ISO/IEC 27701 Privacy Information Management
A privacy information management extension to ISO/IEC 27001. The 2025 edition was published in October 2025; certificates to the 2019 edition run to 31 October 2028.
Who asks for it
Organisations processing personal data at scale, and every existing holder of a 2019-edition certificate.
Typical duration
2–5 months
What a readiness engagement produces
- A written gap analysis with priorities
- Documentation written for your operation
- Training so staff can explain the system
- Internal audit and management review
- An evidence pack ready for the auditor
The two fees
The certification fee is charged by the accredited certification body that audits you and issues the certificate. Our consultancy fee covers gap analysis, documentation, training, internal audit and audit support.
Consultancy fee refund commitment
If your organisation is not recommended for certification at the first certification audit, we refund our consultancy fee in full.
Conditions: the agreed corrective actions are completed, the required records and evidence are provided, and the audit is conducted by an accredited certification body within three months of our readiness sign-off. The commitment covers our consultancy fee only, not the certification body's fees.
Preparing for ISO/IEC 27701?
Tell us the scope and we will give you a written quotation.