Get Demo
↑

ISO 27701 Requirements and Privacy Controls (Controllers vs Processors)

ISO/IEC...

Published: September 2026 Compliance · Privacy 8–12 min read

ISO/IEC 27701:2025 organises PIMS requirements in management-system Clauses 4–10 and restructured annex guidance for privacy controls. Controllers and processors share many themes but differ on purpose determination, instructions, and sub-processor duties.

Related: PIMS explained · Checklist.

Structure first: Focus on Clauses 4–10 and controller/processor control themes. Where a certification body publishes its own control-count summary, cite that source rather than treating informal tallies as part of the ISO text.

Clauses 4–10 (High Level)

Clause
Focus
4 Context
Interested parties, PII scope, roles (controller/processor/joint)
5 Leadership
Policy, roles, resources, accountability
6 Planning
Risks/opportunities, privacy objectives, changes
7 Support
Competence, awareness, documented information
8 Operation
Operational planning, PII processing controls
9 Performance
Monitoring, internal audit, management review
10 Improvement
Nonconformity, corrective action, continual improvement

Controller vs Processor Themes

Note on 2019 Annex A/B

ISO/IEC 27701:2019 presented controller and processor privacy controls in separate annexes (often referenced as Annex A/B). The 2025 edition consolidates and restructures that pattern—map your Statement of Applicability to the edition your CB audits against.

Evidence Auditors Expect

Map Controls to Living Evidence

Use CSA to keep controller and processor artefacts audit-ready.

Frequently Asked Questions

Are Annex A and Annex B still separate in 2025?

The 2025 edition restructures annexes versus the 2019 separate controller/processor annex pattern. Use your CB’s SoA template for the edition under audit.

Does ISO 27701 list every GDPR article?

No. It is a management-system standard. Map controls to legal obligations separately for GDPR, PDPL, CCPA, and others.

Can processors certify without serving EU customers?

Certification depends on your PIMS scope and CB rules, not on a single geography. Scope the processing you claim.

Explained · vs GDPR · CSA Privacy

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!