ISO/IEC
27701 has entered a new phase. Published on 14 October 2025, ISO/IEC
27701:2025 replaces the 2019 edition and transforms the Privacy Information
Management System (PIMS) standard from an extension of ISO/IEC 27001 and
ISO/IEC 27002 into an independent management system standard.
For
organizations currently certified to ISO/IEC 27701:2019, this is not simply an
editorial revision. The new edition changes the structure of the standard,
strengthens privacy governance and reorganizes requirements and controls for
personally identifiable information (PII) controllers and processors.
Under
the transition arrangements communicated to QRC-certified clients,
organizations holding QRC-issued accredited ISO/IEC 27701:2019 certification
must complete their transition to ISO/IEC 27701:2025 by 31 October 2027.
After the applicable deadline, accredited certification against the 2019
edition will no longer remain valid.
So,
what has changed, and what should certified organizations do now?
What Is ISO/IEC 27701:2025?
ISO/IEC
27701:2025 specifies requirements and provides guidance for establishing,
implementing, maintaining and continually improving a Privacy Information
Management System.
A
PIMS helps an organization manage PII systematically by bringing privacy
responsibilities, risks, controls, objectives, monitoring and continual
improvement into a defined management framework. The standard applies to
organizations acting as PII controllers, PII processors or both, regardless of
their type, size or sector.
The
International Organization for Standardization describes ISO/IEC 27701 as a
framework that helps organizations demonstrate accountability, manage risks
involving PII and continually improve privacy practices. It can also support an
organization’s efforts to address applicable privacy obligations, although
certification does not automatically establish compliance with every privacy
law.
The Biggest Change: PIMS Is
Now a Standalone Standard
ISO/IEC
27701:2019 was designed as an extension to ISO/IEC 27001 and ISO/IEC 27002. In
practice, organizations implemented privacy requirements within an existing
Information Security Management System (ISMS).
The
2025 edition changes this model. ISO/IEC 27701 can now be implemented and
audited as an independent management system standard, without ISO/IEC
27001 certification being a prerequisite.
This
makes formal privacy management more accessible to privacy-led organizations
that may not require a separately certified ISMS. It also allows PIMS
governance to be structured around privacy-specific objectives while retaining
the ability to integrate with ISO/IEC 27001 and other management systems.
For
organizations already operating an integrated ISMS and PIMS, the change does
not mean the systems must be separated. The harmonized structure can support
continued integration, provided the organization clearly addresses all
applicable requirements and maintains effective governance across both systems.
Key Changes in ISO/IEC
27701:2025
Alignment
with the ISO Harmonized Structure
The
revised standard follows the familiar management system structure across
Clauses 4 to 10:
- Context
of the organization
- Leadership
- Planning
- Support
- Operation
- Performance
evaluation
- Improvement
This
structure improves alignment with standards such as ISO/IEC 27001, ISO 9001 and
ISO/IEC 42001. Organizations operating multiple management systems may
therefore find it easier to coordinate common processes such as objectives,
competence, internal audits, management reviews, corrective actions and
continual improvement.
However,
structural familiarity should not be mistaken for automatic conformity.
Existing PIMS documentation must be reviewed to ensure privacy-specific
requirements are addressed in their new clause locations and supported by
suitable evidence.
Stronger
Organizational Context and Privacy Governance
The
revised structure places privacy within the organization’s broader strategic
and operational context. Organizations need to consider the nature of their PII
processing, interested parties, applicable legal and regulatory environments,
technology dependencies and internal or external factors that may affect
privacy outcomes.
Leadership
also has a clearer role in ensuring that privacy responsibilities are embedded
across relevant functions. Privacy is not solely an IT or compliance concern
it can affect product design, marketing, human resources, procurement, legal,
customer operations and third-party management.
Updated
Controls for PII Controllers and Processors
ISO/IEC
27701:2025 reorganizes the privacy control structure and continues to
distinguish between responsibilities applicable to PII controllers and PII
processors.
Organizations
should revisit how they determine their role for each processing activity. A
business may act as a controller in one context and a processor in another,
which can change its obligations, contractual responsibilities and applicable
controls.
The
revised annex structure also provides implementation guidance and mappings that
can help organizations understand the relationship between the new and previous
editions.
Greater
Focus on Privacy Risk
The
new edition strengthens the independent treatment of privacy risk within the
management system. Risk assessment should consider how PII processing may
affect individuals as well as the organization.
This
broader perspective is important when evaluating new technologies, automated
decision-making, AI-assisted processing, extensive monitoring, large-scale
analytics, international operations and complex processor relationships.
Improved
Alignment with Other Privacy Frameworks
The
revised standard includes mappings to support comparison and integration with
recognized privacy references, including the ISO/IEC 29100 Privacy Framework
and the EU General Data Protection Regulation. It also provides links to
standards relevant to public-cloud PII processing and the protection of PII.
These
mappings can assist organizations in understanding relationships between
requirements, but they do not replace a legal assessment of the privacy laws
applicable to a particular processing activity or jurisdiction.
Who Needs to Transition?
