HomePlatformComplify PIMS
Complify PIMSISO 27701 : 2025Standalone Standard

Privacy Compliance.
Standalone.
Or Integrated.

Complify PIMS is built on ISO 27701:2025 — the first edition of the standard that can be implemented and certified independently, without ISO 27001 as a prerequisite. Whether you need a standalone privacy certification or want to integrate PIMS with an existing ISMS, Complify supports both paths.

2025
Latest Edition
3
Annexes Covered
Oct 2028
Transition Deadline
PIMS Dashboard● Active
PII Processing Inventory94%
Annex A Controls81%
DSAR Compliance100%
🔔

3 DSARs pending · Earliest deadline: 8 days

The Standard

ISO 27701 : 2025 —
Privacy, standalone.

ISO 27701:2025, released in October 2025, is a landmark revision. For the first time, organizations can implement and certify a Privacy Information Management System independently — without ISO 27001 as a prerequisite.

For organizations already holding ISO 27001, integration remains seamless — shared controls, combined audits, and a single platform for both programs.

See the Certification Paths →
Path A
Standalone PIMS
ISO 27701:2025 only — no ISO 27001 required. Full privacy certification in its own right.
New in 2025
Path B
Integrated ISMS + PIMS
Add ISO 27701 on top of your existing ISO 27001. Shared controls, combined audit, faster certification.
Most efficient
Path C
GDPR Accountability
Use ISO 27701 as a structured GDPR compliance framework. Annex D maps controls directly to GDPR articles.
GDPR mapping
Platform Capabilities

Everything your PIMS
needs. Unified.

Complify PIMS operationalizes every ISO 27701 requirement — from PII processing inventories and privacy risk assessments to data subject rights workflows and cross-border transfer management.

🗂️
PII Processing Inventory

Document all PII processing activities with structured templates aligned to Annex A requirements. Capture data categories, retention periods, and legal basis in a searchable register.

⚖️
Privacy Risk Assessment

Run ISO 27701-aligned privacy risk assessments integrated with your existing risk register. Identify and treat privacy risks across your entire processing landscape.

📋
Data Subject Rights

End-to-end DSAR workflow management with automated deadline tracking. Handle access, erasure, portability, and objection requests within statutory timeframes.

📝
Consent Management

Document consent mechanisms, track revocations, and maintain evidence of valid consent across all processing activities requiring it as legal basis.

🌍
Cross-Border Transfers

Map all international data transfers, document applicable transfer mechanisms (SCCs, BCRs, adequacy decisions), and maintain a compliant transfer register.

📊
Statement of Applicability

Generate a Privacy SoA aligned to ISO 27701 Annex A, B, and C — with justification for inclusions and exclusions, integrated with your ISO 27001 SoA if applicable.

Annex Coverage

Full coverage across
all three Annexes.

Complify PIMS provides built-in workflows, templates, and evidence automation for controls across Annexes A, B, and C of ISO 27701.

A.7.2
Identify Lawful Basis

Document and maintain the legal basis for every PII processing activity in a structured register.

Controller
A.7.3
Consent Management

Determine when and how consent is required, and manage consent lifecycle across all processing.

Controller
A.7.4
Privacy Notice

Generate and maintain privacy notices aligned to ISO 27701 and GDPR transparency requirements.

Controller
A.8.2
Processor Agreements

Document and manage DPAs with sub-processors, including due diligence and audit rights.

Processor
A.7.5
DSAR Handling

Automated workflows for all data subject request types with statutory deadline tracking.

Controller
A.7.9
Records of Processing

Maintain complete RoPA aligned to GDPR Article 30 and ISO 27701 Annex A requirements.

Both
A.7.11
Data Minimisation

Document and enforce data minimisation principles across all processing activities.

Controller
A.8.5
Sub-Processor Management

Full register of sub-processors with change notification workflows and approval processes.

Processor
Certification Journey

ISO 27701 certification
built on your ISMS.

If you already have ISO 27001 certification or are pursuing it with Complify ISMS, adding ISO 27701 is significantly faster — the foundations are already in place.

1
Phase 1 · Weeks 1–2
Scoping & Path Selection

Define your path: standalone PIMS or integrated with an existing ISMS. Complify sets up the appropriate project structure, maps your PII processing landscape, and identifies interested parties.

Standalone or IntegratedScope DefinitionPII Mapping
2
Phase 2 · Weeks 3–5
PII Inventory & Risk Assessment

Build your PII processing inventory, identify privacy risks across your processing landscape, and produce a privacy risk treatment plan with ownership assignments and target dates.

Processing InventoryPrivacy Risk AssessmentRisk Treatment
3
Phase 3 · Weeks 6–12
Control Implementation

Implement privacy controls across all three Annexes. Complify tracks evidence, manages consent workflows, and automates DSAR handling — with a full audit trail for every action.

Annex A ControlsDSAR WorkflowsConsent Management
4
Phase 4 · Weeks 13–14
Internal Audit & Privacy SoA

Complete your Statement of Applicability, run an internal privacy audit, and prepare your documentation package for the external certification body.

Privacy SoAInternal AuditDocumentation
5
Phase 5 · Certification
External Audit & Certification

Grant your certification body structured access via the Complify auditor portal. Manage non-conformities, achieve ISO 27701 certification, then maintain continuous compliance.

Auditor PortalCertificationContinuous Compliance
Get Started

See Complify PIMS in action.

Our specialists will walk you through a tailored demo — showing how Complify PIMS extends your existing ISMS and maps directly to your GDPR obligations.