ISO/IEC 27701 CertificationPrivacy Information Management System

ISO 27701 certification extends your information security programme to protect personal data with ISO/IEC 27701 privacy information management.

Stage 1 & Stage 2 auditsSurveillance auditsOnline verification
ISOCertified
management system
About the Standard

What is ISO/IEC 27701?

ISO/IEC 27701 specifies requirements for a Privacy Information Management System (PIMS) for organisations acting as controllers or processors of personally identifiable information (PII), helping demonstrate compliance with data protection laws.

Who is it for?

  • Organisations handling personal data
  • Cloud and IT service providers
  • Banks, healthcare and telecoms
  • Organisations with ISO/IEC 27001
Start Your Certification
Structure of the Standard

Key Requirements (Clauses 4–10)

ISO/IEC 27701 follows the common high‑level structure shared by ISO management system standards, making it easy to integrate with other standards.

4

Context of the organisation

Understand internal and external issues and interested parties.

5

Leadership

Top management commitment, policy and responsibilities.

6

Planning

Risks, opportunities and measurable objectives.

7

Support

Resources, competence, awareness and documented information.

8

Operation

Planning and control of the processes that deliver results.

9

Performance evaluation

Monitoring, internal audit and management review.

10

Improvement

Corrective action and continual improvement.

Certification Process

How to Get ISO/IEC 27701 Certified

1

Application

Submit an application with details of your organisation, sites, scope and standard(s).

2

Quotation & agreement

We review the application, confirm audit duration and send a quotation and certification agreement.

3

Stage 1 audit

Review of your documentation and readiness for the Stage 2 audit.

4

Stage 2 audit

On‑site audit to evaluate the implementation and effectiveness of your management system.

5

Certification decision

Independent review of audit results and, once any non‑conformities are closed, certificate issue.

6

Surveillance audits

Periodic audits to confirm your system continues to meet the standard while you are certified.

7

Recertification

A recertification audit before your certificate expires to renew your certification.

Training for Your Team

Awareness, internal auditor and lead auditor courses for ISO/IEC 27701 and other standards.

View ISO courses

Verify a Certificate

Check whether a certificate issued by SRA is valid.

Verify now

Rules & Regulations

Read the conditions that apply to certified clients.

Read the rules
FAQ

Frequently Asked Questions

It depends on your organisation’s size, complexity and readiness. After reviewing your application we will give you a clear timeline.

Certificate validity depends on the type of certification and the scheme requirements. The validity period is confirmed in your certification agreement and shown on your certificate, and certification is maintained through surveillance audits.

Yes. It can be audited together with other ISO management system standards in an integrated audit.