Asurvo
Privacy framework

Run ISO 27701 with
confidence.

ISO/IEC 27701:2025 specifies requirements and guidance for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS). This edition is a standalone standard with requirements in clauses 4–10 and controls in Annex A.

Who it's for

Organizations extending an ISMS to cover privacy management.

Scope

Clauses 4–10 plus Annex A controls

Category
Privacy

How Asurvo helps

What you get for ISO 27701.

PIMS requirements and Annex A controls
PII controller and processor roles
Extends ISO 27001 for privacy
Maps to GDPR obligations

Privacy management

Building a privacy information management system that holds up at audit

ISO/IEC 27701 is the international standard for a privacy information management system (PIMS): the policies, roles, processes, and controls an organization uses to govern how it processes personally identifiable information (PII). It is published jointly by ISO and IEC. Organizations use it to show customers, regulators, and partners that privacy is run as a managed system with objectives, reviews, and corrective action, not as a folder of notices.

What changed between the 2019 and 2025 editions

The 2019 edition was written as an extension to ISO 27001 and ISO/IEC 27002. It told you which ISMS clauses to reinterpret with privacy in mind, so a PIMS could only exist on top of an existing ISMS. The 2025 edition restructures the document as a standalone management system standard, with its own requirements in clauses 4 to 10 and its controls in Annex A.

2019 vs 2025 at a glance

2019 vs 2025 at a glance
FormExtension to ISO 27001 and ISO 27002Standalone management system standard
Management system requirementsISMS clauses reinterpreted for privacyOwn clauses 4–10 using the harmonized management system structure
ControlsAdditional guidance plus controller and processor annexesAnnex A controls for PII controllers and PII processors
Relationship to ISO 27001PrerequisiteComplementary; still integrates cleanly with an existing ISMS

In practice, an organization that already holds ISO 27001 can still run both systems together, sharing the risk process, internal audit, and management review. What changes is that privacy scope, objectives, and risks now have to stand on their own rather than being bolted onto security language. Check with your certification body how and when it is transitioning existing certificates to the new edition.

Controller, processor, or both

The first real decision is role. A PII controller decides why and how PII is processed; a PII processor processes PII on behalf of a controller. Most SaaS companies are both: a controller for their own employee and marketing data, and a processor for the customer data inside their product. Annex A controls are organized around these roles, and your Statement of Applicability should state which role each processing activity falls under.

  • Controller-side controls cover lawful basis and purpose identification, privacy notices, consent records, data subject requests, privacy impact assessments, and limits on collection, retention, and onward transfer.
  • Processor-side controls cover processing only on documented customer instructions, supporting the customer with their obligations, sub-processor disclosure and approval, return or deletion at contract end, and cross-border transfer transparency.
  • Shared expectations include records of processing, breach notification paths, and information security controls that protect PII in both roles.

A practical implementation sequence

  1. Map processing activities. Build an inventory of what PII you hold, where it lives, the purpose, the legal basis, retention, recipients, and whether you act as controller or processor.
  2. Set the PIMS scope and context. Record interested parties (customers, regulators, data subjects) and the privacy laws that apply, such as GDPR or CCPA/CPRA.
  3. Assess privacy risk. Extend your risk methodology so it considers harm to data subjects, not only harm to the organization. A risk assessment methodology that already defines likelihood and impact is a good base.
  4. Select Annex A controls and document inclusions and exclusions with justification in the Statement of Applicability.
  5. Operate the controls long enough to produce evidence: DSR tickets closed, PIAs completed, sub-processor changes notified, retention jobs run.
  6. Run an internal audit and management review, raise corrective actions, then book the certification audit.

Evidence certification auditors ask for

Area, Typical artefacts comparison
Scope and contextPIMS scope statement, list of applicable privacy laws, controller/processor role determination
Records of processingProcessing inventory with purpose, legal basis, categories of PII, retention, and recipients
Risk and impactPrivacy risk register, privacy impact assessments with sign-off and follow-up actions
Data subject rightsRequest log, response templates, evidence of identity verification and on-time closure
Processor obligationsCustomer contracts or DPAs, sub-processor list and change notices, deletion certificates
IncidentsBreach procedure, incident records with assessment of notification duty
System performancePrivacy objectives and metrics, internal audit report, management review minutes, corrective actions

Where PIMS programs stall

  • Treating the processing inventory as a one-time spreadsheet. Auditors sample recent product changes and check that the inventory reflects them.
  • Declaring the organization a processor only, then finding HR, recruiting, and marketing data with no controller controls applied.
  • Writing a DSR procedure that nobody has exercised. Keep at least a few real or test requests with timestamps.
  • Excluding Annex A controls without a justification tied to role or processing.
  • Running privacy risk on a separate scale from security risk, so management review cannot compare or prioritize them.

How Asurvo supports an ISO 27701 program

Asurvo covers ISO/IEC 27701 alongside ISO 27001, GDPR, and CCPA/CPRA with automated cross-mapping, so a control such as access review or supplier assessment is evidenced once and credited everywhere it applies. The risk register holds privacy risks with inherent, residual, and target scores; the policy center tracks versions, approvals, and acknowledgements; and the audit workspace manages certification requests, findings, and CAPA. See how cross-mapping works in one control, four frameworks.

FAQ

Frequently asked questions

Do I need ISO 27001 before I can certify to ISO 27701:2025?

The 2019 edition required an ISO 27001 ISMS as its foundation. The 2025 edition is a standalone management system standard, so it is designed to be implemented on its own. Many organizations still run both together because the risk process, internal audit, and management review overlap heavily. Confirm certification arrangements and transition timing with your chosen certification body.

Does ISO 27701 certification mean we comply with GDPR?

No. Certification shows you operate a privacy management system that an independent auditor has assessed against the standard. It is useful evidence of accountability and maps closely to many GDPR obligations, but it is not a legal determination of compliance with GDPR or any other law. Legal obligations such as lawful basis and transfer mechanisms still need their own review.

How do we decide whether we are a PII controller or processor?

Look at each processing activity separately. If you decide the purpose and means of processing, you are a controller for that activity. If you process data only on a customer's documented instructions, you are a processor. Most B2B software companies are both, so they apply controller controls to their own data and processor controls to customer data held in the product.

What is the most time-consuming part of implementing a PIMS?

Usually the processing inventory. It requires input from engineering, HR, marketing, sales, and support to identify every place PII is collected, stored, and shared, with purpose, legal basis, and retention recorded for each. Once that inventory exists and has an owner who keeps it current, risk assessment, control selection, and rights handling become much more straightforward.

Can one set of evidence cover ISO 27701 and ISO 27001?

Largely, yes. Security controls such as access management, logging, supplier assessment, and incident response produce evidence both standards rely on. Privacy-specific items like records of processing, privacy impact assessments, and data subject request logs are additional. A platform that cross-maps controls lets you collect shared evidence once and reference it in both audits.

Ready to run ISO 27701 on Asurvo?

Book a walkthrough and see the framework live.