ISO has published ISO/IEC 27701:2025, Information security, cybersecurity and privacy protection – Privacy information management systems – Requirements and guidance.
The big change: ISO/IEC 27701 is now a standalone management system standard. Organisations no longer need an ISO/IEC 27001 ISMS in order to implement and certify a Privacy Information Management System (PIMS).
Other key changes
- A full set of management system clauses (4 to 10) specific to privacy, using the harmonised structure.
- Alignment with ISO/IEC 27001:2022 and ISO/IEC 27002:2022.
- Updated controls for PII controllers and processors, with expanded guidance on topics such as cloud services and emerging technologies.
Organisations certified to the 2019 edition will have a transition period. Integrated ISO/IEC 27001 and 27701 management systems remain an efficient option for many.
Source: ISO/IEC 27701:2025 (ISO)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.