ISO/IEC 27701 — privacy management, systematized

What the PIMS standard is, and why GDPR obligations map so directly onto its controls.

What it is

ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS), first published in 2019. It is not a standalone standard: it extends ISO/IEC 27001 and 27002, so an organisation first runs an information security management system, then layers privacy controls on top.

It covers both GDPR roles in separate control sets — PII controllers (clause 7 / Annex A) and PII processors (clause 8 / Annex B).

Where the GDPR fits in

ISO 27701 was written with the GDPR in mind. Its informative Annex D maps the standard's controls to GDPR Articles 5–49, and most core GDPR obligations have direct control counterparts:

GDPR requirementISO/IEC 27701:2019 counterpart
Lawful basis and consent (Art. 6–7)7.2 — Conditions for collection and processing
Transparency and data subject rights (Art. 13–22)7.3 — Obligations to PII principals
Data protection by design and by default (Art. 25)7.4 — Privacy by design
Processor contracts and sub-processor control (Art. 28)7.2.6, clause 8 — processor controls
Records of processing (Art. 30)7.2.8 (controller), 8.2.6 (processor)
Data protection impact assessment (Art. 35)7.2.5 — Privacy impact assessment
International transfers (Art. 44–49)7.5, 8.5 — PII sharing, transfer and disclosure

Certification is strong evidence of a working privacy programme — useful under the GDPR's accountability principle (Art. 24) and in customer due diligence — but it is not a compliance guarantee. The standard itself notes the mapping is indicative; the legal obligation remains yours.

Where Vigil28 fits

GDPR Article 28 makes you responsible for knowing — and objecting in time — when your processors add sub-processors. ISO 27701 expects exactly that oversight under its processor controls, and auditors routinely ask for evidence of it.

Vigil28 produces that evidence trail automatically: continuous monitoring of your vendors' sub-processor lists, change alerts before objection deadlines expire, and audit-ready exports for ISO 27001/27701 audits and GDPR Article 30 records.

See pricing