

The exponential growth of the collection of personal information and the increase in data processing has led to concerns about privacy. Keeping data safe is becoming a growing challenge, so organizations are required to implement appropriate controls to ensure that personal data is protected. Therefore, ISO (International Organization for Standardization) has developed the first international standard that supports organizations so that they can safely manage confidential information and can comply with legal requirements: ISO/IEC 27701.
Do you want to know the certification costs?
Fill in the online form and you will receive our response as soon as possible.
We look forward to having you among SRAC's clients!
ISO/IEC 27701 is the international standard that sets out the requirements for a privacy information management system. It was developed by ISO in response to organisations’ need to protect the personally identifiable information they collect, store and process, providing a structured framework for managing privacy risks.
A privacy information management system, known as a PIMS (Privacy Information Management System), is the set of policies, procedures and controls through which an organisation manages personal data. In practice, a PIMS extends the principles of information security to a specific area: the protection of the privacy and personal data of data subjects.
Initially, in the 2019 edition, the ISO 27701 standard functioned as an extension of ISO/IEC 27001 and ISO/IEC 27002 – which meant that an organisation had to already have an ISO 27001 information security management system in place in order to be certified. With the publication of the ISO/IEC 27701:2025 edition (October 2025), the standard has become a stand-alone management standard: it adopts the common high-level structure (clauses 4–10), aligns with ISO 9001, ISO/IEC 27001:2022 and ISO/IEC 42001, and can be implemented and certified independently. Organisations certified under the 2019 edition benefit from a three-year transition period, until October 2028.
The ISO 27701 standard is aimed at both data controllers (those who determine the purposes and means of processing) and data processors (those who process data on their behalf). It applies to organisations of any size and from any sector that collect or process personal data and wish to demonstrate, through a risk-based approach, that they comply with data protection requirements.
One of the most significant advantages of the ISO 27701 standard is the direct support it provides for compliance with the General Data Protection Regulation (GDPR). ISO 27701 provides a practical framework through which an organisation can assess, manage and mitigate the risks associated with the processing of personal data, translating legal requirements into concrete controls. ISO 27701 certification does not automatically equate to GDPR compliance, but it does provide strong evidence that the organisation has implemented appropriate technical and organisational measures – exactly what Article 32 of the GDPR requires.
Certification of a confidential information management system brings tangible benefits:
ISO 27701 certification is not, in itself, required by law. However, compliance with the GDPR is mandatory for any organisation that processes the personal data of individuals in the European Union, and ISO 27701 is one of the most effective tools an organisation can use to structure and demonstrate its compliance. Furthermore, ISO 27701 certification is increasingly sought after in contractual relationships, data processing chains and tenders, as evidence of responsible management of personal data.
The ISO 27701 certification process with SRAC follows clear stages. Once the information security management system has been implemented, the organisation undergoes a conformity assessment by SRAC’s auditors.
The cost of ISO 27701 certification is not fixed, but depends on the size of the organisation, the number of employees, the volume and complexity of data processing operations, the number of sites and the scope of the system. To find out the exact cost of ISO 27701 certification, the best option is to request a personalised quote.
The ISO 27001 certificate is valid for three years, provided that certification is maintained by successfully passing annual surveillance audits. At the end of this period, if the organisation wishes to extend the validity of the certificate, a recertification audit (certification renewal) is carried out.
Organisations certified to the ISO/IEC 27701:2019 standard have a three-year transition period (until October 2028) to migrate to the new ISO/IEC 27701:2025 standard. The transition can be incorporated into the next surveillance or recertification audit to minimise costs and effort. Organisations seeking certification for the first time may do so directly under the new edition.
Find out from the attached article HERE what the main changes are compared with the previous edition of the standard.
Author: Dr Cristian Roncea, Eng., Technical Director, SRAC CERT
SRAC enjoys international recognition through its partnership with IQNET (The International Certification Network). Certified organisations receive, at no additional cost, both the SRAC certificate and the IQNET certificate, which ensures genuine recognition of ISO 27701 certification both on the domestic market and internationally.
Join the leading companies and institutions in Romania that have chosen the SRAC brand: over 10,000 certified organisations, with more than 25,000 certificates awarded over the past 30 years. From top brands to major public institutions, leading companies have chosen our services.
Choose the leader in certification – Get certified with SRAC!








Like ISO 27001, the ISO 27701 standard is based on a risk-based approach, but tailored to personal data. The standard makes a clear distinction between the two main roles in data processing: the data controller, who determines the purposes and means of processing, and the data processor, who processes the data on behalf of the controller. For each role, ISO 27701 sets out specific controls and responsibilities, so that the organisation can demonstrate that it handles personal identifiable information responsibly, regardless of its position in the processing chain.
The requirements of ISO 27701 cover both the elements of a management system (organisational context, leadership, planning, performance evaluation and continuous improvement) and specific confidentiality controls. These include identifying the legal bases for processing, managing consent, ensuring the rights of data subjects, keeping records of processing activities and managing relationships with data processors. In the ISO/IEC 27701:2025 edition, the controls are organised in a dedicated annex, structured according to the roles of controller and processor, and aligned with ISO/IEC 27001:2022 and ISO/IEC 27002:2022.
Vrei să afli prețul pentru certificarea ISO 27701 sau alte detalii?
Request an offer and you will receive a response as soon as possible.
Courses
Are you interested in courses in the upcoming period?
Check the current month's calendar
or go to the training page.