Overview
EN ISO/IEC 27706:2025 (adoption of ISO/IEC 27706:2025) specifies requirements and guidance for bodies that audit and certify Privacy Information Management Systems (PIMS) implemented in accordance with ISO/IEC 27701. It complements the general certification framework in ISO/IEC 17021-1, demonstrating competence, impartiality and reliability of certification bodies performing PIMS certification. The document can be used as a criteria document for accreditation, peer assessment or other audit processes.
Key topics and requirements
This standard covers the full conformity-assessment lifecycle for PIMS certification, including:
- Principles and general requirements
- Legal and contractual matters, impartiality management, conflicts of interest, liability and financing.
- Structural and resource requirements
- Organizational structure, competence of personnel, use of individual auditors and external technical experts, outsourcing and personnel records.
- Information and documentation
- Public information, certification documents, confidentiality, information exchange with clients, reference to certification and use of marks.
- Process requirements for certification activities
- Pre-certification (application review, audit programme, audit time determination), audit planning (scope, objectives, team selection), initial certification audits, audit conduct (specific PIMS elements), audit reporting, certification decision, surveillance and maintenance of certification.
- Complaint, appeal and record-keeping processes
- Requirements for handling appeals, complaints and client records.
- Management system options
- Two compliance options including alignment with ISO 9001 or general management system requirements.
- Annexes
- Annex A: Audit time, Annex B: Methods for audit time calculations.
Practical applications and who should use it
EN ISO/IEC 27706:2025 is intended for:
- Certification bodies expanding or assessing PIMS audit/certification services.
- Accreditation bodies and peer assessors creating criteria for accreditation of privacy certification schemes.
- Third‑party auditors, technical experts and conformity assessment professionals engaged in privacy, information security and cybersecurity certification.
- Privacy officers, compliance managers and legal teams evaluating the credibility of certification providers or preparing for PIMS certification.
Practical uses include:
- Establishing competence criteria for PIMS auditors and technical experts.
- Designing audit programmes, calculating audit time and planning surveillance.
- Demonstrating impartiality, confidentiality and consistent certification decision-making for accreditation.
- Harmonizing PIMS certification practices with existing ISO/IEC 17021-1 processes.
Related standards
- ISO/IEC 27701 - Privacy information management requirements and guidance (PIMS).
- ISO/IEC 17021-1 - General requirements for bodies providing audit and certification of management systems.
- ISO 9001 - Option for management system alignment (quality management).
- Supersedes CEN ISO/IEC/TS 27006-2:2022.
Keywords: ISO/IEC 27706:2025, PIMS certification, privacy information management system, audit and certification bodies, accreditation, ISO/IEC 27701, ISO/IEC 17021-1, audit time, impartiality, competence.