What is ISO 27701?
As of 1 October 2026. ISO/IEC 27701:2025 was published on 14 October 2025 and replaces the 2019 edition; it is now a standalone management-system standard rather than an extension of ISO 27001 (Kiwa). Dazr's control set follows the 2019 controller/processor structure, which carries over in substance; check the transition timeline with your certification body.
ISO/IEC 27701:2019 (Privacy Information Management System). Organisations already running an ISO 27001 ISMS who need a privacy-specific extension: controllers, processors, and joint-controllers who want a single certifiable PIMS aligned with GDPR.
Who needs to comply
- B2B SaaS already certified to ISO 27001 wanting a privacy add-on
- Data processors (especially platforms hosting customer personal data)
- Controllers in regulated sectors (health, finance, public sector)
- Multi-national groups operating GDPR alongside other privacy regimes (CCPA, LGPD, PIPL)
Key ISO 27701 controls covered by Dazr
What auditors look for
ISO 27701 audits sample the same evidence as ISO 27001, plus the PIMS-specific clauses: controller obligations in Annex A and processor obligations in Annex B, with a DPIA register and a sub-processor list as routine sampling targets.
How Dazr helps with ISO 27701
Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. ISO 27701 is one of its eleven frameworks, included from Pro, €99 a month. In practice that means:
- Layer ISO 27701 controls on top of an existing ISO 27001 program in one workspace
- Run the controller / processor split with separate control sets
- Hold DPIAs and records of processing in their own registers, and sub-processors in the vendor register
- Link transfer, SCC and TIA evidence on the relevant controls
- Hand the auditor a read-only view that covers ISMS and PIMS together
Back to the full Dazr Compliance overview › | Sign up free ›