Registrations

ISO 27701 Certification (Privacy)

A genuine, accredited certificate for your privacy programme — built as an extension of ISO 27001, for SaaS and processor businesses that keep hearing “GDPR certification” asked for in enterprise and EU due diligence.

Why founders pick CapEasy

5.0★ across 335+ Google reviews

2,700+ founders served across India

Overview

ISO/IEC 27701 is a Privacy Information Management System (PIMS) standard, and it is not something you can certify against on its own. It extends ISO/IEC 27001 and 27002, adding privacy-specific controls (consent handling, data subject rights, processor obligations) on top of an existing information security management system. That means the starting question for any business asking about ISO 27701 is really about ISO 27001: you either already hold it, or you pursue both together as a single certification project.

The reason this standard gets asked for so often is that the thing enterprise procurement and EU customers actually want — a “GDPR certificate” — does not exist. GDPR does allow certification schemes under Articles 42 and 43, but the only one approved so far by the European Data Protection Board is EU-based and not something an Indian company can walk up and buy. What an Indian SaaS or processor business can honestly obtain instead is ISO 27701: a real, third-party-audited certificate issued by an accredited certification body, addressing the same privacy-management substance a GDPR-literate buyer is actually screening for.

That distinction matters commercially. A vendor security questionnaire or an EU customer’s data processing addendum will often list “GDPR certified” as a checkbox with no real scheme behind it. Presenting ISO 27701 alongside ISO 27001 answers the same diligence question with a certificate that is actually auditable and actually issued by someone other than the company claiming it.

CapEasy prepares your organisation for the ISO 27701 audit — gap analysis against the extended PIMS controls, documentation, internal audit, and readiness for Stage 1 and Stage 2 assessment — and works only with NABCB- or IAF-accredited certification bodies for the actual audit and certificate issuance. We do not issue certificates ourselves; no consultancy does. An unaccredited “certificate” bought cheap from an unrecognised body will not survive a serious enterprise or EU counterparty’s own verification, so accreditation is the one thing we do not compromise on.

Who it’s for

  • SaaS and processor businesses being asked for “GDPR compliance” or “GDPR certification” by EU customers or enterprise procurement, where no such certificate actually exists to buy
  • Companies that already hold, or are concurrently pursuing, ISO/IEC 27001 and want the privacy layer that extends it
  • Data processors and sub-processors handling personal data on behalf of EU or enterprise clients, where a contractual data processing addendum references third-party certification
  • Businesses selling into markets or sectors where vendor security review now covers privacy-programme maturity alongside information security
  • Founders who have been quoted a “GDPR certificate” by another vendor and want to know what is and is not real before paying for it

Eligibility & requirements

  • An existing ISO/IEC 27001-certified information security management system, or a willingness to build one alongside ISO 27701 — the two are not separable
  • Documented privacy roles and responsibilities, including a defined point of contact for privacy matters within the management system
  • Personal data processing activities mapped against the PIMS controls that apply to you as a PII controller, a PII processor, or both
  • Consent and data-subject-rights handling that can be evidenced with records, not just policy documents
  • Processor and sub-processor contracts carrying privacy obligations consistent with what your own PIMS commits to
  • Management commitment to an ongoing three-year certification cycle with annual surveillance audits, not a one-time exercise
  • Willingness to be audited by, and certified through, a NABCB- or IAF-accredited certification body — not an unaccredited or self-styled one

