ISO/IEC 27701 (privacy information management): cited answers and gap reviews
ISO/IEC 27701 extends an information security management system to privacy, with separate controls for PII controllers and processors. Compliance Colleague covers both the 2025 and 2019 editions, including running a standalone PIMS and the move from 2019.
What it covers
- ISO/IEC 27701:2025 and 2019, and the transition between them
- Annex A.1 controller controls, A.2 processor controls and A.3 shared controls
- Privacy risk assessment, DPIAs and records of processing
- A standalone PIMS without ISO 27001
- Mapping to the GDPR
Questions you can ask
- “Which ISO 27701 controls apply to us as a processor only?”
- “Can we certify to ISO 27701:2025 without ISO 27001?”
- “How does A.1 map to GDPR Article 30 records?”
Every answer cites the ISO 27701 requirement, article or control it rests on, so you can check it in seconds.
What you can upload for review
- Your privacy policy or notice, checked against the controller controls
- A record of processing activities (Excel) checked for missing fields
- A processor agreement checked against the processor controls
Files: PDF, Word, Excel or CSV, Visio (.vsdx), draw.io, or an image such as a screenshot. Choose a full review, a prioritized fix list (each gap with its fix and the evidence an assessor will expect) or a short summary, and download the result as Word or PDF.
Crosswalk ISO 27701 to other standards
With ISO 27701 in your plan you can compare it against any standard in the library and see where they align and exactly where they don’t. Common pairings:
What it’s built from
Compliance Colleague works from our own clause-referenced material, checked against: ISO/IEC 27701:2025 catalogue page (Privacy information management systems) (ISO / IEC); ISO/IEC 27701:2025: Key Changes and Guidance (BSI); Revision of ISO/IEC 27701 (DNV). It cites the clause so you can check it against your own copy.
Re-checked every month for new versions, deadlines and penalty changes. Full list on the sources page.
More Global standards
PCI DSS · ISO 27001 · ISO 42001 · SOC 2 · SWIFT CSP · WCAG
Research aid, not legal or audit advice, and not an audit opinion or certification. Verify findings against the official text before relying on them.