The ISO 27701 standard was published on August 6, 2019 (5 months ahead of schedule). This is the first international privacy standard – known as a Privacy Information Management System (PIMS) – to govern secure handling of personally identifiable information (PII). This standard was issued as an extension of ISO IEC 27001:2013. That means ISO IEC 27701 has to be used in conjunction with ISO IEC 27001.
This is worth mentioning that ISO IEC 27701 is the first ISO standard that has provided reference to a non ISO standard e.g. General Data Protection Regulation (GDPR) of the European Union.
Since May of 2018, blockbuster penalties have been imposed on companies like Google, Marriott, and British Airways for GDPR violations. There is no certification scheme available to provide confidence to the organizations and their customers that their personal information is handled in compliance with GDPR requirements.
ISO 27701 addresses all the articles of GDPR (except article 43, which is for the certification bodies). Certification to ISO 27701 is the best possible option available to the organizations looking for a GDPR certification.