"We have the Privacy Mark, but it means nothing to our overseas customers." "We handle personal information law compliance internally, but we have no way to prove it to a third party." These questions come up regularly from companies building PHR services and healthcare SaaS.
The candidate answer is ISO/IEC 27701, usually called PIMS — a privacy information management system.
It is not, however, a standalone certification. It is built as an extension of an ISMS (ISO/IEC 27001) and does not exist without that base. This article covers what 27701 adds, what the split between PII controller and PII processor means in practice, how the certification is used to demonstrate GDPR alignment, and when a PHR operator should consider it.
For the overall picture of ISMS, see What Is an ISMS (ISO/IEC 27001)?.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 and 27701 themselves and the publications of the accreditation and certification bodies. Assessments of compliance with the GDPR or Japan's personal information law should be confirmed with legal counsel.
27701 as an Extension of the ISMS
The defining feature of 27701 is that it does not replace the requirements of ISO/IEC 27001 — it restates and extends them for privacy.
Three layers:
- The 27001 requirements, extended for privacy — PII processing brought into scope, impact on PII principals brought into risk assessment, and so on
- The 27002 controls, reinterpreted in a privacy context
- Additional controls for PII controllers and additional controls for PII processors, held in separate annexes
So the work is not discarding your ISMS documentation and starting over. It is adding a privacy lens to the existing scope, risk assessment, and procedures. A sound ISMS document set makes this realistic; a hollow one will not carry the extension. See ISMS Documentation: How Much to Build.
| Aspect | ISO/IEC 27001 (ISMS) | ISO/IEC 27701 (PIMS) |
|---|---|---|
| What it protects | Information assets generally | PII and the rights of PII principals |
| View of risk | Centred on impact to the organisation | Also includes impact on the individual |
| Standalone | Yes | No — 27001 is a prerequisite |
| Role distinction | None in particular | Additional controls split by PII controller / PII processor |
| Typical use | Proving posture as a condition of trade | Demonstrating a compliance posture; clarifying role division |
PII Controller vs PII Processor
You cannot get far in 27701 without the distinction between PII controller and PII processor, which mirrors the GDPR's controller/processor concepts.
- PII controller: decides why and how PII is processed
- PII processor: processes PII on the controller's instructions
In healthcare the answer varies with the business model.
| Business model | Typical role | Why |
|---|---|---|
| Hospital-facing SaaS (EMR, booking, intake) | Mostly processor | The hospital decides the purpose of processing |
| Consumer PHR app | Mostly controller | Consent is taken from the user directly; you set the purpose |
| PHR sold through employers or insurers | Can be both | Processing for the contracting body mixes with your own service purposes |
| Clinical trial support systems | Depends on contract | Determined by how roles are divided with sponsor and site |
Plenty of companies run for years without settling this. Going through 27701 forces the question. Even without certifying, being able to explain in writing which role you occupy makes customer questionnaires far easier to answer.
See also ISMS for PHR Operators. Controller-side controls cover notice to PII principals, obtaining and recording consent, and handling requests for access, correction, and deletion — the machinery for honouring individual rights. Processor-side controls cover not processing beyond the controller's instructions, managing subcontractors, and handling data at contract termination.
Using It to Demonstrate GDPR Alignment
The most common real-world use of 27701 is demonstrating a compliance posture through third-party audit.
One misreading to avoid: 27701 certification is not proof of GDPR compliance. What it evidences is that a management system for privacy information has been established and is operating. Compliance itself is the territory of supervisory authorities and legal counsel.
It is still useful, because what counterparties usually want to know is whether this company manages personal data as a system rather than by habit. In contract negotiation and due diligence it removes a great deal of explaining from scratch.
Within Japan, recognition of the Privacy Mark remains higher. The uses differ:
| Certification | Main subject | Reach | When it fits |
|---|---|---|---|
| Privacy Mark | Personal information under Japanese law | Strong recognition domestically | B2C, domestic focus, consumer-facing trust |
| ISMS (27001) | Information assets generally | International | B2B condition of trade |
| ISO 27701 (PIMS) | PII and individual rights | International | Overseas business, GDPR context, controller/processor clarity |
| ISO 27018 | PII in the cloud, as a processor | International | Proving entrusted data is not repurposed |
See ISMS vs Privacy Mark and ISO 27017 and ISO 27018. With overseas counterparties, the choice of accreditation body also matters — see ISMS-AC, UKAS and ANAB.
When It Is Worth It for a PHR Operator
The effort is not small. Even sitting on top of an ISMS, it brings scope revision, PII-principal impact added to risk assessment, additional controls, and more auditor-days.
Worth it when
- You have overseas customers, partners, or investors who repeatedly ask for a GDPR-context explanation
- You take data directly from individuals, as in PHR, and want consent, disclosure, and deletion operations evidenced by a third party
- You have many group companies or subcontractors and need the controller/processor division fixed in writing
- Secondary use of personal data — research, AI training — is in your business plan and its controls must be explained
No hurry when
- ISMS or Privacy Mark is the only thing specified as a condition of trade
- Your business is domestic B2B with no overseas enquiries
- Your first ISMS certification is incomplete, or the cycle has not run once
The realistic order is ISMS → (if needed) 27017/27018 → 27701. 27701 is broad; starting it before ISMS operation has stabilised stalls internal audit and management review alike. See Running Internal Audits.
Companies handling medical information are usually also asked to satisfy Japan's three-ministry guidelines. Stacking certifications alone may not meet what customers require — read The Three-Ministry Guidelines alongside this.
Conclusion
- ISO/IEC 27701 is an extension of the ISMS — no standalone certification; 27001 is a prerequisite
- The work is adding a privacy lens to existing scope, risk assessment, and procedures, not rebuilding
- Additional controls split by PII controller / PII processor; settling which you are has value on its own
- Certification is not proof of GDPR compliance — it evidences that the management system exists and operates
- In domestic B2C the Privacy Mark carries more recognition; 27701 earns its keep in overseas and GDPR contexts
- Order it ISMS → (if needed) 27017/27018 → 27701, after the base has run one full cycle
Pottech supports ISMS certification with a focus on healthcare. For companies whose business turns on personal data — PHR, SaMD, clinical trial systems — we support scope design and risk assessment with templates for procedures, registers, and training, including documentation built with later extension in mind.
See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27701 Privacy information management systems | ISO
- ISO/IEC 27001 Information security management systems | ISO
- Personal Information Protection Commission, Japan
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standards themselves and the publications of the accreditation and certification bodies. Judgements on GDPR or Japanese personal information law compliance should be taken with legal counsel.