ISO and IEC published ISO/IEC 27701:2025 on 14 October 2025, replacing the 2019 edition. It is the biggest change to privacy certification since the standard was introduced: ISO 27701 is no longer an add-on to ISO 27001 — it is now a standalone, certifiable Privacy Information Management System (PIMS) standard.
Note: there is no "ISO 27701:2026". The current edition is 2025, and organizations certified to the 2019 edition are now in the transition period.
The short version
- Standalone: you can certify a PIMS without first holding ISO 27001 certification.
- Complete management system clauses: the standard now contains its own Clauses 4–10 instead of supplementing ISO 27001's.
- Reorganized controls: privacy controls for PII controllers and PII processors are consolidated in Annex A instead of being scattered across extension clauses.
- Built for integration: designed to sit alongside ISO 27001, ISO 9001 and ISO 42001 in an integrated management system.
- Same core content: the requirements are drawn from the existing ISO 27701:2019, ISO 27001:2022 and ISO 27002:2022 — so a mature 2019 PIMS is not starting from zero.
ISO 27701:2019 vs ISO 27701:2025 at a glance
| Aspect | ISO/IEC 27701:2019 | ISO/IEC 27701:2025 |
|---|---|---|
| Standard type | Extension to ISO 27001 and ISO 27002 | Standalone management system standard |
| Prerequisite for certification | ISO 27001 certification required | No prerequisite |
| Management system clauses | Supplemented ISO 27001 Clauses 4–10 | Own complete Clauses 4–10 |
| Privacy controls | Spread across extension clauses and annexes | Consolidated in Annex A for controllers and processors |
| Alignment | Aligned to ISO 27001:2013 / 27002:2013 | Aligned to ISO 27001:2022 / 27002:2022 |
| Integration | Only with ISO 27001 | Harmonized structure for ISO 27001, 9001, 42001 and others |
| Regulatory mapping | Mapping to GDPR | Updated mapping annexes (including GDPR) |
What the standalone change means in practice
If you are already certified to ISO 27001 + ISO 27701:2019
You do not need to rebuild. Most of your controls, records of processing, DPIAs and supplier agreements remain valid. The work is mainly:
- mapping your existing PIMS to the new clause and control structure;
- updating the Statement of Applicability to the new Annex A;
- making sure the PIMS has its own scope, privacy objectives, risk assessment, internal audit and management review — rather than relying entirely on the ISMS versions.
Many organizations will keep an integrated ISO 27001 + ISO 27701 system; the 2025 edition simply makes the privacy side self-contained.
If you only need privacy certification
This is the big opportunity. Organizations that process personal data — SaaS providers, healthcare and HR platforms, BPOs, marketing processors — can now certify their privacy program directly, without first implementing a full ISO 27001 ISMS. For companies whose customers ask mainly about GDPR, DPDP or HIPAA-style privacy assurance, this can shorten the path to an independent certificate.
If you are an AI company
Because ISO 27701:2025 shares the harmonized structure with ISO 42001, privacy and AI governance can run on one management system with shared risk, audit and review processes.
Transition: what to expect
Organizations certified to the 2019 edition must move to the 2025 edition within the transition period set by accreditation bodies and their certification body. Ask your certification body for:
- the last date on which they will issue or recertify against the 2019 edition;
- whether your transition can be combined with a surveillance or recertification audit;
- whether they will certify ISO 27701:2025 as a standalone scheme or only alongside ISO 27001.
A practical 5-step transition plan
- Get the 2025 standard and the mapping annex between the 2019 and 2025 editions.
- Gap analysis — map your current PIMS documentation and controls to the new Clauses 4–10 and Annex A.
- Update core documents — PIMS scope, privacy policy, privacy risk methodology, Statement of Applicability, controller/processor role definitions.
- Internal audit and management review against the 2025 edition.
- Transition audit with your certification body.
Common mistakes to avoid
- Assuming ISO 27001 coverage is enough. The 2025 edition expects the PIMS to stand on its own clauses.
- Ignoring controller vs processor roles. Many organizations are both; the control set you apply depends on it.
- Forgetting regulatory mapping. Use the updated annexes to show how the PIMS supports GDPR, India's DPDP Act and other privacy laws.
How ICyberWave can help
ICyberWave provides consulting, implementation, and audit support for privacy management systems — from ISO 27701:2025 gap analyses and standalone PIMS implementation to integrated programs with ISO 27001 and GDPR or DPDP compliance. Learn more about our ISO 27701 support or book a consultation.

