ISO/IEC 27701 Privacy Information Management System (PIMS)

Privacy information management system

Written by

July 15, 2026

Most of the guidance you will find on privacy information management systems is out of date. It tells you that a PIMS is an extension of ISO 27001, and that you need an ISO 27001 certificate before you can certify one. Several certification bodies still publish this on their websites today.

It stopped being true in October 2025. ISO/IEC 27701:2025 is now a standalone management system standard. It has its own requirements, its own controls, and its own certification path. You do not need an ISMS to build a PIMS.

But if you already have one, you are a great deal closer than you think, and this article explains exactly how much closer and exactly where the shortcut runs out.

What Is a Privacy Information Management System?

A Privacy Information Management System (PIMS) is how an organisation manages personal data from the moment it arrives to the moment it is deleted. Collecting it, using it, storing it, sharing it, and getting rid of it when it is no longer needed.

Personally identifiable information (PII) is any data that can identify someone. A name. An email address. A national identity number. Sometimes a device ID or a location record, depending on what else it can be matched against.

It helps to say what a PIMS is not. A privacy policy is a document. Encryption is a control. A PIMS is the system above both. It decides who is responsible for each piece of personal data, what you are allowed to do with it, and what proof exists that you did it properly.

Proof is the part that matters most. Privacy failures are rarely caused by bad intentions. Usually the organisation was doing roughly the right thing and just could not show it when someone asked. A PIMS turns “we handle personal data responsibly” from a claim into something you can prove.

The standard that sets out what a PIMS must contain is ISO/IEC 27701.

PIMS vs ISMS

Most people mix these two up, and the rest of this article depends on keeping them apart.

An Information Security Management System (ISMS) asks whether your data is protected from people who should not have it. A PIMS asks what the people who should have it are allowed to do with it.

PIMSISMS
GovernsHandling of personal dataProtection of information
Core questionWhat are we allowed to do with this, and why?Who can access this?
StandardISO/IEC 27701ISO/IEC 27001
Audited onLawful basis, consent, rights, recordsControls, access, incidents
Usual ownerDPO, legal, or complianceCISO or head of security

What Is ISO/IEC 27701

ISO/IEC 27701 is the international standard for privacy information management systems. ISO and IEC publish it jointly, and the current edition, ISO/IEC 27701:2025, was published on 14 October 2025.

It applies to any organisation that handles personal data, whatever its size or sector. It covers both of the roles the standard recognises: PII controllers and PII processors. More on those below.

The 2019 edition has been withdrawn.

Structure of ISO 27701

Clauses 1 to 3 cover scope, normative references, and terminology. The requirements begin at Clause 4.

From there, the standard follows the ISO harmonised structure, which is the same skeleton used by ISO 27001, ISO 9001, and every other modern ISO management system standard.

  • Clause 4 (Context): What processing is in scope. Which laws apply to you. Who your interested parties are, and what they expect.
  • Clause 5 (Leadership): Top management has to own this. Privacy objectives get set, roles get assigned, and accountability sits with someone whose name you can say out loud.
  • Clause 6 (Planning): Privacy risk assessment, risk treatment, and objectives you can actually measure.
  • Clause 7 (Support): Competence, training, communication, and documented information. The unglamorous plumbing that determines whether any of the rest works.
  • Clause 8 (Operation): The controls that do the daily work: records of processing, rights request handling, privacy impact assessments, transfer governance.
  • Clause 9 (Performance evaluation): Monitoring, internal audit, management review.
  • Clause 10 (Improvement): Nonconformity, corrective action, and the discipline of not making the same mistake twice.

What Changed in ISO 27701:2025

The 2019 edition was an extension. You bolted it onto an ISMS, and the scope of your PIMS could not exceed the scope of your ISO 27001 certificate.

That is gone. The 2025 edition has its own management system requirements in Clauses 4 to 10 and its own set of controls. As Schellman explains, certification no longer requires ISO 27001 at all.

You can still run the two systems together, and most organisations with a working ISMS should. It is now a choice, not a condition.

A second standard arrived at the same time. ISO/IEC 27706:2025 sets the rules for the certification bodies themselves. According to UKAS, the UK’s national accreditation body, it introduces defined competence requirements for PIMS auditors and strengthens the impartiality expected of them.

What that means for you: expect a harder audit than the 2019 era produced. Auditors will look at how you actually manage privacy risk, not just whether you have a document that says you do.

ISO 27701 Transition Deadlines

Certification bodies must finish their own transition by 31 October 2027. Organisations holding a 2019 certificate must transition by 31 October 2028.

Miss the second one and the consequence is real. You cannot renew against the 2019 edition, because it no longer exists. Your certification body treats you as a brand new applicant, which means a full Stage 1 and Stage 2 audit instead of a lighter transition audit. It costs more. It takes longer.

There is a commercial side to this. If your contracts or tenders mention an ISO 27701 certificate, a lapsed one is a sales problem, not just a compliance one.

