Security and privacy

Privacy information management (ISO/IEC 27701)

An extension to ISO/IEC 27001 and 27002 for privacy information management, covering controllers and processors of personal data.

CodeISO 27701
RegionInternational
TypeVoluntary, contractual
Issued byAccredited certification bodies
Last verified2026-10-10
Quick answerCertification · last verified 2026-10-10

An extension to ISO/IEC 27001 and 27002 for privacy information management, covering controllers and processors of personal data. Status: Voluntary, contractual. Issued or recognised by Accredited certification bodies.

CodeISO 27701
RegionInternational
TypeVoluntary, contractual
Issued byAccredited certification bodies
GroupSecurity and privacy
Last verified2026-10-10
How to cite this pageIoT Atlas. "Privacy information management (ISO/IEC 27701)". https://hi-spark.net/certification/iso-27701.html Last verified 2026-10-10.

What it means

ISO/IEC 27701 provides a management framework that maps to privacy regulation, which is useful for IoT companies handling location, camera or health data. It complements but does not replace legal compliance.

Applies to

  • Cloud services that process personal data
  • Mobile apps collecting usage or account data
  • Organisations acting as data processors for enterprise clients

What it does not cover

  • A guarantee of legal compliance in each jurisdiction
  • Device level data protection requirements
  • Consumer consent management software

Verification checklist

  • Start from an operational ISO/IEC 27001 management system
  • Identify the controller and processor roles
  • Extend the risk assessment to personal data
  • Document records of processing and retention