Elbasan, Republic of Albaniainfo@invicta.al+355 69 221 1677
ISO/IEC 27701:2019PIMS3-Year Certificate

ISO/IEC 27701:2019 Privacy Information Management

A formally recognised extension to ISO/IEC 27001 addressing personal data management — specifying requirements for a Privacy Information Management System supporting GDPR compliance.

Apply for Certification How It Works
Standard Information

Everything you need to know about ISO/IEC 27701:2019

ISO/IEC 27701:2019 is an extension to ISO/IEC 27001 and ISO/IEC 27002 that specifies requirements for a Privacy Information Management System (PIMS). It distinguishes between Personal Information Controllers (PICs) — organisations determining purposes and means of processing (GDPR data controllers) — and Personal Information Processors (PIPs) — organisations processing on behalf of controllers (GDPR data processors) — with specific requirements for each role. It integrates seamlessly with an existing ISO 27001 ISMS.

ISO/IEC 27701 applies to any organisation processing personal information — data controllers, data processors, cloud service providers, marketing platforms, HR systems providers, healthcare organisations, financial institutions, and any entity subject to GDPR or equivalent privacy legislation. For organisations already certified to ISO 27001, extending to ISO 27701 adds formal privacy management to an established framework with minimal additional effort.

ISO/IEC 27701 is typically pursued together with ISO/IEC 27001 in a combined audit. The Stage 2 audit assesses whether personal information has been identified and mapped, processing activities have lawful bases, data subject rights can be fulfilled, privacy impact assessments are conducted, breach detection is effective, and privacy accountability can be demonstrated. View the full certification process.

ISO/IEC 27701:2019 certificates are valid for three years, aligned with the ISO 27001 cycle they extend. Surveillance audits assess responses to changes in the regulatory environment — new guidance from data protection authorities, sub-processor changes, and updated transfer mechanisms. Maintaining active ISO 27701 certification provides continuously updated evidence of privacy accountability to regulators, clients, and data subjects.

Ready to pursue ISO/IEC 27701:2019 certification?

Contact us for a no-obligation scoping discussion and tailored quotation.