ISO/IEC 27701:2025 Privacy Information Management System Certification
ISO/IEC 27701:2025 is an international standard that specifies requirements for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS). The standard helps organizations systematically manage privacy risks arising from the processing of personally identifiable information (PII, broadly corresponding to personal data in many legal frameworks) and demonstrate accountability to individuals, customers, partners and regulatory authorities.
This is the second edition of the standard, published by ISO and IEC in October 2025 to replace ISO/IEC 27701:2019. The principal change is that ISO/IEC 27701 has been redrafted as a stand-alone management system standard. Organizations can therefore establish and certify a PIMS under ISO/IEC 27701:2025 without being required to implement or be certified to ISO/IEC 27001. They may still integrate the PIMS with an Information Security Management System (ISMS) under ISO/IEC 27001 to share governance, risk assessment, control, internal audit, management review and improvement processes.
ISO/IEC 27701:2025 applies to organizations of all types, sizes and sectors, including businesses, government bodies and not-for-profit organizations. Depending on each PII processing activity, an organization may act as a PII controller, a PII processor or both.
This role must be determined separately for each processing activity, product or service rather than assigned uniformly across the organization. For example, an organization may determine the purposes and means of PII processing in one activity and therefore act as a PII controller, while in another activity it may process PII only on a customer's instructions and therefore act as a PII processor.
The scope of the Privacy Information Management System (PIMS) should fully cover PII processing activities; relevant categories of PII principals; processing locations; systems and technology platforms; data flows; third parties and subcontracted PII processors; and the countries or jurisdictions in which PII is collected, stored, used, shared or transferred.
The standard follows the management system structure set out in Clauses 4 to 10, covering the context of the organization, leadership, planning, support, operation, performance evaluation and improvement. The privacy risk assessment and treatment process must consider consequences for both the organization and PII principals; determine the necessary controls; establish a risk treatment plan; obtain acceptance of residual risks; and prepare a Statement of Applicability (SoA) identifying the necessary controls, their implementation status and the justification for their inclusion or exclusion.
The control structure and implementation guidance of ISO/IEC 27701:2025 include:
- Controls applicable to PII controllers (Table A.1): These apply to organizations that determine the purposes and means of PII processing. The controls cover lawful basis and processing purposes; consent; privacy impact assessment; obligations to PII principals and the handling of their requests; automated decision-making; privacy by design and by default; PII minimization, quality, retention and disposal; and the sharing, transfer and disclosure of PII.
- Controls applicable to PII processors (Table A.2): These apply to organizations that process PII under customer agreements and instructions. The controls cover processing purposes and conditions; assistance to customers in fulfilling their obligations and responding to PII principal requests; temporary files; the return, transfer or disposal of PII; disclosure requests; and the selection, use and replacement of subcontracted PII processors.
- Common information security controls (Table A.3): These include controls for policies and assigned roles; information classification and labelling; information transfer; identity and access management; supplier management; information security incident and PII breach management; legal compliance; protection of records; endpoint devices; authentication; backup; logging; cryptography; and secure system development.
- Implementation guidance and mappings: Annex B provides guidance on implementing the controls. Other informative annexes provide mappings to the privacy principles in ISO/IEC 29100, the European Union General Data Protection Regulation (GDPR), ISO/IEC 27018, ISO/IEC 29151 and ISO/IEC 27701:2019.
Relationship with ISO/IEC 27001 and ISO/IEC 27002: ISO/IEC 27701:2025 requires the organization to establish, implement and maintain an appropriate information security programme to protect PII. ISO/IEC 27002:2022 provides guidance and information security controls for organizations to consider; however, ISO/IEC 27002 is not a certification standard. Organizations already operating an ISMS under ISO/IEC 27001:2022 can integrate privacy requirements and use ISO/IEC 27002 to support the selection, design and implementation of necessary controls.
