Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
ISO 27701 (2025)
The 2025 edition of ISO/IEC 27701, specifying requirements for a privacy information management system (PIMS).
ISO/IEC 27701:2025 is the current edition of the privacy information management system (PIMS) standard published jointly by ISO and IEC. It specifies requirements and guidance for establishing, implementing, maintaining and continually improving a system for managing the processing of personally identifiable information (PII). The 2025 revision restructures the standard as a standalone management-system standard, so that organisations can build a PIMS aligned with the common structure used across ISO management-system standards.
Where the 2019 edition operated strictly as an extension of ISO/IEC 27001, the 2025 edition is designed to work with an information security management system while standing on its own. Certification is available through accredited certification bodies, allowing organisations to demonstrate structured privacy governance to customers, partners and regulators.
Set up and operate a privacy information management system with defined scope, leadership commitment, roles and objectives.
Identify and treat privacy risks and impacts arising from the processing of personally identifiable information.
Apply the controls relevant to the organisation's role as a PII controller or processor, including transparency and support for individuals' rights.
Monitor, audit, review and improve the PIMS to keep pace with changing privacy risks and obligations.
Read more
Anove scans your stack against ISO 27701 (2025) and 260+ other frameworks in minutes.