ISO/IEC 27701:2025

Privacy Information Management System

ISO/IEC 27701 (2025) is a management system standard: Privacy Information Management System. Specifies management system requirements for managing personally identifiable information (PII), built on top of an information security management system. It applies to organisations processing personal data, especially SaaS, healthcare, finance, HR, marketing and contact centres.

Class
Management system standard
Edition
2025
Related sectors
3
Last verified

What is this standard?

Specifies management system requirements for managing personally identifiable information (PII), built on top of an information security management system.

What ISO/IEC 27701 does not replace

  • It must not be claimed to replace KVKK or GDPR compliance, or legal advice.
  • It does not replace ISO 27001; it is added on top of it.

Who is it for?

Organisations processing personal data, especially SaaS, healthcare, finance, HR, marketing and contact centres.

What triggers an assessment?

  • PII is processed within the ISO 27001 scope.
  • A customer or contract requires a privacy assurance.
  • The processor/controller role needs to be evidenced.

Official source

Last verified:

This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.

Cite this page

Attributing this record helps other researchers verify it independently.

"ISO/IEC 27701:2025." Certifidex, FutureTechnologies. Last verified 4 August 2026. https://certifidex.com/iso-standards/iso-iec-27701-privacy-information-management-system

See all standards →