ISO/IEC 27701:2025 Privacy Information Management System Certification
ISO/IEC 27701:2025 is an international standard that specifies requirements for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS). The standard helps organizations systematically manage privacy risks arising from the processing of personally identifiable information (PII), which corresponds to personal data under many legal frameworks, while providing evidence of accountability to individuals, customers, business partners and regulatory authorities.
This is the second edition, published by ISO and IEC in October 2025, replacing ISO/IEC 27701:2019. A fundamental change in the new edition is that ISO/IEC 27701 has been restructured as a stand-alone management system standard. Organizations can therefore establish and certify a PIMS to ISO/IEC 27701:2025 without being required to hold ISO/IEC 27001 certification. At the same time, the PIMS can still be integrated with an Information Security Management System (ISMS) based on ISO/IEC 27001 so that governance, risk assessment, controls, internal audits, management reviews and improvement processes can be shared.
ISO/IEC 27701:2025 applies to organizations of all types and sizes, including businesses, government bodies and not-for-profit organizations, acting as a PII controller, a PII processor, or both. The role must be determined separately for each PII-processing activity, product or service because an organization may determine the purposes and means of processing in one situation while processing PII only on a customer's instructions in another. The PIMS scope should fully reflect processing activities, categories of PII principals, locations, systems, platforms, data flows, third parties, subcontracted PII processors and the relevant countries or jurisdictions.
The standard follows a management system structure from Clauses 4 to 10, covering the context of the organization, leadership, planning, support, operation, performance evaluation and improvement. A central requirement is that privacy risk assessment and treatment consider consequences for both the organization and PII principals; identify necessary controls; establish a risk treatment plan; obtain acceptance of residual risks; and prepare a Statement of Applicability (SoA) that identifies necessary controls, their implementation status and the justification for inclusion or exclusion.
The control structure and implementation guidance in ISO/IEC 27701:2025 include:
- Controls for PII controllers (Table A.1): These cover purposes and lawful bases; consent; privacy impact assessment; obligations to and requests from PII principals; automated decision-making; privacy by design and by default; PII minimization, quality, retention and disposal; and the sharing, transfer and disclosure of PII.
- Controls for PII processors (Table A.2): These cover customer agreements and instructions; processing purposes; support for customer obligations and PII principal requests; temporary files; the return, transfer or disposal of PII; disclosure requests; subcontracted PII processors and changes to subcontracted PII processors.
- Common information security controls (Table A.3): These include policies, roles, classification and labelling, information transfer, identity and access management, suppliers, incident and PII breach management, legal requirements, protection of records, endpoint devices, authentication, backup, logging, cryptography and secure system development.
- Implementation guidance and mappings: Annex B provides guidance for implementing the controls. Informative annexes map the standard to the privacy principles in ISO/IEC 29100, the EU General Data Protection Regulation (GDPR), ISO/IEC 27018, ISO/IEC 29151 and ISO/IEC 27701:2019.
Relationship with ISO/IEC 27001 and ISO/IEC 27002: ISO/IEC 27701:2025 requires the organization to determine an appropriate information security programme for protecting PII. ISO/IEC 27002:2022 provides guidance and a catalogue of information security control practices for reference, but ISO/IEC 27002 is not itself a certifiable standard. An organization already operating an ISMS based on ISO/IEC 27001:2022 can integrate privacy requirements and use ISO/IEC 27002 to support the selection, design and implementation of controls, helping ensure that necessary information security controls are not overlooked.
Legal and regulatory updates: A PIMS must identify, keep up to date and control the legal, regulatory, authoritative-decision, contractual and internal commitment requirements applicable in each jurisdiction. In Vietnam, organizations should consider the Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP, both effective from 1 January 2026, together with relevant sector-specific legislation. For activities within the scope of the GDPR, Annex D of ISO/IEC 27701 provides an informative mapping to support the assessment of obligations.
Benefits of implementing and certifying ISO/IEC 27701:2025
- Systematic privacy risk governance: Identify, analyse, treat and monitor risks throughout the PII life cycle, including risks to the rights and interests of PII principals.
- Demonstrated accountability: Establish an auditable system of policies, decisions, records and evidence covering purposes, lawful bases for processing, PII principal rights, control selection and operational effectiveness.
- Support for multi-jurisdictional compliance: Provide a common framework for managing legal, regulatory and contractual requirements, while supporting mappings to the GDPR and other applicable personal data protection regulations.
- Enhanced privacy by design: Embed purpose limitation, data minimization, protection by default, quality, retention, disposal and secure PII transfer principles into processes, products and systems.
- Stronger control over the data-processing chain: Clarify responsibilities among controllers, processors, joint controllers and subcontracted PII processors, and increase transparency regarding cross-border transfers, disclosure requests and supplier changes.
- Greater trust and competitive advantage: Provide independent assurance for supplier due diligence, tendering, contracting, digital service delivery and participation in international supply chains.
- Flexible stand-alone or integrated certification: Enable a PIMS to be implemented independently or integrated with ISO/IEC 27001, ISO 9001, ISO/IEC 42001 and other management systems to optimize resources.
GIC Vietnam provides independent assessment and certification services for Privacy Information Management Systems in accordance with ISO/IEC 27701:2025. Certification assesses the conformity and effectiveness of the PIMS within the defined scope, based on ISO/IEC 17021-1 and the specific requirements of ISO/IEC 27706:2025 for bodies providing audit and certification of PIMS. Certification is voluntary; it does not replace legal advice, does not automatically constitute GDPR certification or absolute evidence of compliance with every applicable requirement, and does not guarantee that PII incidents or breaches will not occur.
