Back to Frameworks

ISO/IEC 27701:2025

International
v2025
11 domains
121 controls
Verified

ISO/IEC 27701:2025 is a compliance framework from International with 11 domains and 121 controls. The largest domains are Annex A Table A.1 PIMS controls for PII controllers – ISO/IEC 27701:2025 (35 controls), Annex A Table A.3 information security controls with PII-specific guidance – ISO/IEC 27701:2025 (29 controls), Annex A Table A.2 PIMS controls for PII processors – ISO/IEC 27701:2025 (22 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (11)

Annex A Table A.1 PIMS controls for PII controllers – ISO/IEC 27701:2025

35 controls
Controls in the Annex A Table A.1 PIMS controls for PII controllers – ISO/IEC 27701:2025 domain of ISO/IEC 27701:202531 controls
CodeTitle
iso-iec-27701-2025::A.1.2.2Identify and document purpose
iso-iec-27701-2025::A.1.2.3Identify lawful basis
iso-iec-27701-2025::A.1.2.4Determine when and how consent is to be obtained
iso-iec-27701-2025::A.1.2.5Obtain and record consent
iso-iec-27701-2025::A.1.2.6Privacy impact assessment
iso-iec-27701-2025::A.1.2.7Contracts with PII processors
iso-iec-27701-2025::A.1.2.8Joint PII controller
iso-iec-27701-2025::A.1.2.9Records related to processing PII
iso-iec-27701-2025::A.1.3.10Handling requests
iso-iec-27701-2025::A.1.3.11Automated decision making
iso-iec-27701-2025::A.1.3.2Determining and fulfilling obligations to PII principals
iso-iec-27701-2025::A.1.3.3Determining information for PII principals
iso-iec-27701-2025::A.1.3.4Providing information to PII principals
iso-iec-27701-2025::A.1.3.5Providing mechanism to modify or withdraw consent
iso-iec-27701-2025::A.1.3.6Providing mechanism to object to PII processing
iso-iec-27701-2025::A.1.3.7Access, correction or erasure
iso-iec-27701-2025::A.1.3.8PII controllers' obligations to inform third parties
iso-iec-27701-2025::A.1.3.9Providing copy of PII processed
iso-iec-27701-2025::A.1.4.10PII transmission controls
iso-iec-27701-2025::A.1.4.2Limit collection
iso-iec-27701-2025::A.1.4.3Limit processing
iso-iec-27701-2025::A.1.4.4Accuracy and quality
iso-iec-27701-2025::A.1.4.5PII minimization objectives
iso-iec-27701-2025::A.1.4.6PII de-identification and deletion at the end of processing
iso-iec-27701-2025::A.1.4.7Temporary files
iso-iec-27701-2025::A.1.4.8Retention
iso-iec-27701-2025::A.1.4.9Disposal
iso-iec-27701-2025::A.1.5.2Identify basis for PII transfer between jurisdictions
iso-iec-27701-2025::A.1.5.3Countries and international organizations to which PII can be transferred
iso-iec-27701-2025::A.1.5.4Records of transfer of PII
iso-iec-27701-2025::A.1.5.5Records of PII disclosures to third parties

Annex A Table A.2 PIMS controls for PII processors – ISO/IEC 27701:2025

22 controls
Controls in the Annex A Table A.2 PIMS controls for PII processors – ISO/IEC 27701:2025 domain of ISO/IEC 27701:202518 controls
CodeTitle
iso-iec-27701-2025::A.2.2.2Customer agreement
iso-iec-27701-2025::A.2.2.3Organization’s purposes
iso-iec-27701-2025::A.2.2.4Marketing and advertising use
iso-iec-27701-2025::A.2.2.5Infringing instruction
iso-iec-27701-2025::A.2.2.6Customer obligations
iso-iec-27701-2025::A.2.2.7Records related to processing PII
iso-iec-27701-2025::A.2.3.2Comply with obligations to PII principals
iso-iec-27701-2025::A.2.4.2Temporary files
iso-iec-27701-2025::A.2.4.3Return, transfer or disposal of PII
iso-iec-27701-2025::A.2.4.4PII transmission controls
iso-iec-27701-2025::A.2.5.2Basis for PII transfer between jurisdictions
iso-iec-27701-2025::A.2.5.3Countries and international organizations to which PII can be transferred
iso-iec-27701-2025::A.2.5.4Records of PII disclosures to third parties
iso-iec-27701-2025::A.2.5.5Notification of PII disclosure requests
iso-iec-27701-2025::A.2.5.6Legally binding PII disclosures
iso-iec-27701-2025::A.2.5.7Disclosure of subcontractors used to process PII
iso-iec-27701-2025::A.2.5.8Engagement of a subcontractor to process PII
iso-iec-27701-2025::A.2.5.9Change of subcontractor to process PII

Annex A Table A.3 information security controls with PII-specific guidance – ISO/IEC 27701:2025

