ISO/IEC 27701 (PIMS): The Complete Guide to the 2025 Privacy Standard
regulatory-updates
audit-certification

ISO/IEC 27701 (PIMS): The Complete Guide to the 2025 Privacy Standard

ISO/IEC 27701:2025 is now standalone. What changed, how a PIMS evidences both the GDPR and the Swiss LPD, how certification and transition work, and which training path fits your role.

Géraldine RAYET
Géraldine RAYET
7 min read

ISO/IEC 27701 is the international standard for a Privacy Information Management System, or PIMS. In October 2025 it changed in a fundamental way, moving from an add-on to ISO/IEC 27001 into a standalone standard that can be implemented and certified on its own. This guide covers what the 2025 revision changed, how a PIMS maps to the GDPR and the Swiss LPD at the same time, how certification and audits work, and which training path fits your role.

Where the standard stands today

ISO/IEC 27701:2025 (Edition 2) was published on 14 October 2025 as a standalone standard, no longer an extension of ISO/IEC 27001. Organizations certified to the 2019 edition have until October 2028 to transition, after which 2019-based certificates are no longer valid.

What is ISO/IEC 27701?

ISO/IEC 27701 specifies the requirements for a Privacy Information Management System. Where ISO/IEC 27001 governs information security, ISO/IEC 27701 governs privacy, adding the controls an organization needs when it acts as a controller or processor of personally identifiable information. A certified PIMS turns privacy obligations that usually live in legal opinions and policy documents into an operating system with owners, evidence, and independent assurance behind it.

What is a Privacy Information Management System (PIMS)?

A PIMS is the set of policies, roles, processes, and controls an organization uses to manage personal data responsibly and to demonstrate that it does so. ISO/IEC 27701 is the standard against which a PIMS can be independently certified, which is what a customer, a regulator, or a Swiss Data Protection Officer can rely on.

Certification is issued by an accredited certification body, not by ISO and not by a training provider. Training prepares the people, and the audit certifies the organization. Those are two separate transactions, and the distinction matters when you plan a budget.

Controller or processor: which role are you certifying?

Your role in the data relationship shapes your entire PIMS. A PII controller decides the purposes and means of processing, which makes it accountable for lawful basis, transparency, and the rights of the people whose data it holds. A PII processor acts only on a controller's documented instructions, which shifts its obligations toward security, sub-processor management, and faithful execution. Many organizations are both at once, a controller for their own staff and customer data and a processor for the client data they handle.

PII controller compared with PII processor under ISO/IEC 27701

Dimension: Decides purpose and means

PII controllerYes
PII processorNo, acts on instructions

Dimension: Primary accountability

PII controllerLawful basis, transparency, principal rights
PII processorSecurity, faithful execution, sub-processors

Dimension: Key audit evidence

PII controllerRecords of processing, consent and rights handling
PII processorContracts, instructions log, sub-processor controls

Dimension: Typical example

PII controllerAn employer or a brand holding customer data
PII processorA SaaS vendor, cloud host, or payroll provider

The 2025 revision: ISO/IEC 27701 is now standalone.

The most important thing to understand about ISO/IEC 27701 in 2025 is that it is no longer an extension of ISO/IEC 27001. The 2019 edition required an existing ISO/IEC 27001 ISMS first. The 2025 edition, published as Edition 2 on 14 October 2025, is a standalone standard with its own full set of management-system clauses, so a PIMS can be certified independently of any ISMS. Organizations that already run ISO/IEC 27001 can still integrate the two, which remains the efficient route for security-led teams.

ISO/IEC 27701:2019 compared with 2025

Aspect: Status

2019 editionExtension to 27001 and 27002
2025 edition (Ed. 2)Standalone standard

Aspect: ISO 27001 prerequisite

2019 editionRequired
2025 edition (Ed. 2)Not required

Aspect: Structure

2019 editionPrivacy clauses added onto the ISMS
2025 edition (Ed. 2)Full management-system clauses 4 to 10

Aspect: Annex A

2019 editionSeparate controller and processor annexes
2025 edition (Ed. 2)Consolidated control set

Aspect: Expanded guidance

2019 editionGeneral PII processing
2025 edition (Ed. 2)AI, cloud, biometrics, health data

Aspect: Certification-body guidance

2019 editionGeneral
2025 edition (Ed. 2)Supported by ISO/IEC 27706:2025

Since the 2025 revision you can implement and certify a PIMS with no ISO/IEC 27001 in place. This lowers the barrier for privacy-driven organizations that were never going to pursue a full security certification, and it is the single biggest reason the standard now reaches a wider audience. Teams building a standalone PIMS from the ground up will find the methodology in ISO 27701 Lead Implementer training.

