🇪🇺 GDPR🌍 ISO 27001🚀 Phase 5 · Advanced

GDPR + ISO 27001 — How to Align Security and Privacy Controls

ISO 27001 builds the security machine GDPR demands — but certification is not a privacy shield, and treating it as one is the gap regulators walk through.

GK
Gauri Khatate
🔐 Cybersecurity Expert & Technical Writer·📖 5 min read
📅 June 2026·🏢 SecComply
Aligning ISO 27001 security controls with GDPR privacy obligations

ISO 27001 gives GDPR its security engine and the evidence to prove it — and stops precisely where privacy law keeps going.

Two of the most common acronyms in any compliance conversation get quietly conflated: a company with ISO 27001 certification often assumes it is therefore close to GDPR compliance. It isn’t — and the misunderstanding is expensive. ISO 27001 is a security management standard; GDPR is a privacy law that demands security as one of several obligations. The overlap is real and worth exploiting, but the gap between them is where the fines live — lawful basis, individual rights, retention, and transparency, none of which a security certificate covers.

Article 32
GDPR’s security duty — the part ISO 27001 maps to almost directly
93 controls
ISO 27001:2022 Annex A, the toolkit behind ‘appropriate measures’
ISO 27701
The privacy extension that bridges the standard to GDPR
Not a shield
Certification doesn’t stop a fine for a privacy-specific failure

Where the Two Actually Overlap

Article 32 asks for “appropriate technical and organisational measures” to secure personal data — which is, almost word for word, a description of what an information security management system does. This is ISO 27001’s home turf. Its Annex A controls — access control, cryptography, logging and monitoring, supplier security, incident management — are the practical “how” behind Article 32’s “what.” The connection isn’t theoretical, either: when regulators judge whether a company’s security measures were “appropriate,” they benchmark against recognised standards like ISO 27001 and NIST. A mature ISMS is genuinely strong evidence that the security half of GDPR is handled.

Where ISO 27001 Stops and GDPR Keeps Going

The trouble starts when “the security half” is mistaken for “the whole.” GDPR demands a long list of things ISO 27001 is simply silent on: a lawful basis for every processing activity, enforceable individual rights (access, erasure, portability), transparency notices, storage limitation, data protection impact assessments, breach notification to a regulator within 72 hours and to individuals when the risk is high, controller-processor agreements, and strict rules for moving data outside the EU. None of these is a security control, so none of them lives in an ISO 27001 certificate. A company can run a flawless ISMS and still be exposed on every one of them.

ObligationIn ISO 27001?What GDPR adds
Securing the dataYes — its coreThe legal duty under Art 32, benchmarked to standards
Lawful basis to processNoEvery processing activity needs a valid basis
Individual rightsNoAccess, erasure, portability — on a one-month clock
Retention limitsPartlyStorage limitation tied to purpose, not just records control
Breach handlingIncident mgmt72-hour regulator notice; individual notice when risk is high

Certification Is Evidence, Not Immunity

A certificate helps demonstrate Article 32 compliance and reassures customers — but it has never, on its own, stopped a privacy fine, because most fines aren’t about security at all.

CERTIFIED SECURITY, UNCOVERED PRIVACY — TWO SIDES OF THE LINE

When regulators fined British Airways (£20 million) and Marriott (£18.4 million) over their 2018 breaches, they assessed the companies’ security against recognised standards — the kind ISO 27001 codifies — and found specific control failures. That is exactly the territory the standard is built to govern, and it shows why ISO 27001 matters for Article 32. But the limit of a security framework is just as visible on the other side of the line: Germany’s Deutsche Wohnen was fined €14.5 million not for weak security at all, but for keeping tenant data long past its purpose in an archive that couldn’t delete — a storage-limitation failure no Annex A control would have flagged, because retention isn’t a security question. A company could hold a spotless certificate and still earn that fine. The standard governs how well data is protected; it says nothing about whether the company was allowed to keep it.

