Skip to content
Back to Blog
·9 min read·compliance

ISO/IEC 27701:2025 Explained: India's Standalone Privacy Standard

ISO/IEC 27701:2025 is now a standalone PIMS standard, no ISO 27001 required. See what changed and how it maps to India DPDP Act compliance obligations.

BR

Bachao.AI Research Team

Cybersecurity Research

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

ISO/IEC 27701 is a standalone international standard for building a privacy information management system, or PIMS — a structured, auditable way to govern how your organisation collects, uses, retains, shares, and disposes of personal data. The 2025 revision, published 14 October 2025, replaced the 2019 edition and removed the old requirement to hold ISO/IEC 27001 first: you can now implement and be externally audited against ISO/IEC 27701 entirely on its own. For Indian companies asking whether they need it: if you handle meaningful volumes of personal data as a controller, processor, or both, and want an independently auditable, DPDP Act-aligned way to prove your privacy practices actually operate, ISO/IEC 27701:2025 is now a realistic standalone target rather than a bolt-on to an existing ISMS.

What changed in October 2025, and why it matters

Most articles online about ISO/IEC 27701 still describe the withdrawn 2019 edition. That matters for anyone doing due diligence now, because their central claim — "27701 is not a standalone certification, it only extends 27001/27002" — is no longer true.

ISO/IEC 27701:2025 carries a new title: "Information security, cybersecurity and privacy protection — Privacy information management systems." The old title, "Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management," is gone along with the dependency it described. Three changes drive that shift:

    1. Harmonized high-level structure. The 2025 edition follows ISO's common management-system framework across Clauses 4-10, the same skeleton as ISO 9001 and ISO/IEC 42001, with Clause 5 now "Leadership" — aligning it with the broader ISO family rather than ISO/IEC 27001's numbering.
    2. The control set was regrouped, not mapped 1:1. The old edition bolted privacy guidance onto ISO/IEC 27002's control list, control by control. The 2025 edition drops that mapping: its 78 Annex A controls are now organised as shared, controller-specific, and processor-specific. A new Annex B gives implementation guidance, and Annex F correspondence-maps to the 2019 edition for migrating organisations.
    3. Wider scope. The revision explicitly covers biometric data, health data, IoT devices, and AI privacy risk — categories that barely featured when the 2019 edition was drafted.
ℹ️
INFO
Because ISO/IEC 27701 is no longer pinned to ISO/IEC 27001's Statement of Applicability, your PIMS now needs its own SoA, built directly against the 2025 Annex A control list, with a documented justification for each control. This is new work even for organisations that already run a mature ISMS.

Certification bodies got an update too: ISO/IEC 27706:2025 now covers auditing and certification-body requirements for ISO/IEC 27701, replacing ISO/TS 27006-2:2021. An auditor still quoting the 2021 specification hasn't caught up either.

What a PIMS still does, structurally

None of this changes the basic job of a PIMS. ISO/IEC 27001 answers "is information, generally, adequately protected." ISO/IEC 27701 answers "is personal information, specifically, governed end to end — collected lawfully, used for a stated purpose, retained no longer than needed, and disposable on request." What changed is that a PIMS can now be built and certified as a complete management system in its own right — its own risk assessment, SoA, internal audit cycle, and management reviews — instead of always riding on top of an ISMS. Personal data security still depends on the same discipline an ISMS enforces — access control, encryption, incident response, vendor risk management — but pairing with ISO/IEC 27001 is now a deliberate choice, not a mandatory prerequisite.

PII controller, PII processor, and shared controls

ISO/IEC 27701 keeps the controller/processor distinction from 2019, and it still maps reasonably well onto DPDP Act terminology, even though the legal definitions are not identical.

ISO/IEC 27701 termClosest DPDP Act 2023 conceptPractical implication
PII controllerData FiduciaryDetermines the purpose and means of processing; carries primary compliance and notice obligations
PII processorData ProcessorProcesses personal data on behalf of, and under instruction from, a fiduciary; narrower, contract-bound obligations
PII principalData PrincipalThe individual whose personal data is processed; holds rights over that data
Shared / common controlsApplies across both rolesBaseline privacy controls every organisation handling personal data must apply, regardless of role
What is new in 2025 is that Annex A structures the whole control set around this split rather than treating it as an add-on: shared, controller-specific, and processor-specific controls each sit together, so scoping means working through the section that actually applies to a given data flow rather than filtering a merged list.

