ISO/IEC 27701
Until 2019 this standard was an extension, and nobody certified privacy without first building an entire security management system. The October 2025 revision ended that requirement. For a company that already treats personal data seriously and now has to prove it to a customer or a regulator, the road got significantly shorter.
DM11 prepares your company and runs the implementation. The audit and the certificate come from an accredited certification body that you contract. The standard covers privacy management and does not replace legal advice on data protection law: the two go together, and DM11 has digital law specialists on the team.
Who runs the implementation
Data protection specialists certified by EXIN (DPO, PDPP and PDPF)
ISO/IEC 27001 Lead Auditor certified by BSI
Legal advisory in privacy and data protection
17 years of governance, risk and compliance
WHAT CHANGED, AND WHY IT MATTERS
ISO/IEC 27701 sets the requirements for a privacy information management system. It organises how a company decides what it may do with personal data, who answers for each decision, and how that is evidenced over time. In the revision published on 14 October 2025 it stopped being an appendix to security and started standing on its own.
This is the change that rewrites the budget. In the 2019 version, certifying privacy meant having or building the whole security management system first. The standard is now self-contained, and a company can certify privacy without going through 27001. If you received a recent proposal saying otherwise, it was written against the old version.
The revision adopted the harmonised structure of clauses 4 to 10, the same as ISO 27001 and ISO/IEC 42001 for AI governance. In practice, a company already running one of those reuses context, leadership, planning and management review instead of maintaining three parallel systems.
Annex A separates the controls by role: one set for controllers, another for processors, and a block that applies to both. Defining your role in each processing activity is the first decision of the project and the one that most changes its size. Many companies are a controller in one flow and a processor in another.
The standard carries annexes linking the controls to the GDPR and to other privacy references, including the 2019 version for anyone migrating. That is what makes the certificate useful as an answer to a European customer, and what saves work for a company that already organised itself for a data protection law.
WHO USUALLY NEEDS IT
Data protection law already obliges you, and nobody certifies a law. ISO 27701 comes in when you have to prove to third parties that the obligation is being met with method.
A contract with an EU company usually demands guarantees about personal data processing. An internationally recognised certificate answers that better than a dossier assembled in a hurry, and it answers once for every customer rather than one at a time.
A company that processes data on someone else's behalf receives a privacy questionnaire from every customer, each in a different format. The certificate swaps that queue for a single document, and the processor control set was designed for exactly that role.
An enforcement action, a reported incident, or a sector that became a priority. A working privacy management system is the difference between demonstrating diligence with dated documents and trying to reconstruct the story after the question has arrived.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern repeats. Where a client agrees, we give named references in a conversation.
Payroll and benefits services
The company processed the personal data of thousands of its customers' employees and treated all of it as if it were its own. The contracts did not say who answered for what, and a large customer opened a privacy audit the company had no way to answer.
We started by separating the roles flow by flow: where it was a controller and where it was a processor. That distinction changed the whole design of the programme and much of the contractual wording. The inventory of processing activities, the legal bases and the processor control block followed.
The customer's audit was answered with a document instead of a meeting. The company then began using the same material commercially, because its processor role was clear in the contract and stopped being an argument at every renewal.
Technology, serving Europe
The company had run a data protection compliance project two years earlier, with good results and no maintenance since. When a European customer asked for evidence of adequate processing, what existed was an out-of-date report and the memory of the people who took part.
We reused what the earlier project had left behind, which was more than the board expected, and what was missing was precisely the management system: who reviews, when, with what record. We built that and mapped the controls against the GDPR using the standard's own annexes.
The company ended up with a system that maintains itself and a mapping ready to answer European customers. The earlier project stopped being a sunk cost and became the base of the new one.
Private healthcare
The operation handled health information, which the law treats as sensitive personal data, and applied the same controls to it as to everything else. There was no intent to get it wrong: nobody had made the distinction on paper, so it did not exist in practice.
We classified the processing activities by the nature of the data and reinforced where the law demands more: a specific legal basis, tighter access control, a record of who consults what, and retention periods set by type of information.
