ISO/IEC 27701:2025: Privacy Information Management System

Specifies requirements for a Privacy Information Management System (PIMS). Since the 2025 edition it is a standalone management system standard — it no longer has to sit on top of an ISO/IEC 27001 ISMS.

How personal data is governed — controller and processor responsibilities, privacy-specific controls, and the evidence needed to demonstrate accountability under laws such as the Kenya Data Protection Act and GDPR.

Since the 2025 edition, ISO/IEC 27701 can be certified without ISO 27001. Organisations certified to the 2019 edition (an ISO 27001 extension) should confirm transition arrangements with their certification body. Certification is granted by an accredited certification body — never by Orvella.