Skip to content

GDPR vs ISO 27701

GDPR sets legal requirements for personal data. ISO 27701 supports privacy management; a certificate does not replace assessment of the specific processing.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Run the ISO 27001 readiness scan

Two different purposes

GDPR establishes obligations for processing personal data within its scope. These include principles, lawfulness, information for individuals and their rights. ISO/IEC 27701:2025 is an independent privacy information management system (PIMS) standard. It can be used alongside an ISO 27001 management system. Legal assessment still depends on the specific processing activity.

A practical comparison

QuestionGDPRISO 27701
What is it?European legislation on personal data.A privacy management standard.
What do you assess?Applicable obligations for your role and processing activities.The management system within its selected scope against the standard.
What do you demonstrate?How the specific processing meets applicable requirements.How privacy management is organised and operated.
What does it not replace?A completed record does not replace actual implementation.A standards assessment does not replace a full legal assessment.

What does a certificate say?

Read the standard edition, scope, validity and issuing body. A statement about a defined management system is not an unlimited statement about every activity of a business. Do not automatically equate an ISO 27701 certificate with an approved data protection certification mechanism under GDPR Article 42. Check the specific mechanism and its approval. Article 42 also states that certification under its framework does not reduce the controller’s or processor’s responsibility for compliance.

A practical approach is to connect each processing assessment to an owner, safeguards and evidence of operation. Record, for example, where the legal-basis assessment is held, how information is provided to individuals and who evaluates changes. Use clear references to records of processing and, where relevant, the DPIA. This helps avoid contradictory decisions in different documents about the same activity.

Fictional example: a new customer analysis

A fictional organisation with a PIMS wants to use existing customer data for a new analysis. The project team first examines the purpose, data, legal justification and possible consequences for individuals. Its existing certificate does not automatically resolve this new question. Following assessment, the team records the decision and necessary changes. An owner checks whether settings, information provided and access permissions match that decision. This example describes a working method, not a completed customer engagement.

Start with the question you need to answer

If a customer needs assurance about particular processing, clarify the activity and evidence relevant to the request. If you want to improve privacy management, identify recurring decisions and checks that need better organisation. Keep the scope of every statement clear. Use the GDPR text for legal requirements and the applicable standard for the standards assessment.

Primary sources for this topic

Frequently asked questions

Does ISO 27701 automatically make an organisation GDPR-compliant?
No. Assessment of the privacy management system does not replace assessment of each specific processing activity. Check your role, the applicable legal requirements and how actual operation meets them. Also read the scope and standard edition on a certificate before using it to make a statement to customers or affected individuals.
Is ISO 27701 certification the same as GDPR Article 42 certification?
Do not automatically equate them. Article 42 provides its own framework for approved data protection certification mechanisms. Check the particular mechanism, approved criteria and authorised certification body. Even certification under that article does not remove the controller’s or processor’s responsibility for compliance with GDPR in relation to the processing concerned.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)