ISO 27701
Universal core · ISO/IEC 27701, Privacy information management systems (PIMS)
ISO/IEC
International
First published 2019; revised edition 2025
Certified by accredited bodies, with ISO 27001
Any organisation managing personal data that wants certifiable privacy governance
Curated, versioned & cross-mapped
The obligation, plainly.
ISO 27701 extends the 27001 management system into privacy: a PIMS with clauses for both controllers and processors, covering purpose, consent, data-subject rights, privacy by design and processor relationships. It is the certifiable answer to the question every privacy law asks: can you demonstrate governance?
Its practical power is as a translation layer: one PIMS, evidenced once, speaks to GDPR, the NDPA, POPIA, Kenya's DPA and the rest of the acts in the catalog, which all demand the same underlying discipline under different articles.
Where programmes are tested.
PIMS on an ISMS
The 27001 management system extended with privacy-specific requirements and objectives.
Controller obligations
Purpose, lawful basis, consent, rights handling and privacy by design, operationalised and audited.
Processor obligations
Instructions, sub-processor control, assistance duties and disclosure discipline.
Curated once, evidenced continuously.
- 27701's clauses are curated and cross-mapped to the same privacy controls the African data-protection acts resolve to: one implementation, certifiable internationally, examinable locally.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
ISO 27701, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Do we need ISO 27001 before 27701?
Under the 2019 edition, yes: 27701 extends a 27001 ISMS and is certified with it. The 2025 revision restructures the standard so a PIMS can stand on its own, but in practice the two are still built and audited together, and the catalog cross-maps them as one control estate.
Does ISO 27701 make us GDPR or NDPA compliant?
No standard can, compliance is a legal conclusion, but 27701 is the strongest demonstrable evidence of privacy governance, and its annexes map to GDPR articles. Regulators and buyers treat certification as a serious signal; the legal obligations still need their own mapping, which is what the catalog's cross-walks provide.
Controller and processor: which clauses apply to us?
Whichever roles you actually play, and most organisations play both: controller for their own customers and employees, processor for the services they run for others. The PIMS scopes each role explicitly, and the audit tests them separately.
Why certify privacy governance at all?
Because privacy questionnaires now arrive with every enterprise deal and every regulator engagement. A 27701 certificate answers most of them in one line, and the same controls that earn it evidence the NDPA, POPIA and Kenyan obligations already in your stack.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.