ISO/IEC 27701:2025 Transition - The new ISO/IEC 27701:2025 standard was published on 14 October 2025, replacing ISO/IEC 27701:2019 as the revised standard for Privacy Information Management Systems (PIMS). ISO/IEC 27701:2019 will become obsolete on 31 October 2028.

For further guidance and the transition completion timeline, please refer to the PIMS Transition Policy under Downloads Click Here

This Certification Service is Accredited by JASANZ

(Joint Accreditation System for Australia and New Zealand)

What is PIMS?

A Privacy Information Management System (PIMS) is a comprehensive framework that helps organizations manage and protect personal data while ensuring compliance with privacy laws and regulations. It includes key components such as data governance, risk assessment, policies and procedures, employee training, incident response plans, monitoring and auditing, and management of data subject rights. By implementing a PIMS, organizations can demonstrate accountability and build trust with customers by responsibly handling personal information and safeguarding individuals' privacy rights.

Why Choose PIMS Certification?

Implementing a Privacy Information Management System (PIMS) provides numerous benefits for organizations, including ensuring compliance with privacy laws, mitigating risks of data breaches, and enhancing customer trust through a commitment to data protection. It streamlines data management processes, fosters a culture of privacy awareness among employees, and establishes clear protocols for incident response. Additionally, a PIMS facilitates the handling of data subject rights requests, improves overall customer service, and can serve as a competitive advantage by showcasing robust privacy practices. Ultimately, a PIMS supports a proactive approach to privacy management, benefiting both the organization and its stakeholders.

Enhance Trust: Build credibility with customers and stakeholders by demonstrating your commitment to data privacy.

Compliance Assurance: Stay ahead of legal requirements and avoid costly penalties.

Streamline Processes: Improve efficiency in data management and reduce risks associated with information handling.

Global Recognition: Accredited by JASANZ, our certification is recognized worldwide, opening doors to new markets.

 

Who Should Get Certified?

Organizations of all sizes

Compliance Offices

Information Security/ Data Privacy Providers

Payment handling entities/portals

Data Protection Offices

Any business handling personal data and other service platforms

 

Benefits of choosing BSCIC Certification:

Credibility: BSCIC is recognized for its rigorous standards and practices, enhancing your organization’s credibility in the market.

Expertise: The team comprises experienced auditors with in-depth knowledge of various industries, ensuring comprehensive evaluations.

Cost-Effective: Their services can help identify inefficiencies and areas for improvement, potentially saving costs in the long run.

Compliance Assurance: BSCIC help ensure that your organization adheres to relevant regulations and standards, reducing the risk of non-compliance.

Continuous Improvement: The audit process highlights areas for improvement, fostering a culture of continuous development within the organization.

 

ISO/IEC 27701:2025 Transition

BSCIC is committed to supporting its clients in the transition from ISO/IEC 27701:2019 to ISO/IEC 27701:2025.

The revised ISO/IEC 27701:2025 was published on 14 October 2025 and a transition period will apply in accordance with the applicable accreditation and certification requirements.

Organizations currently certified to ISO/IEC 27701:2019 are required to complete the transition to the 2025 version within the applicable transition period. ISO/IEC 27701:2019 certificates issued by BSCIC will not remain valid beyond 31 October 2028.

Early preparation is recommended to understand the revised requirements, assess their impact on the existing PIMS, identify necessary changes and ensure a smooth and timely transition.

 

Benefits of ISO/IEC 27701:2025

  • Strengthens the organization's privacy information management practices.

  • Enhances the protection and responsible management of Personally Identifiable Information (PII).

  • Improves identification and management of privacy risks and opportunities.

  • Supports compliance with applicable privacy and data protection requirements.

  • Enhances accountability and governance for the processing of personal information.

  • Promotes continual improvement of the organization's Privacy Information Management System (PIMS).

  • Builds stakeholder, customer and business partner confidence in the organization's privacy practices.

  • Supports organizations in addressing evolving privacy expectations and regulatory requirements.

 

How BSCIC Supports Your Transition

BSCIC provides clear guidance, awareness and transition support to help clients understand and prepare for the revised PIMS requirements.

  • Provides transition guidance and key information regarding ISO/IEC 27701:2025.

  • Supports organizations in understanding the revised PIMS requirements.

  • Encourages structured transition planning and timely preparation.

  • Helps organizations identify areas requiring review, modification or improvement.

  • Supports organizations in evaluating the impact of revised requirements on their existing PIMS.

  • Keeps clients informed of relevant transition requirements, accreditation developments and applicable timelines.

  • Provides appropriate information to support organizations in preparing for the transition assessment.

 

BSCIC is committed to making the transition from ISO/IEC 27701:2019 to ISO/IEC 27701:2025 structured, transparent and manageable for its clients.

To know more about our services

Connect with one of the leading Certification Training & Inspection Body in India.