EN ISO/IEC 27701:2021

Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management - Requirements and guidelines (ISO/IEC 27701:2019) EN ISO/IEC 27701:2021

General information

99.60   Withdrawal effective   Oct 22, 2025

CEN/CENELEC

CEN/CLC/JTC 13 Cybersecurity and Data Protection

European Norm

35.030   IT Security

Scope

This document specifies requirements and provides guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS) in the form of an extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy management within the context of the organization.
This document specifies PIMS-related requirements and provides guidance for PII controllers and PII processors holding responsibility and accountability for PII processing.
This document is applicable to all types and sizes of organizations, including public and private companies, government entities and not-for-profit organizations, which are PII controllers and/or PII processors processing PII within an ISMS.

Life cycle

NOW

WITHDRAWN
EN ISO/IEC 27701:2021
99.60 Withdrawal effective
Oct 22, 2025

REVISED BY

PUBLISHED
EN ISO/IEC 27701:2025

Relations

Adopted from ISO/IEC 27701:2019 IDENTICAL




Access Genorma App Everywhere

Get fast and easy access to top European and International standards (EN, ISO, IEC) via your mobile phone, tablet or the web.