An independent, third-party certification body · operating to ISO/IEC 17021-1:2015
Verify a Certificate ↗·Global · Remote & on-site·EN
Certification
Home/Standards/ISO 27701
Privacy Information · PIMS

ISO 27701

A privacy information management system in its own right. We audit your PIMS against ISO/IEC 27701 and, on the evidence, issue certification — independently of the audit team.

ISO/IEC 27701:2025 Standalone since the 2025 edition PIMS · Privacy Information Transition by October 2028
ISO 27701 PIMS

Accreditation status — PIMS

Accredited
Applicable standard
ISO/IEC 27701:2019/2025
Scheme
Privacy Information Management (PIMS)
Scope limitation
None stated

Accredited certification available within the authorised scope — subject to scheme-specific scope and competence requirements. See the full Accreditation & Scope matrix.

What we certify

We audit your privacy information management system — and decide on the evidence

ISO/IEC 27701 sets out a privacy information management system (PIMS): the controls and responsibilities needed to manage personal data as a controller or processor, supporting obligations under privacy law.

The 2025 edition carries its own management system requirements in clauses 4 to 10. Where the 2019 edition was an extension that could only be certified alongside ISO/IEC 27001, the current edition can be certified on its own — privacy no longer waits on an information security certificate.

As an independent certification body, Skyeblanc Certification audits your privacy information management system against ISO 27701 and, where the evidence supports conformity, issues certification. We do not design, document or improve your system — that separation is a requirement of ISO/IEC 17021-1 and is exactly what gives an ISO 27701 certificate its meaning.

The certification decision is made by an independent decision-maker who did not conduct your audit.

The audit

Your ISO 27701 audit, stage by stage

The same defined path for every applicant — the certification decision held independent of the audit team.

01

Stage 1

A readiness review of your documented PIMS — your PII controller and processor roles, the privacy risk assessment, the PIMS scope, and the applicability of each control. Where an information security management system is also in place, how the two relate.

02

Stage 2

Assessment of the PIMS in operation: the privacy-specific controls, records of processing activities, and the handling of PII principal rights — together with the interface to your information security management system where one exists.

03

Decision

An independent decision-maker reviews the evidence and grants — or declines — certification.

04

Surveillance

Annual surveillance audits, then a full recertification at year three renews the cycle.

See the full certification process →
Audit duration

What determines your audit time

Audit duration for ISO 27701 is determined by the applicable scheme requirements — never a flat rate. The main factors:

Effective headcount

The number of people — including shifts and part-time — is the primary driver of audit duration.

Sites & locations

How many sites and where. Multi-site sampling follows IAF MD1.

Scope & complexity

The range of activities and processes within your certified scope.

Shift patterns

Operations across multiple shifts can extend on-site audit time.

Existing certification

Transfers from another accredited body are reviewed under IAF MD2.

Delivery mode

On-site or ICT-assisted remote auditing per IAF MD4, matched to risk.

Fees are fixed for the defined audit programme. A fixed fee covers the audit; it never buys an outcome — certification is granted only on the evidence, by an independent decision-maker.

Applicability

Who ISO 27701 is for

ISO/IEC 27701 suits any organisation that processes personal data and wants to demonstrate privacy governance. We routinely audit across:

Technology & SaaSFinancial servicesHealthcareMarketing & dataHR & payrollTelecomsPublic sector
Related schemes

Often certified alongside ISO 27701

Begin certification

Apply for ISO 27701 certification

Tell us your scope, sites and employee numbers, and we'll return a fixed-fee audit quotation with the programme and timeline.

Prefer pricing first? Request an audit quotation →
No consultancy is offered or implied — Skyeblanc Certification audits and certifies only.