Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 vs GDPR — what ISO 27001 covers and what GDPR still demands

ISO 27001 vs GDPR: The Complete 2026 Compliance Guide

Key Takeaways

  • ISO 27001 vs GDPR is not a choice between two options: ISO 27001 is a voluntary certifiable security standard, GDPR is EU law, and certification is evidence rather than compliance.
  • Article 42(4) GDPR states plainly that a certification “does not reduce the responsibility of the controller or the processor”.
  • The parts of GDPR that ISO 27001 helps with sit in the lower fine tier (10 million euro / 2%). The parts it leaves open sit in the higher tier (20 million euro / 4%).
  • ISO/IEC 27001 is not an approved GDPR certification mechanism. The schemes that are approved are listed in the EDPB’s public register.

Every week a founder asks the same question in the same order, and the ISO 27001 vs GDPR comparison is almost always framed the wrong way round: “we’re getting ISO 27001 — does that cover us for GDPR?” The short answer is no, and the reason is not a technicality. The two documents are different kinds of thing. One is a voluntary management system standard you can be audited against. The other is a regulation that applies to you whether you have ever heard of it or not.

This guide sets out exactly where the two meet, where they do not, and what a business that genuinely needs both should build first.

ISO 27001 vs GDPR at a glance

Before the detail, here is the ISO 27001 vs GDPR comparison reduced to the structural differences that drive everything else:

ISO/IEC 27001:2022GDPR
What it isAn international standard for an information security management systemRegulation (EU) 2016/679 — directly applicable law
Is it optional?Yes. Nobody is legally required to certifyNo. It applies by operation of law
What it protectsInformation of every kind — source code, contracts, pricing, personal dataPersonal data only, and the rights of the people it describes
Central questionIs the risk to the information managed?Is the processing lawful, fair and transparent?
Proof of conformityA certificate from an accredited body, valid three years with annual surveillanceNo certificate. You demonstrate accountability under Article 5(2)
Who enforces itYour certification body. It can suspend or withdraw the certificateSupervisory authorities, with fines and corrective powers
Worst outcomeLoss of certification and the contracts that depended on itUp to 20 million euro or 4% of worldwide annual turnover

That last row is the one people underestimate. Losing a certificate is a commercial problem you can recover from in a recertification cycle. An Article 83(5) fine is calculated against global turnover.

What ISO 27001 actually gives you

ISO/IEC 27001:2022 asks you to define a scope, run a risk assessment, decide which of the 93 Annex A controls apply, and record that decision in a Statement of Applicability under clause 6.1.3 d). Those 93 controls sit in four themes: 37 organizational, 8 people, 14 physical and 34 technological. Amendment 1:2024 added climate change considerations to clauses 4.1 and 4.2 and left Annex A untouched.

What you get is a repeatable machine: risks identified, controls selected, evidence produced, internal audits run, management reviews held, nonconformities corrected. It is genuinely good at making security operational rather than aspirational. See our guide to ISO 27001 certification for how the audit stages work, and our breakdown of the Statement of Applicability for the document auditors open first.

What GDPR actually requires

GDPR is not primarily a security regulation. Security is one article out of ninety-nine. The bulk of the Regulation concerns questions an ISMS never asks: what is your lawful basis for this processing, have you told people about it in language they understand, can they get a copy of their data, can they object, how long do you keep it, and who outside the EEA sees it.

Article 32 is the security article, and it is the one place where the ISO 27001 vs GDPR overlap is real. It requires “appropriate technical and organisational measures to ensure a level of security appropriate to the risk”, and names pseudonymisation and encryption, confidentiality, integrity, availability and resilience, restoration after an incident, and a process for regularly testing the measures. An ISMS built to ISO 27001 produces almost all of that as a by-product.

ISO 27001 vs GDPR: where the two genuinely overlap

Several Annex A controls map onto GDPR obligations closely enough to reuse the same evidence:

Annex A controlGDPR obligation it supports
A.5.31 Legal, statutory, regulatory and contractual requirementsIdentifying that GDPR applies at all
A.5.34 Privacy and protection of personal identifiable information (PII)The hook that connects the ISMS to the Regulation
A.5.33 Protection of recordsIntegrity and confidentiality, Article 5(1)(f)
A.5.14 Information transferSecurity of transfers (not the legality of them)
A.5.19 Information security in supplier relationshipsProcessor due diligence, Article 28(1)
A.5.24 Incident management planning and preparationBeing able to detect a breach in time to report it
A.8.10 Information deletionStorage limitation and erasure requests
A.8.11 Data maskingPseudonymisation, Article 32(1)(a)
A.8.12 Data leakage preventionArticle 32(1)(b)

Article 32(3) makes the relationship explicit: adherence to an approved certification mechanism “may be used as an element by which to demonstrate compliance” with the security requirements. Note the careful wording — an element, and only for Article 32.

ISO 27001 vs GDPR: the five gaps a certificate never closes

These are the obligations an ISO 27001 audit will not test, in the order they tend to cause trouble:

1. Lawful basis

Article 6 requires a lawful basis for every processing operation, and Article 9 adds conditions for special category data. No Annex A control asks whether you were allowed to collect the data in the first place. This is the single biggest gap in the ISO 27001 vs GDPR comparison, and it sits in the higher fine tier.

