Two different purposes
GDPR establishes obligations for processing personal data within its scope. These include principles, lawfulness, information for individuals and their rights. ISO/IEC 27701:2025 is an independent privacy information management system (PIMS) standard. It can be used alongside an ISO 27001 management system. Legal assessment still depends on the specific processing activity.
A practical comparison
| Question | GDPR | ISO 27701 |
|---|---|---|
| What is it? | European legislation on personal data. | A privacy management standard. |
| What do you assess? | Applicable obligations for your role and processing activities. | The management system within its selected scope against the standard. |
| What do you demonstrate? | How the specific processing meets applicable requirements. | How privacy management is organised and operated. |
| What does it not replace? | A completed record does not replace actual implementation. | A standards assessment does not replace a full legal assessment. |
What does a certificate say?
Read the standard edition, scope, validity and issuing body. A statement about a defined management system is not an unlimited statement about every activity of a business. Do not automatically equate an ISO 27701 certificate with an approved data protection certification mechanism under GDPR Article 42. Check the specific mechanism and its approval. Article 42 also states that certification under its framework does not reduce the controller’s or processor’s responsibility for compliance.
Connect legal decisions to operation
A practical approach is to connect each processing assessment to an owner, safeguards and evidence of operation. Record, for example, where the legal-basis assessment is held, how information is provided to individuals and who evaluates changes. Use clear references to records of processing and, where relevant, the DPIA. This helps avoid contradictory decisions in different documents about the same activity.
Fictional example: a new customer analysis
A fictional organisation with a PIMS wants to use existing customer data for a new analysis. The project team first examines the purpose, data, legal justification and possible consequences for individuals. Its existing certificate does not automatically resolve this new question. Following assessment, the team records the decision and necessary changes. An owner checks whether settings, information provided and access permissions match that decision. This example describes a working method, not a completed customer engagement.
Start with the question you need to answer
If a customer needs assurance about particular processing, clarify the activity and evidence relevant to the request. If you want to improve privacy management, identify recurring decisions and checks that need better organisation. Keep the scope of every statement clear. Use the GDPR text for legal requirements and the applicable standard for the standards assessment.