ISO 27001 and GDPR: Where They Overlap, and Where They Don’t

One asks how well you protect information. The other asks whether you may hold it at all.
September 4, 2026
Ivar van Duuren

The short answer

ISO 27001 and GDPR answer different questions, although there is an important area of overlap.

ISO/IEC 27001 is an international standard for managing information security. It asks whether your organisation identifies information security risks, takes appropriate measures to manage them, assigns responsibility and continually improves the way information is protected.

GDPR is European data protection law. It goes further. It asks whether and why personal data may be processed, how much data you collect, how long you keep it, how securely you protect it and whether people can exercise their rights over it.

That distinction matters. You can have excellent security and still process personal data unlawfully. A perfectly encrypted database containing personal data collected without a lawful basis can still be a GDPR problem.

The reverse is also true. You can have a valid lawful basis for processing personal data and still fail to protect that data adequately.

So although GDPR and ISO 27001 overlap significantly on information security, ISO 27001 certification does not make an organisation GDPR compliant.

ISO 27001 and GDPR at a glance

What is it?

ISO 27001 is an international information security management standard. GDPR is EU data protection law.

Primary focus.

ISO 27001 manages information security risks. GDPR governs lawful, fair and secure processing of personal data.

Applies to.

ISO 27001 covers information within the scope of the ISMS. GDPR covers processing of personal data within the scope of the regulation.

Certification.

ISO 27001 can be certified. GDPR provides for certification mechanisms, but there is no general certificate that removes your GDPR obligations.

Individual privacy rights.

Not the primary purpose of ISO 27001. A core requirement of GDPR.

Security measures.

A core part of ISO 27001. Required by GDPR wherever personal data is processed.

Does ISO 27001 prove GDPR compliance? No.

Where ISO 27001 and GDPR overlap

The overlap between GDPR and ISO 27001 is real, and organisations should make use of it.

GDPR requires organisations to implement appropriate technical and organisational measures to protect personal data. What is appropriate depends on factors such as the risks involved, the nature of the data and the context in which it is processed.

ISO 27001 provides a structured way to manage many of those measures. An Information Security Management System, or ISMS, gives you a repeatable process for identifying information security risks, selecting controls, assigning owners, reviewing effectiveness and retaining evidence that measures are actually being operated.

That does not automatically prove that every GDPR requirement has been met. It does, however, provide a strong management structure for the security-related part of GDPR compliance.

If a regulator asks how you assessed a security risk, why a particular measure was selected, who was responsible for it and whether it was reviewed, a well-run ISMS can make those questions much easier to answer.

Incident management is another important overlap

GDPR also contains specific requirements for personal data breaches.

Where a personal data breach is likely to result in a risk to people's rights and freedoms, the controller must notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it.

Where the breach is likely to result in a high risk to individuals, the affected people may also need to be informed, subject to the exceptions set out in GDPR.

ISO 27001 does not create those notification obligations. But an effective ISMS can provide the incident management process that helps an organisation detect, investigate, document and escalate an incident quickly enough to meet them.

The 72-hour requirement becomes much harder to meet when nobody knows who owns the incident, when it started, what information was affected or who needs to make the decision. That is exactly the type of operational problem a management system is designed to prevent.

Where ISO 27001 stops and GDPR continues

The biggest difference is that GDPR is not simply an information security requirement. Security is one part of data protection.

GDPR also requires organisations to address questions such as: what is the purpose of processing this personal data, and what is the lawful basis for doing so? Are we collecting more personal data than we actually need? How long should the data be retained? Who receives or has access to it? Are individuals properly informed? Can people exercise their rights to access, rectify, erase or restrict processing? Where applicable, can they exercise their right to data portability or object to processing? And if consent is relied upon, does that consent meet the GDPR requirements?

Depending on the organisation and processing involved, GDPR may also require records of processing activities, Data Protection Impact Assessments, processor agreements and other privacy-specific documentation and processes.

ISO 27001 does not replace those obligations. An ISO 27001 certification auditor may assess whether relevant legal and regulatory requirements have been identified and appropriately considered within the ISMS. But an ISO 27001 certification audit is not a full GDPR compliance assessment. A data protection supervisory authority can look much further.

