ISO 27701 Certification

International standard ISO/IEC 27701:2025 — Information technology — Security techniques — Requirements for information security management systems — Privacy information management requirements and guidelines.

ISO/IEC 27701 is the international standard used to build and verify a privacy information management system (PIMS). It describes how an organization develops personal data protection: defines roles, assesses risks to people, documents processing operations, responds to data subject requests, and controls subcontractors. In the 2025 edition, it is a standalone standard with its own clause structure 4–10: certification can be obtained independently of other management systems.

Imperium Certific conducts certification audits against ISO/IEC 27701:2025 — either separately or in a single cycle with ISO/IEC 27001, if the company develops both systems simultaneously.

Two certification paths: Before 2025, this standard existed only as an extension. Now there are two paths: a standalone privacy system (suitable for companies where privacy is the primary regulatory pressure) or a combined cycle with ISO 27001 (optimal for those who already have or are simultaneously implementing an information security management system). The scope is described by processes and sites, not the entire company — you can start with one area and add the rest in the next cycle.

§

NAAU Accreditation

Imperium Certific is a certification body accredited by the National Accreditation Agency of Ukraine (NAAU) in accordance with DSTU EN ISO/IEC 17021-1. Certificates issued by an accredited body are recognized under IAF MLA and EA MLA multilateral agreements, ensuring international recognition without additional confirmation procedures.

Кому підходить сертифікація ISO 27701

The standard applies to organizations of any size — both those that determine the purpose of processing and those that perform it on behalf of others. Certification is most often requested by:

Software product and service developers

— applications, self-service platforms, services with end-user accounts

Companies working with the EU market

— service exporters, development outsourcing, subcontractors of European clients for whom GDPR compliance is a contractual condition

Medical and educational organizations

— institutions and platforms processing health, education, and minors' data

HR and recruitment agencies, payroll operators

— working with resumes, verifications, salary data

Financial, insurance, and marketing companies

— scoring, profiling, loyalty programs, mailings

Contact centers and IT outsourcing

— processing on behalf of clients, including cross-border

State and municipal enterprises

— registers, electronic services, citizen appeals

Переваги сертифікації ISO 27701

Independent verification removes the company's obligation to prove process maturity to each client separately.

  • Negotiation and procurement argument. European partners almost always verify how processing is organized on the contractor's side. The certificate covers most supplier questionnaires and reduces contract approvals

  • Evidence base for regulators. The standard requires documenting exactly what inspections expect: processing operations register, grounds, retention periods, impact assessment, breach response procedures. Materials are prepared within the normal cycle, not in a rush

  • Managed risks for people. Both company losses and consequences for data subjects are assessed — this is the approach embedded in European regulation and increasingly expected from Ukrainian business

  • Order in the subcontractor chain. The standard forces organizing the list of subcontractors, delegation conditions, cross-border transfer control — the area where incidents occur most frequently

  • Faster response to people's requests. Access, rectification, erasure, objection to processing have defined routes and deadlines, so requests don't block department work

  • Less duplication. If the company already has an information security management system, privacy is built into it rather than existing as a separate set of policies

Order Certification

ISO 27701 Certification Process

The procedure aligns with other management systems and complies with ISO/IEC 17021-1 requirements; a detailed description is on the certification process page.

Stage 1 — Application and Scope Definition. We clarify the company's roles, data composition and categories, sites, number of employees in scope, subcontractor list, processing geography, and chosen path: standalone or together with another system. We calculate audit duration based on this data.

Stage 2 — Documentation Audit. We verify the privacy policy, processing operations register, risk assessment methodology, data protection impact assessment, request handling procedures, delegation agreements, cross-border transfer rules, internal audit program.

Stage 3 — On-site Audit. The audit team verifies how everything works in practice: whether the processing operations register matches reality, how access is segregated, how people's requests are fulfilled, how breach responses work, whether staff is trained, how subcontractors are controlled.

Stage 4 — Certification Decision. Based on the results, a report is formed with findings and non-conformity remediation deadlines. The decision is made by a person not involved in the audit — ensuring impartiality of assessment.

Stage 5 — Certificate Issuance. The ISO 27701 certificate is valid for three years; the scope states the company's roles and covered processes. The entry is made in the certificate register.

Stage 6 — Surveillance Audits. Annual checks confirm the system operates continuously. Recertification is conducted before the certificate expires. The body is notified separately about significant changes — new data categories, sites, or subcontractors.

ISO 27701 Certification Cost

The cost is determined individually based on preliminary analysis; a preliminary calculation is made via a questionnaire — without on-site visits and without obligations for the client.

Factors affecting cost:

Chosen path — standalone system or combined cycle with ISO 27001
Company role: data controller, processor, or both simultaneously
Data composition and categories, including health and children's data
Number of employees and sites in scope
Processing geography and cross-border transfers
Number of subcontractors with access to data
Presence of existing certificates for other management systems
Need to transition from the 2019 edition

Calculate Cost →

Calculate Cost

Fill in a short questionnaire — we will prepare an offer for your business

Документи для сертифікації ISO 27701

Основний пакет, який перевіряють на аудиті:

  • 1. Privacy policy and internal rules for working with personal data
  • 2. Processing operations register with purpose, grounds, and retention periods
  • 3. Roles and responsibilities distribution, including the privacy officer
  • 4. Risk assessment methodology for people and assessment results
  • 5. Data protection impact assessment for high-risk operations
  • 6. Data subject request handling procedures
  • 7. Breach response procedures and notification of regulator and people
  • 8. Processing delegation agreements and subcontractor list
  • 9. Cross-border transfer rules and grounds
  • 10. Data retention and destruction policy
  • 11. Staff training program
  • 12. Internal audit program and management review materials

Отримати заявку на сертифікацію ISO 27701 →

Надіслати заявку

FAQ

Залишились питання?

Отримати інформацію

Або напишіть нам прямо зараз

Зателефонуємо протягом робочого дня

?