ISO 27001 and GDPR: what it covers
European customers ask Canadian suppliers for ISO 27001 and GDPR compliance in the same email, as though the first delivered the second. It does not. The certificate answers one article of the regulation well and leaves most of the rest untouched, and knowing which is which saves a long argument in a security review.
ISO 27001 evidences Article 32 of the GDPR, the security of processing obligation, and it is good evidence for it. It does not deliver GDPR compliance, and it is not an approved certification mechanism under Article 42, which is the only route the regulation itself provides for demonstrating compliance through a certificate. Of the obligations a European customer is going to ask a Canadian supplier about, a certificate substantially answers one, partly answers three and does nothing for the rest.
Compliance with GDPR is a legal state assessed by supervisory authorities and courts. Certification is evidence you can put in front of a buyer. Treating the first as a consequence of the second is the mistake that ends security reviews badly.
Which GDPR obligations does ISO 27001 actually help with?
| Obligation | Does ISO 27001 help | What still has to exist |
|---|---|---|
| Article 32, security of processing | Substantially | Very little. This is what the standard is for, and the Annex A control set plus the risk assessment is stronger evidence than most GDPR-specific documentation. |
| Article 28, processor obligations | Partly | The data processing agreement itself, the sub-processor authorisation process, and the duty to assist the controller with rights requests. |
| Article 33 and 34, breach notification | Partly | Incident management is required by Annex A, but the 72 hour clock to the supervisory authority, the content of the notification and the duty to inform data subjects are legal duties the standard never mentions. |
| Article 30, records of processing | Partly | An ISMS asset inventory is not a record of processing. Purposes, categories of data subject, recipients, transfers and retention periods are all missing from it. |
| Articles 5 and 6, principles and lawful basis | No | Everything. The standard does not ask why you hold personal information or on what legal basis. |
| Articles 12 to 22, data subject rights | No | Access, rectification, erasure, restriction, portability and objection processes, with the one month response clock. |
| Article 35, data protection impact assessments | No | The assessment itself, and the prior consultation duty where residual risk stays high. |
| Chapter V, international transfers | No | The transfer mechanism, the transfer impact assessment, and the supplementary measures analysis. |
| Article 37, data protection officer | No | The appointment where required, and the independence and reporting line that comes with it. |
The three partial rows are the ones that cause trouble, because a supplier reads them as covered and a buyer reads them as gaps. If you want the management system that does cover the missing rows, that is ISO 27701, which since its 2025 revision is a standalone privacy management system standard with its own certificate.
Does Canada have GDPR adequacy?
Partly, and the precise shape of it is the fact Canadian suppliers most often get wrong on a questionnaire. The European Commission adopted an adequacy decision covering Canadian private-sector organizations subject to PIPEDA, which means personal data can flow from the EEA to those organizations without a separate transfer mechanism such as standard contractual clauses.
Where the adequacy decision stops
It covers commercial activities subject to PIPEDA. It does not cover organizations outside PIPEDA's reach, which includes federal public bodies, non-commercial activity, and employee data at provincially regulated employers. Nor does adequacy remove any other GDPR obligation: you still owe the controller a data processing agreement, records, breach notification support and assistance with rights requests. Adequacy solves the transfer question and nothing else. It is also kept under periodic review, so a contract that relies on it alone with no fallback clause is carrying a risk somebody should have written down.
Canada's own regime is PIPEDA federally, with Quebec, Alberta and British Columbia operating substantially similar provincial statutes for private-sector personal information. Quebec Law 25 is the closest of them to the GDPR in shape, and it is the one that adds duties an ISO 27001 project does not otherwise meet, covered on the Quebec page.
What does a European controller need from you as a processor?
Most Canadian suppliers are processors: the customer decides what personal information is collected and why, and you handle it on their instruction. Article 28 makes the controller responsible for using only processors that provide sufficient guarantees, which is precisely the sentence that generates the request for your certificate.
- A data processing agreement with the Article 28(3) terms: subject matter, duration, nature and purpose, type of personal data, categories of data subject, and the eight processor duties.