Swiss dual compliance: the LPD and the GDPR together

This is where the standard earns its place for Swiss organizations, and it is the angle most guides miss. Because Switzerland sits outside the EU, a Swiss company that offers goods or services to people in the EU is subject to the GDPR extraterritorially while remaining subject to the Swiss LPD at home, so most Swiss organizations of any scale carry both obligations at the same time.

One PIMS, two regimes

ISO/IEC 27701 gives you one control framework that maps to both the EU GDPR and the revised Swiss LPD. You build the mapping once and evidence both regimes together, with a single set of controls, a single audit cycle, and a single body of evidence, instead of running two disconnected compliance programmes.

The revised Swiss LPD, in force since 1 September 2023, shares most of its DNA with the GDPR, covering transparency, purpose limitation, security of processing, and the accountability of controllers and processors. A PIMS built to ISO/IEC 27701 meets both with the same framework rather than through a separate parallel effort.

How ISO/IEC 27701 maps to the GDPR and the Swiss LPD

Privacy obligation: Lawful basis and consent

GDPR anchorArts. 6 to 7
Swiss LPD (revFADP) anchorArt. 6, including 6(7) for high-risk profiling
ISO/IEC 27701 control areaIdentify lawful basis; obtain and record consent

Privacy obligation: Duty to inform and transparency

GDPR anchorArts. 13 to 14
Swiss LPD (revFADP) anchorArt. 19
ISO/IEC 27701 control areaProvide information to PII principals

Privacy obligation: Data subject and principal rights

GDPR anchorArts. 15 to 20
Swiss LPD (revFADP) anchorArt. 25 for access; portability newly added
ISO/IEC 27701 control areaObligations to PII principals

Privacy obligation: Records of processing (RoPA)

GDPR anchorArt. 30
Swiss LPD (revFADP) anchorArt. 12, with a small-organization exemption
ISO/IEC 27701 control areaIdentify and document processing

Privacy obligation: Security of processing

GDPR anchorArt. 32
Swiss LPD (revFADP) anchorArt. 8 and the Ordinance
ISO/IEC 27701 control areaSecurity controls from the 27001 and 27002 lineage

Privacy obligation: Breach notification

GDPR anchorArts. 33 to 34
Swiss LPD (revFADP) anchorArt. 24, to the FDPIC for high-risk breaches
ISO/IEC 27701 control areaPrivacy incident handling

Privacy obligation: Impact assessment (DPIA)

GDPR anchorArt. 35
Swiss LPD (revFADP) anchorArt. 22
ISO/IEC 27701 control areaPrivacy impact assessment

Privacy obligation: Processor and order processing

GDPR anchorArt. 28
Swiss LPD (revFADP) anchorArt. 9
ISO/IEC 27701 control areaPII processor controls, contracts, sub-processors

Privacy obligation: Cross-border transfers

GDPR anchorChapter V, Arts. 44 to 49
Swiss LPD (revFADP) anchorArts. 16 to 17
ISO/IEC 27701 control areaRecords of PII transfers across jurisdictions

The mapping is orientation, not a legal opinion

The article references above are indicative and should be confirmed with qualified Swiss and EU counsel. ISO/IEC 27701 supports and evidences conformity with the GDPR and the LPD; it does not by itself establish legal compliance, which only a competent authority or court can ultimately judge.

ISO/IEC 27701 is not a legal certificate issued by the FDPIC, and no ISO certificate substitutes for the LPD's own requirements. It is an internationally recognized assurance standard, and a certified PIMS is credible evidence of a mature privacy program that a Swiss regulator, an EU counterpart, or a demanding enterprise customer will respect during due diligence. Building the dual-compliance mapping deliberately is a core part of ISO 27701 Lead Implementer training.

Where ISO/IEC 27701 sits next to other standards

Buyers rarely evaluate ISO/IEC 27701 in isolation. ISO/IEC 27001 governs information security through an ISMS, while ISO/IEC 27701 governs privacy through a PIMS, and the two remain natural partners even now that the privacy standard is independent. If you are deciding where to start on the security side, our ISO 27001 certification and training guide covers the ISMS head-on. ISO/IEC 42001 for AI governance and SOC 2 for security attestation are close neighbours to ISO/IEC 27701 without being substitutes for it.

