it builds in review and improvement so that privacy management keeps pace as the organisation and its risks change.

Certification against ISO 27701:2025 means an independent certification body has audited that system and confirmed it meets the requirements of the standard. That independent confirmation is the difference between an organisation stating that it protects personal data and being able to prove it.

The headline change: from extension to standalone

To understand ISO 27701:2025, it helps to understand what came before it. The first edition, published in 2019, was designed as an extension to ISO 27001, the information security standard. In practical terms, this meant an organisation could not certify a privacy management system on its own. It first needed an ISO 27001 information security management system in place, and then added the privacy extension on top. Privacy could not stand alone.

The 2025 edition changed this fundamentally. ISO 27701:2025 is now a complete, standalone management system standard. An organisation can scope, implement, and certify a privacy management system independently, without an ISO 27001 system underneath it. This single change has a wide effect. It means organisations whose primary concern is privacy, but who do not run a full information security programme, can now pursue privacy certification directly. The barrier that the 2019 model created has been removed.

This does not mean the two standards have been separated for good. ISO 27701:2025 adopted the same overall structure that ISO 27001 and other modern management system standards use. As a result, the two still fit together cleanly for any organisation that wants both. What has changed is that running them together is now a choice, not a requirement. An organisation can hold ISO 27701:2025 on its own, hold it alongside ISO 27001, or add it later to an existing ISO 27001 system. The standard now serves all three paths.

What else changed in the 2025 edition

The move to a standalone standard is the most important change, but it is not the only one. The 2025 edition brought several updates that are worth understanding, particularly for organisations planning to certify.

The structure of the standard was aligned to the common framework that ISO uses across its management system standards. This is the same clause structure found in ISO 27001 and in ISO 42001, the AI management standard. For organisations that hold more than one of these standards, this shared structure makes them significantly easier to manage together, because the way each standard is organised is now consistent.

The controls in the standard were also reorganised. ISO 27701:2025 sets out its privacy controls in a clearer arrangement that separates the controls relevant to an organisation acting as a PII controller, the controls relevant to an organisation acting as a PII processor, and the security controls that apply to both. This makes it easier for an organisation to identify exactly which controls apply to its own situation, based on the role or roles it plays with personal data.

Alongside the standard itself, a companion standard was published to govern how certification bodies audit privacy management systems. This companion standard sets the requirements that a body must meet in order to audit and certify organisations against ISO 27701:2025. Its existence raises and standardises the quality of ISO 27701 certification across the industry, which is a benefit to any organisation seeking a certificate that will be trusted by its customers.

Controllers and processors: a key distinction

One of the concepts at the heart of ISO 27701 is the distinction between a PII controller and a PII processor, and it is worth understanding because it shapes how the standard applies to a given organisation.

A PII controller is the organisation that decides why and how personal data is processed. If your organisation determines the purposes for which personal data is collected and used, you are acting as a controller for that data. A PII processor is the organisation that processes personal data on behalf of someone else, following that other party's instructions. If your organisation handles personal data as a service to your clients, you are acting as a processor.

Many organisations are both at once. A software company, for example, might act as a controller for the personal data of its own employees and marketing contacts, while acting as a processor for the personal data its clients store in its platform. ISO 27701:2025 addresses both roles, and the certification audit examines the responsibilities that apply to whichever role or roles an organisation plays. Getting this mapping right is an important part of scoping a privacy management system correctly.

What an ISO 27701:2025 certificate demonstrates

An ISO 27701:2025 certificate is not a decorative badge. It communicates specific, verified facts about how an organisation handles personal data, and understanding what it actually demonstrates helps explain why customers and partners increasingly ask for it.

First, it demonstrates that the organisation knows where personal data lives. A privacy management system begins with understanding what personal data the organisation holds, why it holds it, and how that data moves through its systems and processes. Certification confirms that this mapping has been done properly rather than assumed.

Second, it demonstrates that privacy risk is managed deliberately. The standard requires an organisation to identify the privacy risks relevant to its processing of personal data and to treat those risks with appropriate controls. Certification confirms that these controls exist and operate in practice, not merely that they have been written down.

Third, it demonstrates that the organisation meets its responsibilities in whichever role it plays, as a controller, a processor, or both. This is particularly meaningful for organisations that handle personal data on behalf of clients, because it gives those clients independent assurance about how their data is treated.

Fourth, it demonstrates that privacy is managed as a living system. Because certification is maintained through recurring audits over a three-year cycle, an ISO 27701:2025 certificate signals an active, improving system rather than a single effort that was completed once and then left unattended.

Why privacy management matters now

Privacy has moved from an optional consideration to a business expectation, driven by rising regulation, growing customer awareness, and the increasing commercial cost of getting it wrong. Organisations that handle personal data are more and more often expected to manage it accountably, and, crucially, to be able to show that they do.

This shift is especially visible in India. The Digital Personal Data Protection Act, 2023 is in force, and the Digital Personal Data Protection Rules, 2025 were notified in November 2025, with obligations phasing in over the period that follows. The direction of travel is clear, organisations handling personal data are expected to demonstrate responsible, accountable management of it. This raises a practical question for every business: how do you show, credibly and independently, that you take privacy seriously? Internal assurances carry limited weight with enterprise customers who have their own obligations to consider. An ISO 27701:2025 certificate answers the question with independent evidence in the form of an internationally recognised privacy standard, independently audited.

