BS EN ISO/IEC 27701:2025 is an international standard that establishes requirements and provides guidance for implementing a Privacy Information Management System (PIMS). It is designed to help organisations manage privacy risks related to the processing of Personally Identifiable Information (PII) and to support compliance with global privacy regulations, including the GDPR, CCPA, and similar laws across jurisdictions.
Unlike its predecessor (ISO/IEC 27701:2019), which was dependant on ISO/IEC 27001 and ISO/IEC 27002, this 2025 edition is a fully stand-alone management system standard. This enhances accessibility for organisations not already certified to ISO/IEC 27001 and expands its application across sectors.
This standard is designed for a wide spectrum of stakeholders involved in data privacy and security:
AI Solution providers.
BS EN ISO/IEC 27701:2025 outlines a comprehensive framework for managing privacy risks through the implementation of a Privacy Information Management System (PIMS). It helps organisations securely process Personally Identifiable Information (PII), comply with global regulations like GDPR and CCPA, and maintain transparency with stakeholders.
The standard defines clear roles and responsibilities for PII controllers and processors, promoting accountability in data handling. It supports a risk-based approach by guiding organisations to assess privacy risks and apply appropriate controls based on their context and needs.
The new standard consolidates existing privacy and security controls for PII controllers and processors into a clearer annex structure. The standard includes normative guidance in Annex B, and detailed mappings to GDPR, ISO/IEC 29100, and other relevant privacy frameworks, ensuring global applicability.
BS EN ISO/IEC 27701:2025 is beneficial because it:
The updated BS EN ISO/IEC 27701:2025 supersedes BS EN ISO/IEC 27701:2021. The 2025 revision introduces key enhancements that make the standard more practical, accessible, and aligned with evolving privacy needs:
Understand what privacy information management is, why it matters and how you can help protect personal data across your organization. Learn at your own pace with this 30 minute on-demand course.
BSI recommends this version of standard for organisations operating in or with the UK. The ISO edition is available here if required.