ISO/IEC 27701 was, until this year, an add-on: a document that told an organisation with an ISO 27001 system which extra requirements and controls made it a privacy information management system too. The second edition, ISO/IEC 27701:2025, published in October 2025, cancels and replaces the 2019 edition and is redrafted as a standalone management system standard: its own clauses 4 to 10, its own Annex A, its own certificate under ISO/IEC 27706:2025. This article reads the new edition row by row for a software company, with the catalogue StandardOS keeps of it as the data: 103 requirements, each with the ISO 27001 clause or control it corresponds to, the gap that 27701 asks beyond it, and the GDPR articles its record evidences.
What changed: one standard, one Annex A, two roles
The 2019 edition extended ISO 27001 by reference, so a PIMS could not exist without an ISMS. The 2025 edition applies the harmonized structure ISO uses for all its management system standards: clause 4 context, 5 leadership, 6 planning, 7 support, 8 operation, 9 performance evaluation, 10 improvement, the same numbering ISO 27001:2022 uses, with a privacy policy, privacy objectives and a privacy risk assessment that reads risks to the people whose data is processed, not only risks to the organisation. Clause 6.1.3 selects the controls from Annex A through risk treatment and writes a statement of applicability, exactly as 27001 does with its own Annex A.
Annex A is now one annex in three tables. Table A.1 carries 31 controls for PII controllers, in four groups: conditions for collection and processing, obligations to PII principals, privacy by design and by default, and PII sharing, transfer and disclosure. Table A.2 carries 18 controls for PII processors in the same four groups. Table A.3 carries 29 information security controls that both roles implement, each a 27001 control read for personal data. Annex B gives implementation guidance under the same numbering, and Annex F maps every 2025 control to its 2019 counterpart and back. For a software company the two roles are both present: it is the controller of its own customer and staff data and the processor of the data its customers put into the product, so A.1, A.2 and A.3 all apply, and the GDPR determination says which duties turn on for each.
The 70 rows a 27001 system already half-covers
Seventy of the 103 requirements correspond to something a running ISO 27001 system already has, and none of them is covered in full by it. The 25 clauses correspond to their 27001 twins: the same context, leadership, planning, support, operation, evaluation and improvement, with a gap per clause. The privacy policy of 5.2 sits beside the information security policy and commits to the people concerned; the risk assessment of 6.1.2 assesses risks to PII principals, which is the reasoning a data protection impact assessment needs; the documented information of 7.5 adds the record of processing, the consents, the assessments and the requests to what 27001 controls; the management review of 9.3 takes feedback from PII principals and regulators as an input.
The 29 security controls of Table A.3 correspond one to one to 27001:2022 Annex A controls, and the gap is the same in kind each time: the 27001 control is not written for personal data, and 27701 asks that it be. Classification (A.3.5) names PII and its special categories where 27001 classifies by confidentiality; logging (A.3.25) records who accessed which personal data when, so that a breach can be reconstructed and a request answered; backups (A.3.24) are subject to retention and erasure, so that a restore does not reinstate deleted data; incident management (A.3.11 and A.3.12) plans and runs the breach notifications with their legal deadlines; the secure development life cycle (A.3.27) includes privacy by design and by default; test information (A.3.31) rules out personal data as test data unless de-identified. The remaining 16 correspondences sit in Tables A.1 and A.2, where a privacy control extends a security one: the contracts with processors and the customer agreement extend the supplier agreements of A.5.20, the records of processing extend the protection of records of A.5.33, retention, disposal and temporary files extend the information deletion of A.8.10, the sub-processor controls extend the supplier security of A.5.19.
The 33 rows no security control produces
Thirty-three controls have no 27001 counterpart at all, 24 for controllers and 9 for processors, and they are the substance of privacy: identify and document the purpose (A.1.2.2) and the lawful basis (A.1.2.3); determine, obtain and record consent (A.1.2.4 and A.1.2.5); the privacy impact assessment (A.1.2.6); the joint controller arrangement (A.1.2.8); the ten controls of A.1.3 on the obligations to PII principals, from the information to provide to access, correction, erasure, portability, objection and automated decision-making; limiting collection and processing, accuracy, minimisation and de-identification (A.1.4.2 to A.1.4.6); the basis and the countries for transfers and the records of transfers (A.1.5.2 to A.1.5.4). On the processor side: processing only for the customer's purposes and never for marketing (A.2.2.3 and A.2.2.4), flagging an infringing instruction (A.2.2.5), the customer's obligations and the PII principals' (A.2.2.6 and A.2.3.2), the transfer basis and countries (A.2.5.2 and A.2.5.3), and the handling of disclosure requests (A.2.5.5 and A.2.5.6). A company that starts from its ISO 27001 system builds these from nothing, and the record of processing is the first of them: every other privacy control refers back to it.
The GDPR articles the controls evidence
ISO/IEC 27701 maps itself to the GDPR in its own annex, and the catalogue reads the mapping from the other side: for each control, which article of Regulation (EU) 2016/679 its record evidences. Thirty-two articles appear. Fourteen rows evidence the record of processing of Article 30; eighteen evidence the processor obligations of Article 28, from the customer agreement to the change of subcontractor; twenty-three evidence the security of processing of Article 32; six evidence the breach notification of Article 33; four evidence the impact assessment of Article 35. None of it is a presumption of conformity: the Regulation names no standard, a certificate proves that the process exists, and the supervisory authority reads the process against the text. What the mapping gives a software company is the audit trail in the other direction: when a customer's questionnaire or an authority asks how Article 30 or Article 33 is met, the answer is a control with a record behind it.
What to do with it
The order that works is the catalogue's own. First the 70 rows that extend the 27001 system, because the evidence already exists and the gap is a paragraph per row: name personal data in the classification, add the retention rule to the backup policy, add the notification steps to the incident procedure. Then the 33 privacy-only rows, starting with the record of processing, the lawful basis per purpose and the impact assessment for the features that need one; the processor terms and the breach clock are the two the customers ask about first. A certificate to the 2025 edition is then the third-party check of a system that already answers the Regulation, which is the order in which a buyer under DORA, NIS2 or the GDPR reads it too.