Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
ISO 27701

ISO 27701: a privacy management system on your ISO 27001 evidence

Extend the ISMS you already run into a privacy information management system: controller and processor controls mapped to automated checks and structured evidence, GDPR obligations cross-referenced, and the certification audit run where the evidence lives.

What is ISO 27701?

ISO/IEC 27701 is the international standard for a privacy information management system, a PIMS. It builds on ISO/IEC 27001 and 27002 by adding privacy-specific requirements to the management system clauses and privacy-specific guidance to the security controls, and it adds two sets of controls of its own: one for organizations that decide how and why personally identifiable information is processed, the PII controllers, and one for organizations that process it on another's behalf, the PII processors. The controller controls cover purposes, lawful basis, consent, transparency and the rights of the people whose data is held; the processor controls cover instructions from the controller, sub-processors, international transfers and breach support. The standard maps its controls to the GDPR, so a PIMS doubles as evidence of GDPR accountability. Certification follows the ISO two-stage audit model through an accredited certification body, with surveillance audits in between, and is most often held alongside an ISO 27001 certificate, since the PIMS is built on the ISMS.

In one paragraph

ISO/IEC 27701 is the international standard for a privacy information management system (PIMS). It extends the ISO 27001 information security management system with requirements and controls for protecting personally identifiable information, with separate control sets for organizations that act as PII controllers and as PII processors, and it maps its controls to the GDPR and other privacy laws. Certification is issued by an accredited certification body and is most often held together with ISO 27001.

Who it's for

Companies that already hold or are pursuing ISO 27001 and whose customers in Europe, the UK or Asia-Pacific ask for proof that privacy, not only security, is managed.

With Viglyn

How Viglyn runs ISO 27701

  • The controller and processor control sets mapped to controls in the library, with automated checks where the evidence lives in connected systems and structured evidence requests where it does not
  • Records of processing, consent and purpose records, data subject request handling and transfer mechanisms held as dated evidence with a full audit trail
  • Sub-processor management in the vendor module, with agreements, assessments and the instructions that bind them
  • Every clause and control shared with your ISO 27001 ISMS, so the privacy extension reuses the security evidence instead of duplicating it
  • Stage 1 and Stage 2 run inside Viglyn, with scoped auditor access and workpapers that export with integrity hashes
Straight answers

The ISO 27701 questions that decide it

Do we need ISO 27001 before ISO 27701?

The PIMS is built on an ISMS, so in practice ISO 27701 is implemented and audited together with ISO 27001, and most certificates are issued alongside it. If you already hold ISO 27001, the extension reuses most of your evidence; if you do not, Viglyn runs both from one evidence base.

How long does ISO 27701 take?

Two to four months on top of an existing ISO 27001 management system is typical, because the security clauses carry over. Mapping your processing activities and writing the privacy-specific records is the work; our practitioners do it with you.

How much does ISO 27701 cost with Viglyn?

ISO 27701 counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The certification body's fee is separate and paid by you directly; we take no commission.

Compared with

ISO 27701 against the standards it is weighed with

FAQ

More ISO 27701 questions

Is ISO 27701 the same as GDPR compliance?
No, but it is close. The standard maps its controls to the GDPR articles, so a certified PIMS is strong evidence of accountability under the GDPR. The regulation still has obligations the standard does not certify, such as a lawful basis for each processing activity, which Viglyn tracks as evidence alongside.
Are we a PII controller or a PII processor?
Both, usually. You are a processor for the customer data your product handles on your customers' instructions and a controller for your own employee, marketing and billing data. ISO 27701 has a control set for each role, and Viglyn maps both.
Can ISO 27701 share evidence with SOC 2?
Yes. SOC 2's privacy criteria and ISO 27701's controls overlap substantially, and both rest on the security controls you already run. One evidence base maps across both in Viglyn.

See ISO 27701 run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.