How to implement and certify ISO/IEC 27701

Implementation follows a recognizable arc, whether you are extending an existing ISMS or building a standalone PIMS. You begin by defining scope and confirming whether you certify as a controller, a processor, or both. From there you run a gap analysis against the standard, design and document the missing controls, assign ownership, and operate the system long enough to generate real records. A management review and an internal audit close the loop before you invite an external certification body.

[@portabletext/react] Unknown block type "diagramBlock", specify a component for it in the `components.types` prop

What audit evidence do ISO/IEC 27701 auditors look for?

Auditors look for evidence that the controls are not just written down but genuinely operating. That includes current records of processing, demonstrable handling of data subject requests, functioning risk assessments, contracts and controls covering sub-processors, and clear records of management review and continual improvement. Learning to gather and assess that evidence is the heart of ISO 27701 Lead Auditor training.

How long is an ISO/IEC 27701 certificate valid?

A certificate is issued for a three-year cycle. Surveillance audits during that time confirm the PIMS is still operating, and a recertification audit renews it before the cycle ends. Where a single management system carries both security and privacy, an integrated audit can assess ISO 27701 and ISO 27001 together to cut cost and duplication.

Transitioning from the 2019 edition to 2025

If you were certified under the old edition, the standalone revision affects you directly. Organizations certified to ISO/IEC 27701:2019 have until October 2028 to transition to the 2025 edition, after which 2019-based certificates are no longer valid. That window is generous on paper, and it closes faster than it looks once you account for planning, remediation, and audit scheduling around a certification body's availability.

Because the 2025 edition restructured the standard rather than tweaking it, transition is a real project. The requirements are largely drawn from the existing content of ISO/IEC 27701:2019, ISO/IEC 27001:2022, and ISO/IEC 27002:2022, so a well-run 2019 PIMS already satisfies much of the new standard, and the work concentrates on the restructured clauses and the reorganized controls.

ISO/IEC 27701 transition readiness checklist
The steps below assume an organization currently certified to ISO/IEC 27701:2019. Each names the evidence a certification body will expect.
  • 1. Confirm your current certificate's expiry and map it against the October 2028 deadline, with room for a transition audit.
  • 2. Run a gap analysis against the new clause 4 to 10 structure and the consolidated Annex A. Produce a mapping table as your primary transition evidence.
  • 3. Re-baseline your controller and processor scope under the unified control set.
  • 4. Update documentation: scope statement, records of processing, roles, risk assessments, and evidence records.
  • 5. Identify where AI, cloud, biometric, or health-data processing now needs the expanded guidance applied.
  • 6. Run a full internal audit against the 2025 text before the transition audit.
  • 7. Book the transition audit with your certification body early, before capacity tightens toward 2028.

Expert view from our lead privacy trainer

In the transitions we run, the organizations that struggle are rarely the ones with weak systems. They are the ones that treat a deadline as a documentation exercise and discover at the audit that the restructured controls were never re-baselined against how they actually process data. Start with the gap analysis against the new structure, not with the paperwork. The gap analysis tells you where the real work is, and the documentation follows from it.

The changes are significant enough that most teams benefit from a structured walkthrough of exactly what moved, which is what ISO/IEC 27701 Transition training provides.

Which ISO/IEC 27701 training path is right for you?

Three credentials, three different jobs. The choice follows the role you will play in the PIMS, not your level of existing knowledge.

ISO/IEC 27701 certification paths compared

Certification: ISO 27701 Lead Implementer

Who it is forDPOs, privacy officers, compliance leads, and consultants who own the PIMS
What you can do afterDesign, build, maintain, and improve a PIMS; lead an implementation project

Certification: ISO 27701 Lead Auditor

Who it is forInternal and third-party auditors and certification staff
What you can do afterPlan and run audits, gather and judge evidence, manage an audit programme

Certification: ISO/IEC 27701 Transition

Who it is forProfessionals already certified on the 2019 edition
What you can do afterApply the 2025 changes without repeating the full syllabus
[@portabletext/react] Unknown block type "diagramBlock", specify a component for it in the `components.types` prop

All three are delivered as PECB certification programmes and include the official exam. Abilene Academy is the only PECB Titanium Partner in Switzerland, which matters when your certificate needs to carry weight with EU customers and regulators as well as Swiss ones.

