ISO 27701, implemented.
ISO/IEC 27701:2025 is the international standard for a Privacy Information Management System — and since the October 2025 revision it is stand-alone, certifiable on its own without an ISO 27001 ISMS underneath it. We build the PIMS, map it to the Privacy Act and the 13 Australian Privacy Principles, and take it to certification.
What ISO/IEC 27701:2025 is
ISO/IEC 27701 is the international management system standard for privacy. It was first published in 2019 as an extension that could only sit on top of an ISO 27001 ISMS, and was revised in October 2025. The second edition is stand-alone — PECB states that the 2025 edition introduces a stand-alone PIMS, no longer requiring ISO/IEC 27001-based security management. Most guidance on the web has not caught up with that change, so check which edition a provider is describing before you buy anything.
The annex structure changed with it. Annex A is now one consolidated normative annex of 78 controls across three tables — Table A.1 for PII controllers (31), Table A.2 for PII processors (18), and Table A.3 shared security controls (29). Annex B is now implementation guidance matching Annex A, not the processor control set it was in 2019.
Who needs ISO 27701 in Australia
No Australian law names ISO 27701. What drives it is contractual and regulatory pressure that assumes exactly what a PIMS produces — a documented, repeatable way to demonstrate you handle personal information properly. The Privacy Act 1988 and its 13 Australian Privacy Principles set the obligation; ISO 27701 is how you evidence it to a customer, a board or a regulator without asking them to take your word for it.
In practice the demand concentrates in organisations answering privacy questions in some enterprise procurement processes, SaaS companies acting as PII processors for customer data, health and financial services and government suppliers handling sensitive information, and anyone processing EU personal data who needs GDPR accountability evidence alongside the APPs.
What we actually do
We build the management system inside your environment rather than handing over a template pack. The first decision is the one most projects get wrong: determining, per processing activity, whether you are a PII controller or a PII processor. That determination decides which Annex A table applies, and most organisations are both — controller for their own staff and marketing, processor for their customers’ data.
The work runs from scope and the Clause 4 decisions, through Records of Processing Activities with the role determined per activity, privacy risk assessment and treatment, the Statement of Applicability across Tables A.1, A.2 and A.3 with a written justification per exclusion, control implementation across transparency, PII principal rights, cross-border transfer, retention and disposal, and finally internal audit and management review before the certification audit.
Stand-alone or integrated with ISO 27001?
Since the 2025 revision this is a real choice rather than a foregone conclusion, and it changes the shape and cost of the project. Integrated suits an organisation already holding ISO 27001, because clauses 4 to 10 are shared and the PIMS extends the existing scope instead of duplicating it. Stand-alone suits one whose obligation is privacy-driven and which has no commercial reason to certify information security separately.
Combined audits are more efficient, but the auditor has to be explicit about which certificate each finding attaches to — getting that wrong is a common quality-review failure. Either way the Annex A control work is the same shape, and your role per activity decides which tables apply.
How a PIMS maps to the Privacy Act and the APPs
This is the practical reason Australian organisations implement it rather than something more generic. The Act sets what you must achieve; the PIMS gives you a repeatable way to show you achieved it, with the same records answering GDPR accountability for anyone selling into Europe.
- APP 1 — open and transparent management maps to the privacy policy and Clause 5 leadership
- APP 8 — cross-border disclosure maps to the transfer register and the safeguard relied on per destination
- APP 11 — security of personal information maps to the Table A.3 shared security controls, retention and disposal
- APP 12 and APP 13 — access and correction map to the PII principal rights process
We publish the full 13-APP mapping free, so you can check the logic before engaging anyone.
ISO 27701 implementation — at a glance
| What this service is | ISO/IEC 27701:2025 PIMS implementation, end to end |
|---|---|
| What it is not | Certification — that is issued by an accredited certification body |
| Standard implemented | ISO/IEC 27701:2025, Clauses 4–10 and the 78 Annex A controls |
| Edition note | Stand-alone since October 2025 — an ISO 27001 ISMS is no longer required |
| Annex A structure | Table A.1 controller (31) · Table A.2 processor (18) · Table A.3 shared security (29) |
| Australian mapping | Privacy Act 1988 and all 13 Australian Privacy Principles |
| Also covers | GDPR accountability evidence for organisations processing EU personal data |
| Who it is for | PII controllers, PII processors, and organisations that are both |
| Delivered by | A named Aegentra lead with roles and location stated in the agreed scope |
| Free artefacts | APP mapping, RoPA, controller/processor split and PIMS scope record |
Want your own people to hold the credential instead? Aegentra Academy runs the official PECB ISO 27701 Lead Implementer and Lead Auditor courses. For what organisational certification involves, see the ISO 27701 certification guide for Australia.
