Management System Certification

ISO 27701 – Privacy Information Management System

Extend your ISMS into privacy — and answer the DPDP and GDPR question properly.

  • ISO 27701
  • Recognised internationally

About ISO 27701

What is ISO 27701?

ISO/IEC 27701 is a privacy extension to ISO/IEC 27001 and ISO/IEC 27002. It specifies requirements and guidance for establishing and continually improving a Privacy Information Management System (PIMS) covering the processing of personally identifiable information.

Its defining structural feature is that it separates requirements for PII controllers from those for PII processors, which matters because those two roles carry genuinely different obligations. A SaaS company processing customer data on instruction has different duties from the customer determining the purpose of that processing, and the standard is one of the few frameworks that treats the distinction rigorously.

ISO 27701 cannot be certified on its own — it extends an ISO 27001 ISMS, and the two are audited together, either simultaneously or with ISO 27701 added to an existing certification. For Indian organisations it maps usefully onto the Digital Personal Data Protection Act 2023 duties of a Data Fiduciary, and internationally onto GDPR controller and processor obligations, providing structured evidence for both without claiming to be a legal compliance certificate for either.

Who needs this?

  • SaaS, IT services and BPO organisations processing personal data on behalf of clients
  • Organisations preparing for Digital Personal Data Protection Act obligations in India
  • Companies serving EU, UK or California customers with GDPR or CCPA exposure
  • Healthcare, fintech, insurtech and edtech platforms handling sensitive personal data
  • Marketing, analytics, HR-tech and recruitment technology providers
  • Existing ISO 27001 certified organisations facing privacy questions in client due diligence

Why organisations certify

Key benefits of ISO 27701

What certification actually returns, stated specifically rather than generically.

Credibility

Certification answers privacy due-diligence questionnaires with independently audited evidence instead of self-assessment.

Market Access

EU and UK customers, and increasingly Indian enterprises, require documented privacy governance before signing a data processing agreement.

Risk Reduction

Structured record of processing, lawful basis analysis, retention limits and breach response reduce both incident likelihood and regulatory exposure.

Operational Efficiency

Knowing exactly what personal data you hold, why, and for how long eliminates the storage, backup and migration cost of data you should have deleted.

Customer Trust

Privacy is now a purchasing consideration for consumers and enterprises alike; verified governance is a commercial asset.

Regulatory Compliance

Provides an auditable framework mapping to DPDP Act 2023, GDPR Articles 5, 28, 30, 32, 33 and 35, and comparable regimes.

How it works

Our process for ISO 27701

Every stage has a defined purpose, a realistic duration and a stated output.

  1. 01

    Application & Quotation

    2–3 working days

    You submit an application form covering scope, headcount, sites and shift pattern. We review complexity, confirm audit-day allocation against accreditation rules and issue a fixed quotation.

  2. 02

    Contract & Audit Planning

    1 week

    On acceptance we appoint a lead auditor with verified technical competence for your sector, agree audit dates and share the audit plan in advance.

  3. 03

    Stage 1 — Readiness Review

    1 day (typical)

    A documentation and readiness assessment: scope confirmation, review of your management system documents, internal audit and management review evidence, and identification of anything that would block Stage 2.

  4. 04

    Stage 2 — Certification Audit

    2–5 days (scope dependent)

    On-site assessment of the system in operation. We sample processes, interview staff, examine records and raise findings graded as major, minor or opportunity for improvement.

  5. 05

    Corrective Action & Decision

    2–4 weeks

    You close out any nonconformities with root-cause analysis and evidence. An independent certification decision-maker — not the audit team — reviews the file and grants certification.

  6. 06

    Certificate Issue

    3–5 working days

    A three-year certificate is issued and your organisation is listed on our public certified-client directory for verification by your customers.

  7. 07

    Surveillance & Recertification

    Annual

    Surveillance audits at 12 and 24 months confirm the system remains effective. A full recertification audit is completed before the three-year expiry.

Preparation

Documents required

What we will ask to see. Having these ready before Stage 1 is the single biggest factor in a certification that runs to schedule.

  • Completed and signed application form
  • Certificate of incorporation / business registration
  • Organisation chart and scope statement
  • Management system manual or equivalent documented information
  • Documented processes, procedures and work instructions
  • Internal audit reports covering the full scope
  • Management review minutes
  • Records of corrective actions and continual improvement
  • Applicable legal and regulatory licences for your activity
  • Privacy policy and internal privacy notices
  • Record of processing activities (RoPA) for controller and/or processor roles
  • Lawful basis and consent management records
  • Data protection impact assessments (DPIA) for high-risk processing
  • Data processing agreements with customers and sub-processors
  • Data subject rights request procedure and handling records
  • Retention schedule and secure deletion evidence
  • Personal data breach response plan and notification records
  • Cross-border transfer assessments and safeguards
  • Valid ISO/IEC 27001 certification or concurrent ISMS implementation

Not sure whether your scope is right?

Scope is the single thing most often got wrong, and it appears verbatim on your certificate. We will review yours before you apply, at no charge — it costs us less than fixing it at recertification.

Talk to a specialist

Common questions

ISO 27701 — frequently asked questions

Direct answers, including where the honest answer is inconvenient for us.

No. ISO 27701 is an extension to an ISO 27001 ISMS and has no independent existence. You can certify both together in a single audit programme, or add ISO 27701 to an existing ISO 27001 certificate at a surveillance or recertification audit.

It does not, and no certification can. GDPR and the DPDP Act are laws; compliance is determined by regulators and courts. ISO 27701 gives you a management system that addresses the operational obligations of those laws and produces the evidence a regulator would ask for. It is strong supporting evidence, not a legal shield.

You may well be both, in different contexts — a processor for client data and a controller for your own employee and marketing data. ISO 27701 allows a scope covering both roles, and the audit examines the applicable control set for each.

Question not answered here? Ask a certification specialist — we answer technical questions without requiring an enquiry first.

Talk to us

Talk to a certification expert

Tell us your scope and headcount and we will send a fixed quotation for ISO 27701 with the audit-day calculation shown.

  • Quotation within 2–3 working days
  • IAF MD 5 audit-day calculation included
  • Full three-year cycle cost, not just the first audit
  • Your details are used only to answer this enquiry

Including contractors and shift staff — this sets your audit days.

Tell us your scope, whether design is included, and any deadline you are working to.

Your details are used only to answer this enquiry. We do not sell or share them.

Next step

Ready to certify to ISO 27701?

We will scope it honestly, show you the calculation behind the price, and tell you plainly if the timeline you need is not achievable.