Three years sounds like plenty of time. It is not. Auditor slots get scarce as the deadline nears, and every other certified organisation is queuing for the same people.

If you are starting a PIMS from scratch today, build it against the 2025 edition. There is no sense designing around a standard that has already been withdrawn.

The “Plus One” Approach to Building a PIMS

Plus One is the name for a simple idea. A PIMS is one more layer of governance you already run, not a second programme running next to it.

Be careful about what that does and does not claim. It does not mean a PIMS is an add-on to ISO 27001. Under the 2025 edition it plainly is not. What it means is that the work is cheaper than you expect, because most of the machinery is already installed.

Look at what the two systems share. A way of assessing risk. An inventory of what you hold. Vendor checks. Incident response. Internal audit. Management review. A process for fixing things that go wrong.

None of that gets rebuilt. It gets pointed at personal data as well.

The harmonised clause structure is what makes this work in practice. Your privacy risks go in the same register as your security risks. Your PIMS audit runs on the same cycle as your ISMS audit. Both get reviewed in the same meeting.

Organisations tend to be surprised by this. They expect to build a privacy programme from nothing and find that most of the foundation was poured years ago, for other reasons.

What Your ISMS Does Not Cover

Some privacy obligations have no security equivalent at all. No amount of ISO 27001 maturity will produce them by accident:

  • Lawful basis. Why are you allowed to hold this data in the first place?
  • Consent, and how someone takes it back.
  • Handling requests from people about their own data: access, correction, deletion, portability. Each with a deadline you have to meet.
  • Records of what you process and why.
  • Privacy impact assessments before you launch something new.
  • Rules on how long you keep data, and what you may use it for.
  • Governance of data sent across borders.

These get built. They do not get inherited.

There is also a scoping trap. Because your PIMS is no longer tied to your ISMS, it may need to be wider. A system that never worries your security team can still be a serious privacy exposure. HR data is the obvious one. So is anything marketing touches.

Assume your ISMS scope is the right PIMS scope and you will find out at audit that it was not.

Roles in a PIMS

ISO 27701 organises its controls around two roles. Indonesia’s PDP Law uses the same two, which is what makes the mapping in the next section possible.

PII Controller

The controller decides why personal data is being processed, and how. It is accountable for handling the data lawfully and for being straight with the people it belongs to. That accountability does not transfer when the work does. Hand your payroll to a vendor and you are still the controller. If it goes wrong, it is still your problem.

PII Processor

The processor handles personal data on the controller’s written instructions, and only those instructions. The relationship runs on a contract. Its duties are narrower. Do what you were told and nothing else. Keep the data secure while you hold it. Manage your own subcontractors. Help the controller when a data request or a breach lands.

PIMS and Data Protection Laws in Southeast Asia

A PIMS is not a compliance certificate. ISO 27701 is a voluntary standard. UU PDP is Indonesian law. They are different kinds of things, and a certificate is not a legal defence.

What a PIMS does is produce the evidence those laws ask for. The records. The controls. The audit trail. It is what lets you answer the regulator’s question. It does not stop the regulator asking.

Indonesia’s Personal Data Protection Law

UU PDP No. 27/2022 uses the same controller and processor split that ISO 27701 does. That makes the mapping unusually clean.

A PIMS produces most of what the law asks you to demonstrate. Records of what you process. Evidence of consent, and of consent withdrawn. Responses to data requests within the deadline. Breach notification. Appointment of a data protection officer where the law requires it.

Where it falls short: UU PDP has requirements no international standard anticipates, and enforcement practice in Indonesia is still settling. A PIMS gives you governance. It does not give you the legal interpretation, and that still needs Indonesian counsel.

Singapore’s PDPA and Data Protection Trustmark

Singapore’s Personal Data Protection Act sets obligations a PIMS maps onto directly. Consent. Purpose limitation. Notification. Access and correction. Accuracy. Protection. Retention limits. Rules on transferring data out of Singapore.

There is a useful overlap with the Data Protection Trustmark, Singapore’s voluntary certification for data protection practices, run by IMDA and the PDPC. In July 2025 it became a national standard, SS 714:2025.

Organisations that have prepared for DPTM have already done a good share of what a PIMS needs. It works in reverse as well. Build the PIMS first and DPTM gets much lighter.
If you are going for both, do not run them as separate projects. One set of evidence serves both.

Operating Across Multiple Jurisdictions

Most organisations are not confined to one legal regime. For example, a company in Jakarta with a customer in Frankfurt answers to both UU PDP and the GDPR. Add a Singapore subsidiary and that is three.

The instinct is to run one compliance project per country. Three risk registers. Three audit cycles. Three sets of evidence, maintained separately, slowly drifting apart.

A PIMS gives you one of each, mapped out to all three.

It works because the foundations are shared. Controller and processor mean much the same thing under UU PDP, the PDPA, and the GDPR. The specific duties differ, but they attach to the same roles and rest on the same records. The 2025 edition helps directly here, mapping to ISO/IEC 29100, ISO/IEC 27018, ISO/IEC 29151, and the GDPR.

