In October 2025, the International Standards Organization (“ISO”) released a second version of its flagship standard for privacy governance, ISO/IEC 27701.
The 2025 version, entitled “Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance”, updates and replaces the first edition of the standard from 2019.
Similar to the original version, the 2025 standard provides a structured, certifiable framework for organizations to demonstrate accountability, manage risks, and continually improve their privacy practices around the processing of personally identifiable information (“PII”).
That said, the 2025 version differs from its predecessor in a number of material ways.
Independence from ISO/IEC 27001
The most substantive change in the 2025 version of ISO/IEC 27001 is that it is no longer an extension to ISO/IEC 27001, the leading international standard for information security. Under the 2025 version, organizations can establish and certify a standalone Privacy Information Management System (“PIMS”) without building upon an underlying Information Security Management System (“ISMS”). In other words, ISO/IEC 27701 certification no longer requires certification to ISO/IEC 27001:2022.
That said, given the significant overlap and alignment between the required information security controls and processes in ISO/IEC 27701 and those in ISO/IEC 27001, layering a PIMS on an ISMS is likely still the most effective approach for most organizations.
But by creating independence from ISO/IEC 27001, the International Standards Organization was able to restructure ISO/IEC 27701 with the same architecture as other ISO management system standards (i.e., identical clause numbers, similar clause descriptions, etc.), enabling seamless integration with a variety of other ISO standards, including those for business continuity and quality management, not just information security.
Modified Control Sets
Another key difference in the 2025 version is a reworking of the control sets included in the Annexes of the standard.
ISO/IEC 27701:2025 contains three sets of controls within its Annex A:
- 31 controls for PII Controllers (entities who determine the purposes and means of PII processing);
- 18 controls for PII Processors (entities who carry out PII processing on the instructions of a Controller); and
- 29 security controls for both PII Controllers and PII Processors.
Although the 2025 version has a new numbering scheme as compared to its predecessor, the content of the PII Controller and PII Processor controls in Annexes A.1 and A.2 were not materially changed.
The significant change comes in the form of Annex A.3, which now has mandatory information security control statements that are required for consideration of applicability, as opposed to implementation guidance only, which the 2019 version had contained.
These information security controls must be addressed by both PII Controls and PII Processors and are mapped to the 2022 version of ISO/IEC 27001.
Additional Changes
The 2025 version contains a number of other changes in relation to the prior release:
- The organization’s privacy policy must provide a framework for setting privacy objectives;
- The process for privacy risk treatment must identify and document elements of the organization’s information security program; and
- Implementation guidance for all three sets of controls in ISO/IEC 27701 is now consolidated into Annex B, which should be considered when determining the organization’s relevant PII Controller, PII Processor, and security controls.
Certification and Transition
Organizations seeking initial certification to ISO/IEC 27701 should absolutely implement the 2025 version of the standard rather than its predecessor. Furthermore, ISO has already released ISO/IEC 27706:2025, a standard for certification bodies that enables them to audit and certify to the 2025 version.
That said, the Global Accreditation Cooperation Incorporated (“Global ACI”) has not yet released guidance for organizations that were already certified to the 2019 version to transition to the 2025 version. Past experience indicates that a transition window of 18-36 months will likely be allowed. Resiliam will continue to monitor Global ACI releases for developments and will provide timely updates.