SRAC Logo
hero-certificate
iso icon

ISO 27701 Certification - Privacy information management system

The exponential growth of the collection of personal information and the increase in data processing has led to concerns about privacy. Keeping data safe is becoming a growing challenge, so organizations are required to implement appropriate controls to ensure that personal data is protected. Therefore, ISO (International Organization for Standardization) has developed the first international standard that supports organizations so that they can safely manage confidential information and can comply with legal requirements: ISO/IEC 27701.

Inquiry Form

Do you want to know the certification costs?

Fill in the online form and you will receive our response as soon as possible.

We look forward to having you among SRAC's clients!

Choose
Choose
* required fields

You will receive a response as soon as possible.

 

What does ISO/IEC 27701 mean?

ISO/IEC 27701 is the international standard that sets out the requirements for a privacy information management system. It was developed by ISO in response to organisations’ need to protect the personally identifiable information they collect, store and process, providing a structured framework for managing privacy risks.

 

What is a Privacy Information Management System (PIMS)?

A privacy information management system, known as a PIMS (Privacy Information Management System), is the set of policies, procedures and controls through which an organisation manages personal data. In practice, a PIMS extends the principles of information security to a specific area: the protection of the privacy and personal data of data subjects.

 

From an extension of ISO 27001 to a stand-alone standard

Initially, in the 2019 edition, the ISO 27701 standard functioned as an extension of ISO/IEC 27001 and ISO/IEC 27002 – which meant that an organisation had to already have an ISO 27001 information security management system in place in order to be certified. With the publication of the ISO/IEC 27701:2025 edition (October 2025), the standard has become a stand-alone management standard: it adopts the common high-level structure (clauses 4–10), aligns with ISO 9001, ISO/IEC 27001:2022 and ISO/IEC 42001, and can be implemented and certified independently. Organisations certified under the 2019 edition benefit from a three-year transition period, until October 2028.

 

Who is the ISO 27701 standard aimed at?

The ISO 27701 standard is aimed at both data controllers (those who determine the purposes and means of processing) and data processors (those who process data on their behalf). It applies to organisations of any size and from any sector that collect or process personal data and wish to demonstrate, through a risk-based approach, that they comply with data protection requirements.

 

ISO 27701 and GDPR compliance

One of the most significant advantages of the ISO 27701 standard is the direct support it provides for compliance with the General Data Protection Regulation (GDPR). ISO 27701 provides a practical framework through which an organisation can assess, manage and mitigate the risks associated with the processing of personal data, translating legal requirements into concrete controls. ISO 27701 certification does not automatically equate to GDPR compliance, but it does provide strong evidence that the organisation has implemented appropriate technical and organisational measures – exactly what Article 32 of the GDPR requires.

 

The benefits of ISO 27701 certification

Certification of a confidential information management system brings tangible benefits:

  • provides confidence and a competitive advantage by protecting the personal information of customers and consumers;
  • demonstrates and supports efforts to comply with privacy laws and regulations, including the GDPR;
  • identifies and mitigates risks by implementing rigorous confidentiality controls;
  • demonstrates a genuine commitment to the continuous improvement of the privacy management system;
  • strengthens relationships with partners and customers who process or transfer personal data;
  • facilitates integration with other management systems, such as ISO 27001 (information security) or ISO 9001 (quality management).

 

Is ISO 27701 certification compulsory?

ISO 27701 certification is not, in itself, required by law. However, compliance with the GDPR is mandatory for any organisation that processes the personal data of individuals in the European Union, and ISO 27701 is one of the most effective tools an organisation can use to structure and demonstrate its compliance. Furthermore, ISO 27701 certification is increasingly sought after in contractual relationships, data processing chains and tenders, as evidence of responsible management of personal data.

 

How do you obtain ISO 27701 certification?

The ISO 27701 certification process with SRAC follows clear stages. Once the information security management system has been implemented, the organisation undergoes a conformity assessment by SRAC’s auditors.

