ISO/IEC 27701 Privacy Information Management Systems

Confirms that an organisation manages personal information — where it comes from, where it is held, who it is shared with, and when it is deleted. Since the 2025 revision it can be certified on its own, without ISO/IEC 27001.

ITS own scheme

This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →

What this certification proves

ISO/IEC 27701 does not certify that personal data will never leak. What it examines is whether you know what personal data you hold and where it is, use it only for the purpose it was given for, and delete it when that purpose ends.

It differs from information security in a decisive way. Security assesses risk by harm to the organisation. Privacy adds harm to the person the data is about. A leak that is minor for a company can be permanent for an individual.

The other central idea is role. The same organisation is a controller of personal data for some activities and a processor for others. The obligations differ completely between the two, and getting this wrong makes everything downstream wrong.

🔴 Certificates ITS currently issues are to ISO/IEC 27701:2019, which requires ISO/IEC 27001 certification alongside it. The 2025 edition makes the standard standalone; the date of our move to it will be announced separately, so please plan for 27001 as well.

Who this is for

  • Organisations holding large volumes of customer or member data — commerce, platforms, healthcare, education
  • Organisations processing client personal data under contract — SI, cloud, contact centres, logistics
  • Organisations subject to GDPR or other overseas privacy regulation
  • Organisations already running ISO/IEC 27001 that now need privacy covered

🌱 How this relates to ESG

S Social

Maps onto the S (Social) pillar. Personal data is a question of individual rights, which is why every major ESG framework classifies it as social.

  • GRI 418 (Customer Privacy) — substantiated complaints about privacy breaches and losses of customer data, reported under Social
  • Korea's K-ESG guideline, S domain «information protection» — privacy framework and breach incidents
  • SASB and MSCI place «Data Security and Customer Privacy» in the Social pillar
  • Korea's Personal Information Protection Act — consent, deletion, processor management and breach notification requirements overlap substantially
  • Korea's ISMS-P certification overlaps considerably, so the two can be prepared together
  • GDPR — the standard includes a mapping to GDPR articles, which can be given directly to European customers during due diligence

What certification gives you

How the requirements are structured

This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.

ISO/IEC 27701Privacy Information Management SystemsP · 조항 4 · 5 · 6PlanMap personal dataflows; fix…D · 조항 7 · 8 · AnnexesDoOperate collection,use, sharing and…C · 조항 9CheckVerify consent,deletion and…A · 조항 10ActRemove causes ofbreaches and…
계획 → 실행 → 점검 → 개선이 한 번으로 끝나지 않고 계속 돕니다. 심사에서 보는 것도 «이 바퀴가 실제로 도는가» 입니다.
ClauseTitleIn plain terms
4ContextIdentify the personal data you handle and the law that applies, and fix the controller / processor role.
5LeadershipTop management sets the privacy policy and appoints a privacy officer.
6PlanningAssess privacy risk from both the organisation's and the individual's perspective, and select controls.
7SupportCompetence, training, documented information and records. The privacy notice belongs here.
8OperationRun collection, use, sharing, processing and deletion as defined, and serve data subject requests for access, correction and erasure.
9Performance evaluationCheck consent, deletion and processor management; audit internally and review.
10ImprovementAfter breaches or complaints, remove the cause and revise controls and the notice.
AnnexesControls by roleOne set of controls for controllers, another for processors. You apply the set that matches your role.

※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.

Before you apply, please check

Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.

  • Is there a personal data inventory or flow map — what data, from where, held where, shared with whom, deleted when?
  • Has the controller or processor role been fixed for each activity? This determines which control set applies
  • Is the privacy notice published and does it match what actually happens?
  • Is consent obtained and recorded — when, which items, for what purpose?
  • Is personal data past its retention period actually deleted? Many organisations have the rule but never execute it
  • Are processors and third-party disclosures documented, with protection obligations in the contracts?
  • Is there a procedure and record for handling access, correction and erasure requests?
  • Is there a breach response procedure, including notification deadlines, and has it been exercised?
  • Have you carried out at least one internal audit yourselves? (required before the audit)
See the 8-step certification process →

You can apply for ISO/IEC 27701 certification here

Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.

Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317

※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.

Which audit division handles this

Audits against this standard are carried out by our 정보보안심사본부. See the organisation chart →