ISO 27701
02 Jul 2026

ISO 27701

Relevant Cybersecurity Publications

Description

Who is it intended for?

The ISO 27701 standard applies to any public or private organization, large or small, that wishes to manage privacy in an integrated manner with information security, in accordance with an international standard.

What is it?

ISO/IEC 27701:2019 is an international standard that establishes the requirements an organization must meet to properly manage privacy information (personal data) in an integrated manner with the principles set forth in ISO 27001 and ISO 27002 for information security management. This standard establishes:

The general requirements that must be met, at the management system level, so that privacy information management is carried out using the PDCA (Plan-Do-Check-Act) cycle or Deming cycle and can be established, implemented, and continuously improved, extending within the framework of privacy information the requirements established by ISO 27001 for information security management in general.

Specific guidance on privacy measures to be developed based on the security controls proposed by ISO 27002 and included in Annex A of ISO 27001, which expands these security measures from a privacy perspective.

In this way, the standard lays the groundwork for any organization to preserve the confidentiality, integrity, and availability of personal data in a manner integrated with its Information Security Management System (ISMS), through the application of a continuous information security risk management process that specifically covers the personal data being processed.