Many mid-sized Indian firms are both, depending on the flow: a SaaS company is a controller for its own employee and customer data, but a processor when it hosts data for an enterprise client under a data processing agreement. ISO/IEC 27701 forces that determination to be explicit for every significant data flow — exactly the documentation gap that shows up when a client or regulator asks who is accountable for this data, and under what agreement.

💡
TIP
Before a gap assessment, build a simple data flow inventory: what personal data you hold, where it came from, your role for that flow, and where it goes next. This one artifact feeds both your DPDP work and your 27701 scope.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

Mapping ISO/IEC 27701:2025 to DPDP Act obligations

The DPDP Act 2023 does not reference ISO/IEC 27701 by name, and certification is not, by itself, a legal shield against DPDP enforcement. What it provides is a structured, independently audited operating system for many of the obligations the Act imposes: purpose limitation, data minimisation, security safeguards, retention limits, breach handling, and rights-request processes. Firms that already run a PIMS find DPDP readiness far less green-field, because records of processing, consent tracking, retention schedules, and third-party controls already exist and are already audited on a recurring cycle.

78controls in ISO/IEC 27701:2025 Annex A, now grouped as shared, controller-specific, and processor-specific (ISO)
14 Oct 2025publication date of ISO/IEC 27701:2025, which replaced and withdrew the 2019 edition (ISO)
93controls in ISO/IEC 27001:2022 across 4 themes, still the common reference point if you pair a PIMS with an ISMS (ISO)
up to ₹250 croremaximum penalty under the DPDP Act 2023 for failure to implement reasonable security safeguards (MeitY)
🛡️
SECURITY
The DPDP Act's penalty schedule is steep and tiered — treat safeguard failures as an operational risk category, not a line item to address after an incident. See MeitY's DPDP Act text at meity.gov.in.

Should you still pair it with ISO/IEC 27001?

For many organisations, yes — just not because the standard requires it anymore. Running a PIMS alongside an existing ISMS is still sensible: you reuse the same risk assessment methodology, internal audit programme, and management review cadence, and can align the two certification cycles into one audit calendar. If you do not hold ISO/IEC 27001 and have no near-term plan to pursue it, that is no longer a blocker — a standalone PIMS is a complete way to demonstrate privacy governance to customers, partners, and regulators.

The implementation and migration path

graph TD A[Determine your role
controller processor or shared] --> B[Gap assessment vs
27701 2025 Annex A] B --> C[Implement PIMS controls
and build a standalone SoA] C --> D[Internal audit] D --> E[Management review] E --> F[Stage 1 external audit] F --> G[Stage 2 external audit] G --> H[Certified standalone PIMS] Z[Optional parallel track
existing or new ISO 27001 ISMS] -.-> C Y[Already certified to
27701 2019 edition] --> X[Migrate using Annex F
correspondence table] X --> B style A fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style B fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style C fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style D fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style E fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style F fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style G fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style H fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style Z fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style Y fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style X fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0

A few notes on the stages that trip up first-time programmes:

    1. Gap assessment against 2025 Annex A needs someone familiar with the new grouped structure, not just the old 2019 split — the shared-controls category is new and easy to double-count or miss.
    2. Stage 1 is a documentation and readiness review; Stage 2 tests whether controls actually operate in practice — this is where policy-only implementations get exposed.
    3. Migrating from the 2019 edition does not mean starting over. Annex F maps old requirements to new ones, and certification bodies — now under ISO/IEC 27706:2025 — set a transition window to re-baseline. Confirm your deadline directly with your certification body.
    4. Certification and surveillance is not one-time: like ISO 27001, it carries annual surveillance audits and a full recertification cycle.
⚠️
WARNING
If your organisation certified against ISO/IEC 27701:2019, that edition is withdrawn — not simply "older," but no longer the current normative reference. Continuing to market against 2019 language after your transition deadline is a compliance gap worth closing proactively.

