ISO 27701 - Privacy Information Management System

What is ISO 27701?

ISO/IEC 27701 is the standard for a Privacy Information Management System (PIMS). It sets requirements for how a business manages personal data, both as a controller and as a processor. In its 2025 edition the standard became stand alone and no longer operates only as an extension of ISO/IEC 27001.

Who is ISO 27701 for?

It applies to businesses that process personal data at volume or in sensitive categories: cloud and software providers, tourism businesses, clinics and diagnostic centres, insurance intermediaries, accounting and law firms, marketing agencies, and public sector bodies.

Benefits of ISO 27701

  1. Documented compliance with the General Data Protection Regulation
  2. Clear allocation of controller and processor roles and responsibilities
  3. Reduced exposure to fines and complaints
  4. Faster response to data subject requests
  5. A stronger position in customer due diligence reviews
  6. Controlled chain of subprocessors and third party providers
  7. Credibility with large clients and public authorities
  8. Integrated management alongside ISO/IEC 27001 and ISO/IEC 42001

Certification Requirements

The ISO 27701 management system must meet the applicable legal requirements concerning the business, namely Regulation (EU) 2016/679 and Greek Law 4624/2019, as well as the requirements of the standard. A record of processing activities, a privacy risk assessment and documentation of the technical and organisational measures in place are required.