Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27701 vs GDPR explained

ISO 27701 vs GDPR: 10 Clear Differences and the Mapping (2026)

ISO 27701 vs GDPR is a comparison between a certifiable management system standard and a law, and the first thing to be clear about is that neither replaces the other. The GDPR is Regulation (EU) 2016/679: it binds controllers and processors, sets principles, lawful bases, rights, obligations and penalties of up to €20 million or 4% of worldwide annual turnover, and is enforced by supervisory authorities. ISO/IEC 27701:2025 is a standard for a privacy information management system — a PIMS — that an organisation implements and can have certified by an accredited body; since the October 2025 edition it stands alone, no longer requiring an ISO 27001 certificate underneath it.

The relationship is that a PIMS is one way of organising, evidencing and continually improving the things the GDPR requires, and a certificate is evidence — not proof — that the organisation does them. This guide sets the two side by side on ten points, maps the GDPR’s main obligations to the ISO 27701 clauses and Annex A controls that implement them, lists what each has that the other does not, and answers the question a certificate does and does not settle with a regulator.

ISO 27701 vs GDPR: a management system for a law
GDPR: law, binding, enforced, fines to €20m/4%. ISO 27701:2025: standalone PIMS standard, certifiable, Annex A controller (A.1), processor (A.2) and shared security (A.3) controls. The PIMS organises GDPR compliance; certification evidences it.

ISO 27701 vs GDPR at a glance

GDPR (Regulation (EU) 2016/679) ISO/IEC 27701:2025
What it is EU law on the protection of personal data, applicable since 25 May 2018 International standard for a privacy information management system; second edition published 14 October 2025, replacing 2019
Binding? Yes — on controllers and processors established in the EU or targeting EU residents No — voluntary, unless a contract or tender requires it
Scope of data Personal data of natural persons in the EU Personally identifiable information (PII) of any jurisdiction the organisation scopes
Structure 99 articles in 11 chapters; 173 recitals Clauses 4–10 (harmonized structure) plus Annex A controls: A.1 PII controllers, A.2 PII processors, A.3 information security controls for both
Roles Controller, processor, joint controllers, DPO, representative, supervisory authority PII controller, PII processor, PII principal — with the controls split by role
Rights of individuals Articles 12–22: information, access, rectification, erasure, restriction, portability, objection, automated decision-making Controller controls on handling PII principals’ requests and obligations to them
Security Article 32: appropriate technical and organisational measures A.3 information security controls, plus the risk process in clauses 6 and 8
Verification Supervisory authority investigation and enforcement; Article 42 certification schemes (few exist) Accredited third-party certification audit on a three-year cycle
Consequence of failure Fines, orders, bans on processing, liability to data subjects Nonconformities, suspension or withdrawal of the certificate
Prerequisite None None since 2025 — an ISO 27001 certificate is no longer required

ISO 27701 vs GDPR article by article: the mapping

GDPR obligation Article(s) Where ISO 27701:2025 addresses it
Principles: lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality, accountability 5 Clause 4 context and clause 6 planning set the framework; A.1 controller controls on purpose, lawful basis, minimisation, accuracy and retention implement the principles
Lawful basis and consent 6–9 A.1 controls on identifying and documenting the basis for processing and on obtaining, recording and allowing withdrawal of consent
Information to data subjects (privacy notices) 12–14 A.1 controls on determining and providing information to PII principals
Data subject rights 15–22 A.1 controls on handling requests, and processor controls on assisting the controller
Data protection by design and by default 25 A.1 privacy-by-design control; clause 8 operational planning
Records of processing activities 30 A.1 and A.2 controls on records of processing; clause 7.5 documented information
Security of processing 32 A.3 information security controls; clause 6.1 risk assessment and treatment
Breach notification (72 hours to the authority; to data subjects where high risk) 33–34 A.3 incident controls and A.1/A.2 controls on notifying and assisting; clause 10 improvement
Data protection impact assessment 35 A.1 control on privacy impact assessment; clause 6 planning
Processor contracts and sub-processors 28 A.2 processor controls: documented instructions, customer obligations, sub-processor engagement; A.1 controls on supplier agreements
International transfers 44–49 A.1 and A.2 controls on the basis for and records of transfers between jurisdictions
Data protection officer 37–39 Clause 5 leadership: roles, responsibilities and authorities — the standard does not mandate a DPO, the GDPR does in defined cases

The mapping is close because the 2019 edition was written with the GDPR in view and the 2025 edition kept the controller and processor control families. It is not one-to-one: the standard’s controls are outcome statements the organisation implements to its own risk assessment, and the GDPR’s articles are obligations with specific tests. Our guide to ISO 27701 controls covers the three Annex A tables; GDPR principles covers Article 5.

