Two of the most common acronyms in any compliance conversation get quietly conflated: a company with ISO 27001 certification often assumes it is therefore close to GDPR compliance. It isn’t — and the misunderstanding is expensive. ISO 27001 is a security management standard; GDPR is a privacy law that demands security as one of several obligations. The overlap is real and worth exploiting, but the gap between them is where the fines live — lawful basis, individual rights, retention, and transparency, none of which a security certificate covers.
Where the Two Actually Overlap
Article 32 asks for “appropriate technical and organisational measures” to secure personal data — which is, almost word for word, a description of what an information security management system does. This is ISO 27001’s home turf. Its Annex A controls — access control, cryptography, logging and monitoring, supplier security, incident management — are the practical “how” behind Article 32’s “what.” The connection isn’t theoretical, either: when regulators judge whether a company’s security measures were “appropriate,” they benchmark against recognised standards like ISO 27001 and NIST. A mature ISMS is genuinely strong evidence that the security half of GDPR is handled.
Where ISO 27001 Stops and GDPR Keeps Going
The trouble starts when “the security half” is mistaken for “the whole.” GDPR demands a long list of things ISO 27001 is simply silent on: a lawful basis for every processing activity, enforceable individual rights (access, erasure, portability), transparency notices, storage limitation, data protection impact assessments, breach notification to a regulator within 72 hours and to individuals when the risk is high, controller-processor agreements, and strict rules for moving data outside the EU. None of these is a security control, so none of them lives in an ISO 27001 certificate. A company can run a flawless ISMS and still be exposed on every one of them.
| Obligation | In ISO 27001? | What GDPR adds |
|---|---|---|
| Securing the data | Yes — its core | The legal duty under Art 32, benchmarked to standards |
| Lawful basis to process | No | Every processing activity needs a valid basis |
| Individual rights | No | Access, erasure, portability — on a one-month clock |
| Retention limits | Partly | Storage limitation tied to purpose, not just records control |
| Breach handling | Incident mgmt | 72-hour regulator notice; individual notice when risk is high |
Certification Is Evidence, Not Immunity
A certificate helps demonstrate Article 32 compliance and reassures customers — but it has never, on its own, stopped a privacy fine, because most fines aren’t about security at all.
When regulators fined British Airways (£20 million) and Marriott (£18.4 million) over their 2018 breaches, they assessed the companies’ security against recognised standards — the kind ISO 27001 codifies — and found specific control failures. That is exactly the territory the standard is built to govern, and it shows why ISO 27001 matters for Article 32. But the limit of a security framework is just as visible on the other side of the line: Germany’s Deutsche Wohnen was fined €14.5 million not for weak security at all, but for keeping tenant data long past its purpose in an archive that couldn’t delete — a storage-limitation failure no Annex A control would have flagged, because retention isn’t a security question. A company could hold a spotless certificate and still earn that fine. The standard governs how well data is protected; it says nothing about whether the company was allowed to keep it.
ISO 27701: The Bridge Worth Building
The efficient way to close the gap, for an organisation already certified, is ISO 27701 — the privacy extension that turns an ISMS into a privacy information management system. It adds controls specific to controllers and processors that map directly onto GDPR’s privacy obligations, and it does so within the same management system the company already runs. Rather than building a parallel privacy programme from nothing, 27701 lets the existing ISO 27001 machinery absorb the privacy controls it was never designed to carry — one system, extended, instead of two systems, duplicated.
Certified vs. Actually Compliant
Pattern-matching from real alignment reviews — the gap between holding a certificate and meeting the regulation tends to follow the same shape:
| Looks GDPR-ready | Is actually GDPR-ready |
|---|---|
| ✗ “We’re ISO 27001 certified, so we’re covered” | ✓ Certification used as Art 32 evidence, plus the rest |
| ✗ Security controls, no lawful-basis register | ✓ A documented basis mapped to every activity |
| ✗ Incident process, no 72-hour notification plan | ✓ Breach response built to the regulator’s clock |
| ✗ Strong access control, no rights workflow | ✓ Access, erasure, portability answered on time |
| ✗ Retention left to IT’s discretion | ✓ Storage limitation tied to purpose and law |
| ✗ ISMS scope that ignores privacy | ✓ ISO 27701 extending the system to privacy |
| ✗ Certificate treated as a fine shield | ✓ Certificate as evidence, never as immunity |
Run One Control Set, Satisfy Both
The strategic move is to refuse the false choice between a security programme and a privacy programme. Map the shared controls once — access, cryptography, logging, supplier management, incident response — to both Article 32 and Annex A, so a single piece of evidence answers to both. Then layer the privacy-specific obligations on top: the lawful-basis register, the rights workflows, the retention schedule, the transfer mechanisms, and the ISO 27701 controls. One control library, mapped to multiple frameworks, is far cheaper to run and to audit than two parallel programmes that drift apart.
Final Thought
ISO 27001 and GDPR are partners, not substitutes. The standard gives a company the engine to satisfy GDPR’s security duty and the evidence to prove it — and it stops precisely where privacy law keeps going. The organisations that get the most from both treat the certificate as the security foundation it is, then build the privacy obligations it doesn’t touch on the same management system, rather than mistaking the foundation for the whole building.
The test: list the things GDPR requires that ISO 27001 doesn’t — lawful basis, rights, retention, transfers, regulator notification — and ask whether each has an owner and a workflow, or only a certificate that doesn’t mention them. If the honest answer is “we assumed the certification covered it,” the gap is already open.
Frequently Asked Questions
No. ISO 27001 is a security management standard; GDPR is a privacy law that demands security as one of several obligations. Certification is strong evidence for the Article 32 security duty, but it is silent on lawful basis, individual rights, retention, transparency, and transfers.
On security. Article 32’s appropriate technical and organisational measures map almost directly onto ISO 27001’s Annex A controls — access control, cryptography, logging, supplier security, incident management. Regulators even benchmark appropriate against standards like ISO 27001 and NIST.
A lawful basis per processing activity, enforceable individual rights, transparency notices, storage limitation, DPIAs, 72-hour breach notification, controller-processor agreements, and rules for international transfers. None of these is a security control, so none lives in the certificate.
It is the privacy extension that turns an ISMS into a privacy information management system, adding controller- and processor-specific controls that map onto GDPR’s privacy obligations, within the management system you already run instead of a parallel programme built from nothing.