ISO/IEC 27701 — privacy management, systematized
What the PIMS standard is, and why GDPR obligations map so directly onto its controls.
What it is
ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS), first published in 2019. It is not a standalone standard: it extends ISO/IEC 27001 and 27002, so an organisation first runs an information security management system, then layers privacy controls on top.
It covers both GDPR roles in separate control sets — PII controllers (clause 7 / Annex A) and PII processors (clause 8 / Annex B).
Where the GDPR fits in
ISO 27701 was written with the GDPR in mind. Its informative Annex D maps the standard's controls to GDPR Articles 5–49, and most core GDPR obligations have direct control counterparts:
| GDPR requirement | ISO/IEC 27701:2019 counterpart |
|---|---|
| Lawful basis and consent (Art. 6–7) | 7.2 — Conditions for collection and processing |
| Transparency and data subject rights (Art. 13–22) | 7.3 — Obligations to PII principals |
| Data protection by design and by default (Art. 25) | 7.4 — Privacy by design |
| Processor contracts and sub-processor control (Art. 28) | 7.2.6, clause 8 — processor controls |
| Records of processing (Art. 30) | 7.2.8 (controller), 8.2.6 (processor) |
| Data protection impact assessment (Art. 35) | 7.2.5 — Privacy impact assessment |
| International transfers (Art. 44–49) | 7.5, 8.5 — PII sharing, transfer and disclosure |
Certification is strong evidence of a working privacy programme — useful under the GDPR's accountability principle (Art. 24) and in customer due diligence — but it is not a compliance guarantee. The standard itself notes the mapping is indicative; the legal obligation remains yours.
Where Vigil28 fits
GDPR Article 28 makes you responsible for knowing — and objecting in time — when your processors add sub-processors. ISO 27701 expects exactly that oversight under its processor controls, and auditors routinely ask for evidence of it.
Vigil28 produces that evidence trail automatically: continuous monitoring of your vendors' sub-processor lists, change alerts before objection deadlines expire, and audit-ready exports for ISO 27001/27701 audits and GDPR Article 30 records.
See pricing