Skip to main content

ISO 27701, implemented.

ISO/IEC 27701:2025 is the international standard for a Privacy Information Management System — and since the October 2025 revision it is stand-alone, certifiable on its own without an ISO 27001 ISMS underneath it. We build the PIMS, map it to the Privacy Act and the 13 Australian Privacy Principles, and take it to certification.

What ISO/IEC 27701:2025 is

ISO/IEC 27701 is the international management system standard for privacy. It was first published in 2019 as an extension that could only sit on top of an ISO 27001 ISMS, and was revised in October 2025. The second edition is stand-alone — PECB states that the 2025 edition introduces a stand-alone PIMS, no longer requiring ISO/IEC 27001-based security management. Most guidance on the web has not caught up with that change, so check which edition a provider is describing before you buy anything.

The annex structure changed with it. Annex A is now one consolidated normative annex of 78 controls across three tables — Table A.1 for PII controllers (31), Table A.2 for PII processors (18), and Table A.3 shared security controls (29). Annex B is now implementation guidance matching Annex A, not the processor control set it was in 2019.

Who needs ISO 27701 in Australia

No Australian law names ISO 27701. What drives it is contractual and regulatory pressure that assumes exactly what a PIMS produces — a documented, repeatable way to demonstrate you handle personal information properly. The Privacy Act 1988 and its 13 Australian Privacy Principles set the obligation; ISO 27701 is how you evidence it to a customer, a board or a regulator without asking them to take your word for it.

In practice the demand concentrates in organisations answering privacy questions in enterprise procurement, SaaS companies acting as PII processors for customer data, health and financial services and government suppliers handling sensitive information, and anyone processing EU personal data who needs GDPR accountability evidence alongside the APPs.

What we actually do

We build the management system inside your environment rather than handing over a template pack. The first decision is the one most projects get wrong: determining, per processing activity, whether you are a PII controller or a PII processor. That determination decides which Annex A table applies, and most organisations are both — controller for their own staff and marketing, processor for their customers’ data.

The work runs from scope and the Clause 4 decisions, through Records of Processing Activities with the role determined per activity, privacy risk assessment and treatment, the Statement of Applicability across Tables A.1, A.2 and A.3 with a written justification per exclusion, control implementation across transparency, PII principal rights, cross-border transfer, retention and disposal, and finally internal audit and management review before the certification audit.

Stand-alone or integrated with ISO 27001?

Since the 2025 revision this is a real choice rather than a foregone conclusion, and it changes the shape and cost of the project. Integrated suits an organisation already holding ISO 27001, because clauses 4 to 10 are shared and the PIMS extends the existing scope instead of duplicating it. Stand-alone suits one whose obligation is privacy-driven and which has no commercial reason to certify information security separately.

Combined audits are more efficient, but the auditor has to be explicit about which certificate each finding attaches to — getting that wrong is a common quality-review failure. Either way the Annex A control work is the same shape, and your role per activity decides which tables apply.

How a PIMS maps to the Privacy Act and the APPs

This is the practical reason Australian organisations implement it rather than something more generic. The Act sets what you must achieve; the PIMS gives you a repeatable way to show you achieved it, with the same records answering GDPR accountability for anyone selling into Europe.

We publish the full 13-APP mapping free, so you can check the logic before engaging anyone.

ISO 27701 implementation — at a glance

What this service isISO/IEC 27701:2025 PIMS implementation, end to end
What it is notCertification — that is issued by an accredited certification body
Standard implementedISO/IEC 27701:2025, Clauses 4–10 and the 78 Annex A controls
Edition noteStand-alone since October 2025 — an ISO 27001 ISMS is no longer required
Annex A structureTable A.1 controller (31) · Table A.2 processor (18) · Table A.3 shared security (29)
Australian mappingPrivacy Act 1988 and all 13 Australian Privacy Principles
Also coversGDPR accountability evidence for organisations processing EU personal data
Who it is forPII controllers, PII processors, and organisations that are both
Delivered bySenior NV1-cleared practitioners, on-shore in Australia
Free artefactsAPP mapping, RoPA, controller/processor split and PIMS scope record

Want your own people to hold the credential instead? Aegentra Academy runs the official PECB ISO 27701 Lead Implementer and Lead Auditor courses. For what organisational certification involves, see the ISO 27701 certification guide for Australia.

Frequently asked questions

Do we still need ISO 27001 before ISO 27701?

No, not since the October 2025 revision. ISO/IEC 27701:2025 is a stand-alone management system standard — PECB states the 2025 edition introduces a stand-alone PIMS, no longer requiring ISO/IEC 27001-based security management. The 2019 edition did require it, and a great deal of published guidance still describes that version, so check which edition any provider is quoting. You can still integrate the two, and if you already hold ISO 27001 that is usually the efficient path, but it is now a choice rather than a prerequisite.

Are we a PII controller or a PII processor?

Almost certainly both, and the answer is decided per processing activity rather than per organisation. You are a controller for your own employee records, recruitment and marketing. You are a processor for data your customers put into your platform, where you act on their documented instructions. The determination selects which Annex A table applies: Table A.1 for controllers, Table A.2 for processors, and Table A.3 shared security controls which apply either way.

Does ISO 27701 certification prove Privacy Act compliance?

No standard certifies compliance with an Act. What ISO 27701 gives you is a management system that makes your position demonstrable rather than asserted — documented processing activities, a defensible security posture under APP 11, a transfer register for APP 8, and a rights-handling process for APP 12 and APP 13. When a customer, a board or the OAIC asks how you handle personal information, you have evidence rather than an opinion.

How does this differ from the ISO 27701 courses you sell?

The courses certify a person; this service builds the system. Aegentra Academy runs the official PECB ISO 27701 Foundation, Lead Implementer and Lead Auditor courses for individuals who want the credential. This page is about implementing a PIMS in your organisation. Some clients do both: train the internal owner while we build the system alongside them.

Will you also audit the PIMS you build?

No. Clause 9.2 requires internal audit by someone objective and impartial, and the people who built a system cannot credibly audit it. We run independent internal audits for management systems implemented elsewhere, and where we have done the implementation we will help you find an impartial auditor rather than mark our own work.

What does ISO 27701 implementation cost in Australia?

It depends on scope — how many processing activities, how many systems, whether you are a controller, a processor or both, and whether you are integrating with an existing ISO 27001 ISMS or standing the PIMS up alone. Integration with a certified ISMS is materially cheaper because clauses 4 to 10 already exist and are already audited. We scope it properly before quoting, and certification body fees are separate and paid directly to them.