Skip to main content
Rules Mate

ISO 27701 privacy information management and the Australian Privacy Act

Rules Mate Editorial8 min read

ISO/IEC 27701:2025 is now a standalone privacy management standard. How a PIMS maps to the Australian Privacy Principles, and what it does and does not satisfy.

ISO/IEC 27701 is the international standard for a privacy information management system (PIMS). The 2025 edition made a structural change that matters commercially: the standard is now standalone, no longer an extension you can only implement on top of a certified ISO 27001 information security management system.

For Australian organisations that changes the entry cost, and it makes the mapping question sharper — how much of the Privacy Act does a PIMS actually cover, and what remains untouched.

What changed in the 2025 edition

ISO/IEC 27701:2025 is the second edition and it is a standalone management system standard. The 2019 first edition was drafted as a set of extension requirements to ISO/IEC 27001 and ISO/IEC 27002, which meant a PIMS could not exist without an ISMS underneath it.

The catalogue entry is the ISO/IEC 27701 standard page. The changes with operational consequences:

  • Standalone implementation. The 2025 edition carries a full set of management-system clauses of its own, so an organisation can implement and certify a PIMS without holding ISO 27001. Alignment with ISO/IEC 27001:2022 and ISO/IEC 27002:2022 is retained, so combining them remains straightforward and is usually still the efficient path.
  • Consolidated annexes covering controller and processor guidance.
  • Expanded guidance reaching cloud services, AI-related processing, connected devices, biometrics and health data — all areas where Australian regulatory attention has increased.

If your organisation certified to the 2019 edition, treat this as a revision transition and schedule it with your certification body into a surveillance or recertification audit, as covered in maintaining certification between recertification cycles.

What a privacy information management system requires

A PIMS is a management system for processing personally identifiable information, structured on the harmonised clause 4 to 10 framework with privacy-specific requirements layered on.

The distinctive elements:

  • Determination of roles — whether the organisation acts as a PII controller, a PII processor, or both, for each processing activity. Requirements differ by role.
  • A record of processing activities: what PII is processed, for what purposes, on what basis, with what recipients, for what retention period, and with what cross-border transfers.
  • Privacy risk assessment covering risks to the individuals whose information is processed, not only risks to the organisation.
  • Purpose limitation, minimisation and retention controls applied at the processing-activity level.
  • Rights handling — mechanisms for individuals to exercise the rights available to them.
  • Processor obligations — instructions, sub-processor management, assistance to controllers, and breach notification to the controller.
  • Cross-border transfer controls.
  • Privacy by design considerations in system and process change.

The record of processing activities is the artefact that carries the system. Almost every downstream requirement — retention, minimisation, transfer control, breach assessment, rights handling — depends on knowing what you hold and why.

Mapping ISO 27701 to the Australian Privacy Principles

The standard was drafted with international privacy regimes in mind. It maps well to the Australian Privacy Principles in structure, and imperfectly in detail.

PIMS areaNearest Australian Privacy PrincipleFit
Privacy policy and transparencyAPP 1 open and transparent managementStrong — but APP 1.4 prescribes minimum policy content the standard does not
Anonymity optionsAPP 2 anonymity and pseudonymityWeak — the standard does not require an anonymous dealing option
Collection limitation and lawful basisAPP 3 collection of solicited informationPartial — the APP 3 tests for necessity and sensitive information consent are Australia-specific
Notice at collectionAPP 5 notification of collectionStrong in principle, but APP 5 prescribes specific matters to notify
Purpose limitationAPP 6 use and disclosureStrong
Direct marketing controlsAPP 7 direct marketingPartial — APP 7 has its own opt-out machinery
Cross-border transfer controlsAPP 8 cross-border disclosurePartial — APP 8.1 accountability for the overseas recipient's acts is Australia-specific
Data qualityAPP 10 quality of personal informationStrong
SecurityAPP 11 security of personal informationStrong, especially combined with an ISMS
Retention and destructionAPP 11.2 destruction or de-identificationStrong
Access and correctionAPP 12 and APP 13Strong in structure; Australian timeframes and refusal grounds are local

Rules Mate covers the individual principles in depth — see APP 1.3 privacy policy minimum content, APP 8 overseas disclosure, APP 10 quality of personal information and APP 11 reasonable steps. The authoritative text is on the OAIC site: read the Australian Privacy Principles.

Where the Privacy Act goes beyond ISO 27701

Four areas where certification leaves a gap that has to be closed separately.

The notifiable data breach scheme. The Privacy Act requires an entity to assess a suspected eligible data breach expeditiously and, if the breach is an eligible data breach, to notify the OAIC and affected individuals. There are statutory timeframes and prescribed statement content. ISO 27701 requires breach processes; it does not create the Australian notification duty or its deadlines. Use the NDB timer, read the 30-day rule, and track the obligation at ndb-notification.

APP 8 accountability. Where an APP entity discloses personal information to an overseas recipient, it must take reasonable steps to ensure the recipient does not breach the APPs, and in many cases remains accountable for the recipient's acts. That accountability structure is stronger than a transfer-control requirement and needs specific contractual and assurance treatment. See the obligation app-8-cross-border.

Prescribed policy content. APP 1.4 sets out matters a privacy policy must contain. A PIMS-conformant policy is not automatically APP-compliant. Track it at privacy-policy.

