GDPR & privacy
A privacy management system you can certify - with or without ISO 27001. ISO 27701:2025 is a stand-alone privacy management system standard: records of processing, lawful-basis and retention discipline, DSAR handling and data-transfer controls. Already run ISO 27001? The management systems overlap and most of it carries over. Do not have it? You can still certify.
Independent advisory - not legal advice, and not a certification body.
What ISO 27701 actually is
This changed recently, and a lot of advice has not caught up. Until October 2025, ISO 27701 was an extension - you needed ISO 27001 to use it. The 2025 edition was redrafted as a stand-alone management system standard, and the old edition was withdrawn. Its only normative reference is now ISO/IEC 29100, not ISO 27001. In practice: your organisation can build and certify a privacy management system without an ISMS underneath it. If you already run ISO 27001, the two overlap and most of that work carries over - but it is an overlap, not a prerequisite.
What we do
The same five pieces whether ISO 27701 is your first management system or sits alongside an ISMS you already operate. If you have one, several of these reuse work you already run.
Records of processing (RoPA)
A maintained record of processing activities that maps what personal data your company holds, why, and where it flows - kept current as a live part of the management system, not as a one-off spreadsheet.
Lawful-basis and retention discipline
Each processing activity tied to a lawful basis, with retention periods that are defined, defensible and actually enforced in the control environment rather than just stated in a policy.
DSAR handling workflow
A repeatable data-subject-access-request workflow - intake, identity verification, search, redaction and response - so requests are handled inside statutory timeframes rather than improvised each time.
Data-transfer and sub-processor controls
Transfer mechanisms, sub-processor due diligence and contractual controls mapped to a supplier assurance cadence, so international transfers and vendors are governed, not assumed.
Privacy risk assessed and treated
Privacy-specific risks assessed and treated through one risk methodology, so privacy sits inside the risk register rather than beside it in a separate silo. If you already run ISO 27001, that means mapping onto the Annex A controls you operate rather than building a parallel set.
If you already have ISO 27001
ISO 27701 does not require ISO 27001 - but the two management systems share a structure, so if your company already runs an ISMS you are not starting from zero. Here is where the overlap is real, and where the privacy-specific work still has to be done.
Who it is for
Questions
No. ISO 27701:2025 is a stand-alone management system standard - the 2019 edition that extended ISO 27001 was withdrawn in October 2025, and the current version's only normative reference is ISO/IEC 29100. You can certify to ISO 27701 without holding ISO 27001. If you do already run an ISMS, the management systems overlap and most of that work carries over.
Most of the management system, risk methodology and control work overlaps and is reused. You are adding privacy-specific work: records of processing, lawful-basis and retention discipline, a DSAR workflow and data-transfer controls, plus privacy risk mapped onto the Annex A controls you already operate. The two standards are separate management systems that share a structure, so they can be run and audited together.
It depends on what your buyers ask for. Many teams only need demonstrable GDPR alignment built on the controls they already run; others want ISO 27701 because a certifiable privacy management system is a stronger signal in sales and procurement. Since the 2025 edition stands alone, certification is a real option even if you have no ISO 27001 and no plans for one. We help you decide on a short call rather than assuming the heavier path.
No. Kellwick provides advisory and management-system work, not legal advice. We help your team build and operate the privacy controls and evidence around GDPR; we do not act as your lawyers or provide a legal opinion. Where a legal question arises, we recommend you take qualified legal counsel.
We build the DSAR workflow - intake, identity checks, search, redaction and response templates - and help your team run it. The aim is a repeatable process your people own, so requests are handled consistently and inside statutory timeframes, rather than outsourcing each request.
Scoped on a short call. Pricing depends on the size of your data estate, whether you already run an ISO 27001 ISMS the privacy work can reuse, and whether you want full ISO 27701 certification or demonstrable GDPR alignment. We size the work to what you actually need.
A certifiable privacy management system - standalone, or integrated with the ISMS you already run. We scope the work on a short call.
Certification is issued by accredited certification bodies; DORA supervision is performed by regulators. Kellwick prepares you for these processes; it does not perform them and cannot guarantee their outcome. Kellwick provides advisory and management-system support, not legal advice.
Kellwick is an independent advisory practice. We are not a certification body and do not issue ISO certifications. Certification decisions are made only by accredited certification bodies.