Frequently asked questions

The questions below cover what organizations ask most often when a standard is revised. Each is answered in full in the FAQ section of this page.

Take the next step

If you will build the PIMS, ISO 27701 Lead Implementer is the path. If you will audit against it, ISO 27701 Lead Auditor. If you are moving a 2019 credential to the 2025 edition, the ISO/IEC 27701 Transition course covers exactly what changed. Upcoming session dates are published for all three.

Frequently Asked Questions

No. Since the October 2025 revision, ISO/IEC 27701 is a standalone, independently certifiable standard, not an add-on to ISO 27001. The 2019 edition required an existing ISMS; the 2025 edition (Edition 2) has its own full management-system clauses, so a PIMS can now be certified on its own.

The headline change is independence: the 2025 edition no longer requires ISO 27001. It adopts the standard ISO management-system structure across clauses 4 to 10, consolidates the controller and processor controls in Annex A, and expands guidance for AI, cloud, biometrics, and health data. The transition deadline is October 2028.

Yes, since the 2025 revision. A PIMS can now be implemented and certified independently, with no ISO 27001 prerequisite. Organizations that already run an ISMS can still integrate the two, but a standalone PIMS certificate is now possible, which lowers the entry barrier for privacy-focused organizations not pursuing information-security certification.

Yes. ISO/IEC 27701 provides one control framework that maps to both the EU GDPR and the revised Swiss LPD, which is the dual-compliance position most Swiss organizations need. It does not replace legal obligations, but its controls and audit evidence support and demonstrate conformity with both regimes at once.

Organizations certified to ISO/IEC 27701:2019 have until October 2028 to transition to the 2025 edition, after which 2019 certificates are no longer valid. Because the standard is now standalone with restructured clauses, transition involves a gap analysis and a transition audit rather than a simple document refresh.

Related Training

Courses referenced in this article

Related Questions

Expert answers referenced in this article

What are the main differences between ISO/IEC 27701:2019 and ISO/IEC 27701:2025?

ISO/IEC 27701:2025 is no longer dependent on ISO/IEC 27001 and introduces a new control structure for PII controllers, PII processors, and shared responsibilities.

Read answer

Does ISO/IEC 27701 apply to both PII controllers and PII processors?

Yes. ISO/IEC 27701 defines distinct privacy requirements for both PII controllers and PII processors.

Read answer

How does ISO 27701 support GDPR compliance and regulatory audits?

ISO/IEC 27701 supports GDPR compliance by providing a structured, auditable privacy management system for controls, roles, and accountability, helping organizations evidence GDPR Article 5(2) accountability. The same PIMS also maps to the revised Swiss FADP (LPD), so one system supports both regimes.

Read answer

Is ISO/IEC 27701 certification mandatory for privacy compliance?

No. ISO/IEC 27701 certification is voluntary but helps demonstrate structured privacy governance.

Read answer

What is the difference between ISO/IEC 27701 Lead Implementer and Lead Auditor?

ISO/IEC 27701 Lead Implementer and Lead Auditor are two distinct PECB certifications. The Lead Implementer designs and operates the Privacy Information Management System (PIMS); the Lead Auditor independently assesses its conformity. One builds the system, the other verifies that it meets ISO/IEC 27701 requirements.

Read answer

Who should attend ISO/IEC 27701 Lead Implementer training?

ISO/IEC 27701 Lead Implementer training is for professionals responsible for implementing or governing privacy management systems.

Read answer

What are the prerequisites for ISO 27701 Lead Auditor training?

ISO 27701 Lead Auditor training requires prior knowledge of management systems and auditing, typically ISO 27001 and ISO 19011. Participants should already understand GDPR concepts, information security controls, and audit principles.

Read answer

What is the ISO/IEC 27701 Transition training?

The ISO/IEC 27701 Transition training explains how to move an existing PIMS from ISO/IEC 27701:2019 to ISO/IEC 27701:2025 and adapt it to the new requirements.

Read answer

Get Certified

ISO 27001, NIS2, AI governance & more. Join 2,500+ professionals.

View Courses
Ask our AI Assistant

Related Articles

Continue exploring topics that matter to your organization

We use cookies to improve your experience

Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.