ISO/IEC 27701 Certification
Allcontrols OÜ provides certification of Privacy Information Management Systems (PIMS) against ISO/IEC 27701:2025, for organizations acting as PII controllers, PII processors, or both. Certification activities are performed in accordance with ISO/IEC 17021-1:2015. Certification may be granted on a standalone basis or in combination with ISO/IEC 27001 certification, with combined audits where both standards are in scope. Services are delivered remotely and on-site in the EU/EEA and internationally.
Certification Process
The certification process consists of the following steps:
- Application & Contract: The organization submits an application; Allcontrols reviews it to confirm the scope, the PII controller and/or PII processor role, required competence, and audit duration, and issues a certification agreement.
- Stage 1 Audit: Review of PIMS documentation and readiness for Stage 2 (see below).
- Stage 2 Audit: On-site/remote assessment of PIMS implementation and effectiveness (see below).
- Nonconformity Resolution: Corrections and corrective actions for identified nonconformities must be accepted (major nonconformities — verified) before a certification decision can be made.
- Certification Decision: An independent decision to grant or refuse certification is made by persons not involved in the audit.
- Certificate Issue: Upon a positive decision, a certificate is issued with a validity of three years.
- Surveillance Audits: Conducted at least once a calendar year; the first surveillance audit takes place no later than 12 months from the certification decision date.
- Recertification: A recertification audit is performed before certificate expiry to renew certification for a further three-year cycle.
Stage 1: PIMS Audit Scoping
This stage establishes the scope and audit criteria, reviews the documented structure of the PIMS, and evaluates the organization’s readiness for Stage 2.
- Organizational Structure Review: Examination of the organization’s structure, responsibilities, and governance relevant to the PIMS, including accountability for personal data protection.
- Management Interviews: Discussions with responsible management to understand PIMS oversight and accountability.
- Role Determination: Confirmation of the organization’s role as PII controller, PII processor, or both, for the processing activities in scope.
- Processing Activity and Data Flow Identification: Identification of key personal data processing activities, PII categories, purposes, transfers, and data flows relevant to the audit scope.
- Audit Scope Definition: Determination of organizational units, systems, locations, and processing activities included in the audit.
- Readiness Evaluation: Identification of any areas of concern that could be classified as nonconformities during Stage 2.
Deliverable: Stage 1 audit report and an approved audit plan defining the audit scope, criteria, and Stage 2 audit activities.
Stage 2: PIMS Audit Assessment
This stage evaluates the implementation and effectiveness of the PIMS against ISO/IEC 27701:2025 requirements through document review, interviews, and evidence verification.
- Policy and Control Review: Examination of privacy policies, procedures, registers, notices, and implemented controls.
- Stakeholder Interviews: Interviews with relevant personnel to verify PIMS implementation across organizational functions.
- Control Verification: Assessment of controls related to:
- Privacy governance and accountability
- Conditions for collection and processing of PII
- Lawful basis records and consent management where applicable
- Notices and transparency to PII principals
- Handling of PII principal rights requests
- Privacy by design and by default
- PII sharing, transfer, and disclosure
- Processor and subcontractor obligations and oversight
- Retention, return, and disposal of PII
- Technical and organizational data protection measures
- Privacy incident and breach handling
- Integration with information security controls
Deliverable: The Stage 2 Audit Report, including:
- Audit findings against ISO/IEC 27701:2025 requirements
- Identification of nonconformities and observations
- Assessment of PIMS implementation and effectiveness
- Audit team recommendation regarding certification, submitted for the independent certification decision
Certification Decision & Granting
The decision to grant or refuse certification is made by competent personnel of Allcontrols who did not take part in the audit, based on the audit reports, resolved nonconformities, and any other relevant information. Certification is granted when the PIMS conforms to ISO/IEC 27701:2025 requirements. If certification is refused, the organization is informed of the decision and the reasons for it. The certificate identifies the certified organization, the scope of certification, the PII controller and/or PII processor role, the applicable standard, the locations covered, the certificate number, and the dates of issue and expiry, and is valid for three years subject to successful surveillance.
Maintaining, Renewing & Scope Changes
- Maintaining certification: Surveillance audits are conducted at least annually to verify that the PIMS continues to fulfil the requirements; the first surveillance audit is performed no later than 12 months from the certification decision date.
- Notification of changes: The certified organization must inform Allcontrols without delay of matters that may affect the PIMS or the certification, such as changes to its legal, commercial, or organizational status, processing activities, controller or processor role, key processes and locations, or personal data breaches with a significant impact; Allcontrols determines whether additional audit activities are required.
- Renewing certification: A recertification audit is conducted before the certificate expires to confirm continued conformity and effectiveness of the PIMS for a new three-year cycle.
- Extending the scope: A certified organization may apply to extend the scope of certification; Allcontrols reviews the application and performs the audit activities necessary to decide on the extension.
