ISO 27701 vs GDPR is a comparison between a certifiable management system standard and a law, and the first thing to be clear about is that neither replaces the other. The GDPR is Regulation (EU) 2016/679: it binds controllers and processors, sets principles, lawful bases, rights, obligations and penalties of up to €20 million or 4% of worldwide annual turnover, and is enforced by supervisory authorities. ISO/IEC 27701:2025 is a standard for a privacy information management system — a PIMS — that an organisation implements and can have certified by an accredited body; since the October 2025 edition it stands alone, no longer requiring an ISO 27001 certificate underneath it.
The relationship is that a PIMS is one way of organising, evidencing and continually improving the things the GDPR requires, and a certificate is evidence — not proof — that the organisation does them. This guide sets the two side by side on ten points, maps the GDPR’s main obligations to the ISO 27701 clauses and Annex A controls that implement them, lists what each has that the other does not, and answers the question a certificate does and does not settle with a regulator.

ISO 27701 vs GDPR at a glance
| GDPR (Regulation (EU) 2016/679) | ISO/IEC 27701:2025 | |
|---|---|---|
| What it is | EU law on the protection of personal data, applicable since 25 May 2018 | International standard for a privacy information management system; second edition published 14 October 2025, replacing 2019 |
| Binding? | Yes — on controllers and processors established in the EU or targeting EU residents | No — voluntary, unless a contract or tender requires it |
| Scope of data | Personal data of natural persons in the EU | Personally identifiable information (PII) of any jurisdiction the organisation scopes |
| Structure | 99 articles in 11 chapters; 173 recitals | Clauses 4–10 (harmonized structure) plus Annex A controls: A.1 PII controllers, A.2 PII processors, A.3 information security controls for both |
| Roles | Controller, processor, joint controllers, DPO, representative, supervisory authority | PII controller, PII processor, PII principal — with the controls split by role |
| Rights of individuals | Articles 12–22: information, access, rectification, erasure, restriction, portability, objection, automated decision-making | Controller controls on handling PII principals’ requests and obligations to them |
| Security | Article 32: appropriate technical and organisational measures | A.3 information security controls, plus the risk process in clauses 6 and 8 |
| Verification | Supervisory authority investigation and enforcement; Article 42 certification schemes (few exist) | Accredited third-party certification audit on a three-year cycle |
| Consequence of failure | Fines, orders, bans on processing, liability to data subjects | Nonconformities, suspension or withdrawal of the certificate |
| Prerequisite | None | None since 2025 — an ISO 27001 certificate is no longer required |
ISO 27701 vs GDPR article by article: the mapping
| GDPR obligation | Article(s) | Where ISO 27701:2025 addresses it |
|---|---|---|
| Principles: lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality, accountability | 5 | Clause 4 context and clause 6 planning set the framework; A.1 controller controls on purpose, lawful basis, minimisation, accuracy and retention implement the principles |
| Lawful basis and consent | 6–9 | A.1 controls on identifying and documenting the basis for processing and on obtaining, recording and allowing withdrawal of consent |
| Information to data subjects (privacy notices) | 12–14 | A.1 controls on determining and providing information to PII principals |
| Data subject rights | 15–22 | A.1 controls on handling requests, and processor controls on assisting the controller |
| Data protection by design and by default | 25 | A.1 privacy-by-design control; clause 8 operational planning |
| Records of processing activities | 30 | A.1 and A.2 controls on records of processing; clause 7.5 documented information |
| Security of processing | 32 | A.3 information security controls; clause 6.1 risk assessment and treatment |
| Breach notification (72 hours to the authority; to data subjects where high risk) | 33–34 | A.3 incident controls and A.1/A.2 controls on notifying and assisting; clause 10 improvement |
| Data protection impact assessment | 35 | A.1 control on privacy impact assessment; clause 6 planning |
| Processor contracts and sub-processors | 28 | A.2 processor controls: documented instructions, customer obligations, sub-processor engagement; A.1 controls on supplier agreements |
| International transfers | 44–49 | A.1 and A.2 controls on the basis for and records of transfers between jurisdictions |
| Data protection officer | 37–39 | Clause 5 leadership: roles, responsibilities and authorities — the standard does not mandate a DPO, the GDPR does in defined cases |
The mapping is close because the 2019 edition was written with the GDPR in view and the 2025 edition kept the controller and processor control families. It is not one-to-one: the standard’s controls are outcome statements the organisation implements to its own risk assessment, and the GDPR’s articles are obligations with specific tests. Our guide to ISO 27701 controls covers the three Annex A tables; GDPR principles covers Article 5.