 

The stages and the certification audit

  1. Submission of the request for quotation and finalisation of the contractual details.
  2. The ISO 27701 certification audit comprises the following stages:
    1. review of the management system documentation (including the Statement of Applicability).
    2. Stage 1, in which the specific conditions at the client’s site are assessed; analysis of the stage of implementation of the applicant’s management system and their understanding of the standard’s requirements; assessment of the level of implementation of the PIMS, etc.
    3. Stage 2, in which a practical check is carried out within the company to verify whether the written procedures are actually applied in day-to-day operations.
  3. Addressing any non-conformities and implementing corrective actions.
  4. Issuance of the ISO 27701 certificate, valid for 3 years, subject to annual surveillance audits being carried out.
  5. The recertification audit (certification renewal), to extend the validity of the certificate for a further three-year period.

 

The cost of ISO 27701 certification

The cost of ISO 27701 certification is not fixed, but depends on the size of the organisation, the number of employees, the volume and complexity of data processing operations, the number of sites and the scope of the system. To find out the exact cost of ISO 27701 certification, the best option is to request a personalised quote.

 

Validity and renewal of the certificate

The ISO 27001 certificate is valid for three years, provided that certification is maintained by successfully passing annual surveillance audits. At the end of this period, if the organisation wishes to extend the validity of the certificate, a recertification audit (certification renewal) is carried out.

 

The transition to ISO/IEC 27701:2025

Organisations certified to the ISO/IEC 27701:2019 standard have a three-year transition period (until October 2028) to migrate to the new ISO/IEC 27701:2025 standard. The transition can be incorporated into the next surveillance or recertification audit to minimise costs and effort. Organisations seeking certification for the first time may do so directly under the new edition.

Find out from the attached article HERE what the main changes are compared with the previous edition of the standard.

Author: Dr Cristian Roncea, Eng., Technical Director, SRAC CERT

 

Why SRAC – IQNET international recognition

SRAC enjoys international recognition through its partnership with IQNET (The International Certification Network). Certified organisations receive, at no additional cost, both the SRAC certificate and the IQNET certificate, which ensures genuine recognition of ISO 27701 certification both on the domestic market and internationally.

Join the leading companies and institutions in Romania that have chosen the SRAC brand: over 10,000 certified organisations, with more than 25,000 certificates awarded over the past 30 years. From top brands to major public institutions, leading companies have chosen our services.

Choose the leader in certification – Get certified with SRAC!

Portfolio

British School logo
British School
CONTENTSPEED logo
CONTENTSPEED
DRIFT DATA SYSTEMS logo
DRIFT DATA SYSTEMS
EDUS PLATFORM logo
EDUS PLATFORM
EUROPAYMENT SERVICES logo
EUROPAYMENT SERVICES
PAYTEN PAYMENT SOLUTIONS logo
PAYTEN PAYMENT SOLUTIONS
WHITE IMAGE LOYALTY logo
WHITE IMAGE LOYALTY
WIZROM SOFTWARE logo
WIZROM SOFTWARE

 

The principles and roles set out in ISO 27701

Like ISO 27001, the ISO 27701 standard is based on a risk-based approach, but tailored to personal data. The standard makes a clear distinction between the two main roles in data processing: the data controller, who determines the purposes and means of processing, and the data processor, who processes the data on behalf of the controller. For each role, ISO 27701 sets out specific controls and responsibilities, so that the organisation can demonstrate that it handles personal identifiable information responsibly, regardless of its position in the processing chain.

 

The requirements of the ISO 27701 standard

The requirements of ISO 27701 cover both the elements of a management system (organisational context, leadership, planning, performance evaluation and continuous improvement) and specific confidentiality controls. These include identifying the legal bases for processing, managing consent, ensuring the rights of data subjects, keeping records of processing activities and managing relationships with data processors. In the ISO/IEC 27701:2025 edition, the controls are organised in a dedicated annex, structured according to the roles of controller and processor, and aligned with ISO/IEC 27001:2022 and ISO/IEC 27002:2022.

 

Frequently Asked Questions (FAQ)

What is ISO 27701 and what is it used for?
What is the difference between ISO 27001 and ISO 27701?
Is ISO 27001 still required in order to obtain ISO 27701?
How does ISO 27701 help ensure compliance with the GDPR?
How much does ISO 27701 certification cost?
How long is the ISO 27701 certificate valid for?
What has changed in ISO/IEC 27701:2025?
Who is ISO 27701 certification aimed at?
What do I need to do to get started?

Vrei să afli prețul pentru certificarea ISO 27701 sau alte detalii?

Request an offer and you will receive a response as soon as possible.

Courses

Are you interested in courses in the upcoming period?

Check the current month's calendar

or go to the training page.