WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Something changed in October 2025 that most privacy content on the Australian internet has not caught up with.

ISO/IEC 27701 is now a standalone standard Until the 2025 revision, ISO 27701 was an extension to ISO 27001. You could not certify to it on its own, and it was audited as an add-on to an existing ISMS certification. The 2025 edition removes that dependency. An organisation can now be certified to ISO/IEC 27701 as a standalone Privacy Information Management System, with or without ISO 27001.

That is a genuine strategic shift, not a technical footnote. It means an organisation whose real exposure is privacy rather than broad information security no longer has to build and fund an entire ISMS to get a certificate its customers will accept.

Nathan ISO Consulting implements privacy information management systems for Australian organisations, whether standalone or integrated with an existing ISO 27001 certification. This page explains what changed, how it interacts with Australian privacy law, and how we approach the work.

What actually changed

ISO/IEC 27701:2019ISO/IEC 27701:2025
StatusExtension to ISO 27001 and ISO 27002Standalone management system standard
Standalone certificationNot possiblePossible
ISO 27001 prerequisiteRequiredNot required
Statement of ApplicabilityCombined with the ISMS SoAStandalone, or combined where both are held
Audit approachAudited as an add-on to ISMS certificationAudited in its own right
Who it suitsOrganisations already holding ISO 27001Any organisation handling personal information

Two routes, and how to pick between them

The standalone option is new, which does not automatically make it right for you. The decision usually resolves quickly once you know two things: what your customers are actually asking for, and whether information security exposure exists independently of privacy exposure.

Route one: standalone PIMS

Suits organisations whose primary risk and primary customer question is privacy. Marketing and customer data businesses, HR and recruitment platforms, health and wellbeing services, education providers, membership organisations. If nobody has asked you for ISO 27001 and your exposure is personal information rather than intellectual property or systems availability, standalone is faster, narrower and cheaper to maintain.

Route two: ISO 27001 and ISO 27701 together

Suits organisations already holding ISO 27001, or being asked for it. The two systems share governance, risk methodology, internal audit and management review, so running them together avoids duplicating all of that. If you hold ISO 27001 today, adding 27701 is a materially smaller project than either standard alone.

If you are unsure, the practical test is to look at the last three security or privacy questionnaires a customer sent you and count which certificate they asked for.

Australian privacy law is moving at the same time

ISO 27701 is not Australian law. It is the management system structure most commonly used to satisfy Australian privacy obligations and to bridge to overseas regimes such as the GDPR. Those obligations have been shifting steadily, and more change is in the pipeline.

DevelopmentStatus
Privacy Act 1988 and the 13 Australian Privacy PrinciplesIn force. Applies to most organisations above the turnover threshold plus targeted small businesses
Notifiable Data Breaches schemeIn force since February 2018. Notification to affected individuals and the OAIC where a breach is likely to result in serious harm. Australian law imposes no 72-hour deadline
Stronger OAIC powers and higher penaltiesIn force since December 2024
Statutory tort for serious invasions of privacyIn force since June 2025. Individuals can sue directly for intentional or reckless serious invasions of privacy
Automated decision-making transparencyLegislated, with a grace period ending 10 December 2026. Privacy policies must disclose where automated systems make or substantially assist decisions significantly affecting rights
Privacy Regulations 2025 and Privacy (Credit Reporting) Code 2025In force
Privacy Amendment (Personal Data Protection) Bill 2026Exposure draft released for consultation. Proposes changes to the definition of personal information, a fair and reasonable test, updated consent and tightened breach obligations. Not law

Verify this table against current Attorney-General's Department and OAIC guidance before relying on it. Reform timelines move.

The deadline nobody is talking about The automated decision-making transparency obligation comes out of its grace period on 10 December 2026. If your organisation uses any system that makes, or substantially helps make, decisions significantly affecting people's rights — credit, insurance, employment screening, service eligibility — your privacy policy has to say so. Most organisations we speak to have not started, and many do not yet have an inventory of where automated decisioning sits in their operations.

Controller, processor, or both?

This determination drives which parts of the standard apply to you, and organisations get it wrong in both directions. Some SaaS providers describe themselves as processors while making independent decisions about how personal information is used. Some service businesses call themselves controllers for data they merely hold on a client's instruction.

RoleWhat it meansTypical Australian examples
PII controllerYou determine why and how personal information is processedRetailers, insurers, healthcare providers, employers, membership bodies, education providers
PII processorYou process personal information on behalf of, and on the instructions of, another organisationSaaS platforms, payroll bureaus, BPO providers, cloud hosting, marketing agencies
BothYou act as controller for some activities and processor for othersMost mid-sized technology companies, once you look at HR data alongside customer data

How Nathan ISO Consulting assists

Privacy projects fail in the first fortnight or not at all. Everything downstream depends on knowing what personal information you hold and why, and that is where we start.

Phase one — establishing the ground truth

Personal information inventory: what you collect, why, where it lives, who processes it, what lawful basis applies, and how long you keep it.

