GDPR vs ISO 27701: the law and the standard that evidences it
GDPR is the EU's data protection law; ISO 27701 is the certifiable standard for a privacy management system that maps to it. How they relate, and whether certification is worth it.
The short answer
The GDPR is a law: it binds any organization processing personal data about people in the EU, and compliance is demonstrated through documentation and safeguards, not a certificate. ISO 27701 is a standard: a privacy information management system built on ISO 27001, certified by an accredited body, whose controls map to the GDPR's obligations. You must comply with the GDPR; you may certify to ISO 27701 to prove, in a form buyers recognize, that privacy is managed systematically.
GDPR and ISO 27701, row by row
| GDPR | ISO 27701 | |
|---|---|---|
| What it is | An EU regulation (2016/679), applied since May 2018, mirrored in the UK | An international standard for a privacy information management system |
| Mandatory? | Yes, for anyone in scope | No; chosen to evidence privacy management |
| Certificate | No mandatory scheme (Article 42 schemes exist but are rare) | Yes, from an accredited body, usually alongside ISO 27001 |
| Who enforces or audits | Supervisory authorities, with fines up to 4% of worldwide turnover | The certification body, on a three-year cycle |
| Core obligations or controls | Lawful basis, rights, records of processing, DPIAs, processors, security, breach notification | Controller and processor control sets mapped to those obligations, on an ISMS |
| With Viglyn | Article 32 security checked automatically; records, DPIAs and agreements as dated evidence | The PIMS on the same evidence; Stage 1 and 2 in the platform |
The questions that decide it
Does ISO 27701 make us GDPR compliant?
It gets you most of the way and gives you something to show for it. The standard's controls map to the GDPR articles, so a certified PIMS is strong evidence of accountability. Obligations such as a lawful basis for each processing activity still sit with you, and Viglyn tracks them as evidence alongside.
Do we need ISO 27701 at all?
Only if buyers ask for proof that privacy is managed, which European, UK and Asia-Pacific enterprises increasingly do, or if you want the discipline of a management system around GDPR work. A smaller company can be fully GDPR compliant with documentation alone.
Do we need ISO 27001 first?
In practice yes: ISO 27701 extends the ISO 27001 management system, and most certificates are issued alongside it. If you hold ISO 27001 the extension reuses most of your evidence; if not, Viglyn runs both from one evidence base.
More questions
What does GDPR require that a standard cannot certify?
Is the UK GDPR different?
How much does ISO 27701 cost with Viglyn?
Standards buyers weigh against each other
Find out which one you are closer to
A practitioner maps your gaps for the framework you are going for, in the order to close them, and tells you the honest timeline. Free, no account, no card.
