ISO/IEC 27701:2019 is an extension of the ISO 27000 family dedicated to personal data protection. It can only be applied in conjunction with ISO/IEC 27001 and ISO/IEC 27002: all requirements of the information security management standard apply to the PIMS, supplemented by privacy-specific requirements. The PIMS is therefore a subset of the ISMS, sharing the same governance structure, internal audit processes, management review cycles, and continual improvement framework.
The standard introduces a structuring distinction between two legal and functional roles: the PII Controller, who determines the purposes and means of processing personal data, and the PII Processor, who processes that data on behalf of the controller. Each role has its own set of controls, defined respectively in Annex A (PII Controller) and Annex B (PII Processor). An organisation may act in both roles simultaneously and must then implement both sets of controls.
Standard architecture · Extension, not replacement
ISO/IEC 27701 does not create a standalone management system: it enriches an existing ISMS by integrating privacy protection requirements. Clauses 4 through 10 of ISO 27001 each receive a 27701 extension; the 93 controls of ISO 27002 are complemented by the Annex A and B controls, some of which map directly to GDPR articles listed in Annex C.
Annex C of the standard maps each PIMS control (Annexes A and B) to the corresponding articles of the General Data Protection Regulation (GDPR, (EU) 2016/679). This mapping does not constitute a GDPR compliance certification — which remains the remit of national supervisory authorities — but it facilitates demonstrating the implementation of appropriate technical and organisational measures required by the regulation.
Annex A
PII Controller
Responsable de traitement
The organisation determines the purposes and means of processing. Annex A covers obligations towards data subjects: lawful basis for processing, rights of access, rectification, and erasure, portability, restriction, and objection. It also includes requirements for international data transfers and breach notification to data subjects.
Annex B
PII Processor
Sous-traitant
The organisation processes personal data on behalf of a controller. Annex B covers contractual obligations towards the controller: scope and purpose of processing under contract, management of sub-processors, breach notification obligations, assistance to the controller in fulfilling data subject rights, and return or deletion of data at contract end.
Annex C · GDPR Mapping
Mapping to the General Data Protection Regulation
Annex C cross-references each PIMS control (Annexes A and B) with the corresponding GDPR articles ((EU) 2016/679). This mapping enables organisations subject to GDPR to identify which technical and organisational measures (Article 32) and documentation obligations (Articles 13, 14, 28, 30) the PIMS helps fulfil. It also serves as a support during interactions with supervisory authorities (CNIL, ICO, etc.) or during compliance audits.
ISO/IEC 27701 sits within a normative and regulatory ecosystem that training must make intelligible. Mastering the PIMS requires understanding its foundations (ISO 27001 / 27002), its conceptual frameworks (ISO 29100, ISO 29134), and the regulatory obligations it helps to structure.
ISO/IEC 27701:2019
Privacy Information Management System (PIMS) — extension of ISO 27001 and ISO 27002 for personal data protection
Reference ISO standards
ISO/IEC 27001:2022
ISMS — mandatory foundation for the PIMS. All clauses 4 to 10 apply to the personal data protection scope
ISO/IEC 27002:2022
93 security controls — supplemented by the PIMS controls in Annexes A and B
Privacy protection framework
ISO/IEC 29100
Privacy framework — terminology, actors (PII Principal, Controller, Processor) and foundational privacy principles
ISO/IEC 29134
Guidelines for Privacy Impact Assessment (PIA / DPIA) — operational complement to the PIMS
Regulatory environment
GDPR · (EU) 2016/679
General Data Protection Regulation — Annex C of the standard maps its controls to the relevant GDPR articles
National data protection laws
LGPD (Brazil), PDPA (Thailand), PIPEDA (Canada) — the standard provides an implementation framework applicable beyond the GDPR
ISO/IEC 27701 is often approached as another compliance layer. Its real value is different: it requires organisations to treat personal data protection as a structural component of the management system, not a documentary add-on. That shift — from compliance to governance — is what training must accompany.
Delivery context
ISO/IEC 27701 training is delivered to Data Protection Officers (DPOs), information security managers, auditors, legal counsel specialised in personal data, and IT teams responsible for implementing technical measures. It is particularly suited to organisations already certified to ISO/IEC 27001 that wish to extend their ISMS to cover the privacy dimension, as well as to service providers subject to contractual GDPR compliance obligations.
Training formats
Programmes are delivered in person and online, in French and English. They cover the full implementation cycle — from initial gap analysis to certification readiness — and address in depth both roles (Controller and Processor) as well as the GDPR mapping. Particular attention is given to practical cases involving organisations acting simultaneously in both roles, common in cloud services, healthcare, and digital services sectors.