It is important to be precise about what certification does and does not do. ISO 27701:2025 certification proves that your privacy management system meets the international standard. It is not a legal ruling that your organisation complies with any particular law, and it is not legal advice. What it provides is a strong, independent demonstration of privacy management, which is exactly what a maturing data protection environment rewards. For the interpretation of specific legal obligations, organisations turn to qualified legal advisers. For independent proof that their privacy management system is sound, they turn to certification.

Who needs ISO 27701:2025 certification

ISO 27701:2025 suits any organisation that processes personal data and wants to prove it does so responsibly. The standalone 2025 edition widens the field considerably, because privacy certification no longer depends on first building a full information security system. Several groups feel the need most keenly.

IT and software companies process large volumes of user and client data and are increasingly asked by enterprise customers to demonstrate privacy credentials before a contract is signed. For these organisations, an ISO 27701:2025 certificate is a clear, recognised way to answer privacy questions in procurement and due diligence.

Healthcare organisations handle some of the most sensitive personal data there is, and the expectations around protecting patient information are correspondingly high. A privacy certification provides independent assurance that this data is managed to an international standard.

Banking and financial services organisations handle sensitive customer and transaction data under close regulatory scrutiny. Demonstrating structured, independently assessed privacy management supports both regulatory relationships and customer trust.

Beyond these, ISO 27701:2025 is relevant to any organisation asked to demonstrate privacy management as a condition of doing business, in the same way that information security certification became a supply-chain expectation in earlier years. If your clients send privacy questionnaires, if your contracts require evidence of privacy management, or if you simply want to distinguish your organisation as one that handles personal data properly, ISO 27701:2025 certification is the recognised route.

How ISO 27701:2025 certification works

Certification against ISO 27701:2025 follows a clear, staged process carried out by an independent certification body. Understanding the stages removes much of the uncertainty for an organisation approaching certification for the first time.

The process begins with scoping. The organisation and the certification body agree what the certificate will cover, which parts of the organisation, which processing activities, and which roles as controller or processor. Getting the scope right matters, because the certificate must accurately describe what has been assessed.

The audit itself is conducted in two stages. Stage 1 is a review of the design of the privacy management system. The auditor examines the scope, the privacy policy, the defined roles, and the privacy risk assessment, confirming that the system is complete, consistent, and ready to be assessed in full. Stage 1 identifies any significant gaps early, before the main assessment, which is one of the reasons the audit is split into two stages.

Stage 2 is the main assessment. Here the auditor gathers evidence that the privacy management system operates in practice, not just on paper. The auditor examines records, speaks to the people who run the controls, and tests that the system does what the documentation describes. If the evidence supports certification and any findings are resolved appropriately, certification is confirmed and the certificate is issued.

Certification then runs on a three-year cycle. During that cycle, the certification body conducts surveillance audits, normally once a year, to confirm that the system continues to operate and improve. At the end of the three years, a recertification audit renews the certificate for the next cycle. This ongoing assessment is part of what makes a certificate credible, it reflects a system that is kept current, not one that passed a single audit and was then set aside.

Transitioning from the 2019 version

Organisations that already hold a certificate against the 2019 edition of ISO 27701 will need to move to the 2025 edition. A transition period applies, running to October 2028, by which point certificates based on the older edition will need to have transitioned to the current standard. In practice, the transition is handled through a transition audit, which can often be combined with a scheduled surveillance or recertification audit rather than carried out as an entirely separate exercise. Organisations in this position are best advised to plan the transition in good time rather than leaving it to the end of the period, when demand on certification bodies is likely to be higher.

Choosing a certification body

The value of any certificate depends in part on the credibility of the body that issued it. A certification body audits and certifies organisations, and it must itself operate to recognised standards of competence and impartiality. A key principle here is independence, a certification body cannot both advise an organisation on building its management system and then certify that same system, because doing so would compromise the impartiality of the assessment. This separation is not a formality. It is the foundation of why a certificate can be trusted at all.

When choosing a body to certify your ISO 27701:2025 privacy management system, it is worth confirming that the body operates in compliance with the relevant international requirements for certification bodies, that it is genuinely independent, and that its auditors bring competence in both management system auditing and the specific area of privacy.

Conclusion

ISO 27701:2025 is the current international standard for privacy information management, and its move to a standalone structure is a genuinely significant development. It allows organisations to certify a privacy management system in its own right, independently of ISO 27001, which makes credible, independent privacy certification more accessible than it has ever been. For organisations that handle personal data, and particularly for those in IT, healthcare, and financial services, an ISO 27701:2025 certificate is a clear and credible way to demonstrate that personal data is managed to an international standard, not simply promised.

Certiva Global provides independent ISO 27701:2025 certification and surveillance audits, operating in compliance with ISO/IEC 17021-1. To find out how certification would apply to your organisation, request a no-obligation scoping discussion with our technical team.

Questions

Frequently asked questions

ISO 27701:2025 is the current edition of the international standard for privacy information management. Published in its second edition in 2025, it defines a standalone Privacy Information Management System (PIMS) that can be certified in its own right, without ISO 27001.

Ready to begin your certification journey?

Get a transparent, no-obligation scoping discussion with our technical team.