ISO/IEC 27701 Privacy Information Management Systems

Extends ISO/IEC 27001 to cover personal data. It cannot be certified on its own — it is always operated together with 27001.

ITS own scheme

This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →

Who this is for

  • Organisations already running ISO/IEC 27001 that also handle personal data
  • Processors handling personal data on behalf of client companies
  • Companies subject to GDPR or other privacy regulation

What certification gives you

  • Makes clear, per activity, whether you are the controller or the processor

  • Risk is judged by harm to the organisation and harm to the individual

  • Brings privacy law compliance into one management system