Skip to main content
Guide · Updated 1 August 2026

ISO 27701 Certification Australia: A Complete Guide (2026)

A practical guide to ISO/IEC 27701:2025 — the international standard for a Privacy Information Management System, and since October 2025 a standalone management system standard you can certify against without holding ISO 27001 first. Built for Australian SaaS companies, consultancies, and SMBs that handle personal data and need to demonstrate privacy management to enterprise buyers, EU customers, or regulators. Covers the typical timeline, real AUD costs, Controller vs Processor distinctions, GDPR and Australian Privacy Act mapping, and how to pick a PECB Lead Implementer course.
By Harry Sidhu ISO 27001 Lead Implementer · Director and Principal Consultant, Aegentra11 min readLast reviewed 1 August 2026

What is ISO 27701?

ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS). It was first published in 2019 as an extension to ISO 27001, and was revised on 14 October 2025 into a standalone management system standard. The current edition is published by ISO and IEC as ISO/IEC 27701:2025.

Where ISO 27001 protects information generally, ISO 27701 protects personal information specifically — Personally Identifiable Information (PII) in the standard's vocabulary. It introduces controls for lawful basis, consent management, data subject rights, retention and disposal, breach notification, and supplier processing agreements.

ISO 27701 makes a sharp distinction between two roles. A PII Controller decides why personal data is processed (this is your company for your own employees, customers, marketing lists). A PII Processor processes data on behalf of a controller (this is your SaaS product handling customer data on their instruction). Different controls apply to each role; the Statement of Applicability declares which sections of the standard you are claiming conformance to.

The 2025 revision: ISO 27701 is now a standalone standard

This is the change most ISO 27701 content on the web has not caught up with. On 14 October 2025, ISO and IEC published ISO/IEC 27701:2025, replacing the 2019 edition and restructuring the standard as a standalone management system standard.

Under the 2019 edition, ISO 27701 was written as an extension to ISO 27001 and ISO 27002. You could not certify to it on its own — it was audited as an add-on to an existing ISMS certification. The 2025 edition removes that dependency: an organisation can now be certified against ISO 27701 without first implementing and certifying a full ISO 27001 information security management system.

 2019 edition2025 edition
StatusExtension to ISO 27001 / 27002Standalone management system standard
Certify without ISO 27001?NoYes
PublishedAugust 201914 October 2025
Controls for PII controllersAnnex A31
Controls for PII processorsAnnex A, Table A.218
Information security controlsInherited from ISO 2700129, with expanded guidance

What this changes in practice: privacy-first organisations — a SaaS product handling customer PII, a health or legal practice, a marketing platform — no longer have to build an entire ISMS before they can demonstrate certified privacy management. That was previously the single biggest cost barrier to ISO 27701.

It does not make ISO 27001 pointless. Most Australian enterprise and government buyers still ask for ISO 27001 first, and the two share the same Annex SL management-system structure, so running them together remains the efficient path if you need both. See the ISO 27001 certification guide for that side.

Who needs ISO 27701 certification in Australia?

ISO 27701 is the natural follow-on to ISO 27001 for any Australian organisation whose buyers care about privacy, not just security. The audiences that ask for it:

  • SaaS companies selling into Europe or the UK — EU and UK GDPR makes privacy assurance the procurement hurdle, not security. ISO 27701 is the most credible third-party evidence base.
  • Healthcare and health-tech — handling My Health Record data, sensitive health information, or clinical trial data — and looking to demonstrate management maturity beyond minimum legal compliance.
  • Financial services tech — under APRA CPS 234 (information security) and ASIC reporting obligations, ISO 27701 demonstrates privacy maturity over and above the regulator's baseline.
  • Government technology suppliers — the ongoing Privacy Act review is expected to introduce a statutory tort for serious invasions of privacy and tighten breach notification. ISO 27701 keeps you ahead of those changes.

The shorthand: if your customers store personal data inside your product, or you handle a meaningful volume of personal data about Australian individuals, ISO 27701 is the next certification after ISO 27001.

Industries that need ISO 27701 in Australia

Four sectors generate most Australian ISO 27701 demand: SaaS handling personal data (especially cross-border), healthcare and digital-health vendors, financial services under CDR and APRA, and government and public-sector entities bound directly by the Privacy Act. The pressure shows up differently in each, but the answer is the same management system.

SaaS handling personal data — particularly cross-border

Australian SaaS companies selling into the EU, UK, or California face a privacy bar that is meaningfully higher than the Australian Privacy Act floor. GDPR, UK GDPR, and the California Consumer Privacy Act (CCPA / CPRA) all require documented privacy programmes, lawful-basis tracking, data subject request handling, and supplier diligence. ISO 27701 is the certifiable third-party evidence base buyer procurement teams and EU regulators accept. For an Australian SaaS company already certified to ISO 27001, adding ISO 27701 is the most cost-effective way to unlock European procurement without restructuring the privacy programme.

Healthcare, digital health, and TGA-regulated software

Healthcare providers, pathology operators, telehealth platforms, and digital-health vendors face the My Health Records Act 2012, the Healthcare Identifiers Act, and state health privacy regimes such as the NSW Health Records and Information Privacy Act (HRIPA) and the Victorian Health Privacy Principles (HPPs). The combined surface is hard to maintain without a documented PIMS. ISO 27701 is the standard procurement and ADHA reviewers accept as the framework for the privacy controls that overlay the underlying ISMS. TGA-regulated medical-device software handling personal data inherits the same expectation through the post-market obligations.

Financial services under CDR, APRA, and ASIC

The Australian Consumer Data Right (CDR) regime — initially banking, now expanding to energy and non-bank lending — places accreditation and ongoing privacy-management obligations on data recipients. Banks and credit unions operating under APRA CPS 234 and Australian Financial Services Licensees under ASIC RG 271 all need demonstrable privacy-management capability. ISO 27701, layered on top of an ISO 27001 ISMS, is the cleanest documentary answer to both regulators and CDR auditors.

Government, public sector, and APP-bound entities

Federal, state, and many local-government agencies are bound by the Privacy Act 1988 (or equivalent state privacy legislation such as the NSW Privacy and Personal Information Protection Act). Suppliers handling personal data on their behalf inherit those obligations through the contract. ISO 27701 is increasingly cited in tenders as the privacy-control framework against which suppliers are expected to evidence their programme — particularly in Commonwealth procurement covered by the Protective Security Policy Framework.

Mapping ISO 27701 to Australian privacy law

ISO 27701 is not Australian privacy law, but it is the management-system structure most often used to satisfy Australian privacy obligations and to bridge to cross-border regimes. The table summarises how the standard maps to the regulations Aegentra is most often asked about.

Regulation or frameworkWhat it requiresHow ISO 27701 helps
Privacy Act 1988 (APPs)Thirteen Australian Privacy Principles covering collection, use, disclosure, retention, integrity, access, and correction of personal information.The Controller and Processor control sets map directly onto APP 1-13. ISO 27701 is the standard documentary answer to OAIC enquiries about the privacy management programme.
Notifiable Data Breaches (NDB) schemeEntities must assess and notify eligible breaches to the OAIC and affected individuals.ISO 27701's breach-handling controls (built on the ISO 27001 incident-management baseline) provide the end-to-end assessment, classification, and notification process the NDB scheme expects.
GDPR (EU) and UK GDPRLawful basis, data subject rights, DPIAs, processor agreements, breach notification within 72 hours, DPO appointment where applicable.ISO 27701 was written with GDPR in mind. Annex D and Annex E provide explicit cross-walks to GDPR articles. EU procurement teams accept it as the most efficient third-party evidence base.
Consumer Data Right (CDR)Data recipients accredited under CDR must operate a privacy management programme covering consumer data handling, consent, dashboards, and deletion.The PIMS structure that satisfies CDR's privacy-safeguard obligations is, in practice, an ISO 27701-aligned programme. Auditors accept it as the framework.
Spam Act 2003Consent, identification, and unsubscribe requirements for commercial electronic messages.Annex A controls on lawful basis, consent, and data subject rights cover the consent-collection and withdrawal evidence the ACMA expects in an investigation.
My Health Records Act / HRIPA NSW / HPPs VicSector-specific health-privacy regimes with stricter consent, access, and retention rules than the Commonwealth APPs.The Controller control set extends naturally to sensitive-information categories. A scope-limited PIMS covering the health-data systems is the typical evidence package for ADHA and state regulator reviews.
APRA CPS 234Information-security capability and incident-handling obligations for APRA-regulated entities (which necessarily includes the personal-information systems).ISO 27001 + ISO 27701 together satisfy the privacy overlay APRA expects when the regulated entity processes meaningful volumes of personal data.

The pattern across all seven items is the same: ISO 27701 is rarely a literal requirement, but it is almost always the most efficient documentary answer to a regulator, a CDR auditor, or an enterprise procurement team that asks "show me your privacy management programme."

How long does ISO 27701 certification take?

For an Australian SMB that already operates an ISO 27001 ISMS, the realistic plan is 8–12 weeks of readiness followed by a combined Stage 1 / Stage 2 audit. Most of the time is spent inventorying personal data flows (what PII, where it lives, who processes it, on what lawful basis), updating supplier agreements, and documenting data subject request handling.

If you do not yet have ISO 27001, the standard-of-practice in Australia is to do a joint program — 14–18 weeks of readiness covering both standards, with a single combined audit. The cost saving from a joint audit is significant.

As with ISO 27001, audit bookings need 6–10 weeks lead time. Book Stage 2 at the start of readiness.

Adding ISO 27701 to an existing ISO 27001 certificate costs far less than a greenfield joint program, because the readiness work builds on an ISMS that is already in place.

How much does ISO 27701 certification cost in Australia?

Individual PECB training (Aegentra Academy)

Organisational certification (joint with ISO 27001)

Ranges are typical for an Australian SMB of 10–50 staff. If you already hold ISO 27001 and are adding ISO 27701, costs drop substantially compared to a greenfield joint program.

ComponentTypical AUDFrequency
Add-on readiness (existing ISO 27001)$18,000–$35,000Once
Joint readiness (greenfield 27001 + 27701)$45,000–$80,000Once
Joint Stage 1 + Stage 2 audit$12,000–$25,000Once (every 3 years)
Joint annual surveillanceStarting at $2,500Year 1 + Year 2
Three-year re-certification$12,000–$22,000Year 3
Before any documentation is written, you map every personal data flow and declare whether you act as PII Controller or PII Processor for each one.

The certification process, step-by-step

  1. 01
    Personal data inventory

    Map every flow of personal data — what PII you collect, why, where it lives, who processes it, what lawful basis applies, and how long it is retained. Distinguish data you control from data you process for customers.

  2. 02
    Role determination

    For each in-scope processing activity, declare whether you act as PII Controller, PII Processor, or both. This drives which ISO 27701 control sections apply.

  3. 03
    PIMS design

    Write the privacy policy, the Statement of Applicability for ISO 27701 (standalone under the 2025 edition, or combined with an ISO 27001 SoA if you run both), data subject request procedure, breach notification runbook, and supplier processing agreement template.

  4. 04
    Control implementation

    Configure the controls operationally — consent capture and withdrawal, data subject request handling (access, correction, erasure where applicable), data minimisation, retention enforcement, supplier oversight, cross-border transfer controls.

  5. 05
    Internal audit

    Independent reviewer audits every applicable ISO 27701 control. Typically combined with the ISO 27001 internal audit.

  6. 06
    Management review

    Leadership reviews PIMS performance, privacy incidents, data subject request metrics, and improvement opportunities.

  7. 07
    Stage 1 audit (joint)

    Documentation review by an accredited certification body. Combined ISO 27001 + ISO 27701 review is the standard pattern. 1–3 days remote.

  8. 08
    Stage 2 audit (joint)

    Effectiveness audit. Evidence sampled against both ISMS and PIMS controls. 3–5 days for an SMB.

  9. 09
    Certificate issued

    Three-year certificate covering both standards. Single annual surveillance covers both.

Lead Implementer is the tier whoever owns privacy internally needs; Foundation is an overview and Lead Auditor suits certification-body work.

Choosing a PECB ISO 27701 course

The same three-tier structure as ISO 27001: Foundation (overview), Lead Implementer (practitioner — the one your internal privacy owner needs), Lead Auditor (for auditors and certification body careers). The Lead Implementer course covers PIMS design end-to-end and is the natural follow-on for anyone who has already done ISO 27001 Lead Implementer.

Aegentra Academy is an official PECB authorised training partner in Australia (verifiable on the PECB partner directory). Every enrolment includes the official PECB exam voucher and a free resit within 12 months. Online and instructor-led delivery is available in Melbourne and Sydney.

ISO 27701 vs GDPR vs Australian Privacy Act

These three are not substitutes — they are complementary. GDPR and the Australian Privacy Act 1988 are laws that impose obligations directly on organisations. ISO 27701 is a voluntary management system standard that gives you the auditable framework to demonstrate compliance with those laws.

GDPR applies if you offer goods or services to people in the EU/UK, or monitor their behaviour, regardless of where your company is based. Annex D of ISO 27701 maps every GDPR article to the relevant ISO 27701 clause or control — giving procurement teams a single reference document to chase.

