On this page
- Choose the correct published document
- Match the PIMS to the processing role
- Ask for an activity-based project proposal
- Example: a service business adding outsourced processing
- Plan integration without assuming an outdated dependency
- Common buying questions
- Primary sources and edition check
- Explore more standards buying guides
The verified European product is EN ISO/IEC 27701:2025. This matters beyond the year: ISO describes the 2025 edition as an independent management-system standard. The withdrawn European 2021 edition had an extension role in relation to ISO/IEC 27001 and ISO/IEC 27002. Do not carry that older description into a new purchasing specification. Current European record; ISO independent-system explanation; Earlier edition and replacement.
Choose the correct published document
EN ISO/IEC 27701:2025 — Privacy information management systems
The link below opens the exact published catalogue product named here.
Confirm the final price, taxes, available language, delivery format and permitted users at the merchant checkout. No fixed price is quoted here.
Match the PIMS to the processing role
The scope provides requirements and implementation guidance for a PIMS and is intended for PII controllers and processors responsible for processing. It applies across organisation types and sizes. Published scope.
Use that distinction to frame the work, then establish the actual role for each activity with the appropriate advisers. An organisation can have different responsibilities in different relationships. A service provider’s work for a client and its own employee administration should not be assumed to have identical boundaries merely because both involve personal information.
Ask for an activity-based project proposal
| Decision area | Information the buyer should request |
|---|---|
| Processing activities | Which activities, systems and locations are included in the project? |
| Roles and relationships | How will the organisation’s responsibilities and external-party interfaces be recorded? |
| Information flows | What information enters, moves through and leaves the proposed boundary? |
| Operational ownership | Who approves changes and handles the decisions arising from privacy processes? |
| Evidence and maintenance | What records and working arrangements will remain after implementation support ends? |
Ask bidders to describe their assumptions before comparing price. An offer based on a complete processing inventory may require substantially less discovery work than an offer that creates one. State which inputs already exist, which teams can supply them and which decisions need management approval. That makes the quotation more realistic and helps avoid an implementation schedule built on missing information.
Example: a service business adding outsourced processing
Imagine a service company that stores customer records in its own system and is planning to use an external processing service. Its initial request is for a new privacy policy. A more useful comparison would start with one customer record and trace how the proposed arrangement changes access, responsibilities and communications between the parties.
The buyer could ask who describes the processing purpose, who configures the service, who answers requests and who authorises a change in the supplier. It could also ask how the agreed responsibilities will remain accessible to operational staff. This does not settle the company’s legal role or provide a legal assessment; it is an original way to specify the management work that competing offers include.
Plan integration without assuming an outdated dependency
For information security management, see EN ISO/IEC 27001. For cloud-specific security guidance, see ISO/IEC 27017. For organisational AI management, see EN ISO/IEC 42001. These documents address related but different purchasing objectives.
A business with an existing ISMS can ask how the provider will coordinate shared processes and records. The independent status of the 2025 PIMS does not make integration useless; it changes what should be assumed about the publication’s basis. Request an explicit plan rather than an old package description claiming that every privacy project is simply an add-on to a 2019 or 2021 text.
- Record the full EN ISO/IEC 27701:2025 reference in the order and training brief.
- Identify which older materials describe the withdrawn extension edition.
- Separate implementation support from any external assessment or certification service.
- Specify the actual activities to be evaluated rather than only naming a department.
- Confirm access for privacy, operational and security staff who need to consult the publication.
Common buying questions
Must I already hold ISO/IEC 27001 to use the 2025 standard?
ISO identifies the 2025 edition as an independent management-system standard. Describe any intended integration separately and check the detailed basis of a proposed assessment service. Publisher’s independent-use answer.
Is the 2021 European edition the same purchase?
No. The checked record labels it withdrawn and points to the 2025 replacement. Its title and scope describe the earlier extension approach; use the correct edition for the new project.
Does the standard replace an activity-specific legal review?
Specify that review separately if needed. A management-system engagement should state its scope and deliverables rather than promise that the document alone answers every legal or contractual question.
Primary sources and edition check
- Genorma: published European 2025 privacy standard
- ISO: independent PIMS scope and second edition
- Genorma: withdrawn 2021 extension and replacement
Publication and purchase records checked on 7 October 2026. The examples and procurement questions are original guidance. Detailed implementation requires the applicable licensed text and decisions for the actual project.
Explore more standards buying guides
Browse standards by reference and subject to compare related document choices.
Editorial information
How this page is maintained
No documented technical review of this version is recorded. Sources and an update date are not a conformity assessment.
Scope: Independent privacy information management-system requirements and guidance; distinguishes the 2025 publication from the withdrawn extension edition.
View registered primary sources
Keep this guide useful
Your reading list and topic feeds
Saves stay on this browser. Feeds cover guidance on this website, not every change to a standard.