The transition applies to organizations holding accredited ISO/IEC 27701:2019 certification that want to maintain valid accredited PIMS certification beyond the applicable deadline.  It is relevant across sectors, including:
- Technology
and software companies
- Cloud
and managed service providers
- Financial
institutions and fintech organizations
- Healthcare
and life-sciences organizations
- E-commerce
and digital-platform businesses
- Business
process outsourcing providers
- Government
and public-sector entities
- Organizations
processing employee, customer or partner PII at scale
For
QRC-certified clients, the transition should be planned within the existing
certification cycle so that the required audit and certification activities are
completed no later than 31 October 2027.
What Happens If the Transition
Is Not Completed?
Organizations that do not complete the transition by the applicable deadline risk losing the validity of their accredited ISO/IEC 27701 certification against the withdrawn 2019 edition.  That outcome may affect contractual commitments, supplier qualification, tenders, customer assurance and public claims linked to certified privacy management. Leaving the transition until the end of the window also creates operational risk: identified gaps may require changes to governance, documentation, controls, training and evidence before conformity can be demonstrated.  Early planning provides time to make controlled improvements and align the transition audit with an upcoming surveillance or recertification activity where feasible.
A Practical ISO/IEC 27701:2025
Transition Roadmap
- Review and Scope -  Understand the revised requirements, confirm the certified PIMS scope and identify where the organization acts as a PII controller or processor.
- Assess the Gaps -  Compare the existing PIMS with ISO/IEC 27701:2025, covering governance, privacy risks, controls, documented information and supporting evidence.
- Implement Required Changes -  Update relevant policies, procedures, risk records, responsibilities and privacy controls. Address emerging risks involving AI, cloud services, third parties and cross-border data transfers.
- Validate Readiness -  Build awareness among relevant teams, complete an internal audit and conduct a management review against the revised requirements.
- Complete the Transition Audit -  Coordinate the transition audit with QRC within the existing certification cycle, allowing sufficient time to address findings before 31 October 2027.
Common Transition Mistakes to Avoid
Organizations
can make the transition more manageable by avoiding a few recurring mistakes :
- Treating
the revision as a clause-renumbering exercise
- Assuming
ISO/IEC 27001 certification automatically demonstrates conformity with the
standalone PIMS requirements
- Failing
to reassess controller and processor roles
- Updating
policies without validating operational implementation
- Overlooking
cloud, AI, transfer and third-party processing risks
- Conducting
the internal audit too close to the transition audit
- Waiting
until 2027 to begin planning
The
transition should strengthen the PIMS-not merely preserve the certificate.
Questions Leadership Should
Ask
Leadership
and privacy teams can use the transition to test whether the PIMS remains
aligned with the organization’s current risk environment:
- Can we
clearly identify where and why we process PII?
- Are
our controller and processor roles accurate for each significant
processing activity?
- Have
changes in technology, AI use, cloud services or international transfers
altered our privacy risks?
- Can
process owners demonstrate that documented privacy controls operate
effectively?
- Do our
internal audit and management review processes evaluate privacy outcomes,
not only procedural completion?
- Is our
transition audit scheduled early enough to address unexpected findings?
If
any of these questions are difficult to answer, the organization should
prioritize them within its transition plan.
Plan Your ISO/IEC 27701:2025
Transition with QRC
ISO/IEC
27701:2025 gives privacy management a clearer, independent foundation while
preserving compatibility with established ISO management systems. Organizations
that begin early can use the transition to improve accountability, strengthen
privacy-risk governance and demonstrate continued confidence to customers and
stakeholders.
QRC
Assurance and Solutions is an accredited certification body for ISO/IEC 27701.
QRC-certified clients should coordinate their transition audit within the
existing certification cycle and complete all applicable transition
requirements by 31 October 2027.
Ready to plan your transition
to ISO/IEC 27701:2025?
Contact
QRC to confirm the certification transition process, expected audit
arrangements and suitable scheduling for your organization.
 
Frequently Asked Questions
- When
was ISO/IEC 27701:2025 published?
ISO records the publication date of the second edition as 14 October 2025. It replaces the withdrawn ISO/IEC 27701:2019 edition. - What
is the ISO/IEC 27701:2025 transition deadline for QRC-certified clients?
Under the transition arrangements communicated to QRC-certified clients, the transition must be completed by 31 October 2027. Organizations should confirm their individual audit plan and certification-cycle arrangements with QRC. - Is
ISO/IEC 27001 still required for ISO/IEC 27701:2025?
No. ISO/IEC 27701:2025 is an independent management system standard and can be used without ISO/IEC 27001. Organizations may still integrate their PIMS and ISMS where this supports their objectives and operating model. - Can
the transition audit be combined with a surveillance or recertification audit?
Transition activities may be planned within the existing certification cycle, subject to applicable accreditation and certification arrangements. Organizations should coordinate the timing and audit requirements directly with QRC. - Does
ISO/IEC 27701 certification prove compliance with privacy laws?
Certification demonstrates that the organization’s PIMS conforms to the applicable standard requirements within its certified scope. It can support accountability and regulatory-alignment efforts, but it does not automatically prove compliance with every applicable privacy law.

+91 9594449393
+1 4847906355
+63 9208320598
+44 1519470017
+84 908370948
+7 9639173485
+62 81808037776
+90 5441016383
+66 993367171
+254 725235855
+256 707194495
+46 700548490