ISO/IEC 27701 is the international standard for a Privacy Information Management System, or PIMS. In October 2025 it changed in a fundamental way, moving from an add-on to ISO/IEC 27001 into a standalone standard that can be implemented and certified on its own. This guide covers what the 2025 revision changed, how a PIMS maps to the GDPR and the Swiss LPD at the same time, how certification and audits work, and which training path fits your role.
Where the standard stands today
ISO/IEC 27701:2025 (Edition 2) was published on 14 October 2025 as a standalone standard, no longer an extension of ISO/IEC 27001. Organizations certified to the 2019 edition have until October 2028 to transition, after which 2019-based certificates are no longer valid.
What is ISO/IEC 27701?
ISO/IEC 27701 specifies the requirements for a Privacy Information Management System. Where ISO/IEC 27001 governs information security, ISO/IEC 27701 governs privacy, adding the controls an organization needs when it acts as a controller or processor of personally identifiable information. A certified PIMS turns privacy obligations that usually live in legal opinions and policy documents into an operating system with owners, evidence, and independent assurance behind it.
What is a Privacy Information Management System (PIMS)?
A PIMS is the set of policies, roles, processes, and controls an organization uses to manage personal data responsibly and to demonstrate that it does so. ISO/IEC 27701 is the standard against which a PIMS can be independently certified, which is what a customer, a regulator, or a Swiss Data Protection Officer can rely on.
Certification is issued by an accredited certification body, not by ISO and not by a training provider. Training prepares the people, and the audit certifies the organization. Those are two separate transactions, and the distinction matters when you plan a budget.
Controller or processor: which role are you certifying?
Your role in the data relationship shapes your entire PIMS. A PII controller decides the purposes and means of processing, which makes it accountable for lawful basis, transparency, and the rights of the people whose data it holds. A PII processor acts only on a controller's documented instructions, which shifts its obligations toward security, sub-processor management, and faithful execution. Many organizations are both at once, a controller for their own staff and customer data and a processor for the client data they handle.
PII controller compared with PII processor under ISO/IEC 27701
Dimension: Decides purpose and means
Dimension: Primary accountability
Dimension: Key audit evidence
Dimension: Typical example
The 2025 revision: ISO/IEC 27701 is now standalone.
The most important thing to understand about ISO/IEC 27701 in 2025 is that it is no longer an extension of ISO/IEC 27001. The 2019 edition required an existing ISO/IEC 27001 ISMS first. The 2025 edition, published as Edition 2 on 14 October 2025, is a standalone standard with its own full set of management-system clauses, so a PIMS can be certified independently of any ISMS. Organizations that already run ISO/IEC 27001 can still integrate the two, which remains the efficient route for security-led teams.
ISO/IEC 27701:2019 compared with 2025
Aspect: Status
Aspect: ISO 27001 prerequisite
Aspect: Structure
Aspect: Annex A
Aspect: Expanded guidance
Aspect: Certification-body guidance
Since the 2025 revision you can implement and certify a PIMS with no ISO/IEC 27001 in place. This lowers the barrier for privacy-driven organizations that were never going to pursue a full security certification, and it is the single biggest reason the standard now reaches a wider audience. Teams building a standalone PIMS from the ground up will find the methodology in ISO 27701 Lead Implementer training.
Swiss dual compliance: the LPD and the GDPR together
This is where the standard earns its place for Swiss organizations, and it is the angle most guides miss. Because Switzerland sits outside the EU, a Swiss company that offers goods or services to people in the EU is subject to the GDPR extraterritorially while remaining subject to the Swiss LPD at home, so most Swiss organizations of any scale carry both obligations at the same time.
One PIMS, two regimes
ISO/IEC 27701 gives you one control framework that maps to both the EU GDPR and the revised Swiss LPD. You build the mapping once and evidence both regimes together, with a single set of controls, a single audit cycle, and a single body of evidence, instead of running two disconnected compliance programmes.
The revised Swiss LPD, in force since 1 September 2023, shares most of its DNA with the GDPR, covering transparency, purpose limitation, security of processing, and the accountability of controllers and processors. A PIMS built to ISO/IEC 27701 meets both with the same framework rather than through a separate parallel effort.
How ISO/IEC 27701 maps to the GDPR and the Swiss LPD
Privacy obligation: Lawful basis and consent
Privacy obligation: Duty to inform and transparency
Privacy obligation: Data subject and principal rights
Privacy obligation: Records of processing (RoPA)
Privacy obligation: Security of processing
Privacy obligation: Breach notification
Privacy obligation: Impact assessment (DPIA)
Privacy obligation: Processor and order processing
Privacy obligation: Cross-border transfers
The mapping is orientation, not a legal opinion
The article references above are indicative and should be confirmed with qualified Swiss and EU counsel. ISO/IEC 27701 supports and evidences conformity with the GDPR and the LPD; it does not by itself establish legal compliance, which only a competent authority or court can ultimately judge.
