Compliance · ISO/IEC 27701 ISO/IEC 27701:2025 · PIMS — now stand-alone

ISO/IEC 27701 Privacy Information Management System (PIMS) Readiness

The international standard for managing privacy. As of 2025, ISO/IEC 27701 is a stand-alone, independently certifiable management system. We help you build a PIMS that holds up — designing it with your teams, validating the controls that protect personal data the way an attacker would, and bringing you to audit-ready for a clean Stage 1 and Stage 2 certification audit.

Gap assessment to internal audit. CERT-In Empaneled. The accredited body issues the certificate — we make sure you earn it.

ISO/IEC 27701:2025 Now stand-alone (no longer a 27001 add-on) PII controllers & processors Maps to GDPR & ISO/IEC 29100 CERT-In Empaneled
Standard
ISO/IEC 27701:2025 — stand-alone PIMS
Applies to
PII controllers & processors
Role
Certification-ready — the accredited body issues the certificate
Validation
VAPT-backed technical control validation
02

The benchmark for managing privacy — now a standard in its own right

ISO/IEC 27701 is the international standard for a Privacy Information Management System — a PIMS.

Where ISO/IEC 27001 governs information security, 27701 governs the protection of privacy in the processing of personally identifiable information (PII): the lawful basis for collecting it, the obligations you owe the people it belongs to, privacy by design and by default, and the discipline around sharing, transferring and disclosing it. It is a framework for governing privacy as an ongoing practice — defined scope, privacy risk assessment, controls that treat those risks, leadership oversight, and continual improvement — and certification is independent, third-party proof that the system exists and works.

The 2025 edition changed the standard's nature. The first edition (ISO/IEC 27701:2019) was an extension to ISO/IEC 27001 — you could not certify a PIMS on its own; it rode on an existing ISMS. ISO/IEC 27701:2025, published in October 2025, has been redrafted as a stand-alone management system standard. It now carries its own management-system clauses (4–10) and its own information-security baseline, so an organization can implement and certify a PIMS independently. It still aligns and integrates cleanly with ISO/IEC 27001 and other management systems through the shared harmonized structure — but it no longer depends on them. If you certified against the 2019 edition, the standard includes a mapping to help you transition; if you are starting fresh, you build straight to the 2025 standalone standard.

"Privacy used to ride on top of your security certificate. As of 2025 it stands on its own — so we build a privacy system that's true in its own right, not a clause bolted onto something else."
03

Who ISO/IEC 27701 is for

The standard applies to any organization that processes personal data — as a PII controller, a PII processor, or both — including joint controllers and subcontracted processors. Certification is voluntary, but the pressure to hold it rarely is.

Criterion Why it applies
You're a PII controller You decide why and how personal data is processed, so the obligations to data principals — lawful basis, consent, rights, transparency — land on you. The PIMS is how you evidence that you meet them.
You're a PII processor You process personal data on a customer's instructions, so you must prove you handle it only as agreed, support your customer's obligations, and control your own subcontractors. Certification is fast becoming a contractual expectation for vendors.
You're answerable to GDPR or India's DPDP Act A certified PIMS is the operational backbone for these laws: it turns legal duties into running controls and produces the evidence that demonstrates accountability to regulators.
A customer or partner demands privacy assurance Enterprise buyers and data-sharing partners increasingly require independent privacy certification before they will entrust you with personal data.
You already run ISO 27001 A 27701 PIMS extends your security management into privacy, reusing the same governance discipline — but now as a certificate that stands on its own.
You want one privacy system, many obligations Build the PIMS once and it carries across GDPR, the DPDP Act and your contractual privacy commitments — assess once, reuse the evidence.
04

What the standard actually asks for

ISO/IEC 27701:2025 has two halves. The management-system clauses (4–10) define how the PIMS is run — context, leadership, planning, support, operation, performance evaluation and improvement — and Clause 6 carries a dedicated privacy risk assessment and treatment requirement that drives everything else.

Annex A then provides the reference control objectives and controls, in three normative tables: controls for PII controllers, controls for PII processors, and a shared information-security baseline that applies to both — included precisely because the standard now stands alone. Your Statement of Applicability records, control by control, which you apply and why, with justification for any you exclude.

05

From gap to certification-ready — and beyond

Certification is awarded by an accredited certification body after a two-stage audit. Our job is everything that earns it: building a PIMS that is genuinely sound, running the privacy risk assessment the standard requires, validating that the controls protecting personal data actually work, and assembling the evidence so the audit confirms what is already true.

We take you from a first gap assessment to a confident Stage 2 — and stay with you through surveillance and recertification.

