Appearance
ISO/IEC 27701 — annexes
ISO/IEC 27701:2025 places all its normative privacy controls in Annex A, organized into three role-based tables: Table A.1 for PII controllers, Table A.2 for PII processors, and Table A.3 for controls that apply to both roles. Annex B gives informative implementation guidance; Annex D provides an informative mapping to GDPR. This page covers the structure of each table at the theme level, with reference numbers only.
Quick decision
- You determine purposes and means of processing → apply Table A.1 (PII controller controls), plus Table A.3 (both roles).
- You process PII on behalf of a controller → apply Table A.2 (PII processor controls), plus Table A.3.
- You are both, for different processing activities → apply Table A.1 and Table A.2 per the relevant activities, with Table A.3 throughout.
- You need implementation guidance on a control → consult Annex B (informative).
- You need to demonstrate GDPR alignment → use Annex D as the planning aid; map PIMS controls to GDPR articles to identify where one control produces evidence for both.
TL;DR
- Annex A holds all normative controls in three tables. Table A.1 — PII controllers (31): lawfulness, PII principals' rights, privacy by design, records of processing, transfers. Table A.2 — PII processors (18): documented instructions, assistance to the customer, sub-processor oversight, end-of-processing. Table A.3 — both roles (29): information-security controls adapted for PII protection.
- Annex B — informative implementation guidance for the Annex A controls (not a separate control set).
- Annex D — informative mapping to GDPR articles (planning aid, not a compliance attestation).
- Role drives selection — controller / processor / joint controller per processing activity, with Table A.3 applied regardless. Many organizations operate as more than one role.
- Statement of Applicability records which Annex A controls are included or excluded, with justification.
Primary source
ISO/IEC 27701:2025 — Privacy information management — Requirements and guidance. Annex A (normative) — Table A.1 (PII controllers), Table A.2 (PII processors), Table A.3 (both roles). Annex B (implementation guidance, informative). Annex D (GDPR mapping, informative). Available via the ISO Online Browsing Platform. © ISO. Withdrawn prior edition: ISO/IEC 27701:2019.
Annex A — normative privacy controls (three role-based tables)
The 2025 edition places all normative privacy controls in Annex A, selected per processing activity from the Clause 6.1.3 risk treatment. Annex B provides informative implementation guidance for these controls — it is not a separate control set.
Table A.1 — controls for PII controllers
Table A.1 organizes controls around the controller's privacy obligations (31 controls in the Modulos model, MRF-394). Without reproducing the control text, the high-level structure covers:
| Theme | Focus |
|---|---|
| Lawful, purpose-bound processing | Documenting purpose and lawful basis; defining and operating consent; assessing the need for a privacy impact assessment |
| Contracts and shared responsibility | Contracting with PII processors; agreeing roles with joint PII controllers; maintaining processing records |
| Obligations to PII principals | Informing principals; access, correction, erasure, objection, copies of PII; relaying consent changes and objections to third parties; automated-decision-making duties |
| Privacy by design and by default | Limiting collection and processing to purpose; accuracy; minimization objectives; de-identification / deletion when no longer needed; temporary-file disposal; retention limits; safeguarding transmission |
| Sharing, transfer and disclosure | Identifying transfer bases between jurisdictions; documenting permitted destinations; recording transfers and third-party disclosures |
Table A.2 — controls for PII processors
Table A.2 organizes controls around the processor's obligations to the customer (controller) and, indirectly, to PII principals (18 controls in the Modulos model, MRF-395):
| Theme | Focus |
|---|---|
| Processing under customer instructions | Processing only per documented instructions; no marketing/advertising use without established consent; flagging instructions believed to infringe law; supplying the information the customer needs to demonstrate compliance; processing records |
| Assistance to the customer | Giving the customer the means to meet its obligations to PII principals |
| Privacy by design | Temporary-file disposal; secure return, transfer or disposal of PII; safeguarding transmission |
| Sharing, transfer and disclosure | Informing the customer of transfer bases and intended changes; documenting possible destinations; recording and vetting disclosure requests; engaging or changing sub-processors only as the customer has agreed |
Table A.3 — controls for PII controllers and PII processors
Table A.3 applies to both roles and is selected regardless of whether the organization is a controller, a processor, or both. It adapts information-security controls so that they specifically secure PII processing (29 controls in the Modulos model, MRF-396):
| Theme | Focus |
|---|---|
| Governance | Security policies; roles and responsibilities; classification and labeling; supplier-agreement requirements; documentation of legal and contractual requirements; independent review; compliance checking; awareness and training; confidentiality agreements |
| Operational safeguards | Transfer rules; identity life-cycle and access-rights management; incident-management planning and response; protection of records; clear-desk / clear-screen; storage-media management; secure disposal or re-use of equipment; endpoint protection |
| Technical measures | Secure authentication; backup; logging; cryptography; secure development practices; application-security requirements; secure engineering principles; oversight of outsourced development; protection of test information |
Table A.3 is where the PIMS and the ISO 27001 ISMS meet: these controls mirror the ISO 27001 Annex A information-security controls, re-expressed for the protection of PII.
How to use the Annex A tables
- Apply per processing activity by role — Table A.1 where the organization is a controller, Table A.2 where it is a processor, Table A.3 in either case.
- Drive selection from the privacy risk assessment under Clause 6.1.2.
- Translate controls into operating reality — owned work, cadence, evidence, escalation.
- Record selection in the Statement of Applicability under Clause 6.1.3, justifying any exclusions.
- Consult Annex B for implementation guidance on how each control can be realized.
