An ISO 27701 implementation in 2026 is a different project from the one described in most guides still online, because the standard changed underneath them. ISO/IEC 27701:2025, published 14 October 2025, is a standalone privacy information management system standard with its own clauses 4 to 10 and its own Annex A of controller, processor and information security controls; the 2019 edition it replaced was an extension to ISO 27001, and every implementation plan written for it starts from an ISMS that the 2025 edition no longer assumes. The practical consequence is that there are now two starting points — an organisation with ISO 27001 that extends it, and one without that builds the PIMS on its own — and one destination. This guide sets out an eight-step ISO 27701 implementation plan that works from either start, with the deliverable and the trap at each step, a timeline by organisation size, the differences for controllers, processors and hybrids, and the transition route for a 2019 certificate holder whose certificate lapses on 31 October 2028.

Two starting points, one ISO 27701 implementation
| Extending an ISO 27001 ISMS | Standalone PIMS (no ISMS) | |
|---|---|---|
| Management system clauses 4–10 | Extend the existing scope, policy, risk method, document control, audit programme and management review to cover privacy | Build them for the PIMS — the 2025 edition contains them |
| Information security controls | Largely in place under ISO 27001 Annex A; map to 27701 Annex A.3 and declare in the PIMS statement of applicability | Implement Annex A.3 within the PIMS — the reason the 2025 edition brought them inside |
| Privacy controls (A.1 controller, A.2 processor) | New in both cases | New in both cases |
| Certification | Integrated audit with the ISMS, or a separate PIMS audit | PIMS certificate on its own |
| Typical effort | Lower — most of the system exists | Higher — the system is built once, for privacy |
Our guide to ISO 27001 vs ISO 27701 covers the decision; the steps below mark where the two routes differ.
The eight steps of an ISO 27701 implementation
- Decide roles and scope. Controller, processor or both — per processing activity, not for the organisation as a whole — and the organisational, physical and jurisdictional boundary of the PIMS. The deliverable is the scope statement; the trap is scoping to the legal entity when the processing crosses subsidiaries and suppliers.
- Build the legal and contractual register. Every privacy law and contract clause that applies in scope — GDPR, UK GDPR, CCPA, PDPL, sector rules, customer DPAs — with the requirements each imposes. The deliverable is the register; it becomes the source of the statement of applicability’s justifications. Our guide to ISO 27701 vs GDPR covers the main mapping.
- Inventory PII and map the flows. What PII is held, where, for what purpose, on what basis, shared with whom, transferred where, kept how long. The deliverable is the records-of-processing register and data-flow maps; the trap is inventorying systems rather than processing activities.
- Assess privacy risk. Clause 6.1: risks to PII principals and to the organisation, per processing activity, with a documented method and criteria. Where an ISMS exists, extend its method with privacy impact criteria; where not, define one. The deliverable is the risk register and treatment plan; the trap is assessing only security risk and missing lawfulness, transparency and rights.
- Produce the statement of applicability and implement the controls. Every Annex A control — A.1 for controller activities, A.2 for processor activities, A.3 for both — declared applicable or not with justification, then implemented: notices, consent handling, request procedures, impact assessment, processor instructions, sub-processor management, transfers, retention, and the security controls. The trap is declaring A.3 “inherited from ISO 27001” without checking the PIMS scope matches the ISMS scope.
- Write the documentation and start the records. The clause 4–10 documents and the Annex A records — manual, policy, objectives, procedures, registers. Our guide to ISO 27701 mandatory documents lists them; the trap is writing policies before the records exist to make them true.
- Operate, audit and review. Run the processes for long enough to produce records — three months is the usual minimum before a stage 2 audit — then internal audit against every clause and applicable control, and a management review with decisions recorded.
- Certify. Choose an accredited certification body with ISO 27701 in its accreditation scope; stage 1 (documentation), stage 2 (implementation), then surveillance annually and recertification in year three. Our guide to ISO 27701 certification cost covers the audit-time rules and fees.
