ISO 27701 privacy management for European healthtech
Asteron builds the privacy information management system that turns GDPR obligations into controlled, repeatable operations. We connect privacy roles, processing records, risk assessments, data-subject rights, suppliers, transfers and breach workflows within one auditable system. The service uses ISO/IEC 27701:2025 and is designed for healthtech companies operating as controllers, processors or both across the Netherlands, Germany and the wider European market.
- ISO/IEC 27701:2025 PIMS implemented
- Controller and processor duties mapped
- GDPR and health-data operations connected
- Independent certification readiness prepared
From €9,900 with an existing Compliance Core
What is ISO/IEC 27701:2025?
ISO/IEC 27701 is the international management-system standard for establishing, operating and continually improving a Privacy Information Management System, or PIMS. It helps organisations assign privacy responsibilities, understand how personal information is processed, manage privacy risks and maintain evidence that decisions are followed in practice.
The 2025 edition is a standalone management-system standard. An organisation can implement and certify it without first holding ISO 27001 certification. It remains closely aligned with ISO 27001, however, so existing information-security governance, risk management, internal audit and continual-improvement processes can be reused.
ISO 27701 does not declare an organisation “GDPR compliant.” It creates the operating system and evidence needed to manage privacy obligations consistently and demonstrate accountability.
Why privacy management matters in healthtech
European healthtech companies rarely have one simple privacy role. A company may act as a processor for a hospital, a controller for its own users and employees, and a joint controller within a research or care partnership.
The same product may process identifiers, clinical observations, diagnostic information, device data, behavioural information and support records across several suppliers and countries. Without a functioning management system, legal analyses, contracts, product decisions and technical controls quickly drift apart.
ISO 27701 gives privacy work an operational structure. It connects the data inventory to responsible owners, legal and contractual requirements, product changes, supplier decisions, security controls, incidents and management review.
ISO 27701, ISO 27001 and GDPR answer different questions
An ISO 27701 system can organise and evidence GDPR-related work, but it cannot select a legal basis, provide a binding legal opinion or replace the role of the controller, DPO, supervisory authority or court.
Who should use ISO 27701?
ISO 27701 is relevant when privacy obligations have become too important to manage through isolated policies and spreadsheets. Typical situations include:
- – a healthtech vendor processing patient data for hospitals or clinics
- – a digital-health platform acting as both controller and processor
- – a company completing recurring enterprise privacy questionnaires
- – a product team launching in several European jurisdictions
- – an organisation handling large-scale health, genetic or biometric data
- – a processor managing multiple sub-processors and international transfers
- – an ISO 27001-certified company that needs stronger privacy assurance
- – a company preparing for customer, investor or certification scrutiny
What the Privacy Information Management System covers
Governance and accountability
- – PIMS scope, context and interested parties
- – Controller, joint-controller and processor roles
- – Privacy responsibilities and escalation routes
- – Privacy objectives and management reporting
- – Records of processing activities
- – Applicable legal, regulatory and contractual requirements
- – Privacy risk and opportunity management
- – Internal audit, management review and continual improvement
Operational privacy controls
- – Privacy by design and default
- – DPIA and high-risk processing workflow
- – Data-subject rights and request handling
- – Privacy notices and transparency controls
- – Retention, deletion and data minimisation
- – Processor, sub-processor and supplier governance
- – International-transfer governance
- – Personal-data breach assessment and response
The system is tailored to the organisation’s actual role and processing. Controller and processor responsibilities should not be copied into one generic checklist because the obligations, evidence and decision authority differ.
Health data requires more than a security control
Under the GDPR, data concerning health is special-category personal data. A controller generally needs both a lawful basis under Article 6 and an applicable condition under Article 9. The correct condition depends on the purpose, parties and relevant EU or national law.
Consent is therefore not the automatic answer for every health-data use. Treatment, public interest, research, employment, insurance and digital-health services may rely on different legal routes and safeguards.
ISO 27701 helps ensure that the selected position is documented, approved, reflected in product and supplier controls and reviewed when processing changes. Formal interpretation of the legal basis remains with the client’s DPO or legal adviser.
How Asteron builds the PIMS
Scope and privacy-role baseline
Define the organisations, products, processing activities and markets covered by the PIMS. Confirm where the company acts as controller, processor or joint controller.
Data and obligation mapping
Connect processing records, data categories, purposes, systems, recipients, suppliers, transfers, retention and individual rights to accountable owners and applicable requirements.
Privacy-risk and gap assessment
Assess risks to individuals and gaps in governance, product processes, supplier controls and evidence. Prioritise work according to actual exposure rather than document count.
PIMS implementation
Build the required policies, procedures, registers, decision workflows and review cadence. Reuse compatible ISO 27001 governance and controls where an existing Compliance Core is available.
Operation and evidence
Run the key workflows, complete representative reviews, resolve priority gaps and collect evidence that the PIMS operates beyond its written documentation.
Internal audit and certification readiness
Complete internal audit, management review and corrective actions. Coordinate the independent certification body and prepare process owners for the external audit.
What Asteron delivers
The precise deliverables depend on the agreed scope and existing system maturity. Asteron builds the operational framework and supporting evidence; the client’s legal advisers remain responsible for formal legal opinions and jurisdiction-specific interpretations.
Management-system foundation
- – ISO/IEC 27701:2025 scope and implementation plan
- – PIMS process and responsibility map
- – Controller and processor role mapping
- – Privacy-risk methodology and register
- – Privacy objectives and reporting cadence
- – Integrated policy and procedure set
- – Internal-audit programme
- – Management-review preparation
Operational privacy evidence
- – Processing-activity structure
- – DPIA and privacy-by-design workflow
- – Data-subject request process
- – Privacy-notice governance
- – Supplier and sub-processor review process
- – Transfer and retention decision workflows
- – Personal-data breach assessment process
- – Certification evidence and audit preparation
Netherlands, Germany and wider European operations
GDPR provides the shared European foundation, but health-data processing is also affected by national law, sector rules and supervisory practice.