- Documented instructions, and a commitment to process only on them.
- Confidentiality commitments from everyone with access, which maps directly onto the people controls in Annex A.
- Article 32 security measures, which is where the certificate does its work.
- Sub-processor terms with authorisation, notice of changes, and flow-down of the same obligations. Your supplier register is the input to this and is usually incomplete.
- Assistance with data subject rights requests, breach notification to the controller without undue delay, and deletion or return at the end of the contract.
- Audit and information rights, which is the clause where a certificate earns its money by substituting for an on-site audit.
If a customer asks for both, what do you actually do?
The order that works
Build the security management system, because it is the longer project and because privacy controls sitting on unreliable security controls do not survive an audit. In parallel, and this part is cheap, produce the four privacy artifacts a European buyer will ask for regardless of any certificate: a record of processing activities, a sub-processor list you actually maintain, a data subject rights process with an owner and a clock, and a breach process that names who notifies the controller and within what time. None of the four requires a consultant and all four take days rather than months.
The counter-case
If the European customer is your only European customer and the contract is small, ISO 27001 is an expensive answer to their question. A first certification runs $64,500 to $139,000 CAD in year one for a forty-person company by the itemised costing, and a completed security questionnaire with a data processing agreement and a recent penetration test costs a fraction of that. The certificate becomes the right purchase when the questionnaires arrive faster than you can answer them, or when a tender makes it a gate. Deciding that honestly is what the standard selection tool is for.
The thing not to do
Do not claim GDPR compliance on a website or in a questionnaire because you hold ISO 27001. European buyers read that as either a misunderstanding or a misrepresentation, and both cost you more time than an honest answer that says the certificate covers Article 32, here are the other documents, and here is who owns privacy at our company.
Get quotes for certification with a European customer in scope
Tell us what your buyer asked for and we will match you with Canadian firms that do ISO 27001 and privacy work.
Get matchedCommon questions
Does ISO 27001 certification make us GDPR compliant?
No. It gives strong evidence for Article 32, the security of processing obligation, and partial evidence for the processor duties in Article 28 and for breach handling. Lawful basis, data subject rights, records of processing, impact assessments, international transfers and the data protection officer requirement are all outside the standard. GDPR compliance is a legal state, not something a certificate confers.
Is ISO 27001 an approved GDPR certification under Article 42?
No. Article 42 certification mechanisms are approved by supervisory authorities or the European Data Protection Board against criteria they set, and ISO 27001 is not one of them. That does not reduce its practical value in procurement, where it is the most widely recognised security certificate a supplier can hold. It does mean it carries no legal presumption of anything.
Can EU personal data be sent to a Canadian company?
Yes, where the recipient is a private-sector organization subject to PIPEDA, because the European Commission has adopted an adequacy decision covering those organizations. No standard contractual clauses are needed for that flow. Everything else in the regulation still applies, and the adequacy decision does not cover organizations or activities outside PIPEDA's scope.
Should we do ISO 27001 or ISO 27701 for European customers?
ISO 27001 first in nearly every case, because it is what buyers name, and ISO 27701 second if personal information is central to what you do or a controller has asked for privacy certification specifically. Since the 2025 revision ISO 27701 can be certified standalone, but building a privacy management system without the security one underneath rarely goes well.
Do we need a data protection officer if we get certified?
The two are unrelated. A DPO is required under Article 37 where you are a public authority, where your core activities require regular and systematic monitoring of data subjects on a large scale, or where they involve large scale processing of special category data. Certification neither triggers nor satisfies that requirement, and Annex A asks for security roles rather than a statutory privacy role.
Our customer sent a 200-question GDPR questionnaire. Does the certificate shorten it?
It shortens the security half considerably, because you can answer with a control reference and the Statement of Applicability rather than writing prose. The privacy half is untouched, and that is where the record of processing, the sub-processor list, the rights process and the transfer position do the work. Having those four documents ready is worth more per hour spent than any other preparation.