Illustrative effort split for a 2025 implementation or migration programme

Where the actual work tends to land for a first-time PIMS build or a migration from the 2019 edition — this is illustrative of typical effort distribution, not a measured statistic from a named study.

pie showData title Illustrative effort split for a 27701 2025 programme "Role and scope determination" : 15 "Control implementation and SoA rewrite" : 35 "Documentation and records" : 25 "Audit and evidence" : 25

Common pitfalls for Indian mid-sized firms

    1. Scoping against the old 2019 mental model. A reused 2019-era checklist misses the new shared-controls category and the wider biometric, health-data, IoT, and AI scope.
    2. Retention policies that exist on paper only. Auditors want to see data actually being deleted or anonymised on schedule, not just a policy document.
    3. No real data subject rights process. DPDP and ISO/IEC 27701 both expect a working access/correction/deletion mechanism — not an email inbox nobody monitors.
    4. Treating vendors as out of scope. A third-party processor handling your personal data needs to be covered by your PIMS's contractual and oversight controls too.
ℹ️
NOTE
If you already run a mature ISO 27001 ISMS, most of the work is redirection, not reinvention — the same risk assessment, audit, and review mechanisms carry over. What's genuinely new is the standalone SoA and the re-grouped Annex A.
🎯Key Takeaway
ISO/IEC 27701:2025 is no longer an accessory bolted onto ISO/IEC 27001 — it is a complete, standalone PIMS you can implement and certify on its own, with its own Statement of Applicability, its own grouped controller/processor/shared control set, and wider coverage of biometric, health, IoT, and AI privacy risk. Pairing it with an existing ISMS is still sensible for many firms, but it's a choice now, not a rule. For Indian firms, the same underlying discipline — role clarity, retention enforcement, working rights processes, documented third-party oversight — lines up closely with what the DPDP Act already expects.

Before starting a PIMS gap assessment, it is worth confirming your underlying technical security controls are sound — a privacy management system built on unpatched, misconfigured infrastructure is documentation without a foundation. A free VAPT scan is a fast way to surface exposed services and misconfigurations before an ISO 27701 or DPDP auditor does. Bachao.AI, by Dhisattva AI Pvt Ltd, focuses on continuous automated vulnerability assessment and penetration testing for Indian businesses, and works with a CERT-In empanelled partner where an engagement requires CERT-In empanelment. See the DPDP compliance page and the Bachao.AI blog. References: iso.org and meity.gov.in.

Frequently Asked Questions

Is ISO/IEC 27701 still just an extension of ISO/IEC 27001?
No, not since the 2025 revision. ISO/IEC 27701:2025, published 14 October 2025, replaced the 2019 edition and made the standard a complete, standalone PIMS standard. ISO/IEC 27001 certification is no longer a prerequisite for implementing or being audited against it.
What happened to the old Annex A and Annex B for controllers and processors?
The 2025 edition consolidated the old split into a restructured Annex A, which now groups all 78 controls into shared, controller-specific, and processor-specific controls. A new Annex B provides implementation guidance.
My organisation is already certified to ISO/IEC 27701:2019 — what do we do?
The 2019 edition is withdrawn. Annex F of the 2025 edition provides a correspondence table to migrate your existing controls to the new structure, and certification bodies set a transition window to re-baseline. Confirm your specific deadline with your certification body.
Does ISO/IEC 27701:2025 certification satisfy DPDP Act compliance automatically?
No. The Act does not reference ISO/IEC 27701 by name, and certification is not a legal exemption from DPDP obligations. It does provide a structured, audited operating system for many of the same underlying practices — purpose limitation, retention control, rights handling, and breach management.
Should we still pair ISO/IEC 27701 with ISO/IEC 27001?
It is optional now, but often still sensible. Extending an existing ISMS into a PIMS reuses the same risk assessment, audit, and management review machinery. Without ISO/IEC 27001 plans, a standalone PIMS is a complete option on its own.
Is Bachao.AI a CERT-In empanelled auditor?
Bachao.AI's core platform provides continuous automated vulnerability assessment and penetration testing; where an engagement specifically requires CERT-In empanelment, that work is delivered with a CERT-In empanelled partner.
BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See if your business is DPDP Act compliant

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →