Skip to content

ISO/IEC 27701 — annexes

ISO/IEC 27701:2025 places all its normative privacy controls in Annex A, organized into three role-based tables: Table A.1 for PII controllers, Table A.2 for PII processors, and Table A.3 for controls that apply to both roles. Annex B gives informative implementation guidance; Annex D provides an informative mapping to GDPR. This page covers the structure of each table at the theme level, with reference numbers only.

Quick decision

  • You determine purposes and means of processing → apply Table A.1 (PII controller controls), plus Table A.3 (both roles).
  • You process PII on behalf of a controller → apply Table A.2 (PII processor controls), plus Table A.3.
  • You are both, for different processing activities → apply Table A.1 and Table A.2 per the relevant activities, with Table A.3 throughout.
  • You need implementation guidance on a control → consult Annex B (informative).
  • You need to demonstrate GDPR alignment → use Annex D as the planning aid; map PIMS controls to GDPR articles to identify where one control produces evidence for both.

TL;DR

  • Annex A holds all normative controls in three tables. Table A.1 — PII controllers (31): lawfulness, PII principals' rights, privacy by design, records of processing, transfers. Table A.2 — PII processors (18): documented instructions, assistance to the customer, sub-processor oversight, end-of-processing. Table A.3 — both roles (29): information-security controls adapted for PII protection.
  • Annex B — informative implementation guidance for the Annex A controls (not a separate control set).
  • Annex D — informative mapping to GDPR articles (planning aid, not a compliance attestation).
  • Role drives selection — controller / processor / joint controller per processing activity, with Table A.3 applied regardless. Many organizations operate as more than one role.
  • Statement of Applicability records which Annex A controls are included or excluded, with justification.

Primary source

ISO/IEC 27701:2025Privacy information management — Requirements and guidance. Annex A (normative) — Table A.1 (PII controllers), Table A.2 (PII processors), Table A.3 (both roles). Annex B (implementation guidance, informative). Annex D (GDPR mapping, informative). Available via the ISO Online Browsing Platform. © ISO. Withdrawn prior edition: ISO/IEC 27701:2019.

Annex A — normative privacy controls (three role-based tables)

The 2025 edition places all normative privacy controls in Annex A, selected per processing activity from the Clause 6.1.3 risk treatment. Annex B provides informative implementation guidance for these controls — it is not a separate control set.

Table A.1 — controls for PII controllers

Table A.1 organizes controls around the controller's privacy obligations (31 controls in the Modulos model, MRF-394). Without reproducing the control text, the high-level structure covers:

ThemeFocus
Lawful, purpose-bound processingDocumenting purpose and lawful basis; defining and operating consent; assessing the need for a privacy impact assessment
Contracts and shared responsibilityContracting with PII processors; agreeing roles with joint PII controllers; maintaining processing records
Obligations to PII principalsInforming principals; access, correction, erasure, objection, copies of PII; relaying consent changes and objections to third parties; automated-decision-making duties
Privacy by design and by defaultLimiting collection and processing to purpose; accuracy; minimization objectives; de-identification / deletion when no longer needed; temporary-file disposal; retention limits; safeguarding transmission
Sharing, transfer and disclosureIdentifying transfer bases between jurisdictions; documenting permitted destinations; recording transfers and third-party disclosures

Table A.2 — controls for PII processors

Table A.2 organizes controls around the processor's obligations to the customer (controller) and, indirectly, to PII principals (18 controls in the Modulos model, MRF-395):

ThemeFocus
Processing under customer instructionsProcessing only per documented instructions; no marketing/advertising use without established consent; flagging instructions believed to infringe law; supplying the information the customer needs to demonstrate compliance; processing records
Assistance to the customerGiving the customer the means to meet its obligations to PII principals
Privacy by designTemporary-file disposal; secure return, transfer or disposal of PII; safeguarding transmission
Sharing, transfer and disclosureInforming the customer of transfer bases and intended changes; documenting possible destinations; recording and vetting disclosure requests; engaging or changing sub-processors only as the customer has agreed

Table A.3 — controls for PII controllers and PII processors

Table A.3 applies to both roles and is selected regardless of whether the organization is a controller, a processor, or both. It adapts information-security controls so that they specifically secure PII processing (29 controls in the Modulos model, MRF-396):

ThemeFocus
GovernanceSecurity policies; roles and responsibilities; classification and labeling; supplier-agreement requirements; documentation of legal and contractual requirements; independent review; compliance checking; awareness and training; confidentiality agreements
Operational safeguardsTransfer rules; identity life-cycle and access-rights management; incident-management planning and response; protection of records; clear-desk / clear-screen; storage-media management; secure disposal or re-use of equipment; endpoint protection
Technical measuresSecure authentication; backup; logging; cryptography; secure development practices; application-security requirements; secure engineering principles; oversight of outsourced development; protection of test information

Table A.3 is where the PIMS and the ISO 27001 ISMS meet: these controls mirror the ISO 27001 Annex A information-security controls, re-expressed for the protection of PII.