The difference showed up in access control: dozens of people could reach patient records with no functional need, and nobody knew because there was no log. After the project, access became justified, logged and reviewed.
HOW WE RUN IT
The method is the one we use for ISO 27001, adapted to what privacy has of its own: the role in each processing activity, the legal basis and the data subject's rights. Led by an external specialist, with one focal point from your team, and each requirement assessed on a binary scale rather than a subjective score nobody defends in an audit.
We define the scope and boundaries of the management system (clause 4), engage leadership and set up the privacy governance (clause 5). In parallel we map the personal data processing activities and decide, activity by activity, whether the company is controller or processor.
Scope and boundaries of the management system approved
Inventory of personal data processing activities
Role defined per activity: controller or processor
Privacy governance in place, with the data protection officer formalised
MilestoneProcessing inventory approved and the role defined for 100% of the mapped flows.
We run the gap analysis against clauses 6 and 7, record the legal basis for each processing activity and assess the risks to the data subjects' privacy, which are not the same as information security risks. Where the law requires it, we produce the impact assessment.
Legal basis recorded for every processing activity
Assessment of risks to data subjects' privacy
Data protection impact assessment where applicable
Treatment plan and statement of applicability for the controls
MilestoneLegal bases approved by legal counsel and the treatment plan signed off by leadership.
We implement the Annex A controls matching the company's role, with the shared block serving both. This is the phase where handling data subject requests stops being improvisation: deadline, channel, record and a standard response, plus retention and disposal set by type of data.
Controller controls, processor controls or both, according to the role
A data subject request process, with deadlines and records
Retention and disposal policy by type of data
Privacy clauses reviewed in third-party contracts
MilestoneFirst cycle of data subject requests handled within the deadline and fully recorded.
We run the internal audit (clause 9) with a consultant independent of whoever implemented, conduct the management review and handle the findings (clause 10). We consolidate the evidence and stay with you through both stages of the external audit.
Internal audit run by an independent consultant
Management review, with findings addressed
Consolidated privacy evidence repository
Support through stage 1 and stage 2 of the external audit
MilestoneCertification audit completed and the certificate issued by the accredited body.
HOW LONG IT TAKES
We do not publish a standard timeline, because a published timeline becomes a promise. The spread is even wider here than for ISO 27001, for one specific reason: a company that ran a data protection project with method arrives halfway there, and a company that ran a paper project arrives at roughly zero. The first conversation already tells the two apart.
An up-to-date processing inventory and recorded legal bases take months off. A two-year-old report nobody maintained is usually worth less than it looks, and it is honest to say so before starting.
Being only a controller is the shortest road. Holding both roles across different flows multiplies the applicable controls and the contract clauses to revise.
With ISO 27001 or ISO 42001 in operation, clauses 4 to 10 are the same and much of the governance work is already done. With none, that base has to be built, and it can now be built directly on 27701.
THE ROLES ARE KEPT APART
As with every certifiable standard, the certificate comes from an accredited body you contract, never from DM11, and the clause 9 internal audit is run by someone who did not implement. There is a second separation here: the standard covers management and does not replace legal advice on data protection law. Both sides need to talk, and the project runs with a digital law specialist alongside the management specialist.
DM11 prepares, implements and supports. It issues no certificate
You contract the certification body, and the choice is yours
The clause 9 internal audit is carried out by someone who did not implement
The standard organises the management; interpreting the law stays with counsel
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered straight.
No, and that is the change that alters the maths. Up to the 2019 version, 27701 was an extension and could not be certified without 27001 in place. The revision published on 14 October 2025 made the standard self-contained: it no longer depends on implementing 27001 or 27002. If you received a proposal saying otherwise, it was written against the previous version. Holding 27001 still helps considerably, because clauses 4 to 10 are the same, but it stopped being a prerequisite.
In the first conversation we look at what exists in terms of inventory, legal bases and the data subject request process, and tell you honestly whether the road is short or long.