ISO/IEC 27701 Privacy Information Management System (PIMS) Readiness
The international standard for managing privacy. As of 2025, ISO/IEC 27701 is a stand-alone, independently certifiable management system. We help you build a PIMS that holds up — designing it with your teams, validating the controls that protect personal data the way an attacker would, and bringing you to audit-ready for a clean Stage 1 and Stage 2 certification audit.
Gap assessment to internal audit. CERT-In Empaneled. The accredited body issues the certificate — we make sure you earn it.
The benchmark for managing privacy — now a standard in its own right
ISO/IEC 27701 is the international standard for a Privacy Information Management System — a PIMS.
Where ISO/IEC 27001 governs information security, 27701 governs the protection of privacy in the processing of personally identifiable information (PII): the lawful basis for collecting it, the obligations you owe the people it belongs to, privacy by design and by default, and the discipline around sharing, transferring and disclosing it. It is a framework for governing privacy as an ongoing practice — defined scope, privacy risk assessment, controls that treat those risks, leadership oversight, and continual improvement — and certification is independent, third-party proof that the system exists and works.
The 2025 edition changed the standard's nature. The first edition (ISO/IEC 27701:2019) was an extension to ISO/IEC 27001 — you could not certify a PIMS on its own; it rode on an existing ISMS. ISO/IEC 27701:2025, published in October 2025, has been redrafted as a stand-alone management system standard. It now carries its own management-system clauses (4–10) and its own information-security baseline, so an organization can implement and certify a PIMS independently. It still aligns and integrates cleanly with ISO/IEC 27001 and other management systems through the shared harmonized structure — but it no longer depends on them. If you certified against the 2019 edition, the standard includes a mapping to help you transition; if you are starting fresh, you build straight to the 2025 standalone standard.
"Privacy used to ride on top of your security certificate. As of 2025 it stands on its own — so we build a privacy system that's true in its own right, not a clause bolted onto something else."
Who ISO/IEC 27701 is for
The standard applies to any organization that processes personal data — as a PII controller, a PII processor, or both — including joint controllers and subcontracted processors. Certification is voluntary, but the pressure to hold it rarely is.
| Criterion | Why it applies |
|---|---|
| You're a PII controller | You decide why and how personal data is processed, so the obligations to data principals — lawful basis, consent, rights, transparency — land on you. The PIMS is how you evidence that you meet them. |
| You're a PII processor | You process personal data on a customer's instructions, so you must prove you handle it only as agreed, support your customer's obligations, and control your own subcontractors. Certification is fast becoming a contractual expectation for vendors. |
| You're answerable to GDPR or India's DPDP Act | A certified PIMS is the operational backbone for these laws: it turns legal duties into running controls and produces the evidence that demonstrates accountability to regulators. |
| A customer or partner demands privacy assurance | Enterprise buyers and data-sharing partners increasingly require independent privacy certification before they will entrust you with personal data. |
| You already run ISO 27001 | A 27701 PIMS extends your security management into privacy, reusing the same governance discipline — but now as a certificate that stands on its own. |
| You want one privacy system, many obligations | Build the PIMS once and it carries across GDPR, the DPDP Act and your contractual privacy commitments — assess once, reuse the evidence. |
What the standard actually asks for
ISO/IEC 27701:2025 has two halves. The management-system clauses (4–10) define how the PIMS is run — context, leadership, planning, support, operation, performance evaluation and improvement — and Clause 6 carries a dedicated privacy risk assessment and treatment requirement that drives everything else.
Annex A then provides the reference control objectives and controls, in three normative tables: controls for PII controllers, controls for PII processors, and a shared information-security baseline that applies to both — included precisely because the standard now stands alone. Your Statement of Applicability records, control by control, which you apply and why, with justification for any you exclude.
PII Controllers — Table A.1 (31 controls) — For organizations that determine why and how PII is processed. Four objective groups: Conditions for collection & processing (lawful basis, consent, privacy impact assessment, contracts), Obligations to PII principals (information, rights, access/correction/erasure, automated decisions), Privacy by design & by default (data minimization, accuracy, retention, transmission), and PII sharing, transfer & disclosure (cross-jurisdiction transfers, records of disclosure).
PII Processors — Table A.2 (18 controls) — For organizations that process PII on a customer's behalf. The same four objective groups, reframed around the customer relationship: Conditions for processing (customer agreement, processing only on documented instructions, infringing-instruction notice), Obligations to PII principals (supporting the customer), Privacy by design & by default (temporary files, secure return/disposal, transmission controls), and Sharing, transfer & disclosure (subcontractor disclosure, change notification, handling legally binding requests).
