ISO/IEC 27701 is the international standard for a privacy information management system (PIMS): the policies, roles, processes, and controls an organization uses to govern how it processes personally identifiable information (PII). It is published jointly by ISO and IEC. Organizations use it to show customers, regulators, and partners that privacy is run as a managed system with objectives, reviews, and corrective action, not as a folder of notices.
What changed between the 2019 and 2025 editions
The 2019 edition was written as an extension to ISO 27001 and ISO/IEC 27002. It told you which ISMS clauses to reinterpret with privacy in mind, so a PIMS could only exist on top of an existing ISMS. The 2025 edition restructures the document as a standalone management system standard, with its own requirements in clauses 4 to 10 and its controls in Annex A.
2019 vs 2025 at a glance
In practice, an organization that already holds ISO 27001 can still run both systems together, sharing the risk process, internal audit, and management review. What changes is that privacy scope, objectives, and risks now have to stand on their own rather than being bolted onto security language. Check with your certification body how and when it is transitioning existing certificates to the new edition.
Controller, processor, or both
The first real decision is role. A PII controller decides why and how PII is processed; a PII processor processes PII on behalf of a controller. Most SaaS companies are both: a controller for their own employee and marketing data, and a processor for the customer data inside their product. Annex A controls are organized around these roles, and your Statement of Applicability should state which role each processing activity falls under.
- Controller-side controls cover lawful basis and purpose identification, privacy notices, consent records, data subject requests, privacy impact assessments, and limits on collection, retention, and onward transfer.
- Processor-side controls cover processing only on documented customer instructions, supporting the customer with their obligations, sub-processor disclosure and approval, return or deletion at contract end, and cross-border transfer transparency.
- Shared expectations include records of processing, breach notification paths, and information security controls that protect PII in both roles.
A practical implementation sequence
- Map processing activities. Build an inventory of what PII you hold, where it lives, the purpose, the legal basis, retention, recipients, and whether you act as controller or processor.
- Set the PIMS scope and context. Record interested parties (customers, regulators, data subjects) and the privacy laws that apply, such as GDPR or CCPA/CPRA.
- Assess privacy risk. Extend your risk methodology so it considers harm to data subjects, not only harm to the organization. A risk assessment methodology that already defines likelihood and impact is a good base.
- Select Annex A controls and document inclusions and exclusions with justification in the Statement of Applicability.
- Operate the controls long enough to produce evidence: DSR tickets closed, PIAs completed, sub-processor changes notified, retention jobs run.
- Run an internal audit and management review, raise corrective actions, then book the certification audit.
Evidence certification auditors ask for
Where PIMS programs stall
- Treating the processing inventory as a one-time spreadsheet. Auditors sample recent product changes and check that the inventory reflects them.
- Declaring the organization a processor only, then finding HR, recruiting, and marketing data with no controller controls applied.
- Writing a DSR procedure that nobody has exercised. Keep at least a few real or test requests with timestamps.
- Excluding Annex A controls without a justification tied to role or processing.
- Running privacy risk on a separate scale from security risk, so management review cannot compare or prioritize them.
How Asurvo supports an ISO 27701 program
Asurvo covers ISO/IEC 27701 alongside ISO 27001, GDPR, and CCPA/CPRA with automated cross-mapping, so a control such as access review or supplier assessment is evidenced once and credited everywhere it applies. The risk register holds privacy risks with inherent, residual, and target scores; the policy center tracks versions, approvals, and acknowledgements; and the audit workspace manages certification requests, findings, and CAPA. See how cross-mapping works in one control, four frameworks.