How CapEasy handles it

  1. Confirm your ISO 27001 status. If you are not already certified, the 27001 ISMS build runs first or in parallel, since ISO 27701 has nothing to extend without it
  2. Gap analysis against the ISO 27701 PIMS controls, scoped to whether you act as a PII controller, a PII processor, or both
  3. Documentation build: privacy policy, records of processing, data subject rights procedures, and the PIMS annexes the standard adds on top of your ISMS documentation
  4. Internal audit of the combined ISMS/PIMS, closing findings before you go external
  5. Selection of a NABCB- or IAF-accredited certification body and preparation for its Stage 1 (documentation review) and Stage 2 (implementation) audits
  6. Support through the Stage 1 and Stage 2 audits, including corrective action on any nonconformities the auditor raises
  7. Certificate issuance by the accredited body once the audit closes clean; CapEasy prepares and supports the process, the certification body audits and issues
  8. Surveillance-audit readiness each year through the three-year cycle, so the certificate stays live between assessments

Documents you’ll typically need

  • Your current ISO/IEC 27001 certificate and ISMS documentation, or the state of that build if it is in progress
  • A record of personal data processing activities: what you collect, why, from whom, and where it is stored or transferred
  • Existing privacy policy, consent mechanisms, and any data processing addenda signed with customers or vendors
  • Contracts with processors and sub-processors that touch personal data on your behalf
  • Details of any cross-border data transfers, particularly to or from the EU
  • Evidence of how data subject requests (access, correction, deletion) are currently handled, if at all

CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.

Frequently asked

ISO 27701 Certification (Privacy) — questions founders ask

No, and this is worth being precise about. There is no official, purchasable “GDPR certificate.” GDPR allows certification schemes under Articles 42 and 43, but the only EDPB-approved scheme so far is EU-based and not something an Indian company obtains in the ordinary course. ISO 27701 is a real, accredited, third-party-audited certificate that addresses the same privacy-management substance — consent, data subject rights, processor controls — that a GDPR-literate customer is actually asking about. It is the honest thing to present instead.

Yes. ISO/IEC 27701 is not a standalone standard — it extends ISO/IEC 27001 and 27002 into privacy information management. You need an ISO 27001-certified management system already in place, or you build it alongside 27701 as one combined project. There is no path to a 27701 certificate that skips 27001.

No. Certificates are issued by independent, accredited certification bodies after their own audit, never by the consultancy preparing the applicant. CapEasy runs the gap analysis, documentation and internal audit, and gets you ready for the certification body’s Stage 1 and Stage 2 assessments — the audit and the certificate itself come from an accredited third party.

It matters a great deal. A certificate from a body that isn’t NABCB-accredited (or accredited by an equivalent IAF-MLA-signatory body) does not carry the same international recognition, and a serious enterprise or EU counterparty running their own vendor-security diligence will often check accreditation directly. An unaccredited certificate can look identical on paper but fail exactly the diligence check it was meant to pass. We work only with accredited certification bodies for this reason.

It helps, but it is not a substitute. ISO 27701 is an international privacy-management standard built primarily around GDPR-style obligations, and India’s DPDP Act has its own distinct requirements that do not map one-to-one onto it. A well-run ISO 27701 programme gives you much of the operational discipline DPDP also expects, but DPDP readiness needs its own assessment against Indian law. See our DPDP Act compliance service for that piece.

ISO 27701 follows the same three-year certification cycle as ISO 27001: an initial Stage 1 and Stage 2 audit, then annual surveillance audits to keep the certificate live, and full recertification at the end of the three years. It is not a one-time badge — the certification body continues checking that your PIMS is actually operating, not just documented.

Your CapEasy experts

Connect with us

Talk to the people who handle this work every day — no call centre, no hand-offs.

Ayush Joshi

Ayush Joshi

Co-Founder

Ex-OYO and Tenaciousfly. 7+ years in business development, strategic acquisitions, financing and debt syndication.

Aditya Jain

Aditya Jain

Co-Founder

Ex-Bank of America. 4+ years in investment banking, EU & Indian compliances, ESG compliances, and project management.

Manav Raval

Virtual CFO & Tax Specialist

Section 80-IAC, tax planning and startup compliance. Previously at Toyota Motor Corporation and Jaguar Land Rover.

Book a free consultation.

An honest assessment of where you are and what comes next — no cost, no pressure, no inflated promises.