ISO/IEC 27701:2025 is the second edition of the international standard for Privacy Information Management Systems (PIMS), published in October 2025. The most significant change compared to the previous 2019 edition is that it now operates as a standalone standard, meaning that organizations can be certified against it without requiring prior or parallel certification to ISO/IEC 27001. For organizations already certified to the previous ISO 27701:2019 edition, the following milestones apply:

  • 31 October 2026: All new certifications issued from this date onwards must comply with the 2025 edition.
  • 31 October 2027: After this date, certificates issued against the 2019 edition will no longer be valid, and a full initial audit will be required for recertification.

Key Changes and Features of the 2025 Edition

  • Standalone Structure: The standard adopts the Harmonized Structure of ISO standards, with Clauses 4 to 10. It fully addresses the organizational context, leadership, planning, support, operation, performance evaluation and continual improvement.
  • Risk Management and Climate Change: It introduces explicit requirements for planning changes and taking climate change into consideration within the organization’s context (Clauses 4.1/4.2 and 6.3).
  • Streamlining of Security Controls: 52 controls that were not directly related to privacy have been removed. The standard now includes 29 targeted information security controls from ISO/IEC 27001:2022 that impact data protection, as well as 11 new controls (e.g. Threat Intelligence and Cloud Services).
  • Annex Structure: Annex A now includes 78 privacy controls divided into categories (34 for controllers, 21 for processors and 31 common controls).

Benefits for Organizations

The standard reduces the cost of adoption for organizations seeking to implement an audited privacy governance framework, without requiring the full implementation of an Information Security Management System (ISMS). At the same time, it provides:

  • Alignment with Regulatory Requirements: It supports compliance with the GDPR, the e-privacy directive, the AI Act, the Data Act and other data protection and privacy laws worldwide.
  • Enhanced Accountability and Trust: It provides documented evidence, through an independent external audit, to supervisory authorities, customers and business partners that personal data is managed in a systematic, controlled and reliable manner.
  • Integration of PIA: It integrates the performance of Privacy Impact Assessments (DPIA / PIA) into day-to-day operations.