Menu

Using ISO 27701 for One US State Privacy Program

Using ISO 27701 for One US State Privacy Program

US businesses operating across multiple states face an increasingly complex privacy landscape. California, Virginia, Colorado, Connecticut, Texas, Oregon, and other states have introduced privacy laws that establish requirements for personal data collection, processing, consumer rights, transparency, and organizational accountability. Although these laws share common principles, their specific obligations differ.

ISO 27701 provides a structured framework for establishing one privacy management program across multiple US state privacy laws. Organizations can use it to establish privacy governance, manage personal information, assign responsibilities, and address privacy risks through consistent business processes. This approach can reduce unnecessary duplication while creating a common foundation for managing applicable legal requirements.

However, ISO 27701 certification does not guarantee compliance with every US state privacy law. Organizations must determine which laws apply to their activities and incorporate the specific requirements of each relevant jurisdiction into their privacy management system.

Advance Privacy Management With ISO/IEC 27701:2025. Strengthen Privacy Accountability With INTERCERT Certification.

Why US State Privacy Laws Call for a Single Privacy Program

The Growing Patchwork of US State Privacy Laws

The United States does not have one comprehensive federal consumer privacy law covering all commercial activities and personal information. Instead, organizations must consider applicable federal requirements, state privacy statutes, sector-specific regulations, and other legal obligations relevant to their operations.

California's Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), establishes requirements concerning consumer rights, transparency, and the collection, use, and sharing of personal information. Virginia's Consumer Data Protection Act, Colorado's Privacy Act, Connecticut's Data Privacy Act, and Texas's Data Privacy and Security Act establish their own requirements for covered organizations.

These laws share several principles, including transparency, consumer control over personal data, and accountability for certain processing activities. However, they differ in applicability thresholds, definitions, exemptions, response deadlines, consent requirements, opt-out mechanisms, and enforcement provisions.

For example, a business may need to respond to a consumer access request, process a deletion request, or provide an opt-out mechanism while following different statutory conditions depending on the applicable jurisdiction. Some laws also impose additional obligations for sensitive personal data, targeted advertising, profiling, and data protection assessments.

Managing these differences through completely separate privacy programs can create unnecessary complexity. A unified privacy program built around ISO 27701 can establish common processes while preserving the legal distinctions that matter.

Cost and Risk of Running Separate Programs Per State

Maintaining separate privacy programs for every state can lead to duplicated policies, inconsistent procedures, fragmented data inventories, and unclear accountability. Different departments may maintain separate records for the same personal information, even when they are addressing similar privacy obligations.

This fragmentation can make it difficult to determine what personal information the organization collects, why it is processed, where it is stored, which vendors receive it, and how consumer requests are handled. It can also increase the effort required to update policies when a state introduces new requirements or amends existing legislation.

A unified privacy program establishes shared governance, common operating procedures, and consistent recordkeeping. Instead of creating a completely separate management system for each jurisdiction, organizations can maintain one central privacy framework with specific rules for the laws that apply.

This approach can reduce administrative duplication, improve visibility into privacy risks, and establish clearer accountability across business functions. The organization must still evaluate whether individual state requirements call for additional controls, disclosures, contractual provisions, or technical measures.

What a Unified Privacy Program Looks Like

A unified privacy program establishes common privacy policies, assigns responsibilities, maintains records of personal information processing, and defines how privacy risks are identified and managed. It also establishes processes for handling consumer requests, reviewing vendors, updating privacy notices, and monitoring relevant legal changes.

For example, an organization can maintain one central process for receiving and tracking consumer privacy requests. The process can then apply the appropriate verification requirements, response deadlines, appeal procedures, and statutory exceptions according to the applicable state law.

Similarly, a shared data inventory can record the categories of personal information collected, processing purposes, data recipients, and retention practices. Additional rules can identify when a particular jurisdiction requires a specific disclosure, consent mechanism, or data protection assessment.

The objective is to establish one consistent privacy management structure without treating every state law as identical. ISO 27701 provides the management system foundation, while the organization's legal obligations determine the additional requirements that must be addressed.

What Is ISO 27701?

ISO 27701 as a Privacy Information Management System

ISO/IEC 27701 is an international standard for a Privacy Information Management System (PIMS). It establishes requirements for creating, operating, maintaining, and continually improving a management system focused on privacy information and associated risks.

The standard addresses privacy management responsibilities for organizations that process personally identifiable information (PII), including organizations acting as PII controllers and PII processors. It establishes a structured approach to privacy governance, accountability, risk management, and the handling of personal information.