Keeping legal requirements up to date: The PIMS must identify, update and control applicable statutory and regulatory requirements, decisions issued by competent authorities, contractual requirements and internal commitments in each jurisdiction. In Vietnam, organizations should consider the Law No. 91/2025/QH15 on Personal Data Protection and Decree No. 356/2025/ND-CP detailing certain articles and measures for implementing the Law on Personal Data Protection, both effective from 1 January 2026, together with relevant sector-specific laws and regulations. For activities within the scope of the GDPR, Annex D of ISO/IEC 27701:2025 provides a reference mapping to help organizations determine their applicable obligations.
Benefits of implementing and certifying to ISO/IEC 27701:2025
- Systematic privacy risk governance: Identify, analyse, treat and monitor risks throughout the PII lifecycle, including risks to the rights and interests of PII principals.
- Demonstrated accountability: Establish policies, decisions, records and auditable evidence concerning processing purposes and lawful bases, the rights of PII principals, the selection of controls and operational effectiveness.
- Support for compliance across jurisdictions: Provide a common framework for managing statutory, regulatory and contractual requirements and support mapping to the GDPR and other applicable personal data protection regulations.
- Stronger privacy by design: Embed purpose limitation, data minimization, protection by default, PII quality, retention, disposal and secure transfer principles into processes, products and systems.
- Better control of the data processing chain: Clarify responsibilities among PII controllers, PII processors, joint controllers and subcontracted PII processors, while improving transparency over cross-border transfers, disclosure requests and supplier changes.
- Greater trust and competitive advantage: Provide independent assurance for supplier due diligence, tenders, contract negotiations, digital service delivery and participation in international supply chains.
- Flexible stand-alone or integrated certification: Enable the PIMS to be implemented independently or integrated with ISO/IEC 27001, ISO 9001, ISO/IEC 42001 and other management systems to optimize resources.
GIC Vietnam provides independent audit and certification services for Privacy Information Management Systems under ISO/IEC 27701:2025. Certification assesses the conformity and effectiveness of the PIMS within its defined scope, based on ISO/IEC 17021-1 and the specific requirements of ISO/IEC 27706:2025 for bodies providing audit and certification of PIMS. Certification is voluntary, does not replace legal advice and does not mean that the organization automatically complies with all personal data protection regulations.
This service is suitable for:
- Organizations establishing a new PIMS, transitioning from ISO/IEC 27701:2019 or standardizing an existing PIMS under ISO/IEC 27701:2025.
- Organizations acting as PII controllers, PII processors or joint controllers, or using subcontracted PII processors in their supply chains.
- Providers of software, SaaS, cloud services, data centres, fintech, banking, insurance, e-commerce, healthcare, education, telecommunications, human resources or outsourcing services.
- Organizations processing sensitive PII, children's PII or large volumes of PII; using PII for profiling or automated decision-making; or transferring data across borders.
- Organizations requiring independent evidence to meet requirements relating to customers, contracts, tenders, supplier assessments, compliance due diligence or access to international markets.
- Organizations seeking to integrate privacy governance with an ISMS under ISO/IEC 27001 or other management systems.
1. Certification application & application review
The organization contacts GIC Vietnam and provides information on the proposed PIMS certification scope; its role as a PII controller, PII processor or both for each activity, product or service; categories of PII principals and types of PII; the purposes, volume, complexity and jurisdictions of processing; locations, personnel, platforms, transfer flows, suppliers and subcontracted PII processors; the information security programme; and applicable statutory, regulatory and contractual requirements. GIC Vietnam reviews the application to confirm its competence and determine the audit scope, methods and duration in accordance with ISO/IEC 27706:2025, before agreeing the fees and certification contract.
2. Audit planning & preparation
GIC Vietnam establishes the audit programme and selects an audit team with appropriate competence in PIMS, privacy risk management, applicable laws, the roles of PII controllers and PII processors, and the technologies within scope. The audit plan identifies the objectives, criteria, scope, locations, schedule, on-site or remote methods and activities to be sampled. Audit duration is determined based on the number of persons involved in processing or having access to PII and adjusted for complexity, the types and volume of PII, the number of activities, platforms, locations, jurisdictions and transfer flows. Records, evidence and PII accessed during certification are managed in accordance with confidentiality requirements.
