Something changed in October 2025 that most privacy content on the Australian internet has not caught up with.
| ISO/IEC 27701 is now a standalone standard Until the 2025 revision, ISO 27701 was an extension to ISO 27001. You could not certify to it on its own, and it was audited as an add-on to an existing ISMS certification. The 2025 edition removes that dependency. An organisation can now be certified to ISO/IEC 27701 as a standalone Privacy Information Management System, with or without ISO 27001. |
|---|
That is a genuine strategic shift, not a technical footnote. It means an organisation whose real exposure is privacy rather than broad information security no longer has to build and fund an entire ISMS to get a certificate its customers will accept.
Nathan ISO Consulting implements privacy information management systems for Australian organisations, whether standalone or integrated with an existing ISO 27001 certification. This page explains what changed, how it interacts with Australian privacy law, and how we approach the work.
What actually changed
| ISO/IEC 27701:2019 | ISO/IEC 27701:2025 | |
|---|---|---|
| Status | Extension to ISO 27001 and ISO 27002 | Standalone management system standard |
| Standalone certification | Not possible | Possible |
| ISO 27001 prerequisite | Required | Not required |
| Statement of Applicability | Combined with the ISMS SoA | Standalone, or combined where both are held |
| Audit approach | Audited as an add-on to ISMS certification | Audited in its own right |
| Who it suits | Organisations already holding ISO 27001 | Any organisation handling personal information |
Two routes, and how to pick between them
The standalone option is new, which does not automatically make it right for you. The decision usually resolves quickly once you know two things: what your customers are actually asking for, and whether information security exposure exists independently of privacy exposure.
Route one: standalone PIMS
Suits organisations whose primary risk and primary customer question is privacy. Marketing and customer data businesses, HR and recruitment platforms, health and wellbeing services, education providers, membership organisations. If nobody has asked you for ISO 27001 and your exposure is personal information rather than intellectual property or systems availability, standalone is faster, narrower and cheaper to maintain.
Route two: ISO 27001 and ISO 27701 together
Suits organisations already holding ISO 27001, or being asked for it. The two systems share governance, risk methodology, internal audit and management review, so running them together avoids duplicating all of that. If you hold ISO 27001 today, adding 27701 is a materially smaller project than either standard alone.
If you are unsure, the practical test is to look at the last three security or privacy questionnaires a customer sent you and count which certificate they asked for.
Australian privacy law is moving at the same time
ISO 27701 is not Australian law. It is the management system structure most commonly used to satisfy Australian privacy obligations and to bridge to overseas regimes such as the GDPR. Those obligations have been shifting steadily, and more change is in the pipeline.
| Development | Status |
|---|---|
| Privacy Act 1988 and the 13 Australian Privacy Principles | In force. Applies to most organisations above the turnover threshold plus targeted small businesses |
| Notifiable Data Breaches scheme | In force since February 2018. Notification to affected individuals and the OAIC where a breach is likely to result in serious harm. Australian law imposes no 72-hour deadline |
| Stronger OAIC powers and higher penalties | In force since December 2024 |
| Statutory tort for serious invasions of privacy | In force since June 2025. Individuals can sue directly for intentional or reckless serious invasions of privacy |
| Automated decision-making transparency | Legislated, with a grace period ending 10 December 2026. Privacy policies must disclose where automated systems make or substantially assist decisions significantly affecting rights |
| Privacy Regulations 2025 and Privacy (Credit Reporting) Code 2025 | In force |
| Privacy Amendment (Personal Data Protection) Bill 2026 | Exposure draft released for consultation. Proposes changes to the definition of personal information, a fair and reasonable test, updated consent and tightened breach obligations. Not law |
Verify this table against current Attorney-General's Department and OAIC guidance before relying on it. Reform timelines move.
| The deadline nobody is talking about The automated decision-making transparency obligation comes out of its grace period on 10 December 2026. If your organisation uses any system that makes, or substantially helps make, decisions significantly affecting people's rights — credit, insurance, employment screening, service eligibility — your privacy policy has to say so. Most organisations we speak to have not started, and many do not yet have an inventory of where automated decisioning sits in their operations. |
|---|
Controller, processor, or both?
This determination drives which parts of the standard apply to you, and organisations get it wrong in both directions. Some SaaS providers describe themselves as processors while making independent decisions about how personal information is used. Some service businesses call themselves controllers for data they merely hold on a client's instruction.
| Role | What it means | Typical Australian examples |
|---|---|---|
| PII controller | You determine why and how personal information is processed | Retailers, insurers, healthcare providers, employers, membership bodies, education providers |
| PII processor | You process personal information on behalf of, and on the instructions of, another organisation | SaaS platforms, payroll bureaus, BPO providers, cloud hosting, marketing agencies |
| Both | You act as controller for some activities and processor for others | Most mid-sized technology companies, once you look at HR data alongside customer data |
How Nathan ISO Consulting assists
Privacy projects fail in the first fortnight or not at all. Everything downstream depends on knowing what personal information you hold and why, and that is where we start.