For US businesses, ISO 27701 can provide a common foundation for managing privacy activities across several states. Rather than treating privacy as a collection of independent legal tasks, organizations can incorporate privacy responsibilities into their business processes, operational controls, and management oversight.

ISO/IEC 27701:2025 is the third edition of the standard, published in October 2025. It introduced a standalone management system standard rather than the extension-based structure used in the 2019 edition.

Organizations pursuing certification should identify the applicable edition and confirm the relevant certification arrangements with their chosen certification body.

How ISO 27701 Relates to ISO 27001

ISO/IEC 27001 specifies requirements for an Information Security Management System (ISMS), with a focus on managing information security risks and protecting information's confidentiality, integrity, and availability. ISO/IEC 27701 focuses on privacy information management and the risks associated with processing personally identifiable information.

Information security and privacy are closely connected, but they are not interchangeable. Security controls can protect personal information from unauthorized access, alteration, disclosure, or loss. Privacy management also considers the purposes of processing, appropriate use and sharing, retention, transparency, and the handling of applicable privacy rights.

The 2019 edition of ISO 27701 was designed as an extension to ISO 27001 and ISO 27002. The 2025 edition establishes ISO 27701 as a standalone management system standard, changing how organizations can approach the relationship between privacy and information security management systems.

Organizations already certified to ISO 27001 can coordinate relevant security processes with their privacy management activities where appropriate. Businesses considering ISO 27701 should confirm the applicable edition, certification scope, and any relevant transition arrangements before planning their certification activities.

Why ISO 27701 Works as a Privacy Baseline

ISO 27701 establishes a repeatable structure for managing privacy responsibilities, processing activities, and privacy risks. These management practices can overlap with the organizational and operational expectations found in US state privacy laws.

For example, documented privacy responsibilities can establish ownership of personal information, clarify processing activities, and define how privacy risks are reviewed. These arrangements can form the foundation for managing consumer requests, maintaining transparency, reviewing vendors, and addressing applicable data protection obligations.

The standard also provides a framework for integrating privacy management into organizational processes. This can be valuable for businesses that collect information through websites, mobile applications, digital platforms, customer relationship management systems, and third-party services.

However, ISO 27701 and state privacy laws serve different purposes. The standard establishes management system requirements, while state statutes determine the legal obligations that apply to particular organizations and processing activities. A company must therefore combine ISO 27701 with a current evaluation of applicable legal requirements rather than treating certification as a substitute for legal compliance.

Common Requirements Across US State Privacy Laws

Several US state privacy laws address similar privacy principles, including consumer rights, transparency, controller and processor responsibilities, and the protection of sensitive personal information. ISO 27701 can provide a common management structure for these areas, while jurisdiction-specific procedures address differences between the laws.

Consumer Rights and Request Handling

Many comprehensive state privacy laws provide consumers with rights concerning their personal data. Depending on the applicable statute, these rights can include accessing personal information, correcting inaccuracies, requesting deletion, obtaining a portable copy of data, and opting out of certain processing activities.

California's CCPA establishes rights concerning access, deletion, correction, and opting out of the sale or sharing of personal information, subject to applicable statutory conditions. Other states provide similar rights but differ in their precise scope, exceptions, verification requirements, and response procedures.

A unified privacy program can establish one central process for receiving, recording, verifying, assigning, and tracking consumer requests. It can also establish accountability for ensuring that requests are handled within the applicable legal deadlines.

The process must account for jurisdiction-specific requirements. Organizations may need different procedures for verifying a consumer's identity, handling authorized agents, processing appeals, recognizing opt-out preference signals, or applying statutory exceptions.

ISO 27701 can provide the management structure for these activities, but organizations must determine the exact requirements imposed by each applicable state law.

Controller and Processor Obligations

US state privacy laws commonly distinguish between controllers and processors. A controller generally determines the purposes and means of processing personal data, while a processor processes personal data on behalf of a controller.

The distinction affects how privacy responsibilities are allocated. Controllers may be responsible for providing privacy notices, managing consumer rights, evaluating certain processing risks, and meeting applicable consent or opt-out requirements. Processors may have obligations relating to authorized processing, confidentiality, security, contractual terms, and cooperation with the controller.

ISO 27701 can establish clearer privacy responsibilities, maintain records of processing activities, and create consistent processes for managing third-party relationships. Organizations can use these arrangements to document their roles and identify which responsibilities apply to each processing activity.

