ISO27K

ISO 27701: the privacy management standard

Nearly everything written about ISO/IEC 27701 online describes the 2019 edition, which was an extension you could only certify on top of ISO 27001. The 2025 revision made it a standalone management system standard with its own certificate. If a page tells you that you must already hold ISO 27001, that page is out of date.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

ISO/IEC 27701 is the certifiable standard for a privacy information management system, and since the 2025 revision it stands on its own. You no longer need an existing ISO 27001 certificate to be certified against it, though almost everyone still does both, because the two management systems share their clause structure and running one audit over both saves real money. Budget roughly $8,000 to $20,000 CAD in additional certification body fees where it is added to an ISO 27001 scope, and considerably more where it is built from nothing.

What it does not do is make you compliant with a privacy statute. No certificate does that, and any page suggesting ISO 27701 gives you GDPR, PIPEDA or Law 25 compliance is selling something.

What changed in the 2025 revision?

Three things, and the first one invalidates most of the published guidance.

  1. It became a standalone management system standard. The 2019 edition was written as a set of additions to ISO 27001 and ISO 27002, and a certificate could only be issued against an existing ISO 27001 certification. The current edition carries its own clauses 4 through 10 and can be certified alone.
  2. The structure was rebuilt around the harmonised clause structure that ISO 27001 and ISO 42001 also use, so an integrated management system is genuinely integrated rather than bolted on. Context, leadership, planning, support, operation, performance evaluation and improvement mean the same things across all three.
  3. The controller and processor control sets remain the substance of it. If you determine the purposes for which personal information is processed you are a controller, if you process on someone else's instruction you are a processor, and most Canadian software companies are a processor for customer data and a controller for their own employee and prospect data at the same time.

Check what your certification body is offering

Accredited bodies moved to the new edition at different speeds, and a transition period applies to certificates issued against the 2019 edition. Ask which edition a quote is written against, and if you are being sold the older extension model, ask what the transition will cost you in years two and three rather than only what the certificate costs today. The same principle covers every quote on this site: ask for the audit days across the full cycle, not the headline total.

What does a privacy information management system cover?

The management system requirements are recognisable to anyone who has been through ISO 27001: define the scope, get leadership commitment, assess risk, select and justify controls, train people, run an internal audit, hold a management review, and correct what is broken. The privacy substance sits in the control sets, and that is where it goes beyond security.

What ISO 27701 asks for that ISO 27001 does not
AreaWhat is requiredWhere ISO 27001 stops
Purpose and lawful basisIdentify and document the purpose for each processing activity and the basis for it.Annex A has one control on privacy and protection of personal information. It does not ask why you hold the data.
Records of processingMaintain an inventory of processing activities, categories of data subject, recipients and retention.Asks for an asset inventory, which is not the same thing and rarely contains purpose or retention.
Individual rightsA process for access, correction, deletion, objection and portability requests, with timelines.Silent. An ISMS can be perfectly conformant and have no way to answer an access request.
Consent and noticeObtain, record and allow withdrawal of consent where that is the basis, and provide notice at collection.Silent.
Privacy by designData minimisation, retention limits, de-identification and deletion built into the system rather than added.Partly. Information deletion and data masking are Annex A controls, aimed at security rather than at minimisation.
Sub-processors and transfersDisclose sub-processors, record the countries data moves to, and hold the terms that authorise it.Supplier controls cover security of the supplier, not the legal basis for the transfer.
Breach handlingNotify the controller, and support the controller's own notification duties within the statutory clock.Incident management is required, with no privacy notification duty attached.

Does ISO 27701 help with PIPEDA and Law 25?

It helps, it does not satisfy. The honest framing is that ISO 27701 gives you the operating machinery that Canadian privacy law assumes you already have, without giving you the specific obligations those statutes impose.

PIPEDA

The ten fair information principles in Schedule 1 map onto the ISO 27701 control set closely enough that an implementation covers most of the ground: accountability, identifying purposes, consent, limiting collection, limiting use and retention, accuracy, safeguards, openness, individual access, and challenging compliance. What certification does not do is answer to the Office of the Privacy Commissioner, and a finding against you is not defended by a certificate. What it genuinely gives you is the evidence trail that turns a complaint into a short conversation. The PIPEDA obligations themselves are the thing you comply with.