Phase one — establishing the ground truth
Personal information inventory: what you collect, why, where it lives, who processes it, what lawful basis applies, and how long you keep it.
Role determination for each in-scope activity, documented, because it drives which control sections apply.
Scope definition for the PIMS, and the standalone-versus-integrated decision.
Gap assessment against ISO/IEC 27701:2025 and against the Privacy Act and Australian Privacy Principles together, not separately.
Phase two — building the system
Privacy policy and external privacy notices, including automated decision-making disclosure where it applies.
Statement of Applicability, standalone or combined with an ISO 27001 SoA.
Data subject and individual rights request procedure, covering access and correction under APPs 12 and 13.
Breach assessment and notification runbook aligned to the NDB scheme's serious harm test.
Privacy impact assessment methodology and templates.
Supplier and processor agreements, retention and disposal schedules, and cross-border disclosure controls under APP 8.
Phase three — proving it works
Staff training, with role-specific content for anyone handling access requests or breach triage.
Internal audit against the standard and against your APP obligations.
Documented management review.
Certification body selection, and attendance at Stage 1 and Stage 2.
Post-certification support, including surveillance preparation and reform-driven updates.
Why organisations choose Nathan
| What you will hear elsewhere | What is actually true |
|---|---|
| "You need ISO 27001 before you can do ISO 27701" | Not since October 2025. Standalone PIMS certification is available and is often the better fit |
| "ISO 27701 makes you Privacy Act compliant" | It does not. It gives you the structure and evidence to demonstrate compliance. We map the two explicitly rather than implying one covers the other |
| "You have 72 hours to notify a breach" | That is the GDPR. Australian law applies a serious harm assessment with no fixed 72-hour clock, and your runbook should reflect Australian law |
| "Privacy is a policy exercise" | Privacy is an inventory exercise first. Until you know what personal information you hold and why, the policy is guesswork |
| "We will revisit this after the reforms pass" | The automated decision-making obligation is already legislated with a December 2026 deadline. Waiting is not a neutral choice |
| "Here is our standard PIMS template pack" | Templates cannot determine whether you are a controller or a processor for a given activity, and that determination changes which controls apply |
Where we work
Privacy work is largely location-independent and most of a PIMS project runs remotely. We attend on site for workshops, data mapping sessions and Stage 2 where it helps.
| Location | Sectors we typically serve there |
|---|---|
| Sydney | Financial services, insurance, health technology, SaaS, marketing and data businesses, professional services |
| Melbourne | Health and aged care, education, retail and e-commerce, superannuation, technology |
| Brisbane | Health services, education, government suppliers, technology and logistics platforms |
| Canberra | Commonwealth suppliers and contracted service providers subject to flow-down privacy obligations |
| Perth | Resources services, health, education, and technology firms handling employee and customer data |
| Adelaide | Defence supply chain, health, education, and research organisations |
| Hobart and Darwin | Government-adjacent services, health providers, tourism and membership organisations |
| Regional centres | Delivered remotely, with on-site workshops where data mapping benefits from being in the room |
Start with your data map
If you already have a personal information inventory, send it over. If you do not, that is where we begin, and it is the single most useful thing your organisation can own regardless of whether you certify.
FAQ'S
Yes, since the 2025 edition. ISO/IEC 27701:2025 is a standalone management system standard, so an organisation can be certified to it on its own. Content stating otherwise reflects the superseded 2019 edition, which was an extension to ISO 27001.
No standard confers legal compliance. ISO 27701 gives you the structure, controls and evidence to demonstrate that you manage personal information deliberately. We map the standard against the Australian Privacy Principles explicitly so you can show a regulator or customer where each obligation is met.
You will transition to the 2025 edition within the timeframe your certification body sets. Most of your existing content carries across. The main work is restructuring the Statement of Applicability and adjusting for the standard operating independently rather than as an ISO 27001 extension.
Legislated privacy amendments require organisations to disclose in their privacy policy where automated systems make, or substantially assist in making, decisions that significantly affect an individual's rights. The grace period ends 10 December 2026, so an inventory of automated decisioning should be underway now.
Considerably. The standard was written with GDPR concepts in mind and the 2025 edition strengthens that alignment. For Australian organisations with European customers or operations, a PIMS is the most practical way to run one privacy system across both regimes.
Often both, and the answer differs by activity rather than by organisation. A SaaS business is typically a processor for customer data and a controller for its own employee and prospect data. We document the determination activity by activity, because it drives which controls apply.
Around 14 to 24 weeks for a standalone PIMS, and considerably less where ISO 27001 is already certified. The personal information inventory is the phase that determines the timeline, and it is the phase organisations most often underestimate.
Accredited certification bodies, with accreditation from JAS-ANZ or another IAF signatory. Because standalone certification is recent, accredited scopes are still expanding, so we confirm current accreditation coverage before recommending a body.
Talk to our ISO 27701 team
If a customer questionnaire, privacy requirement or tender triggered this, send it to us. Reviewing the actual requirement helps define the right ISO 27701 scope and implementation approach.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving