AsteronAsteron

    ISO 27701 privacy management for European healthtech

    Asteron builds the privacy information management system that turns GDPR obligations into controlled, repeatable operations. We connect privacy roles, processing records, risk assessments, data-subject rights, suppliers, transfers and breach workflows within one auditable system. The service uses ISO/IEC 27701:2025 and is designed for healthtech companies operating as controllers, processors or both across the Netherlands, Germany and the wider European market.

    View ISO 27701 pricing
    • ISO/IEC 27701:2025 PIMS implemented
    • Controller and processor duties mapped
    • GDPR and health-data operations connected
    • Independent certification readiness prepared

    From €9,900 with an existing Compliance Core

    What is ISO/IEC 27701:2025?

    ISO/IEC 27701 is the international management-system standard for establishing, operating and continually improving a Privacy Information Management System, or PIMS. It helps organisations assign privacy responsibilities, understand how personal information is processed, manage privacy risks and maintain evidence that decisions are followed in practice.

    The 2025 edition is a standalone management-system standard. An organisation can implement and certify it without first holding ISO 27001 certification. It remains closely aligned with ISO 27001, however, so existing information-security governance, risk management, internal audit and continual-improvement processes can be reused.

    ISO 27701 does not declare an organisation “GDPR compliant.” It creates the operating system and evidence needed to manage privacy obligations consistently and demonstrate accountability.

    Why privacy management matters in healthtech

    European healthtech companies rarely have one simple privacy role. A company may act as a processor for a hospital, a controller for its own users and employees, and a joint controller within a research or care partnership.

    The same product may process identifiers, clinical observations, diagnostic information, device data, behavioural information and support records across several suppliers and countries. Without a functioning management system, legal analyses, contracts, product decisions and technical controls quickly drift apart.

    ISO 27701 gives privacy work an operational structure. It connects the data inventory to responsible owners, legal and contractual requirements, product changes, supplier decisions, security controls, incidents and management review.

    ISO 27701, ISO 27001 and GDPR answer different questions

    ISO/IEC 27701:2025
    How does the organisation manage privacy consistently?
    A certifiable Privacy Information Management System for controllers and processors.
    ISO/IEC 27001
    How does the organisation manage information-security risk?
    An Information Security Management System covering information assets and security controls.
    GDPR
    Is each processing activity lawful and are individual rights protected?
    Binding legal obligations concerning principles, legal bases, transparency, rights, security, transfers and accountability.
    GDPR Article 9
    Under what condition may special-category data such as health data be processed?
    Additional legal conditions beyond the general Article 6 legal basis.
    National health-data rules
    What additional conditions apply in a particular country or care setting?
    Jurisdiction-specific requirements concerning healthcare, confidentiality, research, retention or professional duties.

    An ISO 27701 system can organise and evidence GDPR-related work, but it cannot select a legal basis, provide a binding legal opinion or replace the role of the controller, DPO, supervisory authority or court.

    Who should use ISO 27701?

    ISO 27701 is relevant when privacy obligations have become too important to manage through isolated policies and spreadsheets. Typical situations include:

    • a healthtech vendor processing patient data for hospitals or clinics
    • a digital-health platform acting as both controller and processor
    • a company completing recurring enterprise privacy questionnaires
    • a product team launching in several European jurisdictions
    • an organisation handling large-scale health, genetic or biometric data
    • a processor managing multiple sub-processors and international transfers
    • an ISO 27001-certified company that needs stronger privacy assurance
    • a company preparing for customer, investor or certification scrutiny

    What the Privacy Information Management System covers

    Governance and accountability

    • PIMS scope, context and interested parties
    • Controller, joint-controller and processor roles
    • Privacy responsibilities and escalation routes
    • Privacy objectives and management reporting
    • Records of processing activities
    • Applicable legal, regulatory and contractual requirements
    • Privacy risk and opportunity management
    • Internal audit, management review and continual improvement

    Operational privacy controls

    • Privacy by design and default
    • DPIA and high-risk processing workflow
    • Data-subject rights and request handling
    • Privacy notices and transparency controls
    • Retention, deletion and data minimisation
    • Processor, sub-processor and supplier governance
    • International-transfer governance
    • Personal-data breach assessment and response

    The system is tailored to the organisation’s actual role and processing. Controller and processor responsibilities should not be copied into one generic checklist because the obligations, evidence and decision authority differ.

