Back to Field Notes
International Standards/Field Note

ISO/IEC 27701 — Bolting Privacy onto Your ISMS

ISO 27701 is the cleanest path to a defensible global privacy program. The audit overhead is small — if you sequence it right.

Author

Diana Petrov

Director, Governance Practice

Published

January 6, 2026

Read

9 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 0127701 extends 27001 with privacy-specific controls (Annex A for controllers, Annex B for processors) and a Privacy Information Management System (PIMS) on top of an existing ISMS.
  • 02Marginal cost of adding 27701 to an existing 27001 audit is typically 15–25% of the original audit days — not 100%. Sequencing matters: 27001 first, then 27701 in the same cycle.
  • 03Organizations that try both standards in their first cycle tend to over-scope and miss both deadlines. Resist the temptation to combine them on the way up.
  • 04Regulators across the EU treat 27701 as strong evidence of GDPR Article 24 accountability even though it is not yet a Commission-approved Article 42 mechanism. For multinational programs, often the deciding factor.

ISO/IEC 27701 was published in 2019 as an extension to ISO/IEC 27001. It adds privacy-specific controls and a Privacy Information Management System (PIMS) on top of an existing ISMS, giving you a single audit that satisfies both security and privacy stakeholders.

What 27701 adds

  • 01PII controller-specific controls (Annex A) — purpose, consent, subject rights
  • 02PII processor-specific controls (Annex B) — instructions, sub-processors, transfers
  • 03PIMS-specific clauses — leadership, planning, support, operation, evaluation
  • 04Mapping table to GDPR articles, ISO 29100, and several national laws

Sequencing matters

Achieve ISO 27001 first. Then layer 27701 on top in the same audit cycle. The marginal cost of adding 27701 to an existing 27001 audit is typically 15–25% of the original audit days, not 100%.

Organizations that try to do both standards in their first certification cycle tend to over-scope and miss both deadlines.

Where 27701 wins legally

Article 42 of the GDPR explicitly contemplates approved certification mechanisms as a way to demonstrate compliance. While 27701 is not yet a Commission-approved Article 42 mechanism, regulators across the EU treat it as strong evidence of accountability under Article 24. For multinational programs, that is often the deciding factor.

#ISO 27701#Privacy#GDPR

/WRITTEN_BY

Diana Petrov

Director, Governance Practice · Alexa Cybersecurity