ISO/IEC 27701:2025
Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance
Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 64
- Дата публикации:
- 14 октября 2025 г.
- Издание:
- ISO/IEC IS 27701 edition 2 version 1
- ICS:
- 35.030
This document specifies requirements for establishing, implementing, maintaining and continually improving a privacy information management system (PIMS). Guidance is also provided to assist in the implementation of the requirements in this document. This document is intended for personally identifiable information (PII) controllers and PII processors holding responsibility and accountability for PII processing. This document is applicable to all types and sizes of organizations, including public and private companies, government entities and not-for-profit organizations.
Abstract
Overview
ISO/IEC 27701:2025 is the international standard for a Privacy Information Management System (PIMS). It specifies requirements for establishing, implementing, maintaining and continually improving a PIMS and provides implementation guidance. Intended for organizations that process personally identifiable information (PII), the standard helps demonstrate accountability and consistent privacy management across public and private sectors, government entities and not‑for‑profits.
Key topics and requirements
ISO/IEC 27701:2025 follows the ISO management‑system structure and covers practical privacy controls and processes. Major areas include:
- Scope and context: defining the PIMS boundary and understanding interested parties and legal requirements.
- Leadership and governance: top‑management commitment, privacy policy, and clear roles and responsibilities.
- Planning: identification of risks and opportunities, privacy risk assessment and risk treatment, and setting privacy objectives.
- Support and resources: competence, awareness, communications and documented information management.
- Operation: operational planning and control for PII processing, including controls for PII controllers and PII processors.
- Performance evaluation: monitoring, measurement, internal audit and management review.
- Improvement: continual improvement, nonconformity handling and corrective actions.
- Annexes: normative control objectives and controls for PII controllers/processors (Annex A), implementation guidance (Annex B), and mappings to ISO/IEC 29100, GDPR, ISO/IEC 27018 and ISO/IEC 29151.
Keywords: privacy information management system, PIMS, PII, privacy risk assessment, privacy controls, data protection, ISO/IEC 27701:2025.
Practical applications
ISO/IEC 27701:2025 is used to:
- Build or extend an ISO/IEC 27001 information security management system with privacy-specific controls.
- Demonstrate legal and contractual compliance for organizations acting as PII controllers or PII processors.
- Support GDPR readiness and cross-border data protection agreements via mapped guidance to the EU GDPR.
- Provide evidence of privacy governance for suppliers, customers and regulators during audits or due diligence.
- Guide Privacy Officers, CISOs, compliance teams, DPOs and auditors in implementing repeatable privacy risk management and accountability mechanisms.
Who should use it
- Organizations processing PII of any size or sector (public, private, non‑profit)
- Cloud and service providers acting as PII processors or sub‑processors
- Data protection officers, privacy program managers, information security teams and auditors
Related standards
- ISO/IEC 27001 (Information security management) - for alignment/integration
- ISO/IEC 29100 (Privacy framework) - conceptual mapping
- ISO/IEC 27018 and ISO/IEC 29151 - additional mappings provided in the standard
- EU GDPR - mapping and guidance included
ISO/IEC 27701:2025 provides a practical, auditable framework to manage privacy risk, improve accountability and integrate privacy into existing security and compliance programs.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27701:2025
Похожие стандарты
Стандарты, упомянутые в описании