This service is suitable for:
- Organizations establishing a new PIMS, transitioning from ISO/IEC 27701:2019, or aligning their PIMS with ISO/IEC 27701:2025.
- Organizations acting as PII controllers, PII processors or joint controllers, or engaging subcontracted PII processors in their supply chains.
- Providers of software, SaaS, cloud services, data centres, fintech, banking, insurance, e-commerce, healthcare, education, telecommunications, human resources or outsourcing services.
- Organizations processing sensitive PII, children's PII, large-scale data, data used for profiling or automated decision-making, or data transferred across borders.
- Organizations requiring independent evidence to meet customer, contractual, tendering, supplier assessment, compliance due diligence or international market requirements.
- Organizations seeking to integrate privacy governance with an ISO/IEC 27001 ISMS or other management systems.
1. Certification application & application review
The organization contacts GIC Vietnam and provides information on the proposed PIMS certification scope; its role as a PII controller, PII processor or both for each activity, product or service; categories of PII principals and PII; the purposes, volume, complexity and jurisdictions of processing; locations, personnel, platforms, transfer flows, suppliers and subcontracted PII processors; the information security programme; and applicable legal, regulatory and contractual requirements. GIC Vietnam reviews the application to confirm its competence, the scope, audit method and audit time in accordance with ISO/IEC 27706:2025, after which the certification fee and contract are agreed.
2. Audit planning & preparation
GIC Vietnam establishes the certification programme and appoints an audit team with appropriate competence in PIMS, privacy risk management, applicable legislation, PII controller and processor roles, and the technologies within the scope. The audit plan defines the objectives, criteria, scope, locations, schedule, on-site or remote methods and activities to be sampled. Audit time is determined according to the number of people involved in processing or accessing PII and adjusted for the complexity, types and volume of PII, number of activities, platforms, locations, jurisdictions and transfer flows. Records, evidence and PII accessed during certification are handled in accordance with confidentiality requirements.
3. Audit process
The initial certification audit is conducted in two stages:
- Stage 1: Review the PIMS design and documented information, organizational context, scope, organizational roles, privacy policy and objectives, risk assessment and treatment methods, information security programme, Statement of Applicability, controls for PII controllers and processors, internal audits and management review; determine readiness and plan Stage 2.
- Stage 2: Evaluate the implementation and operational effectiveness of the PIMS. Audit samples may cover processing purposes and lawful bases; consent management; privacy impact assessments; fulfilment of PII principal rights; privacy by design and by default; PII minimization, quality, retention and disposal; contracts, subcontracted PII processors and cross-border transfers; incident and PII breach management; information security controls; monitoring, measurement and improvement. The main sequence is: Opening meeting → Interviews → Records review → Sampling of processes, systems and controls → Consolidation of findings → Closing meeting.
4. Audit report & nonconformity management
The audit team prepares a report with sufficient detail to support the certification decision. The report addresses privacy risk assessment, the organization's roles, the control set used, the version of the Statement of Applicability, significant audit trails and samples, conclusions, and any nonconformities. The organization takes immediate correction where necessary, analyses causes, and determines and implements corrective actions within the specified time frame. GIC Vietnam reviews the adequacy and effectiveness of corrective-action evidence and may conduct an additional audit before submitting the file for certification review.
5. Review & certification decision
The reviewer and certification decision-maker, who are independent of the audit team, review the complete file, report and corrective-action evidence. When all requirements are met, GIC Vietnam issues an ISO/IEC 27701:2025 certificate whose scope clearly identifies the Privacy Information Management System; the organization's role for each activity, product or service; the relevant categories of PII principals; and the version of the Statement of Applicability. Where all in-scope activities are performed remotely with no identifiable physical location, this information is reflected in the certification documents. The certificate remains valid for a three-year certification cycle, provided that the organization maintains conformity and completes surveillance audits.
6. Surveillance and recertification
During the certification cycle, GIC Vietnam conducts surveillance audits to confirm that the PIMS continues to be maintained and remains effective. At a minimum, surveillance reviews PIMS effectiveness in relation to its objectives, privacy risk assessment and treatment, maintenance of controls, changes to the Statement of Applicability, internal audits, management reviews, corrective actions and evaluations of compliance with applicable legal requirements. The first surveillance audit is conducted no later than 12 months from the initial certification decision date. The organization must notify GIC Vietnam of significant changes to the scope, roles, processing activities, locations, platforms, suppliers, jurisdictions, or serious incidents. Before the certificate expires, a recertification audit is conducted for the next certification cycle.
International credibility and broad recognition
GIC is a reputable and widely recognized certification body, with accreditation marks from leading organizations such as UKAS (United Kingdom), JASANZ (Australia–New Zealand), CPSC (United States), SAC (Singapore), CNAS (China) and VICAS (Vietnam). Certificates issued by GIC are recognized globally through the Multilateral Recognition Arrangements (MLAs) of the International Accreditation Forum (IAF) and the Asia Pacific Accreditation Cooperation (APAC). This helps organizations reduce technical barriers and facilitates access to international markets.
Professional, impartial and cost-effective services
GIC Vietnam provides services in accordance with the rigorous standards applied in Europe and North America, ensuring independence, impartiality and professionalism throughout the certification audit process. In addition to high service quality, GIC offers reasonable and competitive fees, enabling organizations to use their investment resources effectively while achieving recognition against international standards.
GIC VIETNAM
🏢 Hanoi: 12F, 14 Lang Ha Building, Giang Vo Ward
☎️ Tel: 024.6275 2268 | 📱Hotline: 0984609469
📧 Email: tuandm@gicvn.vn
🏢 Ho Chi Minh City: R502, 160 Nam Ky Khoi Nghia Street,
☎️ Tel: 028.3930 7936