2. Data subject rights

Articles 12 to 22 give people the right to access, rectification, erasure, restriction, portability and objection, generally within one month. An ISMS has no equivalent process, no clock, and no template refusal letter.

3. Records of processing and DPIAs

Article 30 requires a record of processing activities, and this is where the ISO 27001 vs GDPR evidence trail diverges most sharply. Article 30 applies whenever personal data is processed, and the fewer-than-250-employees exemption evaporates the moment processing is “not occasional” — which for any normal business it is. Article 35 requires a data protection impact assessment for high-risk processing. Neither is an ISO 27001 deliverable. We cover both in records of processing activities and the DPIA.

4. International transfers

Chapter V governs sending personal data outside the EEA and sits in the higher fine tier. An ISMS will tell you the transfer is encrypted. It will not tell you whether it is lawful. Our guide to international data transfers covers the mechanisms available.

5. Transparency and breach notification to a regulator

Articles 13 and 14 require privacy notices written for the people whose data you hold. Article 33 requires notification to the supervisory authority without undue delay and, where feasible, within 72 hours. ISO 27001 gives you incident management; it does not give you the regulatory clock or the notice.

Why a certificate is not a defence

Two provisions settle the ISO 27001 vs GDPR question in law rather than opinion.

First, Article 42(4): “A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation and is without prejudice to the tasks and powers of the supervisory authorities.” Even a GDPR-specific certification leaves liability exactly where it was.

Second, ISO 27001 is not one of those certifications. Article 42 schemes have to be approved by a supervisory authority or, for a European Data Protection Seal, by the European Data Protection Board, and every approved scheme appears in the EDPB’s public register of certification mechanisms. Europrivacy, EuroPriSe and BC 5701:2024 are on it. ISO 27001 is not, and no ISO standard is.

The register moved in 2026, which is worth knowing if transfers are your problem. In April 2026 the EDPB adopted Opinions 14/2026 and 15/2026, approving updated Europrivacy criteria as a European Data Protection Seal and — for the first time for any scheme — as a tool for international transfers under Articles 42 and 46. Certification under Article 42 is issued for a maximum of three years and may be renewed.

The fine tiers make the practical stakes clear. Article 32, the security obligation ISO 27001 helps you meet, sits in the lower tier under Article 83(4): up to 10 million euro or 2% of worldwide turnover. The obligations ISO 27001 does not touch — Articles 5 and 6, the data subject rights in Articles 12 to 22, and the transfer rules in Chapter V — sit in the higher tier under Article 83(5): up to 20 million euro or 4%. Certification protects you on the cheaper half.

What to build, and in what order

Treating ISO 27001 vs GDPR as a sequencing problem rather than a choice saves the most effort. For most organisations the order that wastes least is:

  • Start with the data map. A record of processing activities forces you to find every system holding personal data. That same inventory feeds the ISO 27001 asset register and scope, so it is never wasted work.
  • Close the legal gaps next. Lawful basis, privacy notices, a rights procedure with a one-month clock, processor contracts under Article 28, and a transfer register. None of these depend on having an ISMS.
  • Then build the ISMS. Your GDPR work will have produced most of the evidence Annex A wants for A.5.31, A.5.34 and A.8.10.
  • Consider ISO 27701 if privacy is the commercial driver. Since the 2025 edition it is a standalone management system standard and no longer requires an ISO 27001 certificate underneath it — see ISO 27701:2025 vs 2019.

If you want the documents rather than the reading list, our GDPR Toolkit ($99) covers the records of processing, DPIA, rights procedures, privacy notices and processor agreements that ISO 27001 leaves out, and the ISO 27001 Toolkit covers the ISMS side. There is also a full list of GDPR documentation requirements if you would rather build them yourself.

Frequently asked questions

In the ISO 27001 vs GDPR comparison, does certification make us GDPR compliant?

No. It provides strong evidence for Article 32 and useful evidence for accountability under Article 5(2), but it does not address lawful basis, data subject rights, records of processing, DPIAs, transparency or international transfers. Article 42(4) confirms that no certification reduces the controller’s responsibility.

Will an auditor or customer accept ISO 27001 instead of a GDPR assessment?

A security-focused customer often will, which is why the ISO 27001 vs GDPR question comes up in sales rather than legal reviews. A data protection authority will not, and neither will a well-drafted data processing agreement, which asks about Article 28 obligations that ISO 27001 does not test.

Is there a GDPR certification we can actually get?

Yes. Schemes approved under Article 42 are listed in the EDPB register, and Europrivacy is the best known. It is still voluntary, still capped at three years, and still does not transfer liability away from you.

We already have GDPR under control. Is ISO 27001 worth adding?

Usually yes, but for commercial reasons rather than legal ones. Certification shortens security questionnaires and unblocks enterprise procurement. It is a sales asset first and a compliance asset second.

Which comes first if we have to do both this year?

GDPR, because it is already legally binding and the data map it forces you to produce is an input to the ISMS scope. Doing it the other way round means scoping an ISMS before you know where the personal data lives.

The bottom line

The honest summary of ISO 27001 vs GDPR is that they answer different questions, and the certificate answers the cheaper one. ISO 27001 proves you protect data well. GDPR asks whether you should have that data at all, whether the people it belongs to know about it, and whether they can get it back. Build both, but do not mistake one for the other — and start with our GDPR implementation guide if you are starting from nothing.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.