ISO/IEC 27701:2025
Privacy Information Management System
ISO/IEC 27701 (2025) is a management system standard: Privacy Information Management System. Specifies management system requirements for managing personally identifiable information (PII), built on top of an information security management system. It applies to organisations processing personal data, especially SaaS, healthcare, finance, HR, marketing and contact centres.
- Class
- Management system standard
- Edition
- 2025
- Related sectors
- 3
- Last verified
What is this standard?
Specifies management system requirements for managing personally identifiable information (PII), built on top of an information security management system.
What ISO/IEC 27701 does not replace
- It must not be claimed to replace KVKK or GDPR compliance, or legal advice.
- It does not replace ISO 27001; it is added on top of it.
Who is it for?
Organisations processing personal data, especially SaaS, healthcare, finance, HR, marketing and contact centres.
What triggers an assessment?
- PII is processed within the ISO 27001 scope.
- A customer or contract requires a privacy assurance.
- The processor/controller role needs to be evidenced.
Official source
Last verified:
This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.