Certify How You Handle Personal Data
ISO 27701 Privacy Information Management Certification
ISO 27701 is the certifiable standard for managing personal data as a controller or a processor. Since the 2025 edition it stands on its own, so you can certify privacy management with or without ISO 27001.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
ISO/IEC 27701 specifies a privacy information management system, or PIMS, for organisations that handle personal data as a controller, a processor or both. The 2025 edition, published in October 2025, turned it from an extension of ISO 27001 into a standalone management system standard, so certification no longer depends on holding ISO 27001. Its Annex A sets out controls for controllers, for processors and for both, restructured to align with ISO/IEC 27002:2022. It matters because customers increasingly ask how you protect personal data, and because its controls map closely to the DPDP Act and GDPR. We help Indian SaaS, IT services and data-heavy businesses build a PIMS that stands alone or integrates with an existing ISMS, working remotely across India from our Greater Noida and Kanpur offices.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the ISO 27701 engagement, 6 phases in order, each one selectable. Phase 1, PIMS Scoping and Role Mapping. We confirm where you act as a controller and where as a processor, then set the scope of your privacy management system. Activities: Inventory processing activities across the business; Classify each activity as controller or processor; Align the PIMS scope with any existing ISMS scope; Identify applicable privacy laws and contracts. Hands over PIMS Scope Statement and Role Map. Phase 2, Privacy Gap Assessment. We measure your current practices against the ISO 27701 controls and the privacy laws you must meet. You see exactly what is missing. Activities: Assess practices against the clause 4 to 10 requirements; Test the Annex A controller, processor and shared controls; Check alignment with the DPDP Act and GDPR duties; Rank privacy gaps by legal exposure and effort. Hands over Privacy Gap Assessment Report. Phase 3, Privacy Control Design. We design controls for consent, data subject rights, retention, and processor agreements, integrated with any ISMS you already run. Activities: Draft consent and purpose limitation controls; Design the data subject rights handling process; Set retention and deletion schedules; Update processor and sub-processor agreements. Hands over PIMS Control Set and Policy Updates. Phase 4, Implementation and Records. We help you build records of processing and embed privacy into day-to-day operations. Evidence starts flowing as the controls go live. Activities: Build records of processing activities; Embed privacy checks into change and onboarding flows; Train teams on the new privacy procedures; Start collecting evidence in the compliance platform. Hands over Records of Processing Activities and Evidence Trail. Phase 5, Internal Audit. We audit the PIMS against the standard and your legal obligations, then log and prioritise any findings. Activities: Plan the PIMS internal audit alongside the ISMS audit; Sample data subject requests and consent records; Log nonconformities against ISO 27701 controls; Agree corrective actions with control owners. Hands over PIMS Internal Audit Report. Phase 6, Certification Support. We stand with you through the certification audit, run on its own or combined with your ISO 27001 audit. Activities: Prepare the evidence pack for the certification body; Coordinate a combined audit where you also hold ISO 27001; Support interviews with privacy control owners; Close findings raised during the audit. Hands over ISO 27701 Certificate. Each phase begins from the artefact the phase before it produced.
Phase 01 PIMS Scoping and Role Mapping
We confirm where you act as a controller and where as a processor, then set the scope of your privacy management system.
What Happens In This Phase
- Inventory processing activities across the business
- Classify each activity as controller or processor
- Align the PIMS scope with any existing ISMS scope
- Identify applicable privacy laws and contracts
The Handover
PIMS Scope Statement and Role Map
The next phase starts from this.
Phase 01 PIMS Scoping and Role Mapping
We confirm where you act as a controller and where as a processor, then set the scope of your privacy management system.
What Happens In This Phase
- Inventory processing activities across the business
- Classify each activity as controller or processor
- Align the PIMS scope with any existing ISMS scope
- Identify applicable privacy laws and contracts
The Handover
PIMS Scope Statement and Role Map
The next phase starts from this.
- 01
PIMS Scoping and Role Mapping
We confirm where you act as a controller and where as a processor, then set the scope of your privacy management system.
