Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
GDPR vs ISO 27701

GDPR vs ISO 27701: the law and the standard that evidences it

GDPR is the EU's data protection law; ISO 27701 is the certifiable standard for a privacy management system that maps to it. How they relate, and whether certification is worth it.

The short answer

The GDPR is a law: it binds any organization processing personal data about people in the EU, and compliance is demonstrated through documentation and safeguards, not a certificate. ISO 27701 is a standard: a privacy information management system built on ISO 27001, certified by an accredited body, whose controls map to the GDPR's obligations. You must comply with the GDPR; you may certify to ISO 27701 to prove, in a form buyers recognize, that privacy is managed systematically.

Side by side

GDPR and ISO 27701, row by row

GDPRISO 27701
What it isAn EU regulation (2016/679), applied since May 2018, mirrored in the UKAn international standard for a privacy information management system
Mandatory?Yes, for anyone in scopeNo; chosen to evidence privacy management
CertificateNo mandatory scheme (Article 42 schemes exist but are rare)Yes, from an accredited body, usually alongside ISO 27001
Who enforces or auditsSupervisory authorities, with fines up to 4% of worldwide turnoverThe certification body, on a three-year cycle
Core obligations or controlsLawful basis, rights, records of processing, DPIAs, processors, security, breach notificationController and processor control sets mapped to those obligations, on an ISMS
With ViglynArticle 32 security checked automatically; records, DPIAs and agreements as dated evidenceThe PIMS on the same evidence; Stage 1 and 2 in the platform
Straight answers

The questions that decide it

Does ISO 27701 make us GDPR compliant?

It gets you most of the way and gives you something to show for it. The standard's controls map to the GDPR articles, so a certified PIMS is strong evidence of accountability. Obligations such as a lawful basis for each processing activity still sit with you, and Viglyn tracks them as evidence alongside.

Do we need ISO 27701 at all?

Only if buyers ask for proof that privacy is managed, which European, UK and Asia-Pacific enterprises increasingly do, or if you want the discipline of a management system around GDPR work. A smaller company can be fully GDPR compliant with documentation alone.

Do we need ISO 27001 first?

In practice yes: ISO 27701 extends the ISO 27001 management system, and most certificates are issued alongside it. If you hold ISO 27001 the extension reuses most of your evidence; if not, Viglyn runs both from one evidence base.

FAQ

More questions

What does GDPR require that a standard cannot certify?
The lawful basis for each processing activity, the content of your privacy notices, how you honor data subject rights in practice, and decisions about international transfers. A standard can certify that processes exist; the regulator judges whether they are right.
Is the UK GDPR different?
The UK retained the GDPR after leaving the EU as the UK GDPR, with the same structure and obligations and the ICO as regulator. ISO 27701's mapping applies to both.
How much does ISO 27701 cost with Viglyn?
It counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners. The certification body's fee is separate and paid by you directly; we take no commission.

Find out which one you are closer to

A practitioner maps your gaps for the framework you are going for, in the order to close them, and tells you the honest timeline. Free, no account, no card.