ISO/IEC 27701

Also called Privacy Information Management System, PIMS

ComposedNot built

ISO/IEC 27701 certifies a privacy information management system: the documented processes, roles and records by which an organisation handles personal data, assessed by an accredited third party.

What it is evidence of, and what it is not

It is evidence that a management system exists and was audited. It is not evidence that any particular product minimises data, and it is not a legal finding of GDPR compliance. A certified organisation can still process more than it needs; the standard asks whether you manage it, not whether you avoided it.

Why the 2025 restructure changed the ask

Under the 2019 edition, 27701 sat on top of 27001, so a buyer asking for it was implicitly asking for both. The 2025 edition stands alone. An organisation reading an old RFP clause may therefore be answering a question the standard no longer poses.

The distinction worth holding onto

Architecture and certification answer different questions. A system that never collects a document and a system that collects it under a certified process are both defensible positions, and only one of them is a certificate. Conflating them is how privacy claims stop meaning anything.

Where it comes from

Someone else specified this. Solidus assembles it.

ISO/IEC JTC 1/SC 27. The 2025 edition is a standalone management-system standard; the 2019 edition was an extension that required 27001 alongside it. That restructuring matters for anyone reading an older requirement, because the prerequisite changed.

How to check this

Solidus has not built this. The entry explains the concept.

Certification would be evidenced by a certificate from an accredited body, which is the only thing that counts and which Solidus cannot produce. The standard itself is purchasable from ISO; it is not free, unlike the regulations it helps demonstrate compliance with.

Related

ISO/IEC 27701 · Solidus Lexicon