How to use the Annex A tables

  • Apply per processing activity by role — Table A.1 where the organization is a controller, Table A.2 where it is a processor, Table A.3 in either case.
  • Drive selection from the privacy risk assessment under Clause 6.1.2.
  • Translate controls into operating reality — owned work, cadence, evidence, escalation.
  • Record selection in the Statement of Applicability under Clause 6.1.3, justifying any exclusions.
  • Consult Annex B for implementation guidance on how each control can be realized.

Annex D — informative mapping to GDPR

Annex D is an informative cross-reference between the PIMS Annex A controls and the GDPR articles. It is a planning aid, not a compliance attestation:

  • A single Annex A control can produce evidence relevant to multiple GDPR articles.
  • Implementing a mapped control does not automatically satisfy the corresponding GDPR article — GDPR legal interpretation is a separate exercise.
  • Annex D is most useful when planning a single PIMS that also produces GDPR operational evidence.

The mapping typically covers:

GDPR areaPIMS controls in Annex A
Lawfulness, transparency, fairness (Articles 5–7)Table A.1 lawfulness, consent, transparency
PII principals' rights (Articles 12–22)Table A.1 rights handling; Table A.2 assistance to the customer
Controller obligations (Articles 24–30)Table A.1 records of processing, privacy by design
Processor obligations (Article 28)Table A.2 in full
Personal-data breach (Articles 33–34)Table A.1 breach notification + Table A.2 notification to the customer; Table A.3 incident management
Security of processing (Article 32)Table A.3 information-security controls
DPIA (Article 35)Clause 6.1.2 / 6.1.3 privacy risk method plus Table A.1 privacy-impact-assessment evidence
DPO / responsibilities (Article 37)Clause 5.3 roles and responsibilities
Cross-border transfer (Articles 44–50)Table A.1 / Table A.2 transfer controls

How to operationalize the annexes in Modulos

Modulos models the three Annex A control tables as first-class, per-table requirements on the MFF-13 template — one requirement per table:

MFF-13 requirementAnnex A tableControls
MRF-394Table A.1 — PII controllers31
MRF-395Table A.2 — PII processors18
MRF-396Table A.3 — both roles29

MFF-13 also carries the two per-AI-system operational requirements — MRF-243 (Clause 8.2 privacy risk assessment) and MRF-244 (Clause 8.3 privacy risk treatment) — so a single app-level project surfaces both the privacy risk work and the applicable Annex A controls for that AI system.

At the organization level, the OFF-12 evidence pattern complements this — the Statement of Applicability and the control-selection decisions live on ORF-265 (Clause 6.1.3 privacy risk treatment):

TemplateWhere the annex controls livePurpose
MFF-13MRF-394 / MRF-395 / MRF-396 — one requirement per tablePer-table control readiness for each AI system
OFF-12Statement of Applicability + control selection on ORF-265; execution on ORF-275; monitoring on ORF-276; audit on ORF-277 / ORF-278Organization-wide SoA, exclusions and justification, execution and assurance

Practical pattern:

  • Per-table readiness — the three MFF-13 requirements let you track control coverage table by table on each AI-system project, selected by that system's role (controller / processor / both).
  • The SoA artifact is owner-authored documented information attached as evidence on ORF-265; it records which Annex A controls are included or excluded, with justification, across the applicable tables.
  • Per-control evidence (control execution records, exception decisions, sub-processor reviews, DSAR responses) is linked to the Modulos controls under the relevant requirements.
  • Role-determination decisions that drive table selection flow from Clause 4.1 (recorded on ORF-256).

Cross-framework mapping (preview)

ISO 27701 annex elementAdjacent provision
Table A.1 lawfulnessGDPR Articles 5, 6, 7, 9
Table A.1 PII principals' rightsGDPR Articles 12–22
Table A.1 records of processingGDPR Article 30
Table A.1 privacy impact assessmentGDPR Article 35 DPIA; ISO 42001 Clause 6.1.4 AI impact assessment
Table A.1 cross-border transferGDPR Articles 44–50; SCCs; adequacy decisions
Table A.1 automated decision-makingGDPR Article 22; EU AI Act Article 26(11)
Table A.1 personal-data breach notificationGDPR Articles 33–34
Table A.3 information security (incl. incident management)GDPR Article 32; ISO 27001 Annex A.5.24–A.5.28
Table A.2 in fullGDPR Article 28; SCCs Module 2

Source attribution

ISO/IEC 27701:2025Privacy information management — Requirements and guidance, Annex A (normative) — Table A.1 (PII controllers), Table A.2 (PII processors), Table A.3 (both roles); Annex B (implementation guidance, informative); Annex D (informative GDPR mapping). © ISO/IEC. Available via the ISO Online Browsing Platform.

Disclaimer

This page is for general informational purposes and does not constitute legal or certification advice.