ISO/IEC 27701
Also called Privacy Information Management System, PIMS
ISO/IEC 27701 certifies a privacy information management system: the documented processes, roles and records by which an organisation handles personal data, assessed by an accredited third party.
What it is evidence of, and what it is not
It is evidence that a management system exists and was audited. It is not evidence that any particular product minimises data, and it is not a legal finding of GDPR compliance. A certified organisation can still process more than it needs; the standard asks whether you manage it, not whether you avoided it.
Why the 2025 restructure changed the ask
Under the 2019 edition, 27701 sat on top of 27001, so a buyer asking for it was implicitly asking for both. The 2025 edition stands alone. An organisation reading an old RFP clause may therefore be answering a question the standard no longer poses.
The distinction worth holding onto
Architecture and certification answer different questions. A system that never collects a document and a system that collects it under a certified process are both defensible positions, and only one of them is a certificate. Conflating them is how privacy claims stop meaning anything.
Where it comes from
Someone else specified this. Solidus assembles it.
ISO/IEC JTC 1/SC 27. The 2025 edition is a standalone management-system standard; the 2019 edition was an extension that required 27001 alongside it. That restructuring matters for anyone reading an older requirement, because the prerequisite changed.
How to check this
Solidus has not built this. The entry explains the concept.
Certification would be evidenced by a certificate from an accredited body, which is the only thing that counts and which Solidus cannot produce. The standard itself is purchasable from ISO; it is not free, unlike the regulations it helps demonstrate compliance with.