Contracts should reflect the applicable state laws and the actual relationship between the parties. A business should not assume that identifying itself as a processor in a contract automatically determines its legal status under every state statute.

Data Protection Assessments

Certain state privacy laws require organizations to conduct data protection assessments for processing activities that present heightened risks to consumers. These activities may include targeted advertising, specified profiling, processing sensitive personal data, or selling personal data, depending on the applicable law.

Colorado's Privacy Act establishes assessment requirements for specified high-risk processing activities. California also has regulations addressing risk assessments for certain covered businesses and processing activities.

An ISO 27701-based privacy program can establish a consistent process for identifying privacy risks, recording decisions, assigning responsibility, and monitoring risk treatment. These processes can provide a foundation for meeting applicable assessment obligations.

However, a general privacy risk assessment should not automatically be treated as satisfying every statutory data protection assessment requirement. Organizations must determine the activities that trigger an assessment, the information it must contain, applicable review requirements, and any relevant retention or regulatory disclosure obligations.

Sensitive Data and Consent Requirements

Sensitive personal information may include health information, precise geolocation, biometric information, racial or ethnic origin, and other categories defined by the applicable law. The precise definition and associated obligations vary by state.

Some state privacy laws require consent before processing sensitive data within their scope. Other laws establish additional consumer rights or restrictions concerning particular uses and disclosures of sensitive personal information.

A unified privacy program should identify sensitive information across relevant systems, establish appropriate access controls, document processing purposes, and determine when consent or another legally recognized condition is required.

Organizations should also establish procedures for managing consent withdrawal, privacy preferences, retention, and other applicable requirements. ISO 27701 can provide the management framework for these activities, but the specific legal conditions must determine how personal information is processed.

Transparency and Privacy Notices

Transparency is a recurring requirement across US state privacy laws. Depending on the applicable statute, organizations may need to disclose the categories of personal information collected, the purposes of processing, categories of recipients, consumer rights, and methods for exercising those rights.

A unified privacy program can establish ownership of privacy notices, define review procedures, and maintain records of the information used to prepare disclosures. These processes can create consistency across websites, applications, and other customer-facing channels.

However, one generic privacy notice may not satisfy every jurisdiction's requirements. Organizations should determine whether additional disclosures, opt-out links, appeal instructions, or state-specific wording are necessary.

Changes to products, vendors, tracking technologies, and data processing activities should trigger a review of relevant privacy notices. This helps maintain consistency between what an organization communicates and how it actually processes personal information.

Mapping ISO 27701 Controls to US State Law Requirements

Mapping ISO 27701 to US state privacy laws involves identifying the applicable legal obligations and determining how the organization's privacy management system addresses them. The process should distinguish between requirements already covered by existing controls and obligations that require additional procedures or technical measures.

Organizations should consider their business activities, personal information processing, customer locations, vendor relationships, and statutory exemptions when determining which requirements apply. The mapping should also identify the evidence needed to demonstrate that relevant controls operate as intended.

Controller Controls and State Law Obligations

Organizations acting as controllers generally determine why and how personal information is processed. Depending on the applicable law, their responsibilities may include providing privacy notices, responding to consumer requests, managing sensitive data, applying data minimization principles, and evaluating certain processing risks.

An ISO 27701-based privacy program can establish documented responsibilities, maintain processing records, and create consistent processes for managing privacy risks. These arrangements can be mapped to relevant controller obligations under applicable state privacy laws.

For example, a centralized data inventory can record the categories of personal information collected, processing purposes, data recipients, and retention practices. The organization can use these records when reviewing privacy notices, identifying sensitive information, evaluating risks, and determining whether particular processing activities require additional controls.

The mapping must also identify legal obligations that require measures beyond the standard. A state may prescribe a specific opt-out mechanism, a particular disclosure, or a defined response deadline that needs a separate operational procedure.

Processor Controls and Contractual Obligations

Organizations acting as processors must understand their contractual and statutory responsibilities for personal information handled on behalf of customers. Depending on the applicable law, these responsibilities may include following authorized instructions, maintaining confidentiality, applying appropriate security measures, and meeting specified contractual requirements.

ISO 27701 can establish a consistent approach to privacy responsibilities, processing records, third-party relationships, and privacy risk management. Organizations can use these processes to review vendor arrangements and determine whether contractual obligations reflect the actual processing relationship.