ISO 27701 vs GDPR: what the law has that the standard does not
- Legal force and penalties. A PIMS nonconformity costs a corrective action; an Article 5 infringement costs up to 4% of turnover.
- Specific tests. The 72-hour breach clock, the DPO designation criteria, the conditions for valid consent, the transfer mechanisms — the standard points at these areas without restating the tests.
- Rights enforceable by individuals. Data subjects can complain and sue; PII principals under the standard have controls applied for their benefit, not rights against the organisation.
- Jurisdictional reach. Article 3 decides who is bound; the standard applies to whoever adopts it.
What ISO 27701 has that the GDPR does not
- A management system. Scope, leadership, objectives, competence, internal audit, management review and corrective action — the GDPR requires accountability (Article 5(2)) but does not say how to organise it.
- A risk method. Clause 6.1’s assessment and treatment is a repeatable way to decide what “appropriate” means in Article 32 and where DPIAs are needed.
- A processor discipline. A.2 gives processors their own control set and certificate scope, which the GDPR treats mainly through Article 28 contracts.
- Jurisdiction-neutral coverage. One PIMS can cover GDPR, UK GDPR, CCPA, PDPL and other regimes by mapping each into the same controls — the standard’s own annexes have historically provided a GDPR mapping.
- Independent verification. Accredited certification audits on a schedule; the GDPR’s Article 42 schemes remain sparse.
ISO 27701 vs GDPR at the regulator: does a certificate prove compliance?
No, and the standard does not claim it does. A certificate shows that an accredited auditor found a PIMS conforming to ISO 27701 in the scope certified, on the sample examined, at the time of the audit. A supervisory authority investigates the processing itself against the Regulation.
The certificate helps in three concrete ways: it evidences accountability under Article 5(2) and the “appropriate measures” of Articles 24 and 32; it answers customer and tender due diligence that asks for an independent standard; and, for processors, it supports the Article 28(1) test that the controller uses only processors providing sufficient guarantees. It does not replace a lawful basis, a DPIA, a DPO where one is required, or a transfer mechanism. Our guide to GDPR documentation requirements covers the records the Regulation itself expects.
Frequently asked questions
What is the difference in ISO 27701 vs GDPR?
The GDPR is EU law binding controllers and processors, with rights, obligations and fines; ISO 27701 is a voluntary, certifiable standard for a privacy information management system. A PIMS is a way of organising and evidencing GDPR compliance; certification is independent evidence that the system conforms to the standard, not a legal finding of compliance.
Is ISO 27701 certification an Article 42 GDPR certification?
No. Article 42 certifications are approved by supervisory authorities or the EDPB under the Regulation’s own mechanism. ISO 27701 certification is accredited management-system certification under ISO/IEC 17021 rules. It is evidence a regulator may consider, not an approved GDPR certification.
Do we need ISO 27001 to use ISO 27701 for GDPR?
Not since the 2025 edition. ISO 27701:2025 is standalone with its own management system clauses and its own information security controls in Annex A.3. An organisation with ISO 27001 can integrate the two; one without can certify a PIMS on its own.
Which GDPR requirements does ISO 27701 not cover?
The legal specifics: valid consent conditions, the 72-hour notification clock, DPO designation, transfer mechanisms, the Article 3 scope and the penalty regime. The standard requires the organisation to identify and meet applicable legal requirements; it does not restate them.
Does ISO 27701 help outside the EU?
Yes — it is jurisdiction-neutral. One PIMS can carry the GDPR, UK GDPR, CCPA, Saudi PDPL and other regimes as legal requirements mapped into the same controls, which is its main advantage for organisations processing PII in several jurisdictions.
Where this leaves you
Read ISO 27701 vs GDPR as system and law: the Regulation says what must be true of your processing and what happens if it is not; the standard gives you a certifiable way to organise, evidence and improve it, jurisdiction by jurisdiction. Build the PIMS with the GDPR’s articles mapped into its controls, keep the legal specifics the standard leaves to you in the legal register, and treat the certificate as evidence of accountability rather than a substitute for it.
References
- Regulation (EU) 2016/679 — General Data Protection Regulation (EUR-Lex) — The Regulation’s articles and recitals.
- ISO/IEC 27701:2025 — Privacy information management systems — Requirements and guidance — The standalone second edition, published October 2025.
More on ISO 27701
- ISO 27701 vs GDPR — you are here
- ISO 27701: the complete guide
- ISO 27701 controls: the three Annex A tables
- ISO 27701:2025 vs 2019
- GDPR principles: Article 5
- ISO 27701 mandatory documents
The PIMS manual, the GDPR-to-Annex-A mapping matrix, the records of processing register, the privacy impact assessment template and the data subject request procedure are in the ISO 27701 Toolkit, or start with the free templates.