OutputPIMS Scope Statement and Role MapActivities
- Inventory processing activities across the business
- Classify each activity as controller or processor
- Align the PIMS scope with any existing ISMS scope
- Identify applicable privacy laws and contracts
- 02
Privacy Gap Assessment
We measure your current practices against the ISO 27701 controls and the privacy laws you must meet. You see exactly what is missing.
OutputPrivacy Gap Assessment ReportActivities
- Assess practices against the clause 4 to 10 requirements
- Test the Annex A controller, processor and shared controls
- Check alignment with the DPDP Act and GDPR duties
- Rank privacy gaps by legal exposure and effort
- 03
Privacy Control Design
We design controls for consent, data subject rights, retention, and processor agreements, integrated with any ISMS you already run.
OutputPIMS Control Set and Policy UpdatesActivities
- Draft consent and purpose limitation controls
- Design the data subject rights handling process
- Set retention and deletion schedules
- Update processor and sub-processor agreements
- 04
Implementation and Records
We help you build records of processing and embed privacy into day-to-day operations. Evidence starts flowing as the controls go live.
OutputRecords of Processing Activities and Evidence TrailActivities
- Build records of processing activities
- Embed privacy checks into change and onboarding flows
- Train teams on the new privacy procedures
- Start collecting evidence in the compliance platform
- 05
Internal Audit
We audit the PIMS against the standard and your legal obligations, then log and prioritise any findings.
OutputPIMS Internal Audit ReportActivities
- Plan the PIMS internal audit alongside the ISMS audit
- Sample data subject requests and consent records
- Log nonconformities against ISO 27701 controls
- Agree corrective actions with control owners
- 06
Certification Support
We stand with you through the certification audit, run on its own or combined with your ISO 27001 audit.
OutputISO 27701 CertificateActivities
- Prepare the evidence pack for the certification body
- Coordinate a combined audit where you also hold ISO 27001
- Support interviews with privacy control owners
- Close findings raised during the audit
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
What Is Examined, and What it Is Measured Against
Map
Map of the ISO 27701 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: OneTrust, Vanta, Sprinto, Scrut, Microsoft Purview, Jira, Confluence, TrustArc. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO/IEC 27701:2025, ISO/IEC 27001:2022, Digital Personal Data Protection Act 2023, GDPR, NIST Privacy Framework.
What We Run
8 tools
- OneTrust
- Vanta
- Sprinto
- Scrut
- Microsoft Purview
- Jira
- Confluence
- TrustArc
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- ISO/IEC 27701:2025
- ISO/IEC 27001:2022
- Digital Personal Data Protection Act 2023
- GDPR
- NIST Privacy Framework
Deliverables
What You Receive
- Privacy gap assessment report
- Records of processing activities
- PIMS policy set
- Controller and processor control mapping
- Certification audit support
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Do we still need ISO 27001 before ISO 27701?
No, not since the 2025 edition. ISO/IEC 27701:2019 was an extension of ISO 27001, so certification required an information security management system underneath it. ISO/IEC 27701:2025, published in October 2025, is a standalone management system standard with its own clauses and its own Annex A controls, so you can implement and certify a privacy information management system without holding ISO 27001. Many organisations will still run both, because a privacy programme depends on security controls such as access management, logging and incident response, and one integrated system avoids duplicated policies and audits. The decision is commercial: if your customers ask for ISO 27001 as well, build both on one set of controls; if they ask only how you handle personal data, ISO 27701 alone is now a legitimate answer. We scope both options before you commit.
We hold an ISO 27701:2019 certificate. What happens now?
Your certificate stays valid for now, but it will need to move to the 2025 edition within a transition period. Transition arrangements for revised standards are set by the International Accreditation Forum and applied by your certification body, and for most revisions the transition runs for up to three years; because the 2025 edition changed ISO 27701 into a standalone standard, confirm the exact deadline and audit approach with your certification body rather than assuming it. The practical work is a gap assessment against the new clauses and the restructured Annex A, updating your statement of applicability and control mapping, and refreshing records and policies that referred to the 2019 structure. For most organisations with a working programme the gaps are modest. We run that transition assessment and plan the update so it lands in a routine surveillance or recertification audit.
