ISO/IEC 27701 Privacy Information Management Systems
Extends ISO/IEC 27001 to cover personal data. It cannot be certified on its own — it is always operated together with 27001.
ITS own scheme
This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →
Who this is for
- Organisations already running ISO/IEC 27001 that also handle personal data
- Processors handling personal data on behalf of client companies
- Companies subject to GDPR or other privacy regulation
What certification gives you
Makes clear, per activity, whether you are the controller or the processor
Risk is judged by harm to the organisation and harm to the individual
Brings privacy law compliance into one management system