Frequently asked questions
Do we still need ISO 27001 before ISO 27701?
No, not since the October 2025 revision. ISO/IEC 27701:2025 is a stand-alone management system standard — PECB states the 2025 edition introduces a stand-alone PIMS, no longer requiring ISO/IEC 27001-based security management. The 2019 edition did require it, and a great deal of published guidance still describes that version, so check which edition any provider is quoting. You can still integrate the two, and if you already hold ISO 27001 that is usually the efficient path, but it is now a choice rather than a prerequisite.
Are we a PII controller or a PII processor?
Almost certainly both, and the answer is decided per processing activity rather than per organisation. You are a controller for your own employee records, recruitment and marketing. You are a processor for data your customers put into your platform, where you act on their documented instructions. The determination selects which Annex A table applies: Table A.1 for controllers, Table A.2 for processors, and Table A.3 shared security controls which apply either way.
Does ISO 27701 certification prove Privacy Act compliance?
No standard certifies compliance with an Act. What ISO 27701 gives you is a management system that makes your position demonstrable rather than asserted — documented processing activities, a defensible security posture under APP 11, a transfer register for APP 8, and a rights-handling process for APP 12 and APP 13. When a customer, a board or the OAIC asks how you handle personal information, you have evidence rather than an opinion.
How does this differ from the ISO 27701 courses you sell?
The courses certify a person; this service builds the system. Aegentra Academy runs the official PECB ISO 27701 Foundation, Lead Implementer and Lead Auditor courses for individuals who want the credential. This page is about implementing a PIMS in your organisation. Some clients do both: train the internal owner while we build the system alongside them.
Will you also audit the PIMS you build?
No. Clause 9.2 requires internal audit by someone objective and impartial, and the people who built a system cannot credibly audit it. We run independent internal audits for management systems implemented elsewhere, and where we have done the implementation we will help you find an impartial auditor rather than mark our own work.
What does ISO 27701 implementation cost in Australia?
It depends on scope — how many processing activities, how many systems, whether you are a controller, a processor or both, and whether you are integrating with an existing ISO 27001 ISMS or standing the PIMS up alone. Integration with a certified ISMS is materially cheaper because clauses 4 to 10 already exist and are already audited. We scope it properly before quoting, and certification body fees are separate and paid directly to them.
Who will deliver your ISO 27701 implementation?
The privacy-management scope identifies the accountable lead, the relationship to the existing ISMS and any specialist input required for the processing activities inside scope.
- Accountable delivery — ISO 27701 implementation lead. The lead, responsibilities, deliverables and exclusions are recorded in the written scope.
- Specialist contribution — Privacy or information-security support, where required. The function and responsibility are disclosed before specialist work begins.
- Assurance boundary — Implementation, internal audit and certification kept distinct. The engagement record identifies Aegentra’s role. An independent certification body makes the certification decision.
Qualified delivery matched to your scope
Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.
The people assigned to your engagement—and the experience and qualification evidence relevant to their roles—are confirmed in your proposal before work begins.
Team qualifications and credentials
Qualifications, professional credentials and formal training held across Aegentra’s delivery team.
Management systems and audit
- ISO/IEC 27001 Lead Implementer
- PECB ISO/IEC 27001 Lead Auditor
- ISO/IEC 42001 Lead Auditor
- CISA — Certified Information Systems Auditor
- ISM Auditor
Cybersecurity and cloud
- CISSP — Certified Information Systems Security Professional
- CISM — Certified Information Security Manager
- Certificate of Cloud Security Knowledge (CCSK)
- OSCP+ — OffSec Certified Professional Plus
Service delivery and specialist training
- ITIL Expert
- PRINCE2
- Mastering Generative AI for Cybersecurity Certificate
- Essential Eight Assessment Course certificate — TAFEcyber
Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.
Personnel security clearance
NV1 Security ClearanceNV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.
Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.
The delivery model is set by the PIMS boundary and the work retained by the client, not by a fixed team template. View our delivery-team capability.
Where we work
Delivered across Australia — all states and territories — with remote delivery and onsite attendance by arrangement. New Zealand and wider Asia Pacific engagements may be available by arrangement.