ISO 27701

The privacy management standard: what turns a security ISMS into certifiable privacy governance.

Universal core · ISO/IEC 27701, Privacy information management systems (PIMS)

Issued by

ISO/IEC

Region

International

Effective

First published 2019; revised edition 2025

Oversight

Certified by accredited bodies, with ISO 27001

Applies when

Any organisation managing personal data that wants certifiable privacy governance

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

ISO 27701 extends the 27001 management system into privacy: a PIMS with clauses for both controllers and processors, covering purpose, consent, data-subject rights, privacy by design and processor relationships. It is the certifiable answer to the question every privacy law asks: can you demonstrate governance?

Its practical power is as a translation layer: one PIMS, evidenced once, speaks to GDPR, the NDPA, POPIA, Kenya's DPA and the rest of the acts in the catalog, which all demand the same underlying discipline under different articles.

Where programmes are tested.

01

PIMS on an ISMS

The 27001 management system extended with privacy-specific requirements and objectives.

02

Controller obligations

Purpose, lawful basis, consent, rights handling and privacy by design, operationalised and audited.

03

Processor obligations

Instructions, sub-processor control, assistance duties and disclosure discipline.

Curated once, evidenced continuously.

  • 27701's clauses are curated and cross-mapped to the same privacy controls the African data-protection acts resolve to: one implementation, certifiable internationally, examinable locally.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

ISO 27701, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Do we need ISO 27001 before 27701?

Under the 2019 edition, yes: 27701 extends a 27001 ISMS and is certified with it. The 2025 revision restructures the standard so a PIMS can stand on its own, but in practice the two are still built and audited together, and the catalog cross-maps them as one control estate.

Does ISO 27701 make us GDPR or NDPA compliant?

No standard can, compliance is a legal conclusion, but 27701 is the strongest demonstrable evidence of privacy governance, and its annexes map to GDPR articles. Regulators and buyers treat certification as a serious signal; the legal obligations still need their own mapping, which is what the catalog's cross-walks provide.

Controller and processor: which clauses apply to us?

Whichever roles you actually play, and most organisations play both: controller for their own customers and employees, processor for the services they run for others. The PIMS scopes each role explicitly, and the audit tests them separately.

Why certify privacy governance at all?

Because privacy questionnaires now arrive with every enterprise deal and every regulator engagement. A 27701 certificate answers most of them in one line, and the same controls that earn it evidence the NDPA, POPIA and Kenyan obligations already in your stack.

Where it connects.

The full catalog
Cross-mapped with

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.