Reform in motion. Australian privacy law is mid-reform. Amendments creating a statutory tort for serious invasions of privacy, a doxxing offence and enhanced penalties are in force, with further commencements ahead including automated decision-making transparency and the Children's Online Privacy Code. A future reform tranche proposing removal of the small business exemption has been agreed in principle by the Government but is not yet law and has no commencement date — do not build a compliance position on it. See the second tranche outlook, ADM transparency obligations and the Children's Online Privacy Code. A PIMS built against a static snapshot of the law will drift.

Controller and processor roles vs the APP entity concept

ISO 27701 divides requirements between PII controllers and PII processors. Australian privacy law does not use that division.

The Privacy Act applies to APP entities, and an APP entity that holds personal information carries APP obligations regardless of whether it determines the purposes of processing. There is no general processor category with a reduced obligation set the way there is under a controller-processor regime. An Australian service provider that would be a "processor" internationally is still an APP entity with its own APP 11 security duty, its own destruction-or-de-identification duty, and its own notifiable data breach exposure.

Two practical consequences:

  1. Do not import a processor posture into an Australian context. "We are only a processor, the controller is responsible" is not an answer under the Privacy Act.
  2. Contractual allocation does not displace statutory duty. Contracts allocate responsibility between the parties; they do not remove either party's obligations to individuals or to the OAIC.

Note also the employee records exemption, which has no international equivalent and is frequently misapplied — see the employee records exemption in section 7B.

Using a PIMS as APP 11 reasonable-steps evidence

This is the strongest practical argument for ISO 27701 in Australia. APP 11 requires an entity to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.

The OAIC's Guide to securing personal information describes reasonable steps across governance, culture and training, internal practices, ICT security, access security, third-party providers, data breach response, physical security, and destruction or de-identification. Every one of those has a corresponding PIMS requirement, and a certified system produces contemporaneous evidence of each.

What certification does not do: it does not create a safe harbour, it does not bind the OAIC, and it does not convert reasonable steps into a fixed checklist. Reasonable steps is a contextual test weighing the nature of the entity, the amount and sensitivity of the information, the possible adverse consequences, and the practicability of the measure. A certified PIMS is strong evidence in that analysis. It is not a conclusion.

Combining the PIMS with an ISMS strengthens the position considerably, because APP 11's technical dimension maps to information security controls — see ISO 27001 implementation in Australia and run a baseline with the ISO 27001 gap assessment.

Implementation sequence for an Australian organisation

  1. Confirm you are an APP entity and identify any carve-out that applies. Test your readiness position with the Privacy Act readiness scorer.
  2. Build the record of processing activities. Every system, every data flow, every third party, every cross-border transfer. Without it nothing else is reliable.
  3. Determine your role for each activity — controller, processor, or both — for the PIMS, while remembering the Australian obligation set does not turn on that classification.
  4. Run the privacy risk assessment using the same risk criteria as your enterprise framework, per ISO 31000 applied to a compliance program.
  5. Close the APP-specific gaps the standard does not reach: APP 1.4 policy content, APP 5 notices, APP 7 direct marketing, APP 8 accountability, APP 12 and 13 request handling, and the NDB assessment and notification process.
  6. Integrate with your ISMS if you hold one, so context, competence, internal audit and management review run once.
  7. Complete an internal audit cycle and management review before any external audit.
  8. Select a certification body accredited for the scheme — see choosing a JAS-ANZ accredited certification body.

The OAIC is profiled at /regulators/oaic, and the broader picture sits in the privacy topic hub.

Frequently asked

Do I need ISO 27001 before I can implement ISO 27701?

Not since the 2025 edition. The first edition from 2019 was drafted as an extension to ISO/IEC 27001 and ISO/IEC 27002, so a PIMS required an ISMS underneath it. The 2025 edition is a standalone management system standard, though implementing both together remains the efficient path for most organisations.

Does ISO 27701 certification mean I comply with the Australian Privacy Act?

No. The mapping is strong on transparency, purpose limitation, data quality, security, retention, access and correction. It leaves gaps on APP 1.4 prescribed policy content, APP 2 anonymity, APP 5 notice matters, APP 7 direct marketing, APP 8 overseas accountability, and the entire notifiable data breach scheme with its statutory timeframes.

How do controller and processor roles work under Australian privacy law?

They do not, in the way an international regime uses them. The Privacy Act applies to APP entities, and an APP entity holding personal information carries APP obligations regardless of whether it determines the purposes of processing. There is no general reduced-obligation processor category, so a processor posture imported from offshore does not answer an Australian question.

Can a certified PIMS satisfy APP 11 reasonable steps?

It is strong evidence, not a safe harbour. Reasonable steps is a contextual test weighing the nature of the entity, the amount and sensitivity of the information, the possible consequences and the practicability of the measure. A certified PIMS produces contemporaneous evidence across every domain the OAIC identifies, which is why it helps — but the OAIC is not bound by it.

Does a PIMS handle notifiable data breach obligations?

Partly. It requires breach detection, assessment and response processes, which is the operational half. It does not create the Australian statutory duty to assess a suspected eligible data breach expeditiously, notify the OAIC and affected individuals, or meet the prescribed content requirements for the statement. Those have to be built explicitly.

Should I wait for the next round of Privacy Act reforms before implementing?

No. Reforms already in force include the statutory tort, the doxxing offence and enhanced penalties, with further commencements ahead. A proposed removal of the small business exemption has been agreed in principle but is not law and has no commencement date. Build the record of processing activities now — it is the foundation every reform will require.

Related

Related reading