The Australian Privacy Act 1988 and the 13 APPs apply if your organisation has annual turnover over $3M AUD, handles health information, or is in certain regulated sectors. The Privacy Act review (ongoing) is expected to extend obligations to smaller businesses, introduce a statutory tort for serious invasions of privacy, and tighten breach notification.

Practical advice: if your customers store personal data in your product, build ISO 27701 first. The same controls give you defensible evidence under both GDPR and the Privacy Act, and the framework holds when the Privacy Act review concludes.

Are we a PII controller or a PII processor?

Almost certainly both — and the answer is decided per processing activity, not per organisation. This is the first decision in any PIMS and the one most often got wrong, because it propagates through the entire Statement of Applicability.

You are a PII controller where you decide why personal information is processed — your own employee records, recruitment, marketing list, website analytics. You are a PII processor where you act on someone else’s documented instructions — the data your customers put into your platform, and the support tickets that come with it.

The determination decides which Annex A table applies: Table A.1 for PII controllers (31 controls), Table A.2 for PII processors (18), and Table A.3 shared security controls (29) which apply either way. An organisation that is both — which most Australian SaaS businesses are — is in scope for all three.

Getting it wrong is expensive rather than merely untidy: a processor that quietly repurposes customer data for its own product analytics has become a controller for that activity, without the lawful basis or the collection notice a controller needs.

Free ISO 27701 templates and mappings

The four working documents a PIMS actually produces, published in full and free — no email required. They are worked examples for an Australian organisation, not blank forms.

If you would rather the PIMS was built than studied, that is our ISO 27701 implementation service. For the individual credential pathway, see how to become an ISO 27701 Lead Implementer in Australia.

FAQs

No. ISO 27701 is voluntary, but it is the most rigorous privacy management certification available internationally. The Australian Privacy Act 1988 and the Australian Privacy Principles (APPs) set the legal floor; ISO 27701 provides the auditable management system you can demonstrate to procurement teams, regulators, and overseas customers (particularly EU/UK buyers).

Not any more. The ISO/IEC 27701:2025 revision, published 14 October 2025, restructured the standard as a standalone management system standard — an organisation can now be certified against ISO 27701 without holding ISO 27001. Under the superseded 2019 edition it was an extension and could only be audited alongside an existing ISMS certification. In practice a combined ISO 27001 + ISO 27701 audit is still common, because most Australian enterprise and government buyers ask for ISO 27001 anyway and the two share the same Annex SL structure — but it is now a choice, not a requirement.

Most SaaS companies are both, but in different parts of their business. You are a Controller for your own employees and your direct marketing list; you are a Processor for the personal data your customers store inside your product. ISO 27701 has different control sets for each role, and the Statement of Applicability must declare which sections apply to you. Mapping this correctly is one of the early implementation tasks.

Annex D of ISO 27701 explicitly maps every clause and control to the relevant GDPR articles. The mapping is not absolute compliance — GDPR has obligations (data subject rights, breach notification timelines, lawful basis) that ISO 27701 helps you demonstrate but does not guarantee. In practice, ISO 27701 is the strongest off-the-shelf evidence base an Australian SaaS company can produce when an EU buyer asks for GDPR assurance.

The 13 Australian Privacy Principles (APPs) under the Privacy Act 1988 map cleanly onto ISO 27701 controls. Controls covering notice (APP 1, 5), purpose (APP 6), data quality (APP 10), security (APP 11), access and correction (APP 12, 13) all have ISO 27701 equivalents. The Privacy Act review (ongoing through 2026) is expected to tighten obligations; ISO 27701 keeps you ahead of those changes.

The NDB scheme (in force since 2018) requires Australian organisations to notify the OAIC and affected individuals when an eligible data breach occurs. ISO 27701 includes controls for incident response, breach assessment, notification timelines, and root cause analysis — all of which support NDB compliance. The decision to notify, and the legal exposure of that decision, still sits with your privacy officer and legal counsel.

No. The PECB Lead Implementer course certifies you as a practitioner to implement a PIMS. Certifying the company still requires building the PIMS, internal audit, and Stage 1/Stage 2 audit by an accredited body. The course is the right starting point for whoever owns privacy internally.

Identical to ISO 27001 — three-year certificate, annual surveillance audits in years one and two, full re-certification audit in year three. Certificate holders who run both standards usually combine the ISO 27001 and ISO 27701 surveillance into a single annual visit; a standalone PIMS certificate under the 2025 edition runs its own cycle.

Next step

Build a privacy management system that holds up.

Two paths. Both run by senior engineers, not privacy consultants reading from a deck.