Role determination for each in-scope activity, documented, because it drives which control sections apply.

Scope definition for the PIMS, and the standalone-versus-integrated decision.

Gap assessment against ISO/IEC 27701:2025 and against the Privacy Act and Australian Privacy Principles together, not separately.

Phase two — building the system

Privacy policy and external privacy notices, including automated decision-making disclosure where it applies.

Statement of Applicability, standalone or combined with an ISO 27001 SoA.

Data subject and individual rights request procedure, covering access and correction under APPs 12 and 13.

Breach assessment and notification runbook aligned to the NDB scheme's serious harm test.

Privacy impact assessment methodology and templates.

Supplier and processor agreements, retention and disposal schedules, and cross-border disclosure controls under APP 8.

Phase three — proving it works

Staff training, with role-specific content for anyone handling access requests or breach triage.

Internal audit against the standard and against your APP obligations.

Documented management review.

Certification body selection, and attendance at Stage 1 and Stage 2.

Post-certification support, including surveillance preparation and reform-driven updates.

Why organisations choose Nathan

What you will hear elsewhereWhat is actually true
"You need ISO 27001 before you can do ISO 27701"Not since October 2025. Standalone PIMS certification is available and is often the better fit
"ISO 27701 makes you Privacy Act compliant"It does not. It gives you the structure and evidence to demonstrate compliance. We map the two explicitly rather than implying one covers the other
"You have 72 hours to notify a breach"That is the GDPR. Australian law applies a serious harm assessment with no fixed 72-hour clock, and your runbook should reflect Australian law
"Privacy is a policy exercise"Privacy is an inventory exercise first. Until you know what personal information you hold and why, the policy is guesswork
"We will revisit this after the reforms pass"The automated decision-making obligation is already legislated with a December 2026 deadline. Waiting is not a neutral choice
"Here is our standard PIMS template pack"Templates cannot determine whether you are a controller or a processor for a given activity, and that determination changes which controls apply

Where we work

Privacy work is largely location-independent and most of a PIMS project runs remotely. We attend on site for workshops, data mapping sessions and Stage 2 where it helps.

LocationSectors we typically serve there
SydneyFinancial services, insurance, health technology, SaaS, marketing and data businesses, professional services
MelbourneHealth and aged care, education, retail and e-commerce, superannuation, technology
BrisbaneHealth services, education, government suppliers, technology and logistics platforms
CanberraCommonwealth suppliers and contracted service providers subject to flow-down privacy obligations
PerthResources services, health, education, and technology firms handling employee and customer data
AdelaideDefence supply chain, health, education, and research organisations
Hobart and DarwinGovernment-adjacent services, health providers, tourism and membership organisations
Regional centresDelivered remotely, with on-site workshops where data mapping benefits from being in the room

Start with your data map

If you already have a personal information inventory, send it over. If you do not, that is where we begin, and it is the single most useful thing your organisation can own regardless of whether you certify.

FAQ'S

Yes, since the 2025 edition. ISO/IEC 27701:2025 is a standalone management system standard, so an organisation can be certified to it on its own. Content stating otherwise reflects the superseded 2019 edition, which was an extension to ISO 27001.

No standard confers legal compliance. ISO 27701 gives you the structure, controls and evidence to demonstrate that you manage personal information deliberately. We map the standard against the Australian Privacy Principles explicitly so you can show a regulator or customer where each obligation is met.

You will transition to the 2025 edition within the timeframe your certification body sets. Most of your existing content carries across. The main work is restructuring the Statement of Applicability and adjusting for the standard operating independently rather than as an ISO 27001 extension.

Legislated privacy amendments require organisations to disclose in their privacy policy where automated systems make, or substantially assist in making, decisions that significantly affect an individual's rights. The grace period ends 10 December 2026, so an inventory of automated decisioning should be underway now.

Considerably. The standard was written with GDPR concepts in mind and the 2025 edition strengthens that alignment. For Australian organisations with European customers or operations, a PIMS is the most practical way to run one privacy system across both regimes.

Often both, and the answer differs by activity rather than by organisation. A SaaS business is typically a processor for customer data and a controller for its own employee and prospect data. We document the determination activity by activity, because it drives which controls apply.

Around 14 to 24 weeks for a standalone PIMS, and considerably less where ISO 27001 is already certified. The personal information inventory is the phase that determines the timeline, and it is the phase organisations most often underestimate.

Accredited certification bodies, with accreditation from JAS-ANZ or another IAF signatory. Because standalone certification is recent, accredited scopes are still expanding, so we confirm current accreditation coverage before recommending a body.

Talk to our ISO 27701 team

If a customer questionnaire, privacy requirement or tender triggered this, send it to us. Reviewing the actual requirement helps define the right ISO 27701 scope and implementation approach.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance

  • ISO certification success rate chart

    0

    Projects

  • ISO certification statistics graphic

    0

    Services

  • ISO certification growth statistics graphic

    0

    Clients Serving

  • ISO certification success rates infographic

    0

    Countries Serving