ISO/IEC 27701:2025

Privacy Information Management System

For organisations processing personally identifiable information within an ISO 27001 scope.

ClassManagement system standard

Edition2025

What is this standard?

Specifies management system requirements for managing personally identifiable information (PII), built on top of an information security management system.

Who is it for?

Organisations processing personal data, especially SaaS, healthcare, finance, HR, marketing and contact centres.

What triggers an assessment?

  • PII is processed within the ISO 27001 scope.
  • A customer or contract requires a privacy assurance.
  • The processor/controller role needs to be evidenced.

What does it not replace?

  • It must not be claimed to replace KVKK or GDPR compliance, or legal advice.
  • It does not replace ISO 27001; it is added on top of it.

Official source

Last verified:

This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.

See all standards