Home › Frameworks › ISO 27701

ISO 27701 compliance software for privacy information management.

PIMS controls next to ISO 27001, with controller and processor obligations as separate controls (Annex A and B of the 2019 edition), a DPIA register and a vendor register. Included from Pro, €99 a month.

At a glance

  • Clauses 5-8: PIMS-specific extensions to ISO 27001 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement.
  • Annex A (controller): 31 controller-specific controls: lawful basis, data subject rights, transparency, retention, transfers.
  • Annex B (processor): 18 processor-specific controls: contractual basis, sub-processor governance, controller assistance, transfers.
  • GDPR mapping: PIMS clauses mapped to GDPR Articles 5-49 in Annex D for joint use.

On this page

  1. What is ISO 27701?
  2. Who needs to comply
  3. Key ISO 27701 controls covered by Dazr
  4. What auditors look for
  5. How Dazr helps with ISO 27701

What is ISO 27701?

As of 1 October 2026. ISO/IEC 27701:2025 was published on 14 October 2025 and replaces the 2019 edition; it is now a standalone management-system standard rather than an extension of ISO 27001 (Kiwa). Dazr's control set follows the 2019 controller/processor structure, which carries over in substance; check the transition timeline with your certification body.

ISO/IEC 27701:2019 (Privacy Information Management System). Organisations already running an ISO 27001 ISMS who need a privacy-specific extension: controllers, processors, and joint-controllers who want a single certifiable PIMS aligned with GDPR.

Who needs to comply

  • B2B SaaS already certified to ISO 27001 wanting a privacy add-on
  • Data processors (especially platforms hosting customer personal data)
  • Controllers in regulated sectors (health, finance, public sector)
  • Multi-national groups operating GDPR alongside other privacy regimes (CCPA, LGPD, PIPL)

Key ISO 27701 controls covered by Dazr

Clauses 5-8PIMS-specific extensions to ISO 27001 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement.
Annex A (controller)31 controller-specific controls: lawful basis, data subject rights, transparency, retention, transfers.
Annex B (processor)18 processor-specific controls: contractual basis, sub-processor governance, controller assistance, transfers.
GDPR mappingPIMS clauses mapped to GDPR Articles 5-49 in Annex D for joint use.

What auditors look for

ISO 27701 audits sample the same evidence as ISO 27001, plus the PIMS-specific clauses: controller obligations in Annex A and processor obligations in Annex B, with a DPIA register and a sub-processor list as routine sampling targets.

How Dazr helps with ISO 27701

Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. ISO 27701 is one of its eleven frameworks, included from Pro, €99 a month. In practice that means:

  • Layer ISO 27701 controls on top of an existing ISO 27001 program in one workspace
  • Run the controller / processor split with separate control sets
  • Hold DPIAs and records of processing in their own registers, and sub-processors in the vendor register
  • Link transfer, SCC and TIA evidence on the relevant controls
  • Hand the auditor a read-only view that covers ISMS and PIMS together

Back to the full Dazr Compliance overview › | Sign up free ›

ISO 27701 questions, answered.

Do we need ISO 27001 first?

Under the 2019 edition, yes: it extends an ISO 27001 ISMS. The 2025 edition is standalone, although most organisations still run it next to ISO 27001. Dazr lets you enable both frameworks; the same evidence often serves both.

Are we a controller, a processor, or both?

Most B2B SaaS is processor for customer data and controller for marketing and HR data. Dazr lets you record both roles and runs Annex A and Annex B controls in parallel where they apply.

How does this differ from GDPR?

GDPR is the law; ISO 27701 is a certifiable management system that helps demonstrate compliance. The platform tracks both: GDPR Articles 30 and 33 alongside ISO 27701 Annex A and B.

Where is data hosted?

European Union only. Workspace records are encrypted at rest with AES-256-GCM at the application layer; uploaded evidence files rely on the storage provider's at-rest encryption. Italian entity, EU jurisdiction.

Ready to start your ISO 27701 program?

ISO 27701 is included in Pro (€99/mo, up to five frameworks and five users) and Enterprise (€499/mo); self-serve via Mollie, excl. VAT, cancel any time. Free and Basic cover ISO 27001, GDPR and NIS2. Custom is the only tier on a contract, priced on request.