One risk register. One audit cycle. One evidence set. Mapped outward to as many laws as apply to you.

The limit is worth stating plainly. A PIMS produces evidence. It does not tell you what any law requires. That still comes from counsel in each country, and anyone who tells you a certificate replaces legal advice is selling something.

The ISO 27701 Certification Process

Anyone who has been through ISO 27001 will recognise the shape of this. Same machinery, different subject.

1. Gap Analysis

Compare what you do now against what the standard requires. This tells you what already exists, what has to be built, and how wide your PIMS should be. If you are moving from the 2019 edition, this is where the structural changes surface. Better here than at the audit.

2. Implementation

Build the controls, policies, and records the gap analysis found missing. Give each one an owner. Write the Statement of Applicability, which records which controls apply to you and why.

This is the longest stage, and its length depends heavily on how mature your governance already is. An organisation with a working ISMS moves through it faster than one starting cold. That is the Plus One argument showing up on a project plan.

3. Internal Audit and Management Review

Test the system yourself before an external auditor does it for you. Management review closes the loop. Leadership looks at what the audit found and commits to fixing it. Both are Clause 9 requirements, both produce evidence the certification body will want to see, and both are where transitions most often fall apart.

4. Certification Audit

An accredited certification body runs the audit, usually in two stages. Stage 1 checks your documents and decides whether you are ready. Stage 2 checks whether the system you wrote down is the system you actually run.

Under ISO/IEC 27706:2025 your auditor faces stricter competence rules than before. Expect your privacy risk management to get proper scrutiny, not a document check.

5. Certification and Surveillance

The certificate is issued, then kept alive through periodic surveillance audits.

If you are transitioning from the 2019 edition, the transition audit can usually be combined with a surveillance or recertification visit you were having anyway. That saves real money over running it separately. Raise it with your certification body early, before the calendar fills.

How to Start Building a PIMS

Start with five questions about your own organisation.

  1. Can you produce a current record of every activity that touches personal data?
  2. For each one, do you know whether you are the controller or the processor?
  3. Can you show why you are allowed to hold that data?
  4. Do you have a deadline for responding when someone asks about their own data, and can you prove you met it?
  5. Is your PIMS scope worked out on its own terms, or did you assume it matched your ISMS?

The organisations that struggle with privacy governance are rarely the ones with weak security. They are the ones with strong security who assumed it covered privacy too. It does not, but it does most of the work.

The distance between a working ISMS and a certified PIMS is shorter than most people expect. Worth measuring before you decide what it will cost you.
If you want a second opinion on where you stand, Zentara works with organisations on exactly that.

Frequently Asked Questions

1. Is ISO 27001 required for ISO 27701 certification?

No. ISO/IEC 27701:2025 is a standalone standard with its own clauses and controls, so a PIMS can be certified without an ISMS. The 2019 edition did require ISO 27001, which is why older guidance still says otherwise.

2. What is the difference between a PIMS and an ISMS?

An ISMS governs protection against unauthorised access. A PIMS governs what authorised people may do with personal data they legitimately hold. They overlap on risk and audit processes, but not every privacy concern is a security concern.

3. When is the ISO 27701:2025 transition deadline?

Organisations certified to the 2019 edition must transition by 31 October 2028. A lapsed certificate cannot be renewed against the withdrawn edition, which means starting again as a first-time applicant.

4. Does ISO 27701 certification make my organisation compliant with UU PDP?

No. ISO 27701 is a voluntary standard and UU PDP is Indonesian law, so certification is not a legal defence. A PIMS produces the evidence that demonstrates how obligations are met, but compliance is assessed against the law itself.

5. Can a small organisation implement a PIMS without an ISMS?

Yes. Since the 2025 revision, ISO 27701 can be certified independently, removing the cost of building an ISMS first. Organisations handling significant personal data but not needing broad security certification benefit most.

6. How long does ISO 27701 certification take?

Timelines depend on existing governance maturity and PIMS scope. Organisations with a working ISMS move faster because the risk, audit, and review processes already exist. Certification body availability tightens closer to the 2028 deadline.

Watch our FREE webinar: AI vs. Hackers - The Cyber Battle You Didn’t Know Was Happening

Marsha Widagdo, Zentara’s Head of Security Operations (Blue Team), will break down how defenders use AI to spot, triage, and contain real threats—and how attackers are weaponising it in return. Expect practical playbooks, recent cases, and clear steps you can apply.

Where Cybersecurity Meets Community

We’re building a space for cybersecurity practitioners, students, researchers, and enthusiasts to connect, learn, exchange ideas, and grow as a collective. A community built around discourse, industry insights, and driven by mutual goals.

Modern Cybersecurity Services, Built for Complexity

From threat intelligence to vulnerability assessments and incident response, Zentara helps governments and enterprises stay ahead of every attack vector