ISO/IEC 27701 CertificationPrivacy Information Management System
ISO 27701 certification extends your information security programme to protect personal data with ISO/IEC 27701 privacy information management.
management system
What is ISO/IEC 27701?
ISO/IEC 27701 specifies requirements for a Privacy Information Management System (PIMS) for organisations acting as controllers or processors of personally identifiable information (PII), helping demonstrate compliance with data protection laws.
Who is it for?
- Organisations handling personal data
- Cloud and IT service providers
- Banks, healthcare and telecoms
- Organisations with ISO/IEC 27001
Benefits of ISO/IEC 27701
Protect personal data
Controls for collecting, using and storing PII.
Regulatory confidence
Supports PDPL, GDPR and similar laws.
Customer trust
Show clients how their data is handled.
Key Requirements (Clauses 4–10)
ISO/IEC 27701 follows the common high‑level structure shared by ISO management system standards, making it easy to integrate with other standards.
Context of the organisation
Understand internal and external issues and interested parties.
Leadership
Top management commitment, policy and responsibilities.
Planning
Risks, opportunities and measurable objectives.
Support
Resources, competence, awareness and documented information.
Operation
Planning and control of the processes that deliver results.
Performance evaluation
Monitoring, internal audit and management review.
Improvement
Corrective action and continual improvement.
How to Get ISO/IEC 27701 Certified
Application
Submit an application with details of your organisation, sites, scope and standard(s).
Quotation & agreement
We review the application, confirm audit duration and send a quotation and certification agreement.
Stage 1 audit
Review of your documentation and readiness for the Stage 2 audit.
Stage 2 audit
On‑site audit to evaluate the implementation and effectiveness of your management system.
Certification decision
Independent review of audit results and, once any non‑conformities are closed, certificate issue.
Surveillance audits
Periodic audits to confirm your system continues to meet the standard while you are certified.
Recertification
A recertification audit before your certificate expires to renew your certification.
Training for Your Team
Awareness, internal auditor and lead auditor courses for ISO/IEC 27701 and other standards.
View ISO coursesFrequently Asked Questions
It depends on your organisation’s size, complexity and readiness. After reviewing your application we will give you a clear timeline.
Certificate validity depends on the type of certification and the scheme requirements. The validity period is confirmed in your certification agreement and shown on your certificate, and certification is maintained through surveillance audits.
Yes. It can be audited together with other ISO management system standards in an integrated audit.