3. Certification audit
The initial certification audit is conducted in two stages:
- Stage 1: Review the PIMS design and documentation, organizational context, scope, organizational roles, privacy policy and objectives, risk assessment and treatment methods, information security programme, Statement of Applicability, controls applicable to PII controllers and PII processors, internal audits and management reviews; assess readiness and plan Stage 2.
- Stage 2: Evaluate the implementation and effectiveness of the PIMS in practice. The audit may cover processing purposes and lawful bases; consent management; privacy impact assessments; the exercise of PII principal rights; privacy by design and by default; PII minimization, quality, retention and disposal; contracts, subcontracted PII processors and cross-border data transfers; incident and PII breach management; information security controls; and monitoring, measurement and improvement. The main sequence is: Opening meeting → Interviews → Document review → Sampling of processes, systems and controls → Consolidation of findings → Closing meeting.
4. Audit report & handling nonconformities
The audit team prepares a report with sufficient detail to support the certification decision, covering the privacy risk assessment, organizational roles, controls applied, the version of the Statement of Applicability, significant audit trails and samples, conclusions and any nonconformities. The organization makes corrections where necessary, analyses root causes, and determines and implements corrective actions within the specified timeframe. GIC Vietnam reviews the adequacy and effectiveness of the corrective action evidence and may conduct an additional audit before submitting the file for technical review.
5. Technical review & certification
The person or persons responsible for the technical review and certification decision, acting independently of the audit team, review the complete file, report and corrective action evidence. When all requirements are met, GIC Vietnam issues an ISO/IEC 27701:2025 certificate whose scope clearly identifies the Privacy Information Management System; the organization's role for each activity, product or service; the relevant categories of PII principals; and the version of the Statement of Applicability. Where all activities within the scope are performed remotely without an identified physical location, this information is reflected in the certification documents. The certificate remains valid within a three-year certification cycle, provided that the organization maintains conformity and completes the required surveillance audits.
6. Periodic surveillance & recertification
During the certification cycle, GIC Vietnam conducts surveillance audits to confirm that the PIMS continues to be maintained and remains effective. At a minimum, surveillance reviews the effectiveness of the PIMS against its objectives, privacy risk assessment and treatment, maintenance of controls, changes to the Statement of Applicability, internal audits, management reviews, corrective actions and evaluation of compliance with applicable legal requirements. The first surveillance audit is conducted no later than 12 months from the date of the initial certification decision. The organization is required to notify GIC Vietnam of significant changes to its scope, roles, processing activities, locations, platforms, suppliers or jurisdictions, as well as serious incidents. Before the certificate expires, the organization undergoes a recertification audit for the next certification cycle.
International credibility and broad recognition
GIC is a reputable certification body recognized or accepted under appropriate programmes operated by bodies and organizations such as UKAS (United Kingdom), JAS-ANZ (Australia – New Zealand), CPSC (United States), SAC (Singapore), CNAS (China) and VICAS (Vietnam). Certificates issued by GIC within its accredited scope may gain international recognition through the International Accreditation Forum Multilateral Recognition Arrangement (IAF MLA) and the Asia Pacific Accreditation Cooperation Mutual Recognition Arrangement (APAC MRA). This helps organizations reduce technical barriers and facilitates access to international markets.
Professional, impartial and cost-effective services
GIC Vietnam provides services in accordance with rigorous European and North American standards, ensuring independence, impartiality and professionalism throughout the certification process. GIC also offers reasonable and competitive fees, helping organizations use their investment resources efficiently while achieving recognition against international standards.
GIC VIETNAM
🏢 Hanoi: 12F, 14 Lang Ha Building, Giang Vo Ward
☎️ Tel: 024.6275 2268 | 📱Hotline: 0984609469
📧 Email: tuandm@gicvn.vn
🏢 Ho Chi Minh City: R502, 160 Nam Ky Khoi Nghia
☎️ Tel: 028.3930 7936