ISO 27701: Extending Your ISMS to Cover Data Privacy
If your business already holds ISO 27001, you’ve done the hard part — you have an information security management system (ISMS), a risk assessment process, and an audit trail of continual improvement. ISO 27701 takes that existing structure and extends it specifically to cover privacy information management, closing the gap between “we keep data secure” and “we handle personal data responsibly and lawfully.”
For UK businesses juggling GDPR compliance, client assurance requirements, and increasing scrutiny over how personal data is used, ISO 27701 is quietly becoming one of the most useful certifications available — largely because it doesn’t require starting from scratch.
In this article:
– What ISO 27701 actually is
– How it relates to ISO 27001 and GDPR
– Who should be considering it
– What’s actually involved in extending your ISMS
– Practical steps to get started
What ISO 27701 Actually Is
ISO 27701 is a privacy extension to ISO 27001. Rather than being a standalone certification, it’s structured as an add-on — a Privacy Information Management System (PIMS) that sits on top of an existing ISMS, adding specific controls and requirements around the processing of personal data.
This matters practically: you cannot certify to ISO 27701 in isolation. You need ISO 27001 in place first (or be implementing it alongside), because ISO 27701 works by adding privacy-specific clauses and controls to the existing ISO 27001 structure rather than duplicating it.
How It Relates to ISO 27001 and GDPR
It’s worth being clear about what each piece actually does, because they get conflated constantly:
– ISO 27001 is about information security broadly — protecting the confidentiality, integrity, and availability of information, whatever that information is.
– ISO 27701 narrows the focus specifically to personal data — how it’s collected, processed, stored, shared, and eventually deleted, with particular attention to the roles of data controller and data processor.
– GDPR is UK/EU law, not a certification. It’s mandatory; ISO 27701 is voluntary.
The connection between the two is what makes ISO 27701 valuable: it operationalises many of the accountability principles GDPR expects — such as demonstrating lawful basis for processing, maintaining records of processing activity, and managing data subject rights — inside a certifiable management system. It doesn’t guarantee GDPR compliance on its own, but it gives you a robust, auditable structure that makes compliance far more demonstrable to regulators, clients, and partners.
Who Should Be Considering It
ISO 27701 is particularly relevant if:
– You already hold ISO 27001 and handle personal data as a core part of your business — HR data, customer records, health data, or client data processed on behalf of others.
– You’re a data processor for other organisations — cloud providers, payroll bureaus, marketing agencies, IT service providers — where clients increasingly ask for evidence of privacy management, not just security.
– You operate internationally and need to demonstrate privacy compliance across multiple jurisdictions, since ISO 27701 maps to various global privacy frameworks, not just GDPR.
– You’re regularly filling out security and privacy questionnaires as part of procurement processes — a PIMS certification can replace a lot of that manual back-and-forth with a simple certificate reference.
If personal data isn’t a significant part of what you handle, the standalone ISO 27001 may be sufficient without adding this layer.
What’s Actually Involved in Extending Your ISMS
Because ISO 27701 builds on ISO 27001’s structure, the additions are targeted rather than a wholesale rebuild:
– Additional risk assessment specific to privacy — not just “could this data be breached” but “is this data being processed lawfully, proportionately, and transparently.”
– Defining your role clearly — controller, processor, or both — since the standard has distinct requirements depending on which applies, and many organisations are actually both for different data sets.
– Expanding your records of processing activity (ROPA) into something that satisfies both GDPR’s Article 30 requirements and ISO 27701’s documentation expectations.
– Reviewing data subject rights processes — access requests, deletion requests, rectification — and making sure they’re formally embedded in the management system rather than handled ad hoc.
– Extending supplier and third-party due diligence to specifically cover how those parties handle personal data, not just general security posture.
Practical Steps to Get Started
– Confirm your ISO 27001 foundation is solid first. ISO 27701 amplifies whatever’s already there — gaps in the base ISMS will show up in the privacy extension too.
– Map out your data flows before anything else. You can’t assess privacy risk properly without knowing what personal data you hold, where it goes, and who touches it.
– Clarify controller/processor status for each data set you handle — this shapes almost every subsequent requirement.
– Involve whoever handles GDPR compliance day-to-day (DPO, legal, or ops) directly in the implementation, not as an afterthought consulted at the end.
– Use existing GDPR documentation as a starting point, not a replacement — much of your Article 30 records, DPIAs, and privacy notices will feed directly into the PIMS, but they’ll need restructuring to satisfy audit requirements.
– Budget more time for the first year than you expect. Because it depends on ISO 27001 being mature, rushing the extension before the base ISMS has bedded in tends to create audit friction later.
The Bottom Line
ISO 27701 isn’t about reinventing your approach to data privacy — it’s about giving the privacy work you’re likely already doing under GDPR a proper, certifiable structure that clients and regulators can trust. For businesses already on the ISO 27001 journey, it’s one of the more efficient certifications to add, precisely because it doesn’t ask you to start over.
If you’d like support extending your ISMS to cover data privacy with ISO 27701, CAW Consultancy can help you build on what you already have rather than duplicating effort.
Get in touch with CAW Consultancy today for a free, no-obligation consultation — visit https://www.cawconsultancy.co.uk to find out how we can help you stay compliant and confident.

Leave a comment