+359 887 407 840 office@escert.com Stara Zagora · Sofia · Plovdiv
BGEN
New editionISO/IEC 27701:2025 is now a standalone standard

ISO/IEC 27701 certification for personal data protection

We certify privacy information management systems to ISO/IEC 27701 in Bulgaria under the established certification procedures of CERTIND S.A. The standard provides a verifiable framework for everything you do with personal data — and links directly to ISO/IEC 27001. The audit is conducted in Bulgarian, and you will receive a tailored quote within two hours.

  • Certification bodyCERTIND S.A.
  • Scopecontrollers and processors
  • Quotewithin 2 hours during business hours
Employee working with personal data on a laptop in an office

The standard at a glance

What is ISO/IEC 27701?

ISO/IEC 27701 is the international standard that sets out the requirements for a privacy information management system (PIMS). It governs what the organization does with the personal data it collects and processes — from the legal basis and purpose to erasure — and how this is demonstrated to customers, partners and the supervisory authority.

The privacy management requirements derive mainly from the General Data Protection Regulation (GDPR) and the guidelines of the European Data Protection Board. Because the GDPR provides the most detailed framework, the standard is also applicable to organizations under other legal regimes — for example, HIPAA, the Gramm-Leach-Bliley Act and the California Consumer Privacy Act in the USA.

The current edition is ISO/IEC 27701:2025, and it changed the most important thing: the standard is now standalone, and the system can be certified separately, without the organization being certified to ISO/IEC 27001. The 2019 edition was only an extension of ISO/IEC 27001 and ISO/IEC 27002. What changed.

The link with information security remains: the two standards are most often implemented and audited together, because personal data protection builds on information security measures. How the two standards fit together.

Who ISO/IEC 27701 is for

  • IT and cloud services Software and service providers that process their customers’ data.
  • Services with large volumes of customer data Telecoms, insurance, finance, healthcare, education.
  • Public sector Administrations and organizations that process citizens’ data.
  • Subcontractors Anyone who processes personal data on behalf of another organization.

NewThe 2025 edition

What changed in ISO/IEC 27701:2025

The change is fundamental, not cosmetic: the standard steps out of the shadow of ISO/IEC 27001 and becomes a standalone management system with its own requirements.

ISO/IEC 27706 was also published in 2025 — the requirements for bodies that audit and certify privacy information management systems. It is the basis on which this scheme may be accredited in the future.

The four differences at a glance

  • Standalone

    Separate certification

    The system can be built and certified on its own. Under the 2019 edition this was impossible — the organization first had to be certified to ISO/IEC 27001 and then extended the scope of its audit.

  • Title and subject

    Privacy information management systems

    The new title is “Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance”.

  • Who it is for

    Controllers and processors

    The standard is written for organizations that determine the purposes and means of processing, and for those that process personal data on another organization’s behalf — with clearly divided responsibilities.

  • The audit

    Requirements for bodies

    ISO/IEC 27706:2025 sets out the requirements for certification bodies for this scheme — the step that makes accredited certification to ISO/IEC 27701 possible.

ISO/IEC 27701 · roles

Who is responsible for what with personal data

The standard divides the requirements by role. Most organizations are both at once — a controller for the data of their own employees and customers, and a processor for the data their customers entrust to them.

  • decides why and howData controller
    • Determines the purposes and means of processing
    • Has a legal basis for every processing operation and documents it
    • Informs people what it does with their data
    • Ensures they can exercise their rights — access, rectification, erasure
    • Assesses the impact where the risk is high and notifies breaches
  • acts on instructionsData processor
    • Processes data only on documented instructions from the controller
    • Demonstrates the security measures it applies
    • Does not engage a sub-processor without authorization
    • Assists the controller with data subject requests
    • Returns or deletes the data at the end of the service

The auditor checks records, not declarations: contracts and instructions, the record of processing activities, responses to data subject requests, sub-processor files and how the organization responded to incidents.

ISO/IEC 27701 · the link

How it builds on ISO/IEC 27001

Personal data protection builds on information security. That is why the two standards are implemented together — with shared documentation, a combined internal audit and a combined certification audit.

  • Personal dataISO/IEC 27701

    Legal basis and purpose of processing, data subject rights, transparency, retention periods, sub-processors, data transfers.

