Skip to main content

For six years, ISO 27701 came with an asterisk. It was a genuinely useful privacy framework, closely aligned to GDPR, well regarded by regulators and customers alike, but you could only get certified to it if you already had, or were simultaneously pursuing, ISO 27001. A processor-only business with no interest in a full information security management system had no clean path to 27701 certification on its own terms. That asterisk is gone. ISO/IEC 27701:2025, published on 14 October 2025, makes the Privacy Information Management System a standalone, independently certifiable standard for the first time.

That’s the headline. The practical question for anyone already running a 27701:2019 PIMS is narrower: what specifically changed, what’s the actual deadline, and what does the migration work look like. This piece answers all three.

Key takeaways

  • ISO/IEC 27701:2025 restructures the standard around its own Clauses 4 to 10, following the ISO Harmonised Structure, rather than being layered on top of ISO 27001 and ISO 27002 as an extension.
  • Annex A has been rebuilt into three tables totalling 78 controls: 31 for PII controllers (Table A.1), 18 for PII processors (Table A.2), and 29 shared security controls (Table A.3), replacing the 2019 edition’s 90-plus embedded subclauses.
  • The standard is now standalone certifiable. ISO 27001 certification is no longer a prerequisite, though the two still integrate well if you hold both. A companion standard, ISO/IEC 27706:2025, gives certification bodies the accreditation basis to audit PIMS implementations on their own.
  • Existing ISO 27701:2019 certificates remain valid until 1 October 2028, a standard three-year transition window, but your certification body’s own accreditation deadline will typically land in 2026 or 2027, earlier than the client-facing cut-off.
  • The core privacy content, RoPA obligations, consent, data subject rights, breach notification, carries forward largely unchanged. Migration is mostly a documentation and scoping exercise, not a rebuild of the underlying programme.

What actually changed

Standalone structure. The single biggest change is architectural. ISO/IEC 27701:2019 had no clauses of its own for context, leadership, planning, or performance evaluation; it pointed back to ISO 27001’s for all of that, adding privacy-specific requirements on top. ISO/IEC 27701:2025 has its own complete set of Clauses 4 to 10, written to the same Harmonised Structure every current-generation ISO management system standard shares (the same structure behind ISO 27001, ISO 22301, and ISO 42001). That’s what makes standalone certification possible: the standard no longer needs to borrow another standard’s management system scaffolding to function.

A rebuilt Annex A. The 2019 edition’s approach was to take ISO 27002’s security controls and layer more than 90 PII-specific subclauses across several dense clauses. The 2025 edition replaces that with three clearly separated control tables: Table A.1 for PII controller obligations (31 controls), Table A.2 for PII processor obligations (18 controls), and Table A.3 for shared security controls common to both roles (29 controls), for 78 controls in total. If your organisation is purely a processor, or purely a controller, for a given scope, the applicable control set is now much easier to isolate than it was under the old embedded structure.

New and updated mapping annexes. Annex D’s mapping to GDPR has been refreshed. New annexes map the standard to ISO/IEC 29100 (the general privacy framework) and to ISO/IEC 27018 and 27551, and a correspondence annex maps every 2025 clause and control back to its nearest 2019 equivalent, which is the single most useful document you’ll use during a gap analysis.

A new accreditation standard. ISO/IEC 27706:2025, published the same day, sets out the requirements certification bodies must meet to audit and certify PIMS implementations under 27701, alongside their existing ISO/IEC 17021-1 obligations. Its existence is what turns “standalone certification is now possible” from a statement in the standard’s scope section into something your certification body can actually deliver.

Why standalone status matters in practice

Under the 2019 edition, a data processor with no meaningful information security scope beyond basic IT hygiene, a payroll bureau, a market research firm, a niche SaaS tool handling a narrow dataset, faced an awkward choice: build a full ISMS it didn’t otherwise need just to unlock 27701 certification, or skip formal certification and rely on contractual assurances and questionnaires instead. The 2025 edition removes that trade-off. A PIMS can now be scoped and certified on its own terms, sized to the organisation’s actual privacy footprint rather than inherited from an information security scope built for a different purpose.

For organisations that already hold both certifications, little changes in day-to-day terms. ISO 27001 and ISO 27701 still integrate cleanly, the shared Harmonised Structure guarantees that, and running them as an integrated management system remains the more efficient path if your organisation genuinely needs both. What’s changed is that this is now a choice rather than a mandatory dependency.

The migration path for existing 27701:2019 holders

Get the dates right first. ISO/IEC 27701:2025 was published 14 October 2025, which starts a standard three-year transition period. The client-facing deadline, the date after which a 27701:2019 certificate is no longer valid regardless of when it was issued or renewed, is 1 October 2028. That is not, however, the date to plan around. Certification bodies are themselves on a tighter clock set by their national accreditation body, commonly landing sometime across 2026 and into 2027, after which they must be auditing exclusively to the 2025 edition. Ask your certification body directly for their own transition date rather than assuming the 2028 deadline applies to when you need to act.

Run the gap analysis against the correspondence annex. The standard’s own correspondence annex, mapping 2025 clauses and controls back to their 2019 equivalents, is the fastest route through this. Use it to re-map your existing Statement of Applicability from the old Annex A and B references to the new Table A.1, A.2, and A.3 numbering, flagging anywhere a 2019 control has been split, merged, or newly introduced (particularly around the sharper controller/processor separation) rather than simply renumbered.