- Reducing the scope: The scope of certification is reduced when the organization persistently or seriously fails to meet the certification requirements for parts of the scope, or upon the organization’s request.
Suspension, Restoration & Withdrawal
Certification may be suspended when, for example:
- the certified PIMS persistently or seriously fails to meet certification requirements, including requirements for the effectiveness of the PIMS;
- the certified organization does not allow surveillance or recertification audits to be conducted at the required frequency;
- the certified organization misuses the certificate or certification mark and fails to take corrective action;
- the certified organization voluntarily requests a suspension.
During suspension, the organization’s certification is temporarily invalid and the organization must refrain from further promotion of its certification. Certification is restored if the issue that resulted in the suspension is resolved within the time defined by Allcontrols (normally not exceeding six months). Failure to resolve the issue results in withdrawal of certification or reduction of the scope. Upon withdrawal, the organization must cease all use of the certificate and any reference to certification.
Use of Certificate & Certification Mark
- The certificate and certification mark may be used only in relation to the certified scope, role, and locations, and in accordance with Allcontrols’ rules for the use of the mark.
- The certification mark must not be applied to products or product packaging, or used in any way that may be interpreted as denoting product conformity.
- Certification applies to the organization’s PIMS and must not be presented in a misleading manner or in a way that brings Allcontrols into disrepute; certification does not constitute evidence of compliance with data protection legislation.
- Upon suspension or withdrawal of certification, all use of the certificate, the mark, and references to certification must cease.
Complaints & Appeals
Any organization or interested party may submit a complaint about Allcontrols’ certification activities or a certified client, or an appeal against a certification decision, by contacting [email protected]. Receipt of each complaint or appeal is acknowledged, and the submitter is provided with progress reports and the outcome. Complaints and appeals are reviewed, and decisions on them are made, by personnel not involved in the subject of the complaint or appeal. Complaints concerning a certified organization are examined with regard to the effectiveness of its certified PIMS and are referred to the certified organization where appropriate. Allcontrols treats the identity of complainants and appellants confidentially, and submitting a complaint or an appeal does not result in any discriminatory action against the submitter.
Certificate Verification
To verify the validity and status of a certificate issued by Allcontrols (certified organization, applicable standard, scope, role, and locations), please contact [email protected]. Information on granted, suspended, or withdrawn certifications is provided upon request.
Impartiality
Allcontrols’ top management is committed to impartiality in its management system certification activities. Allcontrols understands the importance of impartiality, identifies and analyses risks to impartiality on an ongoing basis, manages conflicts of interest, and ensures the objectivity of its certification activities through a dedicated oversight mechanism. Allcontrols does not provide management system consultancy or internal audits to organizations it certifies, and does not certify management systems on which it has provided consultancy.
Basis of Work
Certification activities are conducted in accordance with the following standards:
- ISO/IEC 27701:2025: Privacy Information Management Systems — certification criteria.
- ISO/IEC 17021-1:2015: Requirements for bodies providing audit and certification of management systems.
- ISO/IEC 27006-1:2024: Requirements for bodies providing audit and certification of ISMS.
- ISO/IEC TS 27006-2: Requirements for bodies providing audit and certification — Part 2: Privacy information management systems.
- ISO/IEC 27001:2022 / ISO/IEC 27002:2022: Information security management and controls, where the PIMS builds on the organization’s ISMS.
- ISO/IEC 29100:2024: Privacy framework.
Frequently Asked Questions
-
What is ISO 27701:2025?
ISO/IEC 27701:2025 is a privacy information management standard that helps organizations manage personal data and support compliance with privacy regulations, while aligning with or integrating into an ISO/IEC 27001-based management system.
-
How does ISO 27701:2025 support GDPR compliance?
It provides a structured framework for managing personal data, helping organizations meet key GDPR requirements like data protection and subject rights.
-
Is ISO 27701:2022 certification mandatory for GDPR compliance?
No, it’s not mandatory but supports GDPR compliance by offering best practices for privacy management.
-
What are the main benefits of ISO 27701:2025?
It enhances privacy controls, strengthens compliance with regulations, and builds trust with stakeholders.
-
Who should implement ISO 27701:2025?
Organizations that process personal data and want to improve their privacy management and compliance with global standards like GDPR.
-
Does ISO 27701:2025 cover all GDPR requirements?
No, but it addresses most key areas such as data processing, subject rights, and security controls.
-
What’s the difference between ISO 27701:2025 and GDPR?
ISO 27701:2025 is a standard providing guidelines for privacy management, while GDPR is a regulation that mandates how organizations must handle personal data in the EU.
-
How long does it take to implement ISO 27701:2025?
It depends on the organization’s size and current privacy practices, but typically it takes several months.
Service or request a one-time secure code review.
or a security assessment!