Annex D — informative mapping to GDPR
Annex D is an informative cross-reference between the PIMS Annex A controls and the GDPR articles. It is a planning aid, not a compliance attestation:
- A single Annex A control can produce evidence relevant to multiple GDPR articles.
- Implementing a mapped control does not automatically satisfy the corresponding GDPR article — GDPR legal interpretation is a separate exercise.
- Annex D is most useful when planning a single PIMS that also produces GDPR operational evidence.
The mapping typically covers:
| GDPR area | PIMS controls in Annex A |
|---|---|
| Lawfulness, transparency, fairness (Articles 5–7) | Table A.1 lawfulness, consent, transparency |
| PII principals' rights (Articles 12–22) | Table A.1 rights handling; Table A.2 assistance to the customer |
| Controller obligations (Articles 24–30) | Table A.1 records of processing, privacy by design |
| Processor obligations (Article 28) | Table A.2 in full |
| Personal-data breach (Articles 33–34) | Table A.1 breach notification + Table A.2 notification to the customer; Table A.3 incident management |
| Security of processing (Article 32) | Table A.3 information-security controls |
| DPIA (Article 35) | Clause 6.1.2 / 6.1.3 privacy risk method plus Table A.1 privacy-impact-assessment evidence |
| DPO / responsibilities (Article 37) | Clause 5.3 roles and responsibilities |
| Cross-border transfer (Articles 44–50) | Table A.1 / Table A.2 transfer controls |
How to operationalize the annexes in Modulos
Modulos models the three Annex A control tables as first-class, per-table requirements on the MFF-13 template — one requirement per table:
| MFF-13 requirement | Annex A table | Controls |
|---|---|---|
MRF-394 | Table A.1 — PII controllers | 31 |
MRF-395 | Table A.2 — PII processors | 18 |
MRF-396 | Table A.3 — both roles | 29 |
MFF-13 also carries the two per-AI-system operational requirements — MRF-243 (Clause 8.2 privacy risk assessment) and MRF-244 (Clause 8.3 privacy risk treatment) — so a single app-level project surfaces both the privacy risk work and the applicable Annex A controls for that AI system.
At the organization level, the OFF-12 evidence pattern complements this — the Statement of Applicability and the control-selection decisions live on ORF-265 (Clause 6.1.3 privacy risk treatment):
| Template | Where the annex controls live | Purpose |
|---|---|---|
| MFF-13 | MRF-394 / MRF-395 / MRF-396 — one requirement per table | Per-table control readiness for each AI system |
| OFF-12 | Statement of Applicability + control selection on ORF-265; execution on ORF-275; monitoring on ORF-276; audit on ORF-277 / ORF-278 | Organization-wide SoA, exclusions and justification, execution and assurance |
Practical pattern:
- Per-table readiness — the three MFF-13 requirements let you track control coverage table by table on each AI-system project, selected by that system's role (controller / processor / both).
- The SoA artifact is owner-authored documented information attached as evidence on
ORF-265; it records which Annex A controls are included or excluded, with justification, across the applicable tables. - Per-control evidence (control execution records, exception decisions, sub-processor reviews, DSAR responses) is linked to the Modulos controls under the relevant requirements.
- Role-determination decisions that drive table selection flow from Clause 4.1 (recorded on
ORF-256).
Framework mapping
Four layers, one reusable spine.
Frameworks
EU AI Act
ISO 42001
Requirements
Art. 9.1Risk management
Art. 10.2Data governance
6.1.1Risk assessment
Components
Risk identification
Impact analysis
Evidence
Risk register
Test results
Controls
The reusable spine
One control satisfies many requirements across many frameworks, and groups the components and evidence beneath them.
Risk assessment process
Data validation checks
Edge from any layer card crosses into the Controls spine — the same control may serve a regulatory article, a standards clause, a downstream component, and the evidence that closes it.
Cross-framework mapping (preview)
| ISO 27701 annex element | Adjacent provision |
|---|---|
| Table A.1 lawfulness | GDPR Articles 5, 6, 7, 9 |
| Table A.1 PII principals' rights | GDPR Articles 12–22 |
| Table A.1 records of processing | GDPR Article 30 |
| Table A.1 privacy impact assessment | GDPR Article 35 DPIA; ISO 42001 Clause 6.1.4 AI impact assessment |
| Table A.1 cross-border transfer | GDPR Articles 44–50; SCCs; adequacy decisions |
| Table A.1 automated decision-making | GDPR Article 22; EU AI Act Article 26(11) |
| Table A.1 personal-data breach notification | GDPR Articles 33–34 |
| Table A.3 information security (incl. incident management) | GDPR Article 32; ISO 27001 Annex A.5.24–A.5.28 |
| Table A.2 in full | GDPR Article 28; SCCs Module 2 |
Related pages
ISO 27701 overview
Hub: PIMS structure, controller / processor distinction, GDPR alignment
PIMS foundations (scope + roles + certification)
Scope, controller / processor determination, certification cycle
Clauses 4–10 (implementation guide)
Annex SL backbone with PIMS-specific additions
Operationalizing in Modulos
OFF-12 + MFF-13 rollout, PIMS evidence patterns
Integration with GDPR
How the PIMS produces the operational evidence GDPR requires
Source attribution
ISO/IEC 27701:2025 — Privacy information management — Requirements and guidance, Annex A (normative) — Table A.1 (PII controllers), Table A.2 (PII processors), Table A.3 (both roles); Annex B (implementation guidance, informative); Annex D (informative GDPR mapping). © ISO/IEC. Available via the ISO Online Browsing Platform.
Disclaimer
This page is for general informational purposes and does not constitute legal or certification advice.