What ISO/IEC 27701 actually asks of you
The request usually comes from a customer rather than a regulator. A security questionnaire with a privacy section. A data processing agreement returned with tracked changes. Somewhere in it, a question that is harder to answer than it looks: how do we know you handle our people’s data the way you say you do?
Assurances are cheap at that point, and everyone gives the same ones.
ISO/IEC 27701 is the standard that turns the answer into something a customer can examine. As of the 2025 edition, it is also a standard an organisation can hold on its own.
What changed in 2025
The 2019 edition was an extension. It could only be certified alongside ISO/IEC 27001, so any organisation wanting to demonstrate privacy management first had to build and certify an information security management system. For many, that was the reason it never happened: the privacy case was clear, and the security project standing in front of it was not.
The 2025 edition carries its own management system requirements in clauses 4 to 10. A privacy information management system can now be certified in its own right.
If you already hold a certificate to the 2019 edition, there is a date to work back from: certificates transition to the 2025 edition by October 2028. That is further away than it sounds, because a transition means a real audit against a revised standard rather than a reprint of the certificate you have.
The idea underneath it
Privacy law says what you must achieve. It says very little about how, which is why two organisations can both be acting lawfully and look nothing alike internally.
The standard asks a narrower question: can you say what personal data you hold, why you hold it, who you share it with, and can you show that what you say is what actually happens?
It starts with a piece of vocabulary worth getting right, because the duties follow from it. POPIA speaks of a responsible party and an operator. GDPR speaks of a controller and a processor. The standard speaks of a PII controller and a PII processor. They are the same distinction: whoever decides why personal data is processed, and whoever processes it on someone else’s instructions. Most organisations are both, in different parts of the business, and the first thing the standard asks is that you know which you are, activity by activity.
What the standard requires
In outline, ISO/IEC 27701 asks you to:
- Decide your role for each processing activity, controller or processor, and record it
- Know what personal data you hold, where it came from, why you have it, and how long you intend to keep it
- Record the purpose and the basis for each use, and stop the uses that have neither
- Answer the people whose data it is when they ask, within the time the law allows, and keep evidence that you did
- Bind the processors you rely on, and know what they do with what you send them
- Design privacy into new services rather than retrofitting it after launch
- Detect, investigate and report breaches, and deal with what caused them
- Train the people who handle the data, and review the whole system at management level
Most organisations already do parts of this. What certification adds is that it is written down, applied when the person who set it up is on leave, and examined by someone who does not work for you.

What changes in practice
Customer questionnaires. The same questions arrive from every enterprise buyer, and answering them from scratch each time is how contradictions get into writing. A certified system answers them from one set of facts.
Contracts. A data processing agreement is full of warranties about what you will and will not do with personal data. Certification is evidence that those warranties rest on something operational rather than on the drafting.
Several regimes at once. POPIA, GDPR and CCPA ask different questions of the same underlying facts. Building one system that holds those facts is less work than maintaining three answers, and it is far easier to keep current.
Incidents. The difference between a bad week and a bad year is usually whether the route for recording, investigating and reporting a breach existed before the breach did. Under POPIA, notification obligations run to the Information Regulator and, in most cases, to the people affected.
What it does not do
An honest account has to include this, because this standard is oversold more than most.
Certification demonstrates that a privacy information management system exists and is being used. It is not a finding of legal compliance with POPIA, GDPR or any other statute. No certification body can make that finding. Under POPIA that authority sits with the Information Regulator, not with us.
It is also not a GDPR Article 42 certification, which is a separate mechanism requiring approval by a supervisory authority. The two get conflated in sales conversations, and they are not interchangeable.
Nor does it certify your software, your infrastructure or your security controls. Information security is ISO/IEC 27001’s subject. The two interlock, and they are commonly audited in one programme, but a privacy certificate says nothing about how well your systems are defended.
Where it starts
It starts with scope: which processing activities, in which roles, in which parts of the organisation. The scope statement is what appears on the certificate, and it is the first thing a careful customer reads. A narrow scope that is honestly stated is worth more than a broad one that does not survive reading.
If you hold a 2019 certificate, October 2028 is the date to plan back from. If you do not, the question this standard was written to answer is the one your customers will put to you next year, in a questionnaire, with a deadline.
