Find the expert you need
Choose a service
Or choose a subject
If you need technical support, please visit our Contact us page.
Hey there! We've noticed you're visiting us from the United States. Click the button below to visit the US version of our website for the best user experience.
Information security, cybersecurity and privacy protection - Privacy information management systems - Requirements and guidance.
Enhance your organisation’s privacy management with ISO/IEC 27701:2025, the international standard for establishing, implementing, maintaining and continually improving a privacy information management system (PIMS).
In today’s digital world, almost every organisation processes personally identifiable information (PII) — and the volume, variety and complexity of this data continues to grow. Increasingly, organisations must also collaborate with partners and third parties to manage PII responsibly. Protecting privacy throughout these processes is not only a societal expectation, but also a legal requirement in many jurisdictions around the world.
ISO/IEC 27701:2025 provides a comprehensive framework for establishing, implementing, maintaining and continually improving a PIMS.
This standard includes detailed mapping to:
The standard can be used by PII controllers (including joint controllers) and PII processors (including those working with subcontractors). By complying with its requirements, organisations can demonstrate clear, verifiable evidence of how they manage and protect PII. This evidence supports:
Additionally, ISO/IEC 27701:2025 enables seamless alignment or integration of your PIMS with other management systems — particularly the information security management system (ISMS) defined in ISO/IEC 27001.
Ensure your organisation meets global privacy expectations and regulatory demands with confidence.