About ISO/IEC 27701

ISO/IEC 27701* is a privacy extension to ISO/IEC 27001 Information Security Management and ISO/IEC 27002 Security Controls. An international management system standard, it provides guidance on the protection of privacy, including how organizations should manage personal information, and assists in demonstrating compliance with privacy regulations around the world.


Benefits of ISO/IEC 27701:

• Builds trust in managing personal information
• Provides transparency between stakeholders
• Facilitates effective business agreements
• Clarifies roles and responsibilities
• Supports compliance with privacy regulations
• Reduces complexity by integrating with the leading information security standard ISO/IEC 27001


Who should use ISO/IEC 27701?

ISO/IEC 27701 is applicable to all types and sizes of organizations, including public and private companies, government entities and not-for-profit organizations. It provides guidance for organizations who are responsible for PII processing within an information security management system (ISMS), specifically:

  • PII controllers (including those who are joint PII controllers)
  • PII processors


Get started with ISO/IEC 27701

  • Buy ISO/IEC 27701 from the BSI shop
  • Manage access to ISO/IEC 27701 and other information security standards easily with BSOL, our online standards management tool
  • Consider a training course with our expert tutors to help you understand the standard and implement it within your organization

Register your interest in ISO/IEC 27701 certification