ISO/IEC 27701 is not a legal certificate issued by the FDPIC, and no ISO certificate substitutes for the LPD's own requirements. It is an internationally recognized assurance standard, and a certified PIMS is credible evidence of a mature privacy program that a Swiss regulator, an EU counterpart, or a demanding enterprise customer will respect during due diligence. Building the dual-compliance mapping deliberately is a core part of ISO 27701 Lead Implementer training.
Where ISO/IEC 27701 sits next to other standards
Buyers rarely evaluate ISO/IEC 27701 in isolation. ISO/IEC 27001 governs information security through an ISMS, while ISO/IEC 27701 governs privacy through a PIMS, and the two remain natural partners even now that the privacy standard is independent. If you are deciding where to start on the security side, our ISO 27001 certification and training guide covers the ISMS head-on. ISO/IEC 42001 for AI governance and SOC 2 for security attestation are close neighbours to ISO/IEC 27701 without being substitutes for it.
How to implement and certify ISO/IEC 27701
Implementation follows a recognizable arc, whether you are extending an existing ISMS or building a standalone PIMS. You begin by defining scope and confirming whether you certify as a controller, a processor, or both. From there you run a gap analysis against the standard, design and document the missing controls, assign ownership, and operate the system long enough to generate real records. A management review and an internal audit close the loop before you invite an external certification body.
What audit evidence do ISO/IEC 27701 auditors look for?
Auditors look for evidence that the controls are not just written down but genuinely operating. That includes current records of processing, demonstrable handling of data subject requests, functioning risk assessments, contracts and controls covering sub-processors, and clear records of management review and continual improvement. Learning to gather and assess that evidence is the heart of ISO 27701 Lead Auditor training.
How long is an ISO/IEC 27701 certificate valid?
A certificate is issued for a three-year cycle. Surveillance audits during that time confirm the PIMS is still operating, and a recertification audit renews it before the cycle ends. Where a single management system carries both security and privacy, an integrated audit can assess ISO 27701 and ISO 27001 together to cut cost and duplication.
Transitioning from the 2019 edition to 2025
If you were certified under the old edition, the standalone revision affects you directly. Organizations certified to ISO/IEC 27701:2019 have until October 2028 to transition to the 2025 edition, after which 2019-based certificates are no longer valid. That window is generous on paper, and it closes faster than it looks once you account for planning, remediation, and audit scheduling around a certification body's availability.
Because the 2025 edition restructured the standard rather than tweaking it, transition is a real project. The requirements are largely drawn from the existing content of ISO/IEC 27701:2019, ISO/IEC 27001:2022, and ISO/IEC 27002:2022, so a well-run 2019 PIMS already satisfies much of the new standard, and the work concentrates on the restructured clauses and the reorganized controls.
- 1. Confirm your current certificate's expiry and map it against the October 2028 deadline, with room for a transition audit.
- 2. Run a gap analysis against the new clause 4 to 10 structure and the consolidated Annex A. Produce a mapping table as your primary transition evidence.
- 3. Re-baseline your controller and processor scope under the unified control set.
- 4. Update documentation: scope statement, records of processing, roles, risk assessments, and evidence records.
- 5. Identify where AI, cloud, biometric, or health-data processing now needs the expanded guidance applied.
- 6. Run a full internal audit against the 2025 text before the transition audit.
- 7. Book the transition audit with your certification body early, before capacity tightens toward 2028.
Expert view from our lead privacy trainer
In the transitions we run, the organizations that struggle are rarely the ones with weak systems. They are the ones that treat a deadline as a documentation exercise and discover at the audit that the restructured controls were never re-baselined against how they actually process data. Start with the gap analysis against the new structure, not with the paperwork. The gap analysis tells you where the real work is, and the documentation follows from it.
The changes are significant enough that most teams benefit from a structured walkthrough of exactly what moved, which is what ISO/IEC 27701 Transition training provides.
Which ISO/IEC 27701 training path is right for you?
Three credentials, three different jobs. The choice follows the role you will play in the PIMS, not your level of existing knowledge.
ISO/IEC 27701 certification paths compared
Certification: ISO 27701 Lead Implementer
Certification: ISO 27701 Lead Auditor
Certification: ISO/IEC 27701 Transition
All three are delivered as PECB certification programmes and include the official exam. Abilene Academy is the only PECB Titanium Partner in Switzerland, which matters when your certificate needs to carry weight with EU customers and regulators as well as Swiss ones.
Frequently asked questions
The questions below cover what organizations ask most often when a standard is revised. Each is answered in full in the FAQ section of this page.
Take the next step
If you will build the PIMS, ISO 27701 Lead Implementer is the path. If you will audit against it, ISO 27701 Lead Auditor. If you are moving a 2019 credential to the 2025 edition, the ISO/IEC 27701 Transition course covers exactly what changed. Upcoming session dates are published for all three.