Common — Table A.3 (29 controls) — The information-security baseline that applies to controllers and processors: policies and roles for information security, classification and labelling, information transfer, identity and access management, supplier-agreement security, incident management, protection of records, awareness and training, confidentiality agreements, cryptography, secure development and more — the security foundation that protects PII underneath the privacy controls.
The management system itself — Context · Leadership · Planning · Support · Operation · Performance Evaluation · Improvement — runs on a continual Plan-Do-Check-Act cycle, so the PIMS keeps improving rather than decaying between audits.
The standard maps its controls to these frameworks.
From gap to certification-ready — and beyond
Certification is awarded by an accredited certification body after a two-stage audit. Our job is everything that earns it: building a PIMS that is genuinely sound, running the privacy risk assessment the standard requires, validating that the controls protecting personal data actually work, and assembling the evidence so the audit confirms what is already true.
We take you from a first gap assessment to a confident Stage 2 — and stay with you through surveillance and recertification.
FIG. 02 — PIMS certification lifecycle · 01–06 Intect-led · 07–08 accredited certification body · 09 the three-year cycle
The whole cycle is a Plan-Do-Check-Act loop — privacy risk assessment and implementation (Plan/Do), internal audit and management review (Check), remediation and continual improvement (Act). The PIMS is built to get better with every pass, not just to clear one audit.
What an engagement includes
We scope to where you are — a first-time PIMS, a 2019-extension-to-2025-standalone transition, or sustaining an existing certificate — and cover the work end to end, for your role as controller, processor, or both.
Role determination
controller, processor, joint controller, or subcontractor — per processing activity
Gap assessment against ISO/IEC 27701:2025
management clauses + Annex A Tables A.1, A.2, A.3
PIMS scope definition
processing activities, systems, sites, functions and third parties
Privacy risk assessment and risk treatment plan
Clause 6
Statement of Applicability
inclusion/exclusion decisions with justification across the applicable control tables
Privacy policy and procedure suite
consent, data-principal rights, retention, transfer, breach handling
Records of processing and data-mapping support
Control-implementation support across people, process and technology
remediation of identified gaps
Technical control validation
penetration testing and configuration review of the controls that protect PII: access rights, secure authentication, cryptography, and PII transmission/transfer controls
Evidence collection and an audit-ready artifact pack
Remediation retest after fixes
Internal audit, conducted to the standard's requirements by CISA-certified IS auditors
Management-review pack for leadership oversight
Pre-assessment / mock Stage 1 and Stage 2
Liaison and support through the certification body's Stage 1 and Stage 2 audits
Surveillance-audit support across the three-year cycle
Recertification readiness
Continuous-compliance guidance as your processing, risks and obligations evolve
We audit like we attack
A paper audit confirms that a privacy control is written down. We confirm that the control protecting the personal data actually holds.
Most readiness work stops at the document
The conventional path to ISO 27701 reviews policies, samples records and ticks the controls that have documentation behind them. That satisfies the letter of the standard — but a written access-control policy and an access-control system an attacker can walk through are not the same thing, and an encryption clause is not proof the data in transit is actually encrypted. The gaps that never appear in a document review are exactly the gaps that surface in a personal-data breach.
We test the control, not just the claim
Intect is CERT-In Empaneled with an offensive-security heritage, so our readiness work is technically validated. Where the standard expects access rights, secure authentication, cryptography and PII-transmission controls to actually protect personal data, our researchers test them — safely, the way an adversary would — and bring you pentest-backed evidence that the control performs. You walk into Stage 2 with the controls around your PII already proven against a real probe, and you leave with privacy that means it.
The certificate proves you have a privacy system. Our testing proves the controls around the data actually work.
PENTEST-BACKED EVIDENCEWhat you receive
Every engagement produces the artefacts your team needs to operate the PIMS — and the evidence pack an accredited certification body expects to review.
Gap assessment report
Your current state mapped against ISO/IEC 27701:2025, with role determination and a prioritized roadmap to certification-ready.
Privacy risk assessment & treatment plan
A defensible methodology, privacy risk register and treatment decisions covering risks to PII principals and the organization (Clause 6).
Statement of Applicability
Each applicable Annex A control across the controller, processor and common tables, included or excluded, with documented justification.
Privacy policy & procedure suite
The PIMS documentation set — consent, rights handling, retention, transfer, breach response — written to the standard and tailored to how you actually operate.