Does ISO 27701 make us compliant with the DPDP Act?
It gets you a long way, but it does not replace the law. ISO 27701's controls for consent, notice, purpose limitation, data subject rights, retention, processors and breach handling map closely to the duties the DPDP Act places on Data Fiduciaries, and a certified PIMS is strong evidence that you manage personal data systematically. The Act, however, has requirements a management system standard cannot know about, such as its specific notice content, consent manager arrangements, children's data rules, Significant Data Fiduciary duties and the breach intimation procedure in the DPDP Rules, 2025, most of which apply from 13 May 2027. We map each ISO 27701 control to the corresponding DPDP Act and Rules obligation during the gap assessment, close the legal gaps on top, and build one set of records that serves both the certification audit and your DPDP Act compliance.
How do the controller and processor controls differ?
A controller decides why and how personal data is processed; a processor handles it on a controller's instructions. ISO/IEC 27701:2025 reflects that split in Annex A, which contains 34 controls for controllers, 21 for processors and 31 that apply to both, restructured to align with ISO/IEC 27002:2022. Controller controls cover areas such as identifying the lawful basis, consent, notices, data subject rights and privacy by design. Processor controls cover acting only on instructions, assisting the controller with rights requests, sub-processor management and returning or deleting data at the end of a contract. Many businesses are both: a SaaS company is typically a controller for its own customer and employee data and a processor for the data its customers put into the platform. We map every processing activity to its role during scoping so the right controls apply.
Should we do ISO 27701 and ISO 27001 together?
If your customers ask for both, yes, on one set of controls. The standards share a management system structure, clauses four to ten, so risk assessment, internal audit, management review and corrective action can run once for both, and security controls such as access control, logging and incident response serve as evidence for each. Certification bodies commonly audit the two together, which reduces audit days compared with separate audits. If you already hold ISO 27001, adding ISO 27701 is mainly the privacy controls, records of processing and rights handling on top of what exists. If you hold neither and customers only ask about personal data, the 2025 edition lets you start with ISO 27701 alone and add ISO 27001 later. We recommend the order during scoping based on the contracts and questionnaires you are actually receiving, not on what sounds most complete.
How long does ISO 27701 certification take?
For a first certificate, usually four to six months, and our phases add up to that. Scoping and role mapping takes one to two weeks, the privacy gap assessment two to three, control design three to four, implementation and records of processing four to eight, and the internal audit one to two, before the certification body's audit. An organisation that already runs ISO 27001 moves faster, because the management system, risk process and many security controls exist. What stretches the timeline is usually the records of processing: finding every place personal data is collected, stored and shared, including spreadsheets, exports and third-party tools nobody listed. The certification body's availability also matters, so book the audit window early. We commit to a date after the gap assessment, once the size of the records and remediation work is clear.
What does ISO 27701 support cost?
We do not publish a figure for ISO 27701, because the work varies too much between organisations for a range to be useful. The quote depends on the number of processing activities and data flows in scope, whether you act as a controller, a processor or both, how many sites and business units are covered, whether ISO 27001 already exists or is being built at the same time, and how much of the records of processing and rights handling already works. Two costs sit outside our fee: the accredited certification body's audit fee, which you contract directly, and your own team's time building records and running the new procedures. Combining ISO 27701 with an existing or parallel ISO 27001 programme usually lowers the total, because the management system is shared. We scope first, then give you a fixed price in writing for the work.
Who issues the ISO 27701 certificate?
An accredited certification body issues it after a certification audit of your privacy information management system, and it must stay independent of whoever built that system. SecureRoot is not a certification body and does not issue certificates; a consultant offering to build your PIMS and then certify it would be auditing its own work. What we do is everything before and around the audit: scoping, the privacy gap assessment, control design, records of processing, training, the internal audit, and support through the certification body's audit, including preparing control owners for interviews and closing any findings. We also help you choose a certification body accredited for ISO 27701 and, where you hold ISO 27001, one that can audit both together. The certificate carries the certification body's name; the clean result comes from the preparation that goes before it.
Keep Moving Through Compliance
Service 2 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.