That is why treating ISO 27001 certification as evidence that an organisation is automatically GDPR compliant is a mistake.

Why an ISO 27001 certificate is not GDPR compliance

This is worth stating plainly, because the distinction is sometimes lost in compliance marketing. There is no ISO 27001 certificate that makes an organisation GDPR compliant.

GDPR applies directly to organisations that fall within its scope. Those obligations continue regardless of which ISO standards an organisation has implemented or certified.

The GDPR does provide for approved certification mechanisms, but certification does not remove the responsibility of controllers or processors to comply with the regulation. An ISO 27001 certificate, specifically, is evidence that an information security management system has been assessed against ISO 27001, not that every GDPR obligation has been assessed.

What a management system can give you is something extremely valuable: demonstrability. GDPR includes an accountability principle. Organisations are not only expected to comply with their obligations; they need to be able to demonstrate how they do so.

That means maintaining evidence. Why was a decision made? Who owns the measure? When was it last reviewed? Is the control still operating? What happened after an incident? Was the risk reassessed when something changed?

This is where many organisations struggle over time. The challenge is often not that they misunderstood GDPR when they first implemented it. The challenge is keeping the processes, responsibilities, measures and evidence current two or three years later.

A management system helps turn one-off compliance work into an ongoing process. Not because the system itself makes you compliant, but because it helps make compliance managed, evidenced and repeatable.

What about ISO/IEC 27701?

For organisations looking for a management system standard specifically focused on privacy, ISO/IEC 27701 is the more relevant standard. Importantly, this changed with the publication of ISO/IEC 27701:2025.

The previous 2019 edition was designed as an extension to ISO/IEC 27001 and ISO/IEC 27002. The 2025 edition is now a standalone management system standard for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS). It can therefore be implemented independently, while still being designed to integrate effectively with ISO 27001.

ISO 27701 can help organisations structure privacy responsibilities, risks, controls and evidence and support the demonstration of compliance with privacy regulations such as GDPR. But the same principle applies: implementing or certifying a management system does not transfer your legal responsibility to the standard or the software you use to manage it.

Where the measures actually get operated

This is where the practical challenge starts. Privacy and information security often concern the same systems, suppliers, assets, risks and people. Yet in many organisations they are managed separately.

The privacy register sits in one spreadsheet or tool. The asset inventory lives somewhere else. Security controls are documented in the ISMS. Actions are tracked in another application. Evidence sits in SharePoint or Teams. Incident information is maintained separately again. The result is duplication, and over time those different descriptions of the organisation can start to contradict each other.

ISOPlanner™ is not a GDPR compliance solution, and we would not describe it as one. No software product can determine your lawful basis for processing personal data, decide whether a particular processing activity is legally permitted or replace the legal judgement required to meet GDPR obligations.

What ISOPlanner™ does provide is a structured environment for the operational management around compliance. Records of processing activities can be managed alongside assets and other compliance information. Technical and organisational measures can be linked to responsibilities, actions and evidence. Risks can be assigned owners and reviewed over time. Incidents, controls and follow-up activities become part of the same management cycle instead of separate compliance exercises.

For organisations already working with Microsoft 365, this can also reduce the need to build an entirely separate way of working around compliance.

The value is not that a tool makes you GDPR compliant. The value is that the decisions, responsibilities, measures and evidence that support your compliance are less likely to disappear into disconnected spreadsheets, documents and inboxes.

Start with the obligation, then manage it

The order matters. Start by understanding what GDPR requires from your organisation and why you are processing personal data. Determine your purposes, lawful bases, responsibilities, retention requirements and the rights that apply.

Then make sure the measures needed to support those obligations are managed somewhere they will still be visible, owned and reviewed years from now.

ISO 27001 can provide a strong management foundation for information security. ISO 27701 can extend that management discipline into privacy. Neither replaces GDPR. But together with a well-operated management system, they can make it considerably easier to turn compliance from a one-off documentation exercise into something your organisation can actually maintain and demonstrate.

This article provides general information about GDPR and ISO standards and should not be considered legal advice.

See your measures evidenced in one place

Related Posts