29 controls
Controls in the Annex A Table A.3 information security controls with PII-specific guidance – ISO/IEC 27701:2025 domain of ISO/IEC 27701:202529 controls
CodeTitle
iso-iec-27701-2025::A.3.10Addressing information security within supplier agreements
iso-iec-27701-2025::A.3.11Information security incident management planning and preparation
iso-iec-27701-2025::A.3.12Response to information security incidents
iso-iec-27701-2025::A.3.13Legal, statutory, regulatory and contractual requirements
iso-iec-27701-2025::A.3.14Protection of records
iso-iec-27701-2025::A.3.15Independent review of information security
iso-iec-27701-2025::A.3.16Compliance with policies, rules and standards for information security
iso-iec-27701-2025::A.3.17Information security awareness, education and training
iso-iec-27701-2025::A.3.18Confidentiality or non-disclosure agreements
iso-iec-27701-2025::A.3.19Clear desk and clear screen
iso-iec-27701-2025::A.3.20Storage media
iso-iec-27701-2025::A.3.21Secure disposal or re-use of equipment
iso-iec-27701-2025::A.3.22User endpoint devices
iso-iec-27701-2025::A.3.23Secure authentication
iso-iec-27701-2025::A.3.24Information backup
iso-iec-27701-2025::A.3.25Logging
iso-iec-27701-2025::A.3.26Use of cryptography
iso-iec-27701-2025::A.3.27Secure development life cycle
iso-iec-27701-2025::A.3.28Application security requirements
iso-iec-27701-2025::A.3.29Secure system architecture and engineering principles
iso-iec-27701-2025::A.3.3Policies for information security
iso-iec-27701-2025::A.3.30Outsourced development
iso-iec-27701-2025::A.3.31Test information
iso-iec-27701-2025::A.3.4Information security roles and responsibilities
iso-iec-27701-2025::A.3.5Classification of information
iso-iec-27701-2025::A.3.6Labelling of information
iso-iec-27701-2025::A.3.7Information transfer
iso-iec-27701-2025::A.3.8Identity management
iso-iec-27701-2025::A.3.9Access rights

Context of the organization – ISO/IEC 27701:2025

4 controls
Controls in the Context of the organization – ISO/IEC 27701:2025 domain of ISO/IEC 27701:20254 controls
CodeTitle
iso-iec-27701-2025::4.1Understanding the organization and its context
iso-iec-27701-2025::4.2Understanding the needs and expectations of interested parties
iso-iec-27701-2025::4.3Determining the scope of the privacy information management system
iso-iec-27701-2025::4.4Privacy information management system

Further information on annexes – ISO/IEC 27701:2025

1 controls

Improvement – ISO/IEC 27701:2025

2 controls
Controls in the Improvement – ISO/IEC 27701:2025 domain of ISO/IEC 27701:20252 controls
CodeTitle
iso-iec-27701-2025::10.1Continual improvement
iso-iec-27701-2025::10.2Nonconformity and corrective action

Leadership – ISO/IEC 27701:2025

3 controls
Controls in the Leadership – ISO/IEC 27701:2025 domain of ISO/IEC 27701:20253 controls
CodeTitle
iso-iec-27701-2025::5.1Leadership and commitment
iso-iec-27701-2025::5.2Privacy policy
iso-iec-27701-2025::5.3Roles, responsibilities and authorities

Operation – ISO/IEC 27701:2025

3 controls
Controls in the Operation – ISO/IEC 27701:2025 domain of ISO/IEC 27701:20253 controls
CodeTitle
iso-iec-27701-2025::8.1Operational planning and control
iso-iec-27701-2025::8.2Privacy risk assessment
iso-iec-27701-2025::8.3Privacy risk treatment

Performance evaluation – ISO/IEC 27701:2025

8 controls
Controls in the Performance evaluation – ISO/IEC 27701:2025 domain of ISO/IEC 27701:20256 controls
CodeTitle
iso-iec-27701-2025::9.1Monitoring, measurement, analysis and evaluation
iso-iec-27701-2025::9.2.1General
iso-iec-27701-2025::9.2.2Internal audit programme
iso-iec-27701-2025::9.3.1General
iso-iec-27701-2025::9.3.2Management review inputs
iso-iec-27701-2025::9.3.3Management review results

Planning – ISO/IEC 27701:2025

6 controls
Controls in the Planning – ISO/IEC 27701:2025 domain of ISO/IEC 27701:20255 controls
CodeTitle
iso-iec-27701-2025::6.1.1General
iso-iec-27701-2025::6.1.2Privacy risk assessment
iso-iec-27701-2025::6.1.3Privacy risk treatment
iso-iec-27701-2025::6.2Privacy objectives and planning to achieve them
iso-iec-27701-2025::6.3Planning of changes

Support – ISO/IEC 27701:2025

8 controls
Controls in the Support – ISO/IEC 27701:2025 domain of ISO/IEC 27701:20257 controls
CodeTitle
iso-iec-27701-2025::7.1Resources
iso-iec-27701-2025::7.2Competence
iso-iec-27701-2025::7.3Awareness
iso-iec-27701-2025::7.4Communication
iso-iec-27701-2025::7.5.1General
iso-iec-27701-2025::7.5.2Creating and updating documented information
iso-iec-27701-2025::7.5.3Control of documented information

What is ISO/IEC 27701:2025 and who does it apply to?

ISO/IEC 27701:2025 is a compliance framework from International with 11 domains and 121 controls. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/IEC 27701:2025 actually require?

ISO/IEC 27701:2025 has 121 controls organised across 11 domains. The largest domains are Annex A Table A.1 PIMS controls for PII controllers – ISO/IEC 27701:2025 (35 controls), Annex A Table A.3 information security controls with PII-specific guidance – ISO/IEC 27701:2025 (29 controls), Annex A Table A.2 PIMS controls for PII processors – ISO/IEC 27701:2025 (22 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/IEC 27701:2025 do I already cover?

ISO/IEC 27701:2025 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement ISO/IEC 27701:2025?

Start your ISO/IEC 27701:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27701:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 121 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 694 frameworks.

Get Started Free →

Free forever — no credit card required