    Health data requires more than a security control

    Under the GDPR, data concerning health is special-category personal data. A controller generally needs both a lawful basis under Article 6 and an applicable condition under Article 9. The correct condition depends on the purpose, parties and relevant EU or national law.

    Consent is therefore not the automatic answer for every health-data use. Treatment, public interest, research, employment, insurance and digital-health services may rely on different legal routes and safeguards.

    ISO 27701 helps ensure that the selected position is documented, approved, reflected in product and supplier controls and reviewed when processing changes. Formal interpretation of the legal basis remains with the client’s DPO or legal adviser.

    How Asteron builds the PIMS

    1. Scope and privacy-role baseline

      Define the organisations, products, processing activities and markets covered by the PIMS. Confirm where the company acts as controller, processor or joint controller.

    2. Data and obligation mapping

      Connect processing records, data categories, purposes, systems, recipients, suppliers, transfers, retention and individual rights to accountable owners and applicable requirements.

    3. Privacy-risk and gap assessment

      Assess risks to individuals and gaps in governance, product processes, supplier controls and evidence. Prioritise work according to actual exposure rather than document count.

    4. PIMS implementation

      Build the required policies, procedures, registers, decision workflows and review cadence. Reuse compatible ISO 27001 governance and controls where an existing Compliance Core is available.

    5. Operation and evidence

      Run the key workflows, complete representative reviews, resolve priority gaps and collect evidence that the PIMS operates beyond its written documentation.

    6. Internal audit and certification readiness

      Complete internal audit, management review and corrective actions. Coordinate the independent certification body and prepare process owners for the external audit.

    What Asteron delivers

    The precise deliverables depend on the agreed scope and existing system maturity. Asteron builds the operational framework and supporting evidence; the client’s legal advisers remain responsible for formal legal opinions and jurisdiction-specific interpretations.

    Management-system foundation

    • ISO/IEC 27701:2025 scope and implementation plan
    • PIMS process and responsibility map
    • Controller and processor role mapping
    • Privacy-risk methodology and register
    • Privacy objectives and reporting cadence
    • Integrated policy and procedure set
    • Internal-audit programme
    • Management-review preparation

    Operational privacy evidence

    • Processing-activity structure
    • DPIA and privacy-by-design workflow
    • Data-subject request process
    • Privacy-notice governance
    • Supplier and sub-processor review process
    • Transfer and retention decision workflows
    • Personal-data breach assessment process
    • Certification evidence and audit preparation

    Netherlands, Germany and wider European operations

    GDPR provides the shared European foundation, but health-data processing is also affected by national law, sector rules and supervisory practice.

    For the Netherlands, healthtech companies may need to account for the Dutch GDPR Implementation Act, medical confidentiality and care-sector requirements, Autoriteit Persoonsgegevens guidance and NEN 7510 where health information is processed within the Dutch healthcare ecosystem.

    For Germany, privacy governance may also need to reflect the Federal Data Protection Act, state-level rules, medical confidentiality, social-data requirements and the expectations of the relevant German supervisory authority.

    ISO 27701 creates one controlled privacy-management system across the organisation. Dutch, German and other national requirements should be added as traceable jurisdictional obligations rather than maintained in separate and conflicting privacy programmes.

    ISO 27701 pricing

    From an existing Compliance Core
    €9,900

    This route reuses established governance, risk, audit, evidence and continual-improvement processes. The work focuses on the privacy-specific scope, controller and processor requirements, operational workflows and certification evidence.

    As the first Asteron framework project
    €27,900

    This route establishes the required management-system foundation alongside the ISO 27701 privacy requirements. It is intended for organisations without a sufficiently mature Compliance Core to reuse.

    These published starting prices apply to the initial 10–50 employee band shown on the Pricing page. Larger organisations, multiple legal entities, complex controller/processor models or unusually broad product scopes are priced using the applicable company-size and complexity band.

    The existing-Core route saves €18,000 because security governance, risk, audit and operating processes can be reused rather than rebuilt.

    Payment terms (fixed-scope)
    • 40% at signing
    • 40% when the agreed audit-ready milestone is reached
    • 20% after certification

    Prices exclude VAT where applicable.