01 · Intect
Gap Assessment
We measure your current privacy and security posture against ISO/IEC 27701:2025 — clauses and all three Annex A tables — and produce a clear gap report with a prioritized roadmap, including which role(s) you hold (controller, processor, or both).
02 · Intect
Privacy Risk Assessment
We run the privacy risk assessment and treatment the standard mandates in Clause 6 — identifying risks to PII principals and to the organization, assessing consequences and likelihood, and prioritizing treatment.
03 · Intect
PIMS Implementation
We build the policy and procedure suite, stand up the controls across the controller, processor and common control sets, and support remediation of every gap from step one.
04 · Intect
Statement of Applicability
We produce the SoA — every applicable Annex A control, included or excluded, with documented justification — the document the auditor returns to most.
05 · Intect · CISA-certified
Internal Audit
Our CISA-certified IS auditors conduct the internal audit the standard requires, independently checking that controls are not just documented but operating.
06 · Intect
Pre-Assessment (Mock Audit)
We run a mock Stage 1 and Stage 2 — auditing you the way the certification body will, so there are no surprises on the day.
07 · Accredited body
Stage 1 Audit (Documentation)
Conducted by the accredited certification body. A readiness and documentation review of your PIMS, scope and SoA. We support you through it.
08 · Accredited body
Stage 2 Audit (Implementation) → Certificate
Conducted by the accredited certification body. The in-depth assessment that tests whether your controls genuinely operate. On success, the certificate is issued.
09 · Ongoing
Surveillance & Recertification
Certification runs on a three-year cycle: annual surveillance audits keep it live, and a full recertification audit renews it. We support continuous compliance across the whole cycle.

FIG. 02 — PIMS certification lifecycle · 01–06 Intect-led · 07–08 accredited certification body · 09 the three-year cycle

The whole cycle is a Plan-Do-Check-Act loop — privacy risk assessment and implementation (Plan/Do), internal audit and management review (Check), remediation and continual improvement (Act). The PIMS is built to get better with every pass, not just to clear one audit.

06

What an engagement includes

We scope to where you are — a first-time PIMS, a 2019-extension-to-2025-standalone transition, or sustaining an existing certificate — and cover the work end to end, for your role as controller, processor, or both.

Assess
01

Role determination

controller, processor, joint controller, or subcontractor — per processing activity

02

Gap assessment against ISO/IEC 27701:2025

management clauses + Annex A Tables A.1, A.2, A.3

03

PIMS scope definition

processing activities, systems, sites, functions and third parties

04

Privacy risk assessment and risk treatment plan

Clause 6

Build
05

Statement of Applicability

inclusion/exclusion decisions with justification across the applicable control tables

06

Privacy policy and procedure suite

consent, data-principal rights, retention, transfer, breach handling

07

Records of processing and data-mapping support

08

Control-implementation support across people, process and technology

remediation of identified gaps

Validate (the offensive edge)
09

Technical control validation

penetration testing and configuration review of the controls that protect PII: access rights, secure authentication, cryptography, and PII transmission/transfer controls

10

Evidence collection and an audit-ready artifact pack

11

Remediation retest after fixes

Prepare for audit
12

Internal audit, conducted to the standard's requirements by CISA-certified IS auditors

13

Management-review pack for leadership oversight

14

Pre-assessment / mock Stage 1 and Stage 2

15

Liaison and support through the certification body's Stage 1 and Stage 2 audits

Sustain
16

Surveillance-audit support across the three-year cycle

17

Recertification readiness

18

Continuous-compliance guidance as your processing, risks and obligations evolve

07

We audit like we attack

A paper audit confirms that a privacy control is written down. We confirm that the control protecting the personal data actually holds.

Evidence on paper

Most readiness work stops at the document

The conventional path to ISO 27701 reviews policies, samples records and ticks the controls that have documentation behind them. That satisfies the letter of the standard — but a written access-control policy and an access-control system an attacker can walk through are not the same thing, and an encryption clause is not proof the data in transit is actually encrypted. The gaps that never appear in a document review are exactly the gaps that surface in a personal-data breach.

Evidence that's been proven

We test the control, not just the claim

Intect is CERT-In Empaneled with an offensive-security heritage, so our readiness work is technically validated. Where the standard expects access rights, secure authentication, cryptography and PII-transmission controls to actually protect personal data, our researchers test them — safely, the way an adversary would — and bring you pentest-backed evidence that the control performs. You walk into Stage 2 with the controls around your PII already proven against a real probe, and you leave with privacy that means it.

The certificate proves you have a privacy system. Our testing proves the controls around the data actually work.

PENTEST-BACKED EVIDENCE
08

What you receive

Every engagement produces the artefacts your team needs to operate the PIMS — and the evidence pack an accredited certification body expects to review.

01

Gap assessment report

Your current state mapped against ISO/IEC 27701:2025, with role determination and a prioritized roadmap to certification-ready.

02

Privacy risk assessment & treatment plan

A defensible methodology, privacy risk register and treatment decisions covering risks to PII principals and the organization (Clause 6).

03

Statement of Applicability

Each applicable Annex A control across the controller, processor and common tables, included or excluded, with documented justification.

A.1 + A.2 + A.3
04

Privacy policy & procedure suite

The PIMS documentation set — consent, rights handling, retention, transfer, breach response — written to the standard and tailored to how you actually operate.

