ISO 27701 for controllers and processors: what changes

ISO 27701 is not a standalone privacy silver bullet, but a critical extension that turns a security-focused ISO 27001 setup into a robust Privacy Information Management System (PIMS). If your firm handles personal data, the shift from 'protecting assets' to 'protecting data subjects' requires a fundamental change in how you document, process, and justify every byte of information you hold.

Michael McCarroll 16 min read Updated June 2026

The Controller's Burden: Accountability and Transparency

If you are a Controller, you own the risk and the relationship with the data subject. Your primary shift under ISO 27701 is from technical security to legal accountability, requiring you to justify why you are collecting data in the first place. You must document specific purposes for processing and ensure that these are communicated clearly to subjects before data is ever ingested.

Clause 7 of the standard specifically targets Controllers, introducing requirements that go far beyond standard IT security. You are now responsible for ensuring that the PII (Personally Identifiable Information) you hold is accurate, up-to-date, and limited to what is strictly necessary. This implies a need for a robust data retention schedule that is actually enforced, not just written in a policy.

Furthermore, as a Controller, you take on the burden of third-party risk management from a privacy perspective. You must ensure that every processor you hire provides sufficient guarantees regarding technical and organisational measures. This means your vendor onboarding process must now include a privacy impact assessment for any tool that touches customer or employee data.

  • Documenting the legal basis for processing (Consent, Contract, Legitimate Interest).
  • Maintaining a comprehensive Record of Processing Activities (RoPA) under Clause 7.2.2.
  • Implementing Privacy by Design and Default in the SDLC.
  • Providing transparent privacy notices that meet PIMS requirements.
  • Managing Data Subject Access Requests (DSARs) within defined timelines.

The Processor's Shift: Stewardship and Instruction Compliance

Processors often make the mistake of thinking ISO 27701 is 'ISO 27001 with more encryption.' This is incorrect. As a Processor, your role under Annex B is to demonstrate that you are a reliable steward of someone else's data, strictly adhering to their instructions. You are no longer just protecting your own perimeter; you are protecting your customer's legal liability.

The standard requires Processors to maintain record-keeping that mirrors the Controller's instructions. If a client tells you to delete data after 30 days, you need an automated or audited manual process to prove that happened. You must also be prepared to support your customers during audits, providing them with the clear documentation they need to satisfy their own compliance requirements.

Sub-processing is another area where many firms fail to meet the standard. You cannot simply outsource a function to a third party without notifying the Controller and ensuring a data processing agreement (DPA) is in place. ISO 27701 forces you to map these relationships and keep them updated in a central register that is reviewed at least annually.

  • Restricting processing to the documented instructions of the Controller.
  • Ensuring sub-processors are held to the same contractual standards.
  • Assisting the Controller in meeting their DSAR obligations.
  • Providing evidence of security measures to the Controller upon request.
  • Notifying the Controller of any data breach without undue delay.

Integrating PIMS with your Existing ISMS

To achieve ISO 27701, you don't throw away your ISO 27001 documentation; you refine it. The management system requirements in Clause 5 and 6 require you to integrate privacy into your existing risk management framework. This means when you identify a risk to 'Confidentiality,' you must also evaluate the risk to the 'Rights and Freedoms' of the individual.

Terminology changes slightly but significantly. Where ISO 27001 talks about 'Information Assets,' ISO 27701 focuses on 'PII.' Your asset register may need a new column or a secondary view that categorises data by its sensitivity and the role your organisation plays (Controller vs. Processor) for that specific data set.

Internal audits must also evolve. A standard security audit might check if a firewall is configured correctly, but a PIMS audit will check if the marketing team is still using a lead list that was supposed to be deleted six months ago. Bridging this gap requires training your auditors to look for data lifecycle issues rather than just technical vulnerabilities.

  • Defining the PIMS scope to include all personal data environments.
  • Updating the Statement of Applicability (SoA) to include PIMS-specific controls.
  • Conducting a Privacy Impact Assessment (PIA) for high-risk processing.
  • Merging Privacy into the Internal Audit cycle.

