ISO/IEC 27701:2019 · PIMS

Privacy management built into the management system

ISO/IEC 27701:2019 extends ISO/IEC 27001 and ISO/IEC 27002 to the management of Personally Identifiable Information (PII). The standard specifies requirements and provides guidance for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS).

The standard and its positioning

ISO/IEC 27701:2019 is an extension of the ISO 27000 family dedicated to personal data protection. It can only be applied in conjunction with ISO/IEC 27001 and ISO/IEC 27002: all requirements of the information security management standard apply to the PIMS, supplemented by privacy-specific requirements. The PIMS is therefore a subset of the ISMS, sharing the same governance structure, internal audit processes, management review cycles, and continual improvement framework.

The standard introduces a structuring distinction between two legal and functional roles: the PII Controller, who determines the purposes and means of processing personal data, and the PII Processor, who processes that data on behalf of the controller. Each role has its own set of controls, defined respectively in Annex A (PII Controller) and Annex B (PII Processor). An organisation may act in both roles simultaneously and must then implement both sets of controls.

Standard architecture · Extension, not replacement

ISO/IEC 27701 does not create a standalone management system: it enriches an existing ISMS by integrating privacy protection requirements. Clauses 4 through 10 of ISO 27001 each receive a 27701 extension; the 93 controls of ISO 27002 are complemented by the Annex A and B controls, some of which map directly to GDPR articles listed in Annex C.

Annex C of the standard maps each PIMS control (Annexes A and B) to the corresponding articles of the General Data Protection Regulation (GDPR, (EU) 2016/679). This mapping does not constitute a GDPR compliance certification — which remains the remit of national supervisory authorities — but it facilitates demonstrating the implementation of appropriate technical and organisational measures required by the regulation.

The two roles: PII Controller and PII Processor

Annex A

PII Controller

Responsable de traitement

The organisation determines the purposes and means of processing. Annex A covers obligations towards data subjects: lawful basis for processing, rights of access, rectification, and erasure, portability, restriction, and objection. It also includes requirements for international data transfers and breach notification to data subjects.

Annex B

PII Processor

Sous-traitant

The organisation processes personal data on behalf of a controller. Annex B covers contractual obligations towards the controller: scope and purpose of processing under contract, management of sub-processors, breach notification obligations, assistance to the controller in fulfilling data subject rights, and return or deletion of data at contract end.

Annex C · GDPR Mapping

Mapping to the General Data Protection Regulation

Annex C cross-references each PIMS control (Annexes A and B) with the corresponding GDPR articles ((EU) 2016/679). This mapping enables organisations subject to GDPR to identify which technical and organisational measures (Article 32) and documentation obligations (Articles 13, 14, 28, 30) the PIMS helps fulfil. It also serves as a support during interactions with supervisory authorities (CNIL, ICO, etc.) or during compliance audits.

Training approach

ISO/IEC 27701 sits within a normative and regulatory ecosystem that training must make intelligible. Mastering the PIMS requires understanding its foundations (ISO 27001 / 27002), its conceptual frameworks (ISO 29100, ISO 29134), and the regulatory obligations it helps to structure.

ISO/IEC 27701:2019

Privacy Information Management System (PIMS) — extension of ISO 27001 and ISO 27002 for personal data protection

Reference ISO standards

ISO/IEC 27001:2022

ISMS — mandatory foundation for the PIMS. All clauses 4 to 10 apply to the personal data protection scope

ISO/IEC 27002:2022

93 security controls — supplemented by the PIMS controls in Annexes A and B

Privacy protection framework

ISO/IEC 29100

Privacy framework — terminology, actors (PII Principal, Controller, Processor) and foundational privacy principles

ISO/IEC 29134

Guidelines for Privacy Impact Assessment (PIA / DPIA) — operational complement to the PIMS

Regulatory environment

GDPR · (EU) 2016/679

General Data Protection Regulation — Annex C of the standard maps its controls to the relevant GDPR articles

National data protection laws

LGPD (Brazil), PDPA (Thailand), PIPEDA (Canada) — the standard provides an implementation framework applicable beyond the GDPR

ISO/IEC 27701 is often approached as another compliance layer. Its real value is different: it requires organisations to treat personal data protection as a structural component of the management system, not a documentary add-on. That shift — from compliance to governance — is what training must accompany.

Dominique Bourra · PECB Platinum Trainer

International experience

Delivery context

ISO/IEC 27701 training is delivered to Data Protection Officers (DPOs), information security managers, auditors, legal counsel specialised in personal data, and IT teams responsible for implementing technical measures. It is particularly suited to organisations already certified to ISO/IEC 27001 that wish to extend their ISMS to cover the privacy dimension, as well as to service providers subject to contractual GDPR compliance obligations.

Training formats

Programmes are delivered in person and online, in French and English. They cover the full implementation cycle — from initial gap analysis to certification readiness — and address in depth both roles (Controller and Processor) as well as the GDPR mapping. Particular attention is given to practical cases involving organisations acting simultaneously in both roles, common in cloud services, healthcare, and digital services sectors.

ISO/IEC 27701 certified training · All PECB levels
Foundation · Lead Implementer · Lead Auditor · In-house tailored programmes

Request a programme