ISO 27701 implementation timeline by organisation
| Organisation | Route | Typical timeline to stage 2 (our estimate) | Where the time goes |
|---|---|---|---|
| Small processor (SaaS, one product, ISO 27001 held) | Extension | 3–5 months | A.2 controls, customer instruction records, sub-processor register, three months of operation |
| Small controller (no ISMS) | Standalone | 6–9 months | Building clauses 4–10 and A.3 from nothing; PII inventory; notices and request handling |
| Mid-size hybrid (controller for staff and customers, processor for clients; ISO 27001 held) | Extension | 5–8 months | Role split per activity; both control tables; legal register across jurisdictions |
| Large multi-jurisdiction controller (no ISMS, or ISMS with a narrower scope) | Standalone or scope extension | 9–15 months | Scope alignment; inventory at scale; DPIAs; integration of existing privacy programme artefacts |
| 2019 certificate holder | Transition | 2–4 months of gap work before the next scheduled audit | Clause 4–10 items previously borrowed; A.3 declaration; Annex F mapping of old controls to new |
Controllers, processors and hybrids
- Controllers carry A.1: lawful basis, consent, notices, rights handling, impact assessment, retention, sharing and transfer. The work is with legal, marketing, HR and product — wherever purposes are decided.
- Processors carry A.2: acting on documented instructions, meeting customer obligations, engaging sub-processors with authorisation, assisting the customer with requests and breaches, returning or disposing of PII. The work is with account management, engineering and procurement.
- Hybrids — most organisations — carry both, split per activity. The inventory in step 3 is where the split is made, and the statement of applicability records it. A processor that also decides purposes for analytics is a controller for that activity, whatever the contract says.
Transitioning a 2019 certificate
Certificates issued to ISO/IEC 27701:2019 remain valid until 31 October 2028 and then lapse. The transition is smaller than a fresh implementation because the privacy controls carry over — the 2025 edition’s Annex F maps each 2019 control to its successor — and larger than a relabel because the management system clauses and the A.3 security controls now have to be evidenced inside the PIMS rather than pointed at in the ISMS. Fold the transition into a scheduled surveillance or recertification visit in 2026 or 2027; certification bodies set their own earlier cut-offs for 2019 audits and slots compress as the date approaches. Our guide to ISO 27701:2025 vs 2019 covers what changed.
Frequently asked questions
How long does an ISO 27701 implementation take?
Three to five months for a small processor extending an ISO 27001 ISMS; six to nine for a small controller building a standalone PIMS; nine to fifteen for a large multi-jurisdiction organisation — our estimates, with three months of operating records before stage 2 in every case.
Do we need ISO 27001 first?
Not since October 2025. ISO 27701:2025 is standalone; a PIMS can be built and certified on its own, with the information security controls in Annex A.3. Where ISO 27001 exists, extending it is faster.
What is the first step?
Deciding roles — controller, processor or both — per processing activity, and the PIMS scope. Everything downstream, from the legal register to the statement of applicability, depends on it.
Which controls apply to us?
A.1 for activities where you are a controller, A.2 where you are a processor, A.3 for both. The statement of applicability declares each control applicable or not with justification, per the roles established in the inventory.
What happens to our 2019 certificate?
It remains valid until 31 October 2028, then lapses. Transition at a scheduled surveillance or recertification audit in 2026 or 2027, closing the clause 4–10 and A.3 gaps and using Annex F to map the controls.
Where this leaves you
Run the ISO 27701 implementation in the order the standard’s logic runs: roles and scope, legal register, inventory, risk, applicability and controls, documents and records, operation and audit, certification — from an ISMS if you have one and on its own if you do not. The 2025 edition removed the prerequisite; it did not remove the work.
References
- ISO/IEC 27701:2025 — Privacy information management systems — Requirements and guidance — The standalone second edition; Annex A controls and Annex F mapping to 2019.
- Regulation (EU) 2016/679 — General Data Protection Regulation (EUR-Lex) — The principal legal requirement most implementations map first.
More on ISO 27701
- ISO 27701 implementation — you are here
- ISO 27701: the complete guide
- ISO 27701 mandatory documents
- ISO 27701 controls: the three Annex A tables
- ISO 27701:2025 vs 2019
- ISO 27701 certification cost
The implementation roadmap, the scope and roles workbook, the legal register, the PII inventory and data-flow templates, the privacy risk assessment method, the statement of applicability and the full PIMS document set are in the ISO 27701 Toolkit, or start with the free templates.