ISO 27701 vs GDPR: what the law has that the standard does not

  • Legal force and penalties. A PIMS nonconformity costs a corrective action; an Article 5 infringement costs up to 4% of turnover.
  • Specific tests. The 72-hour breach clock, the DPO designation criteria, the conditions for valid consent, the transfer mechanisms — the standard points at these areas without restating the tests.
  • Rights enforceable by individuals. Data subjects can complain and sue; PII principals under the standard have controls applied for their benefit, not rights against the organisation.
  • Jurisdictional reach. Article 3 decides who is bound; the standard applies to whoever adopts it.

What ISO 27701 has that the GDPR does not

  • A management system. Scope, leadership, objectives, competence, internal audit, management review and corrective action — the GDPR requires accountability (Article 5(2)) but does not say how to organise it.
  • A risk method. Clause 6.1’s assessment and treatment is a repeatable way to decide what “appropriate” means in Article 32 and where DPIAs are needed.
  • A processor discipline. A.2 gives processors their own control set and certificate scope, which the GDPR treats mainly through Article 28 contracts.
  • Jurisdiction-neutral coverage. One PIMS can cover GDPR, UK GDPR, CCPA, PDPL and other regimes by mapping each into the same controls — the standard’s own annexes have historically provided a GDPR mapping.
  • Independent verification. Accredited certification audits on a schedule; the GDPR’s Article 42 schemes remain sparse.

ISO 27701 vs GDPR at the regulator: does a certificate prove compliance?

No, and the standard does not claim it does. A certificate shows that an accredited auditor found a PIMS conforming to ISO 27701 in the scope certified, on the sample examined, at the time of the audit. A supervisory authority investigates the processing itself against the Regulation.

The certificate helps in three concrete ways: it evidences accountability under Article 5(2) and the “appropriate measures” of Articles 24 and 32; it answers customer and tender due diligence that asks for an independent standard; and, for processors, it supports the Article 28(1) test that the controller uses only processors providing sufficient guarantees. It does not replace a lawful basis, a DPIA, a DPO where one is required, or a transfer mechanism. Our guide to GDPR documentation requirements covers the records the Regulation itself expects.

Frequently asked questions

What is the difference in ISO 27701 vs GDPR?
The GDPR is EU law binding controllers and processors, with rights, obligations and fines; ISO 27701 is a voluntary, certifiable standard for a privacy information management system. A PIMS is a way of organising and evidencing GDPR compliance; certification is independent evidence that the system conforms to the standard, not a legal finding of compliance.

Is ISO 27701 certification an Article 42 GDPR certification?
No. Article 42 certifications are approved by supervisory authorities or the EDPB under the Regulation’s own mechanism. ISO 27701 certification is accredited management-system certification under ISO/IEC 17021 rules. It is evidence a regulator may consider, not an approved GDPR certification.

Do we need ISO 27001 to use ISO 27701 for GDPR?
Not since the 2025 edition. ISO 27701:2025 is standalone with its own management system clauses and its own information security controls in Annex A.3. An organisation with ISO 27001 can integrate the two; one without can certify a PIMS on its own.

Which GDPR requirements does ISO 27701 not cover?
The legal specifics: valid consent conditions, the 72-hour notification clock, DPO designation, transfer mechanisms, the Article 3 scope and the penalty regime. The standard requires the organisation to identify and meet applicable legal requirements; it does not restate them.

Does ISO 27701 help outside the EU?
Yes — it is jurisdiction-neutral. One PIMS can carry the GDPR, UK GDPR, CCPA, Saudi PDPL and other regimes as legal requirements mapped into the same controls, which is its main advantage for organisations processing PII in several jurisdictions.

Where this leaves you

Read ISO 27701 vs GDPR as system and law: the Regulation says what must be true of your processing and what happens if it is not; the standard gives you a certifiable way to organise, evidence and improve it, jurisdiction by jurisdiction. Build the PIMS with the GDPR’s articles mapped into its controls, keep the legal specifics the standard leaves to you in the legal register, and treat the certificate as evidence of accountability rather than a substitute for it.

References

More on ISO 27701

The PIMS manual, the GDPR-to-Annex-A mapping matrix, the records of processing register, the privacy impact assessment template and the data subject request procedure are in the ISO 27701 Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.