ISO 27701 Certification
ISO/IEC 27701 is the international standard used to build and verify a privacy information management system (PIMS). It describes how an organization develops personal data protection: defines roles, assesses risks to people, documents processing operations, responds to data subject requests, and controls subcontractors. In the 2025 edition, it is a standalone standard with its own clause structure 4–10: certification can be obtained independently of other management systems.
Imperium Certific conducts certification audits against ISO/IEC 27701:2025 — either separately or in a single cycle with ISO/IEC 27001, if the company develops both systems simultaneously.
Two certification paths: Before 2025, this standard existed only as an extension. Now there are two paths: a standalone privacy system (suitable for companies where privacy is the primary regulatory pressure) or a combined cycle with ISO 27001 (optimal for those who already have or are simultaneously implementing an information security management system). The scope is described by processes and sites, not the entire company — you can start with one area and add the rest in the next cycle.
NAAU Accreditation
Imperium Certific is a certification body accredited by the National Accreditation Agency of Ukraine (NAAU) in accordance with DSTU EN ISO/IEC 17021-1. Certificates issued by an accredited body are recognized under IAF MLA and EA MLA multilateral agreements, ensuring international recognition without additional confirmation procedures.
Кому підходить сертифікація ISO 27701
The standard applies to organizations of any size — both those that determine the purpose of processing and those that perform it on behalf of others. Certification is most often requested by:
Software product and service developers
— applications, self-service platforms, services with end-user accounts
Companies working with the EU market
— service exporters, development outsourcing, subcontractors of European clients for whom GDPR compliance is a contractual condition
Medical and educational organizations
— institutions and platforms processing health, education, and minors' data
HR and recruitment agencies, payroll operators
— working with resumes, verifications, salary data
Financial, insurance, and marketing companies
— scoring, profiling, loyalty programs, mailings
Contact centers and IT outsourcing
— processing on behalf of clients, including cross-border
State and municipal enterprises
— registers, electronic services, citizen appeals
Переваги сертифікації ISO 27701
Independent verification removes the company's obligation to prove process maturity to each client separately.
-
Negotiation and procurement argument. European partners almost always verify how processing is organized on the contractor's side. The certificate covers most supplier questionnaires and reduces contract approvals
-
Evidence base for regulators. The standard requires documenting exactly what inspections expect: processing operations register, grounds, retention periods, impact assessment, breach response procedures. Materials are prepared within the normal cycle, not in a rush
-
Managed risks for people. Both company losses and consequences for data subjects are assessed — this is the approach embedded in European regulation and increasingly expected from Ukrainian business
-
Order in the subcontractor chain. The standard forces organizing the list of subcontractors, delegation conditions, cross-border transfer control — the area where incidents occur most frequently
-
Faster response to people's requests. Access, rectification, erasure, objection to processing have defined routes and deadlines, so requests don't block department work
-
Less duplication. If the company already has an information security management system, privacy is built into it rather than existing as a separate set of policies
Order Certification
ISO 27701 Certification Process
The procedure aligns with other management systems and complies with ISO/IEC 17021-1 requirements; a detailed description is on the certification process page.
Stage 1 — Application and Scope Definition. We clarify the company's roles, data composition and categories, sites, number of employees in scope, subcontractor list, processing geography, and chosen path: standalone or together with another system. We calculate audit duration based on this data.
Stage 2 — Documentation Audit. We verify the privacy policy, processing operations register, risk assessment methodology, data protection impact assessment, request handling procedures, delegation agreements, cross-border transfer rules, internal audit program.
Stage 3 — On-site Audit. The audit team verifies how everything works in practice: whether the processing operations register matches reality, how access is segregated, how people's requests are fulfilled, how breach responses work, whether staff is trained, how subcontractors are controlled.
Stage 4 — Certification Decision. Based on the results, a report is formed with findings and non-conformity remediation deadlines. The decision is made by a person not involved in the audit — ensuring impartiality of assessment.
Stage 5 — Certificate Issuance. The ISO 27701 certificate is valid for three years; the scope states the company's roles and covered processes. The entry is made in the certificate register.
Stage 6 — Surveillance Audits. Annual checks confirm the system operates continuously. Recertification is conducted before the certificate expires. The body is notified separately about significant changes — new data categories, sites, or subcontractors.
ISO 27701 Certification Cost
The cost is determined individually based on preliminary analysis; a preliminary calculation is made via a questionnaire — without on-site visits and without obligations for the client.
Factors affecting cost:
Calculate Cost →
Calculate Cost
Fill in a short questionnaire — we will prepare an offer for your business
Документи для сертифікації ISO 27701
Основний пакет, який перевіряють на аудиті:
- — 1. Privacy policy and internal rules for working with personal data
- — 2. Processing operations register with purpose, grounds, and retention periods
- — 3. Roles and responsibilities distribution, including the privacy officer
- — 4. Risk assessment methodology for people and assessment results
- — 5. Data protection impact assessment for high-risk operations
- — 6. Data subject request handling procedures
- — 7. Breach response procedures and notification of regulator and people
- — 8. Processing delegation agreements and subcontractor list
- — 9. Cross-border transfer rules and grounds
- — 10. Data retention and destruction policy
- — 11. Staff training program
- — 12. Internal audit program and management review materials
Отримати заявку на сертифікацію ISO 27701 →
Надіслати заявкуFAQ
No. In the 2025 edition, the standard is standalone: the audit is conducted without a certificate for an information security management system. If such a system already exists, both assessments are combined in a single cycle — this is cheaper and faster than two separate audits.
ISO/IEC 27018 is a set of controls for a cloud processor performing client's instructions; it works within ISO 27001 certification and is not a separate certificate. ISO 27701 is a full-fledged privacy information management system at the organizational level, with its own certificate, covering both the processor and the data controller.
No, and no certificate does. The standard is built on the same principles as the regulation and provides a ready-made evidence structure: processing register, grounds, impact assessment, breach notification procedures. But the legal responsibility for compliance lies with the company itself.
The standard became standalone, received clause structure 4–10 and its own annex with controls. Together with it, ISO/IEC 27706:2025 was published — requirements for bodies conducting such audits. The practical consequence: privacy certification became available to companies that don't need a full information security management system.
Transition to the new edition by October 31, 2028. The most convenient way is during a planned surveillance or recertification audit: then only the gap between existing documents and the new structure needs to be bridged, not a complete re-implementation. Preparation should start at least six months before the chosen date.
Або напишіть нам прямо зараз
Зателефонуємо протягом робочого дня