Technical Controls: Beyond Standard Encryption

While ISO 27001 Annex A gives you a foundation of 93 controls (in the 2022 version), ISO 27701 adds significant depth to how these are applied to personal data. For example, access control is no longer just about keeping hackers out; it is about ensuring that an employee in Finance cannot see PII in the HR system without a legitimate business reason. This granular level of control is a core requirement of the standard.

Logging becomes a privacy tool under ISO 27701. You aren't just logging failed login attempts for security; you are logging access to sensitive records to ensure that data is not being misused internally. If a breach occurs, these logs are the only way to determine exactly which data subjects were affected, which is a mandatory reporting requirement under most global privacy laws.

Technical measures like pseudonymisation and 'Privacy by Design' are now audit criteria. If you are building a new feature, you must prove that privacy was considered at the requirements stage, not bolted on at the end. An auditor will want to see the Jira tickets or design documents where privacy requirements were explicitly defined and tested before the code went to production.

  • Access Control: Restricting PII access to specific roles (Need-to-Know).
  • Logging and Monitoring: Tracking who accessed PII and when.
  • Encryption: Using strong standards for data at rest and in transit.
  • Data Masking: Using pseudonymisation to reduce risk in dev/test environments.

Implementation Strategy and Timelines

The road to ISO 27701 certification usually takes between 4 and 9 months, depending on the maturity of your existing ISO 27001 system. The first month should be dedicated to role definition; many companies find they are a Controller for employee data but a Processor for customer data, requiring them to implement controls from both Annex A and Annex B of the standard.

Data discovery is often the most time-consuming phase. You cannot protect what you don't know you have. Teams often find PII lurking in legacy databases, Slack channels, or forgotten AWS buckets. Fixing these 'data leaks' before the auditor arrives is essential to passing the certification. It is better to find these yourself during the gap analysis stage than have them flagged as a Major Non-Conformity later.

Finally, ensure your leadership team understands the stakes. ISO 27701 is a strategic asset that shortens sales cycles with enterprise clients who are terrified of GDPR fines. By positioning the PIMS as a business enabler rather than an IT burden, you ensure the budget and resources are available to maintain the system long-term. Maintenance is harder than implementation; it requires a culture of privacy, not just a folder of policies.

  • Define the PII Controller/Processor roles clearly for every product line.
  • Perform a comprehensive Data Discovery exercise to locate 'Shadow PII'.
  • Update your Risk Assessment methodology to include Impact on Data Subjects.
  • Review and sign Data Processing Agreements with all high-risk vendors.
  • Train staff on privacy-specific incident response (the 72-hour window).

Build a GDPR-ready Privacy Framework with ISO-STANDARD.app

Stop managing privacy out of spreadsheets. Our GRC platform maps ISO 27001 security controls directly to ISO 27701 privacy requirements, helping you build a demonstrably compliant PIMS that wins enterprise trust.

ISO-STANDARD.app ships a ready-to-adopt ISO 27701 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Frequently asked questions

Can I get ISO 27701 certification without having ISO 27001?
No, you cannot. ISO 27701 is an extension standard, meaning it builds upon the Annex A controls and Management System requirements of ISO 27001. You must be certified to or seeking certification for ISO 27001 simultaneously to achieve 27701.
What is the main difference between a Controller and a Processor in the standard?
A controller determines the purposes and means of processing personal data, whereas a processor acts on behalf of the controller. ISO 27701 has separate annexes (Annex A for Controllers, Annex B for Processors) with different control sets reflecting these distinct legal obligations.
How long does it take to implement ISO 27701?
For a mid-market firm with an existing ISO 27001 certification, expect a 4 to 6-month runway. This involves gap analysis, updating the Record of Processing Activities (RoPA), conducting DPIAs, and updating third-party contracts before the external audit.
Does ISO 27701 satisfy GDPR requirements?
While ISO 27701 is not a formal GDPR certification under Article 42, it is the closest international equivalent. Regulators view it as 'best practice' evidence that you have a functional Privacy Information Management System, which can significantly mitigate fines in the event of a breach.
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →