Services: Electrical testing and certification, environmental or chemical testing

The new version of ISO/IEC 27701 Privacy Information Management System (PIMS) standard has been officially released.


Time:

2025-11-12

The new version of ISO/IEC 27701 Privacy Information Management System (PIMS) standard has been officially released. The new standard is released in an independent form and is no longer an extension of ISO/IEC 27001, so organizations do not need to obtain Information Security Management System (ISMS) certification in advance.

Recently, the revised version of ISO/IEC 27701:2025 standard has been officially released. As the latest version of the Privacy Information Management System (PIMS), this standard has entered a new stage of development, no longer as an extension of ISO/IEC 27001, but as an independent management system standard.

 

 


Core changes in the new version of ISO/IEC 27701:2025 standard

01. Independent MSS certification

The new standard is released in an independent form and is no longer an extension of ISO/IEC 27001, so organizations do not need to obtain Information Security Management System (ISMS) certification in advance. This change significantly lowers the implementation threshold, making it easier for more types of organizations to adopt the standard.


02. Adopt a coordinated structure (HS)

ISO/IEC 27701:2025 adopts the ISO Management System Coordination Structure (HS) to align with other international standardization organization management system standards such as ISO 9001, ISO/IEC 20000-1, ISO/IEC 27001, ISO/IEC 42001, and facilitate integrated management with other ISO standards.


03. Maintain compatibility with ISO/IEC 27001

The revised version integrates the relevant control measures of ISO/IEC 27002 and incorporates specialized guidance on privacy management through Appendix A and Appendix B, forming an independent set of control measures;


04. Update control measures and appendix content

The new standard integrates and optimizes the control measures framework, which currently includes six appendices covering implementation guidelines for PII controllers and processors, as well as comparative explanations with privacy regulations such as GDPR.


05. Strengthen privacy risk management mechanism

In response to the privacy challenges brought by emerging technologies such as artificial intelligence, cloud computing, cross-border data flow, and automated decision-making, the new standards further strengthen the requirements for privacy risk management.

 


Comparison with the depth of major changes in the 2019 version

 

 

In terms of changes

2019 version of ISO/IEC 27701

2025 version of ISO/IEC 27701
Standard Type

Extended standards based on ISO/IEC 27001 and 27002

Independent standard - no longer relying on ISO/IEC 27001

Certification Requirements Must first obtain ISO/IEC 27001 certification Can independently authenticate
Structural Framework Using the structure of ISO/IEC 27001:2013 Compliant with ISO Coordination Structure (HS)
Framework for Control Measures Dependency on ISO/IEC 27001 Appendix A Control Items Simplify to 31 items (controllers)+18 items (processors)+29 shared controls

Appendix Composition

Independently set Appendix A (Controller) and B (Processor) Unified Appendix A (including A.1/A.2/A.3)+Added Guideline Appendix B
Global Coordination Focus on the coordination between GDPR and ISO/IEC 27001:2013 Widely compatible with GDPR, CCPA, LGPD, PIPL and other regulations
Range of data types Universal Personally Identifiable Information (PII) Expand to biometric, health, IoT, AI data
Risk Management Based on ISMS Risk Management Measures Establish a dedicated privacy risk management mechanism
Statement of Applicability According to ISO/IEC 27001 requirements, it is mandatory to provide No longer requiring association with ISO/IEC 27001 SOA, a separate SOA needs to be established (acceptable reasons for clause exclusion need to be explained)

 


The Value and Significance of the New Standard for Enterprises

 

1. Simplify compliance process - The new independent framework eliminates reliance on ISO/IEC 27001, making standard adoption easier. This means that all requirements for implementing an internationally recognized Privacy Information Management System (PIMS) can now be found in a single document.

2. Strengthening privacy protection capabilities - By optimizing control measures and governance structures, the revised standards further enhance the level of protection for personally identifiable information (PII), helping organizations establish more comprehensive trust and accountability mechanisms.

3. Connecting with the global regulatory system - the standard content extensively connects with international mainstream privacy regulations such as GDPR, CCPA, LGPD, PIPL, etc., helping enterprises build a privacy management framework with international compatibility.

 

 

Action Guide

 

1. Initiate gap analysis and transfer route planning

Organizations that have obtained PIMS certification internationally are required to immediately conduct a comprehensive gap assessment in accordance with their new terms and Appendix A. At the same time, we should actively connect with certification agencies, comprehensively consider the transitional period arrangements and current audit cycles, and plan a scientific and reasonable migration path and execution plan.   

 

2. Optimize institutional system and governance structure

According to the new version of the standard, the system will update institutional documents including privacy policies, risk assessment mechanisms, Statement of Applicability (SoA), and job responsibilities to ensure that the overall governance framework fully complies with the provisions proposed in the new standard.

 

3. Establishing a continuous monitoring and forward-looking adaptation mechanism

Referring to Annex B implementation guidelines, establish and improve a regular monitoring system, enhance the dynamic response and self optimization capabilities of the privacy information management system to internal and external environmental changes, and ensure continuous compliance and system foresight.

 

4. Strengthen internal training and professional capacity building

Organize specialized training for relevant stakeholders, deeply interpret standard changes, pay special attention to new risks brought by emerging scenarios such as cloud services, artificial intelligence, and cross-border data transmission, and comprehensively enhance the organization's implementation and response capabilities in privacy information management.

 


As a professional third-party testing and certification service organization, Jiayu Testing has qualifications such as CMA and CNAS, and has obtained laboratory accreditation from multiple authoritative certification institutions at home and abroad. It has a skilled professional technical team, rich industry service experience, and strong testing technology capabilities. Jiayu Testing strictly follows relevant national certification and accreditation laws and regulations, and provides system certification consulting services suitable for enterprise operation. Welcome to contact us at 400-9269-886!
 

 
手机官网
手机官网

Wechat Public

Account