# ISO 27701, Layering PIMS on Top of ISO 27001

> ISO/IEC 27701 as an extension of an ISO 27001 ISMS: structure of the standard, controls for controllers and processors, joint audits.

- Source: https://www.sidd.swiss/en/insights/iso-27701-pims/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

ISO/IEC 27701:2019 (formally Privacy Information Management, Extension to ISO/IEC 27001 and ISO/IEC 27002 for Privacy Information Management) is the international standard for Privacy Information Management Systems (PIMS). It builds explicitly on ISO 27001, an ISO 27701 certification is not possible without a certified ISMS under ISO 27001. For Swiss companies that already run ISO 27001 and must also prove GDPR or DSG compliance, the ISO 27701 extension is the most economical path to a recognized privacy certification.

**This article covers:**

- The architecture of ISO 27701 as an extension to ISO 27001 and ISO 27002
- The two roles in the PIMS: controller (PII Controller) and processor (PII Processor)
- Extensions to the ISO 27001 main clauses and Annex A for privacy
- The two additional annexes (Annex A for controllers, Annex B for processors)
- Mapping to GDPR Art. 5–35 and DSG Art. 6–22
- Joint audit feasibility and effort estimate

Intended audience: CISOs, DPOs, ISMS managers, and executive sponsors building an integrated compliance strategy for information security and privacy. We also address the common question whether ISO 27701 proves GDPR conformity, the short answer: indicatively yes, formally no, but it substantially reduces the audit burden during customer audits.

## Architecture of ISO 27701

ISO 27701 is conceptually an extension, not a standalone standard. It adopts the main clauses 4–10 of ISO 27001 unchanged and adds privacy-specific requirements. Annex A of ISO 27701 contains PII-controller-specific controls; Annex B contains PII-processor-specific controls. Both annexes are implemented in addition to Annex A of ISO 27001.

Structural mechanics:

- **Clauses 5–8 of ISO 27701:** extend the ISO 27001 main clauses 4–10 with privacy aspects. E.g. Clause 5.2 (Information Security Policies) is extended by a Privacy Information Management Policy.
- **Annex A of ISO 27701 (31 additional controls):** mandatory for controllers. Addresses conditions for collection, obligations to PII principals (= data subjects), privacy by design, PII sharing.
- **Annex B of ISO 27701 (18 additional controls):** mandatory for processors. Addresses conditions for collection in the processor context, obligations to PII principals via customer, PII sharing logic.
- **Annex C, D, E, F:** mapping tables to the GDPR and to ISO 29100 (Privacy Framework). Not mandatory but practically useful.

Prerequisite for certification: you must either already hold a certified ISMS under ISO 27001 or have both standards audited simultaneously. An isolated ISO 27701 certification is not possible, which makes the standard an additive investment for organizations already certified under ISO 27001.

## Controller vs. Processor, the two roles

ISO 27701 cleanly distinguishes the two privacy roles also central to GDPR and DSG:

**PII Controller** (corresponds to controller in the DSG and the GDPR): the entity deciding on purposes and means of processing. Example: a Swiss online shop managing customer accounts.

**PII Processor** (corresponds to processor in the DSG and the GDPR): the entity processing on behalf of the controller. Example: a Swiss SaaS provider hosting the online shop's customer accounts.

At certification, the company chooses which role(s) to certify:

- **Controller only:** Annex A implemented, Annex B not.
- **Processor only:** Annex B implemented, Annex A not.
- **Both:** both annexes implemented. Common for SaaS providers that process customer data (processor) and at the same time hold their own employee and customer data (controller).

The certificate explicitly names the role(s). A company certified as processor that also presents itself as controller toward customers (e.g. for marketing databases) needs a role extension at the next audit.

Practical implication: most of our mandates combine both roles, because pure processor or pure controller constellations are rare in practice. Anyone running a SaaS product almost always has employee data (controller role for HR) as well as customer data as processor.

## Main clause extensions

ISO 27701 supplements the ISO 27001 main clauses with privacy-specific requirements. The most important:

- **Clause 5.2.1 (Privacy Information Management Policy):** separate PIMS policy in addition to the ISMS policy, or integrated document.
- **Clause 6.12 (Privacy in Risk Assessment):** the risk assessment must explicitly include privacy risks. This is the bridge to the DPIA under Art. 22 DSG and Art. 35 GDPR.
- **Clause 7.4 (Awareness):** employees must have not only information-security awareness but also privacy awareness, including training on data-subject rights and breach reporting.
- **Clause 7.5 (Documented Information):** extended by privacy-specific documents: record of processing activities (Art. 30 GDPR / Art. 12 DSG), DPIA reports, data-subject right responses, breach register.
- **Clause 8 (Operation):** extended by operational planning for privacy: DPIA workflow, data-subject-rights workflow, breach response.
- **Clause 9.1 (Monitoring):** privacy-specific metrics (e.g. SLA fulfillment on access requests, number of breaches, training coverage).

Many Swiss companies have already implemented these extensions, driven by the DSG, which sets its own duties for the record (Art. 12), DPIA (Art. 22), and breach reporting (Art. 24). The ISO 27701 certification then mostly becomes documentation and audit work, not substantive build.