For the Netherlands, healthtech companies may need to account for the Dutch GDPR Implementation Act, medical confidentiality and care-sector requirements, Autoriteit Persoonsgegevens guidance and NEN 7510 where health information is processed within the Dutch healthcare ecosystem.
For Germany, privacy governance may also need to reflect the Federal Data Protection Act, state-level rules, medical confidentiality, social-data requirements and the expectations of the relevant German supervisory authority.
ISO 27701 creates one controlled privacy-management system across the organisation. Dutch, German and other national requirements should be added as traceable jurisdictional obligations rather than maintained in separate and conflicting privacy programmes.
ISO 27701 pricing
This route reuses established governance, risk, audit, evidence and continual-improvement processes. The work focuses on the privacy-specific scope, controller and processor requirements, operational workflows and certification evidence.
This route establishes the required management-system foundation alongside the ISO 27701 privacy requirements. It is intended for organisations without a sufficiently mature Compliance Core to reuse.
These published starting prices apply to the initial 10–50 employee band shown on the Pricing page. Larger organisations, multiple legal entities, complex controller/processor models or unusually broad product scopes are priced using the applicable company-size and complexity band.
The existing-Core route saves €18,000 because security governance, risk, audit and operating processes can be reused rather than rebuilt.
- – 40% at signing
- – 40% when the agreed audit-ready milestone is reached
- – 20% after certification
Prices exclude VAT where applicable.
Independent certification audit
Asteron builds the PIMS, prepares the evidence, coordinates the audit schedule and supports the organisation through certification. Asteron cannot issue the ISO 27701 certificate or act as the independent certification body because that would create a conflict of interest.
The client selects, contracts and pays the certification body directly. The audit payment never passes through Asteron.
- – €4,500–€6,000 for organisations with 10–50 employees
- – €6,000–€9,000 for organisations with 51–150 employees
The certification body confirms its own quotation based on scope, headcount, locations, audit duration and certification model. Organisations should also confirm that the selected body can audit the applicable ISO/IEC 27701:2025 scope.
Responsibilities and boundaries
Asteron
- – Designs and implements the agreed PIMS
- – Integrates privacy with existing security governance
- – Structures operational workflows and evidence
- – Trains process owners for their assigned responsibilities
- – Performs internal readiness activities
- – Coordinates certification preparation and findings
Your organisation
- – Determines processing purposes and means where acting as controller
- – Provides accurate information about data, systems and suppliers
- – Selects legal bases and Article 9 conditions with legal or DPO input
- – Assigns responsible owners and approves decisions
- – Implements required product and technical changes
- – Operates the PIMS after implementation
- – Contracts and pays the independent certification body
Frequently asked questions
What is ISO/IEC 27701?
ISO/IEC 27701 is an international standard for establishing, implementing, maintaining and continually improving a Privacy Information Management System.
What changed in ISO/IEC 27701:2025?
The 2025 edition became a standalone management-system standard. It can be implemented and certified without ISO 27001, while remaining closely aligned with ISO 27001 for organisations that want an integrated system.
Is ISO 27701 certification the same as GDPR compliance?
No. ISO 27701 helps manage privacy responsibilities and demonstrate accountability, but GDPR compliance depends on the lawfulness and operation of each processing activity.
Do we need ISO 27001 first?
No. ISO 27701:2025 can stand alone. An existing ISO 27001-based Compliance Core can nevertheless reduce cost and duplicated implementation work substantially.
What is the difference between a controller and a processor?
A controller determines why and how personal data is processed. A processor handles personal data on the controller’s documented instructions. One company may hold different roles for different processing activities.
Does ISO 27701 cover health data?
It can govern processing of health data, but it does not itself provide the Article 6 legal basis or Article 9 condition required under the GDPR.
Does ISO 27701 include a DPIA?
It establishes the governance and workflow for privacy-risk assessment and DPIAs. Individual DPIAs included in the project depend on the agreed scope.
What if we already hold ISO 27701:2019 certification?
The 2025 edition supersedes the 2019 edition. The organisation should confirm the applicable transition arrangements with its certification body and plan the required PIMS changes.
How long does implementation take?
Timing depends on scope, existing ISO 27001 maturity, number of processing activities, supplier complexity and availability of process owners. Asteron confirms the plan after the initial assessment.
How much does ISO 27701 cost?
For the initial published company-size band, implementation starts at €9,900 from an existing Asteron Compliance Core or €27,900 as the first framework project. External certification-body fees are separate.
Who issues the certificate?
An independent certification body issues the certificate. Asteron prepares the system and evidence but cannot independently certify its own implementation work.
Official references
- – ISO/IEC 27701:2025 — ISO
- – ISO/IEC 27706:2025 — ISO
- – Regulation (EU) 2016/679 — EUR-Lex
- – European Data Protection Board guidance for controllers and processors
- – European Data Protection Board guidance on privacy by design and DPIAs
- – Autoriteit Persoonsgegevens
- – German federal and state data-protection authorities
Last reviewed: July 2026
Asteron is not endorsed by or partnered with ISO, IEC, the European Commission, any supervisory authority or certification body.
Related services and frameworks
Make privacy accountability part of everyday operations
We will assess your privacy roles, processing landscape, existing security system and target markets, then define the practical route to ISO 27701:2025 certification readiness.