    View full pricing

    Independent certification audit

    Asteron builds the PIMS, prepares the evidence, coordinates the audit schedule and supports the organisation through certification. Asteron cannot issue the ISO 27701 certificate or act as the independent certification body because that would create a conflict of interest.

    The client selects, contracts and pays the certification body directly. The audit payment never passes through Asteron.

    Indicative external certification-body fees
    • €4,500–€6,000 for organisations with 10–50 employees
    • €6,000–€9,000 for organisations with 51–150 employees

    The certification body confirms its own quotation based on scope, headcount, locations, audit duration and certification model. Organisations should also confirm that the selected body can audit the applicable ISO/IEC 27701:2025 scope.

    For a fixed-scope engagement, if the agreed certification outcome is not reached because an Asteron deliverable is incomplete or deficient, Asteron corrects that work at no additional professional fee within the contracted scope. This does not control or override the independent auditor’s judgement and does not cover new scope, legal changes or client-side implementation failures.

    Responsibilities and boundaries

    Asteron

    • Designs and implements the agreed PIMS
    • Integrates privacy with existing security governance
    • Structures operational workflows and evidence
    • Trains process owners for their assigned responsibilities
    • Performs internal readiness activities
    • Coordinates certification preparation and findings

    Your organisation

    • Determines processing purposes and means where acting as controller
    • Provides accurate information about data, systems and suppliers
    • Selects legal bases and Article 9 conditions with legal or DPO input
    • Assigns responsible owners and approves decisions
    • Implements required product and technical changes
    • Operates the PIMS after implementation
    • Contracts and pays the independent certification body

    Frequently asked questions

    What is ISO/IEC 27701?

    ISO/IEC 27701 is an international standard for establishing, implementing, maintaining and continually improving a Privacy Information Management System.

    What changed in ISO/IEC 27701:2025?

    The 2025 edition became a standalone management-system standard. It can be implemented and certified without ISO 27001, while remaining closely aligned with ISO 27001 for organisations that want an integrated system.

    Is ISO 27701 certification the same as GDPR compliance?

    No. ISO 27701 helps manage privacy responsibilities and demonstrate accountability, but GDPR compliance depends on the lawfulness and operation of each processing activity.

    Do we need ISO 27001 first?

    No. ISO 27701:2025 can stand alone. An existing ISO 27001-based Compliance Core can nevertheless reduce cost and duplicated implementation work substantially.

    What is the difference between a controller and a processor?

    A controller determines why and how personal data is processed. A processor handles personal data on the controller’s documented instructions. One company may hold different roles for different processing activities.

    Does ISO 27701 cover health data?

    It can govern processing of health data, but it does not itself provide the Article 6 legal basis or Article 9 condition required under the GDPR.

    Does ISO 27701 include a DPIA?

    It establishes the governance and workflow for privacy-risk assessment and DPIAs. Individual DPIAs included in the project depend on the agreed scope.

    What if we already hold ISO 27701:2019 certification?

    The 2025 edition supersedes the 2019 edition. The organisation should confirm the applicable transition arrangements with its certification body and plan the required PIMS changes.

    How long does implementation take?

    Timing depends on scope, existing ISO 27001 maturity, number of processing activities, supplier complexity and availability of process owners. Asteron confirms the plan after the initial assessment.

    How much does ISO 27701 cost?

    For the initial published company-size band, implementation starts at €9,900 from an existing Asteron Compliance Core or €27,900 as the first framework project. External certification-body fees are separate.

    Who issues the certificate?

    An independent certification body issues the certificate. Asteron prepares the system and evidence but cannot independently certify its own implementation work.

    Official references

    • – ISO/IEC 27701:2025 — ISO
    • – ISO/IEC 27706:2025 — ISO
    • – Regulation (EU) 2016/679 — EUR-Lex
    • – European Data Protection Board guidance for controllers and processors
    • – European Data Protection Board guidance on privacy by design and DPIAs
    • – Autoriteit Persoonsgegevens
    • – German federal and state data-protection authorities

    Last reviewed: July 2026

    Asteron is not endorsed by or partnered with ISO, IEC, the European Commission, any supervisory authority or certification body.

    Make privacy accountability part of everyday operations

    We will assess your privacy roles, processing landscape, existing security system and target markets, then define the practical route to ISO 27701:2025 certification readiness.

    View ISO 27701 pricing