Overview
ISO/IEC 27701 is a Privacy Information Management System (PIMS) standard, and it is not something you can certify against on its own. It extends ISO/IEC 27001 and 27002, adding privacy-specific controls (consent handling, data subject rights, processor obligations) on top of an existing information security management system. That means the starting question for any business asking about ISO 27701 is really about ISO 27001: you either already hold it, or you pursue both together as a single certification project.
The reason this standard gets asked for so often is that the thing enterprise procurement and EU customers actually want — a “GDPR certificate” — does not exist. GDPR does allow certification schemes under Articles 42 and 43, but the only one approved so far by the European Data Protection Board is EU-based and not something an Indian company can walk up and buy. What an Indian SaaS or processor business can honestly obtain instead is ISO 27701: a real, third-party-audited certificate issued by an accredited certification body, addressing the same privacy-management substance a GDPR-literate buyer is actually screening for.
That distinction matters commercially. A vendor security questionnaire or an EU customer’s data processing addendum will often list “GDPR certified” as a checkbox with no real scheme behind it. Presenting ISO 27701 alongside ISO 27001 answers the same diligence question with a certificate that is actually auditable and actually issued by someone other than the company claiming it.
CapEasy prepares your organisation for the ISO 27701 audit — gap analysis against the extended PIMS controls, documentation, internal audit, and readiness for Stage 1 and Stage 2 assessment — and works only with NABCB- or IAF-accredited certification bodies for the actual audit and certificate issuance. We do not issue certificates ourselves; no consultancy does. An unaccredited “certificate” bought cheap from an unrecognised body will not survive a serious enterprise or EU counterparty’s own verification, so accreditation is the one thing we do not compromise on.
Who it’s for
- SaaS and processor businesses being asked for “GDPR compliance” or “GDPR certification” by EU customers or enterprise procurement, where no such certificate actually exists to buy
- Companies that already hold, or are concurrently pursuing, ISO/IEC 27001 and want the privacy layer that extends it
- Data processors and sub-processors handling personal data on behalf of EU or enterprise clients, where a contractual data processing addendum references third-party certification
- Businesses selling into markets or sectors where vendor security review now covers privacy-programme maturity alongside information security
- Founders who have been quoted a “GDPR certificate” by another vendor and want to know what is and is not real before paying for it
Eligibility & requirements
- An existing ISO/IEC 27001-certified information security management system, or a willingness to build one alongside ISO 27701 — the two are not separable
- Documented privacy roles and responsibilities, including a defined point of contact for privacy matters within the management system
- Personal data processing activities mapped against the PIMS controls that apply to you as a PII controller, a PII processor, or both
- Consent and data-subject-rights handling that can be evidenced with records, not just policy documents
- Processor and sub-processor contracts carrying privacy obligations consistent with what your own PIMS commits to
- Management commitment to an ongoing three-year certification cycle with annual surveillance audits, not a one-time exercise
- Willingness to be audited by, and certified through, a NABCB- or IAF-accredited certification body — not an unaccredited or self-styled one
How CapEasy handles it
- Confirm your ISO 27001 status. If you are not already certified, the 27001 ISMS build runs first or in parallel, since ISO 27701 has nothing to extend without it
- Gap analysis against the ISO 27701 PIMS controls, scoped to whether you act as a PII controller, a PII processor, or both
- Documentation build: privacy policy, records of processing, data subject rights procedures, and the PIMS annexes the standard adds on top of your ISMS documentation
- Internal audit of the combined ISMS/PIMS, closing findings before you go external
- Selection of a NABCB- or IAF-accredited certification body and preparation for its Stage 1 (documentation review) and Stage 2 (implementation) audits
- Support through the Stage 1 and Stage 2 audits, including corrective action on any nonconformities the auditor raises
- Certificate issuance by the accredited body once the audit closes clean; CapEasy prepares and supports the process, the certification body audits and issues
- Surveillance-audit readiness each year through the three-year cycle, so the certificate stays live between assessments
Documents you’ll typically need
- Your current ISO/IEC 27001 certificate and ISMS documentation, or the state of that build if it is in progress
- A record of personal data processing activities: what you collect, why, from whom, and where it is stored or transferred
- Existing privacy policy, consent mechanisms, and any data processing addenda signed with customers or vendors
- Contracts with processors and sub-processors that touch personal data on your behalf
- Details of any cross-border data transfers, particularly to or from the EU
- Evidence of how data subject requests (access, correction, deletion) are currently handled, if at all
CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.