Quebec Law 25

Law 25 imposes duties that no international standard contains: a designated person in charge of the protection of personal information by default the person with the highest authority, mandatory confidentiality incident reporting to the Commission d'acces a l'information, privacy impact assessments before certain projects and before communicating personal information outside Quebec, the right to data portability, and the right to be informed when a decision is based exclusively on automated processing. A privacy management system makes each of those easier to run and none of them automatic. The Quebec page covers the French-language documentation question, which applies here too.

Health information

PHIPA in Ontario and the equivalent provincial health statutes elsewhere sit outside PIPEDA for health custodians, and ISO 27701 knows nothing about them specifically. If you are a health information custodian or an agent of one, the management system is useful and the statutory duties are still the ones that bind you.

When is ISO 27701 worth the money, and when is it not?

Worth it

When European customers are asking. GDPR Article 28 makes a controller responsible for using only processors that provide sufficient guarantees, and a privacy management system certificate is the cleanest way a Canadian supplier answers that in one line instead of a forty-page questionnaire. It is also worth it when personal information is the product rather than a by-product of it, and when you have already been through a privacy incident and need to show a regulator or a customer that something structural changed.

Not worth it

When nobody has asked. Privacy certification is a sales asset and it is a poor first purchase: if a buyer has not named it, the money buys more security outcome inside an ISO 27001 scope than it does here. It is also the wrong purchase when what you actually need is a privacy lawyer, which is most often the case for consent design, cross-border transfer structures and Law 25 impact assessments. And it is premature before ISO 27001 exists in almost every case, not because the standard requires it any more, but because the security controls underneath a privacy program have to work first.

Get quotes for privacy and security certification

Tell us your scope and which standards your customers named, and we will match you with Canadian firms that do this work.

Get matched

Common questions

Do I need ISO 27001 before ISO 27701?

Not since the 2025 revision. ISO 27701 is now a standalone management system standard and can be certified on its own. Most organizations still do ISO 27001 first or at the same time, because the clause structure is shared, a single integrated audit costs less than two separate ones, and privacy controls sitting on top of weak security controls do not survive contact with an auditor.

How much does ISO 27701 certification cost in Canada?

Where it is added to an existing or concurrent ISO 27001 scope, expect roughly $8,000 to $20,000 CAD in additional certification body fees for the first cycle, plus consultant time if the privacy documentation does not exist. Built standalone with no management system in place, the figure looks much closer to a first ISO 27001 certification, so $15,000 to $40,000 CAD in audit fees and a larger readiness bill behind it.

Does ISO 27701 certification make us GDPR compliant?

No. GDPR compliance is a legal state, not a certificate, and ISO 27701 is not an approved certification mechanism under Article 42 of the regulation. What it does is give a controller strong evidence that a processor has sufficient guarantees under Article 28, and give you the records and processes that most GDPR obligations assume. The GDPR page maps this article by article.

What is the difference between a controller and a processor here?

A controller determines the purposes and means of processing personal information. A processor handles it on the controller's documented instruction. ISO 27701 has separate control sets for the two roles and you implement whichever apply, which for most Canadian software companies means both: processor for customer data, controller for your own employee, candidate and prospect records.

Is ISO 27701 better than ISO 27018?

For a European buyer, yes, because it is a certifiable management system with its own certificate rather than a code of practice recorded inside an ISO 27001 scope statement. ISO 27018 is cheaper, narrower and specific to public cloud processors, and it remains a reasonable answer when one customer named it. The comparison is set out on the cloud pair page.

How long does ISO 27701 take to implement?

Six to twelve months alongside an ISO 27001 implementation, and three to six months added where a working ISMS already exists. The long pole is almost never the documentation. It is building the records of processing inventory and the individual rights process, because both require somebody to walk every system and ask what personal information it holds, why, and for how long.