ISO 27701: The Bridge Worth Building

The efficient way to close the gap, for an organisation already certified, is ISO 27701 — the privacy extension that turns an ISMS into a privacy information management system. It adds controls specific to controllers and processors that map directly onto GDPR’s privacy obligations, and it does so within the same management system the company already runs. Rather than building a parallel privacy programme from nothing, 27701 lets the existing ISO 27001 machinery absorb the privacy controls it was never designed to carry — one system, extended, instead of two systems, duplicated.

Certified vs. Actually Compliant

Pattern-matching from real alignment reviews — the gap between holding a certificate and meeting the regulation tends to follow the same shape:

Looks GDPR-readyIs actually GDPR-ready
✗ “We’re ISO 27001 certified, so we’re covered”✓ Certification used as Art 32 evidence, plus the rest
✗ Security controls, no lawful-basis register✓ A documented basis mapped to every activity
✗ Incident process, no 72-hour notification plan✓ Breach response built to the regulator’s clock
✗ Strong access control, no rights workflow✓ Access, erasure, portability answered on time
✗ Retention left to IT’s discretion✓ Storage limitation tied to purpose and law
✗ ISMS scope that ignores privacy✓ ISO 27701 extending the system to privacy
✗ Certificate treated as a fine shield✓ Certificate as evidence, never as immunity

Run One Control Set, Satisfy Both

The strategic move is to refuse the false choice between a security programme and a privacy programme. Map the shared controls once — access, cryptography, logging, supplier management, incident response — to both Article 32 and Annex A, so a single piece of evidence answers to both. Then layer the privacy-specific obligations on top: the lawful-basis register, the rights workflows, the retention schedule, the transfer mechanisms, and the ISO 27701 controls. One control library, mapped to multiple frameworks, is far cheaper to run and to audit than two parallel programmes that drift apart.

Final Thought

ISO 27001 and GDPR are partners, not substitutes. The standard gives a company the engine to satisfy GDPR’s security duty and the evidence to prove it — and it stops precisely where privacy law keeps going. The organisations that get the most from both treat the certificate as the security foundation it is, then build the privacy obligations it doesn’t touch on the same management system, rather than mistaking the foundation for the whole building.

The test: list the things GDPR requires that ISO 27001 doesn’t — lawful basis, rights, retention, transfers, regulator notification — and ask whether each has an owner and a workflow, or only a certificate that doesn’t mention them. If the honest answer is “we assumed the certification covered it,” the gap is already open.

Does Your Certificate Cover GDPR — or Only the Security Half of It?

SecComply maps your ISO 27001 controls against GDPR article by article — using the certification as Article 32 evidence, then building the lawful-basis register, rights workflows, retention schedule, transfer mechanisms, and ISO 27701 controls the standard leaves out.

Frequently Asked Questions

Does ISO 27001 certification make me GDPR compliant?

No. ISO 27001 is a security management standard; GDPR is a privacy law that demands security as one of several obligations. Certification is strong evidence for the Article 32 security duty, but it is silent on lawful basis, individual rights, retention, transparency, and transfers.

Where do ISO 27001 and GDPR overlap?

On security. Article 32’s appropriate technical and organisational measures map almost directly onto ISO 27001’s Annex A controls — access control, cryptography, logging, supplier security, incident management. Regulators even benchmark appropriate against standards like ISO 27001 and NIST.

What does GDPR require that ISO 27001 does not?

A lawful basis per processing activity, enforceable individual rights, transparency notices, storage limitation, DPIAs, 72-hour breach notification, controller-processor agreements, and rules for international transfers. None of these is a security control, so none lives in the certificate.

How does ISO 27701 fit in?

It is the privacy extension that turns an ISMS into a privacy information management system, adding controller- and processor-specific controls that map onto GDPR’s privacy obligations, within the management system you already run instead of a parallel programme built from nothing.