## Annex A for Controllers, the 31 additional controls

Annex A of ISO 27701 contains 31 controller controls, organized into four areas. A compact overview of the most important:

**A.7.2 Conditions for Collection and Processing (8 controls):**

- A.7.2.1 Purpose identification, documented purpose limitation
- A.7.2.2 Lawful basis, legal basis (consent, contract, legal obligation, etc.)
- A.7.2.3 Consent, consent mechanisms with revocability
- A.7.2.5 PIA, Privacy Impact Assessment / DPIA

**A.7.3 Obligations to PII Principals (10 controls):**

- A.7.3.1 Information to PII Principals, privacy notice (Art. 19 DSG)
- A.7.3.2 Providing information, mandatory content of the information
- A.7.3.5 Access to PII, right of access (Art. 25 DSG)
- A.7.3.7 PII correction, right of rectification (Art. 32 DSG)
- A.7.3.8 PII erasure, right of erasure (Art. 32 DSG)
- A.7.3.9 PII portability, data portability (Art. 28 DSG)

**A.7.4 Privacy by Design and Default (9 controls):**

- A.7.4.1 Limit collection, data minimization
- A.7.4.5 PII de-identification, pseudonymization / anonymization
- A.7.4.6 PII de-identification at end of life, secure deletion
- A.7.4.9 PII transmission controls, encrypted transmission

**A.7.5 PII Sharing, Transfer and Disclosure (4 controls):**

- A.7.5.1 Identify basis for PII transfer, transfer basis
- A.7.5.2 Countries and international organisations, third-country transfer
- A.7.5.3 Records of PII transfers, transfer register
- A.7.5.4 Records of disclosures, disclosure register

These controls largely correspond to the GDPR duties under Art. 5–35. Anyone with a GDPR compliance dossier can evidence most controls with existing documents.

## Annex B for Processors, the 18 additional controls

Annex B of ISO 27701 contains 18 processor controls, also organized into four areas. These controls address the specific situation of a processor, accountable to the controller, but with its own obligations toward data subjects.

**B.8.2 Conditions for Collection and Processing (6 controls):**

- B.8.2.1 Customer agreement, contractual framework (DPA)
- B.8.2.2 Organization's purposes, processing only for the customer's purposes
- B.8.2.3 Marketing and advertising use, prohibition of own use
- B.8.2.4 Infringing instruction, duty to notify in case of unlawful instructions

**B.8.3 Obligations to PII Principals (1 control):**

- B.8.3.1 Obligations to PII Principals, support of the controller in fulfilling data-subject rights

**B.8.4 Privacy by Design and Default (4 controls):**

- B.8.4.1 Temporary files, secure handling of temporary files
- B.8.4.2 Return, transfer or disposal of PII, data return / deletion at contract end
- B.8.4.3 PII transmission controls, encrypted transmission

**B.8.5 PII Sharing, Transfer and Disclosure (7 controls):**

- B.8.5.1 Basis for PII transfer between jurisdictions, third-country transfer
- B.8.5.2 Countries and international organisations to which PII can be transferred, list of third countries
- B.8.5.4 Records of PII disclosures to third parties, disclosure register
- B.8.5.6 Engagement of a subcontractor, sub-processor management
- B.8.5.7 Change of subcontractor, change procedure

For SaaS providers, B.8.5.6 (engagement of a subcontractor) and B.8.5.7 (change of subcontractor) are particularly audit-critical, they mirror the clause 9 requirements of the 2021 EU SCCs. A well-maintained sub-processor inventory is audit-ready here.

## Joint audit and value

In practice three audit strategies are common, depending on maturity and target market:

- **Sequential certification:** first ISO 27001, then 6–12 months later ISO 27701 as an extension. Recommended when ISO 27001 is fresh and needs to stabilize.
- **Joint audit:** ISO 27001 and ISO 27701 audited simultaneously. Most accredited CBs (SQS, SGS, TÜV SÜD, BSI) offer this. Saves 20–30 % of audit cost compared with the sequential approach.
- **ISO 27701 as a surveillance extension:** with an existing three-year ISO 27001 cycle, the ISO 27701 is integrated into the next surveillance. Requires that mandatory documentation is already in place.

**Effort for the ISO 27701 extension:**

- With existing GDPR / DSG compliance: 15–30 additional person-days, plus CHF 6,000–15,000 in additional CB fees (depending on headcount).
- With unclear privacy maturity: 60–120 person-days, plus CHF 12,000–30,000 in additional CB fees.

**Value of certification:**

- Audit reduction in customer audits: an ISO 27701 certificate often replaces 60–80 % of privacy audit questions.
- GDPR Art. 42 explicitly allows certifications as a compliance indicator. ISO 27701 is not yet an officially recognized EU certification under Art. 42, but supervisory authorities (including the FDPIC) consider it as an indicator.
- A sales argument in B2B, especially in the EU and the US market.
- A structured foundation for Privacy by Design in the SDLC.

Anyone already holding ISO 27001 and operating across multiple markets with privacy requirements should seriously consider ISO 27701, the effort-benefit ratio is clear.

## How SIDD supports you

SIDD runs joint implementations of ISO 27001 and ISO 27701 for Swiss companies, sequentially or combined, depending on maturity and strategy. Our [ISMS / ISO 27001 engagement](https://www.sidd.swiss/en/services/iso-27001-isms) can be extended modularly with the ISO 27701 extension, including Annex A and Annex B implementation, mapping to DSG and GDPR, and preparation for the joint audit. We provide the privacy policy, the PIMS register, and DPIA templates that fit seamlessly into the existing ISMS.

For parallel privacy advisory we combine the ISO 27701 engagement with our [Swiss data-protection advisory](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) or the [external GDPR DPO](https://www.sidd.swiss/en/services/data-protection-officer-eu). If you are a Swiss company without an EU establishment but active in the Union market, we also act as your [EU representative under Art. 27 GDPR](https://www.sidd.swiss/en/services/eu-representative). Documentation, the DPIA module, the record of processing activities, and the breach tracker run in the [Priverion platform](https://www.sidd.swiss/en/priverion-platform).

Schedule an initial conversation via the [contact form](https://www.sidd.swiss/en/contact), in 60 minutes we provide an assessment of your joint-audit readiness and an effort indicator. For a written proposal, use the [quote form](https://www.sidd.swiss/en/quote).

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
