ISO 27701
The international standard for privacy information management systems, for organisations that process personal data as controllers or processors.
The 2019 edition extended ISO 27001 and could only be used alongside it. The 2025 edition is a management system standard in its own right, though it is still built to align with ISO 27001, and many organisations run the two together. Organisations can be certified against it; as with any certificate, the scope is worth reading.
Source: ISO/IEC 27701:2025 ↗
Related terms
ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.