05

Records of processing & data-mapping pack

The inventory of processing activities that underpins the PIMS.

06

Internal audit report

Independent verification, by CISA-certified IS auditors, that controls are operating, not just documented.

07

Management review pack

The oversight evidence leadership needs for performance evaluation.

08

Pre-assessment / mock audit report

A dry run of Stage 1 and Stage 2, with findings to close before the real thing.

09

Technical control validation report

Pentest-backed evidence that the controls protecting PII — access, authentication, encryption, transmission — genuinely work, with remediation guidance and retest.

VAPT-BACKED
10

Audit-ready evidence pack

Collected, organized artefacts that map cleanly to the controls and clauses.

ISO/IEC 27701:2025 Stand-alone PIMS PII controllers & processors CERT-In Empaneled Maps to GDPR & ISO/IEC 29100 · Supports ISO 27001, GDPR and DPDP Act readiness
09

Why teams choose Intect for ISO 27701

CERT-In Empaneled CISA-certified auditors in-house

CERT-In Empaneled — An assessor accredited under India's national cybersecurity authority — credibility the audit room recognizes.

CISA-certified auditors in-house — Our engagement team includes CISA-certified IS auditors, so the internal audit and pre-assessment that prepare you for certification are run by recognized professionals.

We build and we break — Most consultancies only write privacy policy. We implement the PIMS and then test the controls protecting personal data like attackers, so your evidence is proven, not asserted.

One partner, the full cycle — From first gap assessment through Stage 2 support, surveillance and recertification — continuity instead of handoffs.

10

Frequently asked questions

Does Intect issue the ISO 27701 certificate?

No — and no consultancy can. The certificate is issued by an independent, accredited certification body after it conducts the Stage 1 and Stage 2 audits. Intect makes you certification-ready: we build and validate the PIMS, run the privacy risk assessment, the internal audit and the mock audit, and support you through the certification body's audits. Our in-house CISA-certified auditors strengthen the internal-audit work — they do not, and cannot, issue the ISO certificate. Keeping readiness and certification separate is exactly what preserves the audit's independence.

What changed in the 2025 edition?

The big change: ISO/IEC 27701 was redrafted as a stand-alone management system standard. The 2019 edition was an extension to ISO/IEC 27001 — you couldn't certify a PIMS without an ISMS underneath it. The 2025 edition, published in October 2025, has its own management-system clauses and its own information-security baseline, so you can implement and certify a PIMS independently. It still aligns and integrates with ISO 27001 if you run one, but it no longer depends on it.

Do I still need ISO 27001 first?

No longer. Under the 2025 standalone edition you can certify a PIMS on its own — that's why the standard now carries its own common information-security control table (Table A.3). If you already hold ISO 27001, your PIMS integrates neatly with it through the shared structure, and much of your security baseline carries over; but a prior 27001 certificate is no longer a prerequisite.

What's the difference between a PII controller and a PII processor here?

The standard has separate control tables for each. Controllers (Table A.1) decide why and how PII is processed and carry the obligations to data principals. Processors (Table A.2) process PII on a customer's instructions and carry obligations around acting only as instructed and managing subcontractors. Both share the common security baseline (Table A.3). If you act in both roles, the standard requires you to treat each role separately — we scope the PIMS to whichever role(s) apply to you.

How does this relate to GDPR and India's DPDP Act?

A PIMS is the operational backbone for both. GDPR and the DPDP Act set the legal duties; ISO/IEC 27701 turns them into running, auditable controls and produces the evidence of accountability. The standard even publishes a mapping to the GDPR (Annex D) and to the ISO/IEC 29100 privacy principles (Annex C). The laws themselves are not "certifiable," but a 27701 certificate is strong, independent evidence that you operate a privacy program that supports them.

We certified against ISO 27701:2019 — what now?

The 2025 edition replaces the 2019 edition. Because it is now standalone, the transition is more than cosmetic, so the standard includes a correspondence mapping to the 2019 controls to guide it. We scope the work to wherever you are — re-baselining your existing controls against the new structure and closing the gaps the standalone format introduces.

How long does certification take?

It depends on the size and complexity of your processing, which role(s) you hold, and how mature your current controls are — which is exactly what the gap assessment establishes first. We give you a realistic, evidence-based timeline up front rather than a generic promise, and sequence the work so nothing blocks the certification audit.

What happens after we're certified?

Certification runs on a three-year cycle. The accredited body conducts annual surveillance audits to confirm the PIMS is still operating, and a full recertification audit at the end of the cycle. We support you across all of it, so the certificate stays live and the PIMS keeps improving.

11

One privacy system, many obligations

A well-built PIMS is the operational foundation for far more than one certificate.

Scope an engagement

Build a privacy system that's ready to be certified.

Tell us where you are — first PIMS, a 2019-to-2025 standalone transition, or maintaining an existing certificate — and we'll scope a readiness assessment that fits, or connect you with an assessor.