  • Information securityISO/IEC 27001

    Risk assessment, access control, encryption, backups, logs, physical security, incident management.

  • Managing the organizationISO 9001

    Processes, responsibilities, documented information, internal audits and management review — the common framework on which the other two are built.

Three standards, one audit

The three systems use the same processes, documents and records. That is why they are implemented and audited together, and the combined audit is usually shorter than three separate audits.

Shared documentationCombined internal auditCombined certification auditShorter audit

How ISO/IEC 27701 certification works

The process is the same for every organization and follows ISO/IEC 17021-1, the international standard for certification bodies. Only the audit duration differs — it depends on the number of employees, the sites and the complexity of the activity.

The process in detail
  1. 01 Enquiry and quoteYou describe your activity, number of employees and sites. You receive a quote with the scope, audit duration and price.within 2 hours during business hours
  2. 02 Contract and audit planOnce the contract is signed, we agree the dates, the scope and the audit team.dates that suit you
  3. 03 Stage 1 — readiness reviewThe auditor reviews the scope, the record of processing activities, the legal bases, the retention periods and the contracts with processors, and assesses whether the system is ready.documents, scope, readiness
  4. 04 Stage 2 — on-site auditThe work is checked on site — how data subjects exercise their rights, how access and sub-processors are managed, what happened when an incident occurred, and what records all of this has left.in Bulgarian, at your premises
  5. 05 Corrective actionsIf nonconformities are found, you are given a deadline to correct them and submit evidence.only if needed
  6. 06 Decision and certificateAn independent certification decision and issue of the certificate by CERTIND S.A.under CERTIND S.A. procedures

What the price of ISO/IEC 27701 certification depends on

The price of the certificate is not fixed, because it is calculated from several factors, including the audit days your organization requires, which are determined under the mandatory document IAF MD 5.

ISO certification pricing
  • Complexity and sector

    How many and what categories of personal data you process, and how many systems they pass through.

  • Number of sites

    Offices, service centres and locations from which data is processed.

  • Number of employees

    Full-time and part-time staff.

  • Number and type of standards

    When combined in a single audit with ISO/IEC 27001 or ISO 9001, the audit is usually shorter.

What is not included in the certification price

A consultant to implement the system is a separate cost. A certification body cannot provide consultancy to the organizations it certifies — this is an impartiality requirement under ISO/IEC 17021-1.

A tailored quote for your organization

Describe your activity, number of employees and sites — within two hours during business hours you will receive a quote with scope and price.

Exact quote within 2 hours

Questions and answers

Frequently asked questions about ISO/IEC 27701

Answers to the questions our clients ask most often before certification.

Didn’t find an answer? Call us — we will answer right away. +359 887 407 840 office@escert.com

Do we need an ISO/IEC 27001 certificate first?

Not any more. Under the 2025 edition, ISO/IEC 27701 is a standalone standard and the system can be certified separately. Under the old 2019 edition, certification was possible only as an extension of the scope of an existing ISO/IEC 27001 certificate.

Is ISO/IEC 27701 certification accredited?

No. The scheme is outside the scope of CERTIND S.A.’s RENAR accreditation. The certificate is issued under the body’s established procedures after an actual audit. The accredited standard in this field is ISO/IEC 27001.

Does the certificate replace GDPR compliance?

No. The certificate shows that you have a working privacy information management system verified by an independent body. Compliance with the Regulation remains the organization’s responsibility — the standard brings order to it and makes it verifiable.

We are only a processor — is it worth it?

Yes, and directly so. Clients who entrust processing to you are obliged to vet their subcontractors. The certificate shortens that vetting and is often a condition in a contract or tender.

How long is the certificate valid?

Three years. Surveillance audits are carried out in the second and third years, and after the end of the cycle comes recertification, which keeps the certificate valid.

ISO/IEC 27701 · Free quote

ISO/IEC 27701 certification

Describe your activity, the organization’s locations, number of employees and types of standards — within two hours during business hours you will receive a quote with the scope, audit duration and an all-inclusive price.

  • Certification bodyCERTIND S.A.
  • Auditin Bulgarian, at your premises
  • Quotewithin 2 hours during business hours