Reconsider your scope, not just your documentation. Because the PIMS no longer has to sit inside your ISMS boundary, this is a natural point to ask whether your current scope still makes sense, whether it should now cover privacy activities that sit outside your existing information security scope, or whether it’s still the right fit as-is. Most organisations that already hold both certifications will keep the scopes aligned; it’s worth confirming that deliberately rather than by default.

Update the paperwork, then audit against it. Scope statements, policies, and the SoA all need to cite ISO/IEC 27701:2025 rather than the 2019 edition, and internal procedures should reflect the new Clause 4 to 10 structure. Run an internal audit against the updated system before your transition or recertification visit; certification bodies are, reasonably, going to expect evidence the organisation has actually operated against the new requirements, not just relabelled documents.

Time it with your existing audit cycle where you can. A transition review can run as a standalone assessment or be folded into your next scheduled surveillance or recertification audit, right up until the transition deadline closes. For most organisations already on an annual audit cycle, bundling the transition into the next scheduled visit is the more efficient route, provided it happens comfortably before your certification body’s own accreditation cut-off.

What doesn’t need to change

It’s worth being explicit about what the 2025 edition does not disturb, because the structural changes can make the revision sound bigger than it is at the operational level. The substance of privacy control requirements, how you handle consent, data subject rights, breach notification, and processing records, carries forward with clearer role separation, not a rewrite. A Records of Processing Activities register that was thorough enough for a 2019-edition audit, in line with the gaps we’ve covered in common Article 30 failures, remains thorough enough now. For what an auditor actually tests on the day, our walk-through of a 27701 Stage 1 audit covers the RoPA scrutiny and controller/processor classification testing that carry over largely unchanged to the 2025 edition. The migration work is concentrated almost entirely in structure, scope, and documentation, not in re-doing the underlying privacy programme.

Practical questions to ask now

  • Has your certification body confirmed their own accreditation transition date, and does your next audit fall before or after it?
  • Have you mapped your current Statement of Applicability to the new Annex A.1, A.2, and A.3 structure using the standard’s correspondence annex?
  • Does your PIMS scope still make sense now that it doesn’t have to match your ISMS boundary, or should it be reconsidered?
  • If you don’t currently hold ISO 27001 and previously ruled out 27701 certification because of the prerequisite, is that decision worth revisiting now?
  • Have policies, scope statements, and internal audit procedures been updated to reference ISO/IEC 27701:2025, or do they still cite the 2019 edition?

Closing

Most standard revisions tidy up wording and renumber a few clauses. This one removes a structural dependency that shaped who could realistically pursue 27701 certification at all. For organisations already running an integrated ISMS and PIMS, the migration is a bounded documentation and gap-analysis exercise with a clear three-year runway. For organisations that previously ruled out 27701 because ISO 27001 wasn’t otherwise on their roadmap, it’s worth a second look now that the dependency is gone.

If you’d like help running a gap analysis against the 2025 edition, or scoping a standalone PIMS from scratch, get in touch. Our ISO 27701 and GDPR & Privacy services both cover this ground.

Common questions

What actually changed between ISO/IEC 27701:2019 and ISO/IEC 27701:2025?
The headline change is structural: the 2019 edition was an extension bolted onto ISO 27001, with over 90 subclauses layered on top of ISO 27002 controls. The 2025 edition is a standalone management system standard with its own Clauses 4 to 10 following the ISO Harmonised Structure, and a restructured Annex A of 78 controls across three tables: 31 for PII controllers, 18 for PII processors, and 29 shared security controls. New annexes map the standard to ISO 29100, ISO 27018/27551, and GDPR, and a correspondence annex maps every 2025 requirement back to its 2019 equivalent.
Can I get certified to ISO 27701 on its own now, without ISO 27001?
Yes. That's the single biggest change in the 2025 edition. Under 2019, 27701 certification required a corresponding ISO 27001 scope, either already certified or certified alongside it. Under 2025, ISO/IEC 27701 is a standalone certifiable standard in its own right. It still integrates cleanly with an existing ISMS if you have one, but it's no longer a prerequisite. A companion standard, ISO/IEC 27706:2025, was published the same day to give certification bodies the accreditation basis to audit PIMS implementations independently.
What is the actual deadline to transition from ISO 27701:2019 to ISO 27701:2025?
ISO/IEC 27701:2025 was published on 14 October 2025, starting a three-year transition period. Existing ISO 27701:2019 certificates remain valid until 1 October 2028, provided your certification body still recognises them, but they become invalid after that date regardless of when they were last renewed. Your certification body's own deadline for completing its accreditation transition sits earlier than that, typically some time in 2026 or 2027 depending on which national accreditation body oversees them, so check with them directly rather than assuming you have until 2028 to start.
What does a gap analysis need to cover when migrating an existing PIMS?
Four things in practice: mapping your current Statement of Applicability from the old Annex A and B control references to the new Annex A.1, A.2, and A.3 table numbering, using the standard's own correspondence annex as a crosswalk; deciding whether your PIMS scope should now extend beyond your existing ISMS boundary now that it can stand alone; updating scope statements, policies, and the SoA to cite the 2025 edition; and running an internal audit against the new Clauses 4 to 10 before your transition or recertification audit.
Does my existing GDPR Records of Processing Activities need to change for the 2025 edition?
No, not substantively. The control content covering processing records, consent, data subject rights, and breach notification is carried forward with updated numbering and clearer controller and processor separation, not rewritten from scratch. A well-maintained Article 30 RoPA that satisfied ISO 27701:2019 will still satisfy the 2025 edition. The work is almost entirely in re-mapping documentation and scope, not re-doing the underlying privacy programme.

Ready to discuss your requirements?

Let's have a conversation about how we can help your organisation.

Let's talk