June 2026. ISO/IEC 27701:2025 is an independent PIMS standard. It can be integrated with an existing ISO 27001 management system. Enterprise customers and supervisors increasingly ask for integrated security and privacy evidence, not separate folders that contradict each other.
Coordinate the PIMS and ISMS
- define the PIMS scope and explain its relationship to the ISMS scope;
- assess all applicable PIMS requirements; an additional SoA section alone is not a complete implementation;
- shared risk assessment, tag privacy and security risks;
- DPO involved in risk, DPIA and incidents with personal data.
GDPR overlap
ISO 27701 does not replace GDPR compliance. It helps with processor agreements, subprocessors, DPIAs and data subject rights, if you link evidence to controls. Link to privacy hub and ISO 27701.
Practical route
- Assess current practice against ISO/IEC 27701:2025, including management system requirements and relevant privacy measures.
- Prioritise high-impact processing (HR, customer data, healthcare).
- Internal audit sample on DPIA + privacy incident register.
For a specific customer request, record the privacy information requested and who is authorised to disclose it. One management review agenda for both prevents contradictory messages.
Processors and subprocessors
ISO 27701 emphasises PII in the chain: which subprocessors, which countries, which assurance. Update processor agreements when ISO 27701 controls introduce new requirements, not only at contract renewal.
DPIAs and 27701 risk treatment must reference the same processing. Duplicate descriptions with contradictory conclusions are due diligence red flags.
Select an appropriate internal audit sample based on risk and previous findings, from DPIA to technical measure and retention.
Next steps in your ISMS
Turn this article into one concrete action in your risk register or improvement plan: owner, deadline, expected evidence. Discuss progress in the next management review, auditors and chain partners want decisions, not policy intent alone. Link where possible to existing ISO 27001, NIS2 or GDPR documentation so you do not maintain parallel folders.
Questions on scope, certification or chain requirements? Use our readiness overview and knowledge base for deeper guidance. This article does not replace legal or audit advice for your situation.
Share relevant findings briefly with line management and procurement, compliance becomes workable when the whole organisation recognises the same priorities. Repeat the chosen action quarterly in team meetings and update evidence locations in your SoA or control plan so surveillance samples are easy to answer.