Records of processing & data-mapping pack
The inventory of processing activities that underpins the PIMS.
Internal audit report
Independent verification, by CISA-certified IS auditors, that controls are operating, not just documented.
Management review pack
The oversight evidence leadership needs for performance evaluation.
Pre-assessment / mock audit report
A dry run of Stage 1 and Stage 2, with findings to close before the real thing.
Technical control validation report
Pentest-backed evidence that the controls protecting PII — access, authentication, encryption, transmission — genuinely work, with remediation guidance and retest.
Audit-ready evidence pack
Collected, organized artefacts that map cleanly to the controls and clauses.
Why teams choose Intect for ISO 27701
CERT-In Empaneled — An assessor accredited under India's national cybersecurity authority — credibility the audit room recognizes.
CISA-certified auditors in-house — Our engagement team includes CISA-certified IS auditors, so the internal audit and pre-assessment that prepare you for certification are run by recognized professionals.
We build and we break — Most consultancies only write privacy policy. We implement the PIMS and then test the controls protecting personal data like attackers, so your evidence is proven, not asserted.
One partner, the full cycle — From first gap assessment through Stage 2 support, surveillance and recertification — continuity instead of handoffs.
Frequently asked questions
Does Intect issue the ISO 27701 certificate?
No — and no consultancy can. The certificate is issued by an independent, accredited certification body after it conducts the Stage 1 and Stage 2 audits. Intect makes you certification-ready: we build and validate the PIMS, run the privacy risk assessment, the internal audit and the mock audit, and support you through the certification body's audits. Our in-house CISA-certified auditors strengthen the internal-audit work — they do not, and cannot, issue the ISO certificate. Keeping readiness and certification separate is exactly what preserves the audit's independence.
What changed in the 2025 edition?
The big change: ISO/IEC 27701 was redrafted as a stand-alone management system standard. The 2019 edition was an extension to ISO/IEC 27001 — you couldn't certify a PIMS without an ISMS underneath it. The 2025 edition, published in October 2025, has its own management-system clauses and its own information-security baseline, so you can implement and certify a PIMS independently. It still aligns and integrates with ISO 27001 if you run one, but it no longer depends on it.
Do I still need ISO 27001 first?
No longer. Under the 2025 standalone edition you can certify a PIMS on its own — that's why the standard now carries its own common information-security control table (Table A.3). If you already hold ISO 27001, your PIMS integrates neatly with it through the shared structure, and much of your security baseline carries over; but a prior 27001 certificate is no longer a prerequisite.
What's the difference between a PII controller and a PII processor here?
The standard has separate control tables for each. Controllers (Table A.1) decide why and how PII is processed and carry the obligations to data principals. Processors (Table A.2) process PII on a customer's instructions and carry obligations around acting only as instructed and managing subcontractors. Both share the common security baseline (Table A.3). If you act in both roles, the standard requires you to treat each role separately — we scope the PIMS to whichever role(s) apply to you.
How does this relate to GDPR and India's DPDP Act?
A PIMS is the operational backbone for both. GDPR and the DPDP Act set the legal duties; ISO/IEC 27701 turns them into running, auditable controls and produces the evidence of accountability. The standard even publishes a mapping to the GDPR (Annex D) and to the ISO/IEC 29100 privacy principles (Annex C). The laws themselves are not "certifiable," but a 27701 certificate is strong, independent evidence that you operate a privacy program that supports them.
We certified against ISO 27701:2019 — what now?
The 2025 edition replaces the 2019 edition. Because it is now standalone, the transition is more than cosmetic, so the standard includes a correspondence mapping to the 2019 controls to guide it. We scope the work to wherever you are — re-baselining your existing controls against the new structure and closing the gaps the standalone format introduces.
How long does certification take?
It depends on the size and complexity of your processing, which role(s) you hold, and how mature your current controls are — which is exactly what the gap assessment establishes first. We give you a realistic, evidence-based timeline up front rather than a generic promise, and sequence the work so nothing blocks the certification audit.
What happens after we're certified?
Certification runs on a three-year cycle. The accredited body conducts annual surveillance audits to confirm the PIMS is still operating, and a full recertification audit at the end of the cycle. We support you across all of it, so the certificate stays live and the PIMS keeps improving.
One privacy system, many obligations
A well-built PIMS is the operational foundation for far more than one certificate.
Build a privacy system that's ready to be certified.
Tell us where you are — first PIMS, a 2019-to-2025 standalone transition, or maintaining an existing certificate — and we'll scope a readiness assessment that fits, or connect you with an assessor.