Back to Columns
ISMS & Certification11 min read

ISO 27701 (PIMS): Connecting Privacy to Your ISMS

September 14, 2026

ISO 27701 (PIMS): Connecting Privacy to Your ISMS
Share this article

"We have the Privacy Mark, but it means nothing to our overseas customers." "We handle personal information law compliance internally, but we have no way to prove it to a third party." These questions come up regularly from companies building PHR services and healthcare SaaS.

The candidate answer is ISO/IEC 27701, usually called PIMS — a privacy information management system.

It is not, however, a standalone certification. It is built as an extension of an ISMS (ISO/IEC 27001) and does not exist without that base. This article covers what 27701 adds, what the split between PII controller and PII processor means in practice, how the certification is used to demonstrate GDPR alignment, and when a PHR operator should consider it.

For the overall picture of ISMS, see What Is an ISMS (ISO/IEC 27001)?.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 and 27701 themselves and the publications of the accreditation and certification bodies. Assessments of compliance with the GDPR or Japan's personal information law should be confirmed with legal counsel.

27701 as an Extension of the ISMS

The defining feature of 27701 is that it does not replace the requirements of ISO/IEC 27001 — it restates and extends them for privacy.

Three layers:

  1. The 27001 requirements, extended for privacy — PII processing brought into scope, impact on PII principals brought into risk assessment, and so on
  2. The 27002 controls, reinterpreted in a privacy context
  3. Additional controls for PII controllers and additional controls for PII processors, held in separate annexes

So the work is not discarding your ISMS documentation and starting over. It is adding a privacy lens to the existing scope, risk assessment, and procedures. A sound ISMS document set makes this realistic; a hollow one will not carry the extension. See ISMS Documentation: How Much to Build.

AspectISO/IEC 27001 (ISMS)ISO/IEC 27701 (PIMS)
What it protectsInformation assets generallyPII and the rights of PII principals
View of riskCentred on impact to the organisationAlso includes impact on the individual
StandaloneYesNo — 27001 is a prerequisite
Role distinctionNone in particularAdditional controls split by PII controller / PII processor
Typical useProving posture as a condition of tradeDemonstrating a compliance posture; clarifying role division

PII Controller vs PII Processor

You cannot get far in 27701 without the distinction between PII controller and PII processor, which mirrors the GDPR's controller/processor concepts.

  • PII controller: decides why and how PII is processed
  • PII processor: processes PII on the controller's instructions

In healthcare the answer varies with the business model.

Business modelTypical roleWhy
Hospital-facing SaaS (EMR, booking, intake)Mostly processorThe hospital decides the purpose of processing
Consumer PHR appMostly controllerConsent is taken from the user directly; you set the purpose
PHR sold through employers or insurersCan be bothProcessing for the contracting body mixes with your own service purposes
Clinical trial support systemsDepends on contractDetermined by how roles are divided with sponsor and site

Plenty of companies run for years without settling this. Going through 27701 forces the question. Even without certifying, being able to explain in writing which role you occupy makes customer questionnaires far easier to answer.

See also ISMS for PHR Operators. Controller-side controls cover notice to PII principals, obtaining and recording consent, and handling requests for access, correction, and deletion — the machinery for honouring individual rights. Processor-side controls cover not processing beyond the controller's instructions, managing subcontractors, and handling data at contract termination.

Using It to Demonstrate GDPR Alignment

The most common real-world use of 27701 is demonstrating a compliance posture through third-party audit.

One misreading to avoid: 27701 certification is not proof of GDPR compliance. What it evidences is that a management system for privacy information has been established and is operating. Compliance itself is the territory of supervisory authorities and legal counsel.

It is still useful, because what counterparties usually want to know is whether this company manages personal data as a system rather than by habit. In contract negotiation and due diligence it removes a great deal of explaining from scratch.

Within Japan, recognition of the Privacy Mark remains higher. The uses differ:

CertificationMain subjectReachWhen it fits
Privacy MarkPersonal information under Japanese lawStrong recognition domesticallyB2C, domestic focus, consumer-facing trust
ISMS (27001)Information assets generallyInternationalB2B condition of trade
ISO 27701 (PIMS)PII and individual rightsInternationalOverseas business, GDPR context, controller/processor clarity
ISO 27018PII in the cloud, as a processorInternationalProving entrusted data is not repurposed

See ISMS vs Privacy Mark and ISO 27017 and ISO 27018. With overseas counterparties, the choice of accreditation body also matters — see ISMS-AC, UKAS and ANAB.

When It Is Worth It for a PHR Operator

The effort is not small. Even sitting on top of an ISMS, it brings scope revision, PII-principal impact added to risk assessment, additional controls, and more auditor-days.

Worth it when

  • You have overseas customers, partners, or investors who repeatedly ask for a GDPR-context explanation
  • You take data directly from individuals, as in PHR, and want consent, disclosure, and deletion operations evidenced by a third party
  • You have many group companies or subcontractors and need the controller/processor division fixed in writing
  • Secondary use of personal data — research, AI training — is in your business plan and its controls must be explained

No hurry when

  • ISMS or Privacy Mark is the only thing specified as a condition of trade
  • Your business is domestic B2B with no overseas enquiries
  • Your first ISMS certification is incomplete, or the cycle has not run once

The realistic order is ISMS → (if needed) 27017/27018 → 27701. 27701 is broad; starting it before ISMS operation has stabilised stalls internal audit and management review alike. See Running Internal Audits.

Companies handling medical information are usually also asked to satisfy Japan's three-ministry guidelines. Stacking certifications alone may not meet what customers require — read The Three-Ministry Guidelines alongside this.

Conclusion

  1. ISO/IEC 27701 is an extension of the ISMS — no standalone certification; 27001 is a prerequisite
  2. The work is adding a privacy lens to existing scope, risk assessment, and procedures, not rebuilding
  3. Additional controls split by PII controller / PII processor; settling which you are has value on its own
  4. Certification is not proof of GDPR compliance — it evidences that the management system exists and operates
  5. In domestic B2C the Privacy Mark carries more recognition; 27701 earns its keep in overseas and GDPR contexts
  6. Order it ISMS → (if needed) 27017/27018 → 27701, after the base has run one full cycle

Pottech supports ISMS certification with a focus on healthcare. For companies whose business turns on personal data — PHR, SaMD, clinical trial systems — we support scope design and risk assessment with templates for procedures, registers, and training, including documentation built with later extension in mind.

See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.

References and Sources

Note: interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standards themselves and the publications of the accreditation and certification bodies. Judgements on GDPR or Japanese personal information law compliance should be taken with legal counsel.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.