ISO 27701: Privacy Information Management That Goes Beyond GDPR Paperwork
Most organisations can produce a privacy policy, a data protection impact assessment template, and a register of processing activities. Fewer can demonstrate that ISO 27701 privacy information management is actually happening — with clear ownership, ongoing monitoring, and evidence that controls work in practice rather than existing only on paper. ISO 27701 is the standard built to close that gap, extending an organisation’s information security management system to cover privacy specifically.
In this article:
What ISO 27701 actually is
How it relates to GDPR and ISO 27001
The core requirements explained
Who should be considering it
Practical steps to get started
What ISO 27701 Actually Is
ISO 27701 is a privacy information management system (PIMS) extension standard — it does not stand alone but builds directly on top of ISO 27001, adding specific requirements and controls for managing personal data as both a data controller and/or data processor. Because it is an extension rather than a separate management system, organisations already certified to ISO 27001 typically find it a natural next step rather than starting from zero.
How It Relates to GDPR and ISO 27001
This is where the standard earns its value, so it is worth separating the pieces clearly:
GDPR is UK/EU law — a legal obligation with specific requirements around lawful basis, data subject rights, breach notification, and more. It is not a certifiable management system; it is the regulation you must comply with regardless.
ISO 27001 is the information security management system standard, covering the confidentiality, integrity, and availability of information broadly — not personal data specifically.
ISO 27701 sits on top of ISO 27001 and translates privacy law obligations, including much of what GDPR requires, into concrete management system controls: roles, processes, documentation, and continual improvement specific to personal data.
In practice, ISO 27701 certification gives an organisation (and its customers, regulators, and partners) credible, externally audited evidence that GDPR-type obligations are being actively managed, not just described in a policy document that has not been reviewed since it was written.
The Core Requirements Explained
PIMS-specific roles and responsibilities — clear ownership of privacy obligations, distinct from general information security roles, so accountability does not get lost between teams.
Controller and processor-specific controls — the standard explicitly separates requirements depending on whether you are determining the purposes of processing (controller) or processing on someone else’s behalf (processor).
Privacy risk assessment — extending standard information security risk assessment to explicitly consider risks to data subjects, not just to the organisation.
Data subject rights processes — documented, tested procedures for handling access requests, corrections, deletions, and objections, rather than improvising when a request actually arrives.
Third-party and processor management — formal controls over how personal data is shared with and handled by suppliers and partners.
Continual improvement and monitoring — ongoing review of privacy controls against evolving risk and regulatory expectations, not a one-off implementation exercise.
Who Should Be Considering It
Organisations already certified to ISO 27001 looking for the most efficient way to formalise privacy management on top of existing infrastructure.
Data processors handling personal data on behalf of clients, where certification provides strong contractual reassurance without clients needing to audit privacy controls themselves.
Organisations operating across multiple jurisdictions, where a recognised international standard helps demonstrate consistent privacy practice regardless of local law variations.
Businesses that have had a near-miss or actual data incident, where certification provides credible evidence of strengthened practice going forward.
Any organisation for whom “we comply with GDPR” is currently more of a claim than something they can evidence under scrutiny.
Practical Steps to Get Started
Confirm your ISO 27001 foundation is solid first. ISO 27701 extends that system — gaps in the base ISMS will surface as gaps in the PIMS too.
Clarify whether you are acting as controller, processor, or both, for each relevant data flow. This shapes which specific controls apply and is often more nuanced than assumed.
Audit your data subject rights process by actually testing it. Submit an internal test access request and time how smoothly it is handled end-to-end.
Map personal data flows to third parties explicitly, including sub-processors, and check contracts reflect current practice rather than a template signed years ago.
Assign clear privacy ownership, separate from general IT security roles, even if it is the same person wearing two hats — the accountability needs to be explicit.
Build privacy risk review into existing management review cycles, rather than treating it as a separate, occasional exercise disconnected from the main ISMS.
Frequently Asked Questions
Do we need ISO 27001 before ISO 27701
Yes. ISO 27701 is an extension to ISO 27001, not a standalone standard. You must have ISO 27001 in place first, though it does not need to be certified — the foundation just needs to be solid.
Is ISO 27701 a legal requirement in the UK
No, but GDPR is. ISO 27701 is a way to demonstrate that you are managing GDPR obligations systematically. Many organisations use it as evidence of compliance when regulators or customers ask questions.
Can ISO 27701 replace a Data Protection Officer
No. If GDPR requires you to appoint a DPO (typically if you are a public authority or process data at scale), that is a separate legal requirement. ISO 27701 complements DPO responsibilities but does not replace them.
How long does ISO 27701 certification take
Typically 12 to 16 weeks from initial assessment, depending on the maturity of your ISO 27001 system and how well your privacy processes are already documented. We have delivered faster with organisations that already have strong information security foundations.
The Bottom Line
ISO 27701 turns “we comply with GDPR” from an assertion into something an organisation can actually demonstrate — with clear ownership, tested processes, and evidence that privacy is managed as a living system, not a policy document gathering dust.
If you would like support building a privacy information management system that goes beyond paperwork, CAW Consultancy can help.
Get in touch with CAW Consultancy today for a free, no-obligation consultation — visit https://www.cawconsultancy.co.uk to find out how we can help you stay compliant and confident.

Leave a comment