The ISO 27701 controls moved in the 2025 edition, and not just by being renumbered. Where the 2019 standard split privacy controls across two annexes and borrowed its security controls from whatever ISO 27001 implementation sat underneath it, the 2025 edition consolidates everything into a single Annex A with three tables — and brings a set of information security controls inside the standard itself.
This guide sets out how the ISO 27701 controls are now organized, what each table is for, how they line up with ISO 27001 Annex A, and what that means for the applicability statement you have to produce.

How the ISO 27701 controls are organized in 2025
ISO/IEC 27701:2025 — Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance — replaced the 2019 edition in October 2025. Its Annex A is titled “PIMS reference control objectives and controls for PII controllers and PII processors” and holds three tables:
| Table | Applies to | Covers |
|---|---|---|
| A.1 | PII controllers | Lawful basis and purpose, consent and withdrawal, notice to data subjects, records of processing, rights handling, privacy by design, sharing and onward transfers |
| A.2 | PII processors | Acting on documented instructions, customer obligations, sub-processor engagement, assisting the controller, return and disposal, transfer records |
| A.3 | Both | Information security controls that any organization processing PII needs, whichever role it plays |
The counts published by certification bodies differ, because subclauses can be tallied more than one way — BSI’s guidance counts 34 controller controls, 21 processor controls and 31 shared controls, while other published tallies are lower. Do not build a project plan on a headline number from a blog. Take the count from the copy of the standard you are certifying against, because that is the list your Statement of Applicability has to answer.
Why the third table exists
This is the change that matters. Under the 2019 edition, ISO 27701 was an extension to ISO 27001 and ISO 27002, so it could assume an information security management system underneath it and simply add the privacy layer. The 2025 edition is a standalone management system standard — a Privacy Information Management System can be certified without an ISO 27001 certificate — and a standalone standard cannot assume controls it does not contain. Table A.3 is where those assumed security controls came inside.
Practically, none of A.3 will surprise anyone running an ISMS: the security controls it names already existed in some form in the 2019 edition or in ISO 27002:2022. What changed is that they are now yours to declare and evidence within the PIMS, rather than inherited by reference.
ISO 27701 controls and ISO 27001 Annex A
The two control sets answer different questions about the same data. ISO 27001 Annex A asks whether information is protected. The ISO 27701 controls ask whether personal information is processed lawfully, fairly and transparently, and whether the people it describes can exercise their rights.
Three practical rules follow:
- Do not duplicate the control. Where an A.3 control corresponds to an ISO 27002 control you already operate, the implementation is the same implementation. What you add is the privacy-specific scope statement — that the control covers systems processing PII.
- Do duplicate the evidence trail. An auditor assessing the PIMS will want to see the control operating on the systems in the PIMS scope, which may be a subset or a superset of the ISMS scope. Those two scopes drifting apart is the most common finding when both certificates are held.
- Map once, formally. The 2025 edition includes annexes with correspondence mappings, including to the 2019 edition. Use them rather than re-deriving your own crosswalk, and record the mapping as a controlled document so the next audit does not repeat the work.
Choosing which ISO 27701 controls apply to you
Role determines table. If you only ever determine the purposes and means of processing, A.1 and A.3 apply. If you only ever process on documented instructions, A.2 and A.3 apply. Most organizations are both, for different processing activities, and the honest answer is that the applicability statement has to be written per processing activity rather than per company.
A worked example: a SaaS business is a processor for customer data held in its platform, and a controller for its own employee and marketing data. It cannot exclude A.1 on the grounds that “we are a processor” — its HR processing says otherwise. The record of processing activities is what settles this, which is why it comes before the applicability statement, not after.
Writing the applicability statement
The mechanics are the ones an ISO 27001 practitioner already knows: list every control in the applicable tables, state whether it is applied, justify inclusion or exclusion, and reference where the implementation lives. Two habits are worth carrying over specifically:
- Justify exclusions against the record of processing, not against convenience. “We do not transfer PII outside the country” is a verifiable statement; “not applicable to our business model” is not.
- Reference the artifact, not the intention. A control line that points at a named procedure with a version and an owner survives an audit. One that points at a paragraph in a policy usually does not.
What this means if you certified to the 2019 edition
Certificates issued against ISO/IEC 27701:2019 remain valid until October 2028 and then lapse, so the transition is a planned piece of work rather than an emergency. The efficient sequence is: map your existing Annex A and Annex B implementations onto the new consolidated tables using the correspondence annexes; identify which A.3 security controls you were inheriting from ISO 27001 and now have to declare inside the PIMS; then rewrite the applicability statement against the new numbering rather than editing the old one, because partial renumbering is how gaps get hidden.
Frequently asked questions
How many ISO 27701 controls are there?
It depends on how subclauses are counted and which tables apply to your role. BSI’s guidance gives 34 controller, 21 processor and 31 shared controls; other published tallies differ. Count from the standard you are certifying against.
Do we still need ISO 27001 to use the ISO 27701 controls?
No. Since the 2025 edition a PIMS can be built and certified on its own, which is exactly why the security controls in table A.3 were brought inside the standard.
Are the privacy controls themselves different from 2019?
The substance largely carried over; the annexes were consolidated and renumbered. That makes the mapping exercise real work even where the control text is familiar.
Do the ISO 27701 controls satisfy GDPR?
They give you a defensible structure and much of the evidence, but no standard confers legal compliance. The mapping annexes show correspondence to privacy regulation; the legal assessment remains yours.
Can we keep one Statement of Applicability for both standards?
You can keep one document, but keep the two control lists distinct within it and state the scope for each. Merging them into a single undifferentiated list is what causes scope drift between the ISMS and the PIMS.
Where this leaves you
The 2025 ISO 27701 controls are easier to work with than the 2019 arrangement — one annex, three tables, and no dependency on someone else’s ISMS to supply the security half. The work is in the mapping: establish which role you play for each processing activity, take the control list from the standard rather than from a summary, reuse ISO 27002 implementations where A.3 overlaps them, and rewrite the applicability statement rather than patching the old one.
References
- ISO/IEC 27701:2025 — Privacy information management systems, requirements and guidance.
- BSI — ISO/IEC 27701:2025 key changes and guidance — Annex A restructuring and control counts.
More on privacy management
- The ISO 27701 controls — you are here
- ISO 27701:2025 vs 2019: what changed
- ISO 27701 and privacy information management
- Writing a Statement of Applicability
Policies, records and the applicability statement are all in the ISO 27701 Toolkit, or start with the free ISO templates.