Contracts may need to address authorized processing purposes, confidentiality, security, subcontractor arrangements, incident notification, deletion or return of personal information, and cooperation with consumer rights requests where required.

Organizations should not assume that a single contract template satisfies every state law. Contractual provisions must reflect the applicable jurisdiction, the nature of the processing activity, and the obligations imposed on each party.

Where State-Specific Differences Remain

ISO 27701 provides a common privacy management framework, but it does not remove differences between US state privacy laws. Organizations must maintain a current record of applicable legal requirements and determine where additional controls or procedures are necessary.

For consumer requests, a centralized process can manage intake and tracking while applying the correct verification requirements, response deadlines, appeal procedures, and statutory exceptions. Privacy notices can follow a common review process while incorporating additional disclosures or opt-out mechanisms required by particular states.

Sensitive personal information requires separate consideration because states differ in their definitions, consent requirements, and restrictions on processing. Organizations should identify the relevant data categories and apply the legal conditions that govern each activity.

Data protection assessments also require jurisdiction-specific consideration. A general privacy risk assessment should not automatically be treated as satisfying every statutory assessment obligation. Organizations must evaluate the activities that trigger assessments, the required assessment content, and applicable retention or disclosure requirements.

Vendor management presents similar considerations. Organizations can establish consistent third-party oversight while ensuring that contracts reflect the applicable requirements for processing instructions, confidentiality, security, subcontractors, and consumer rights requests.

Maintaining a current legal obligations register and mapping each requirement to relevant policies, procedures, and controls allows organizations to manage these differences within one privacy management system. This makes ISO 27701 a practical baseline for multi-state privacy compliance without assuming that certification guarantees compliance with every applicable law.

Building One Privacy Program Around ISO 27701

A unified privacy program should connect governance, operational procedures, records, technology, and legal obligations. Its scope should reflect the organization's actual processing activities and the laws that apply to those activities.

Setting the Scope and Privacy Governance Structure

Organizations should begin by identifying the business units, products, services, systems, locations, and processing activities covered by the privacy management system. The scope should include relevant personal information collected directly from consumers and information received from customers, partners, vendors, or other third parties.

The organization should then determine which US state privacy laws may apply. This requires considering business activities, consumer locations, applicable processing or revenue thresholds, statutory exemptions, and the types of personal information involved.

Privacy governance should establish executive accountability, define decision-making authority, and assign responsibility for monitoring legal developments. Legal, privacy, information security, procurement, product, marketing, and customer service teams may each have responsibilities within the program.

Clear governance ensures that privacy decisions are not limited to one department and that changes in business operations are evaluated for their potential effect on privacy obligations.

Defining Roles: Controller, Processor, and Joint Responsibilities

Organizations should identify their role for each relevant processing activity. A company may act as a controller when collecting information through its own website but act as a processor when handling customer information under contractual instructions.

Role classification should reflect the actual processing relationship and the definitions established by the applicable law. Contractual labels alone do not determine a party's legal role.

A responsibility matrix can establish who maintains processing records, manages consumer requests, reviews vendors, handles privacy incidents, evaluates risks, and updates privacy notices. Where responsibilities are shared, the organization should define ownership, escalation procedures, and decision-making authority.

This structure reduces ambiguity when a request, incident, vendor change, or new product affects multiple departments or jurisdictions.

Aligning Policies, Records, and Risk Treatment

A unified privacy program should maintain consistent records of personal information, processing purposes, data recipients, retention practices, and relevant privacy risks. These records should be sufficiently detailed to inform business decisions and demonstrate how the privacy management system operates.

Policies must translate into operational procedures. For example, a retention policy should correspond with actual system deletion practices, while a consumer request procedure should specify how requests are received, verified, assigned, completed, and recorded.

Risk treatment should address identified privacy risks through appropriate organizational and technical measures. Depending on the processing activity, these measures may include access restrictions, encryption, data minimization, retention controls, vendor safeguards, and changes to product design.

Organizations should periodically evaluate whether these measures remain appropriate as business activities, technologies, and legal obligations change.

Managing Variations Across States Within One Framework

Organizations should maintain shared privacy processes alongside a current legal obligations register. This register should identify applicable laws, relevant provisions, accountable owners, required actions, and evidence demonstrating how obligations are addressed.

For example, a centralized consumer request system can apply different deadlines, appeal procedures, and exceptions according to the relevant jurisdiction. A common data inventory can inform several privacy processes while separate rules identify when particular assessments or disclosures are required.

Organizations should monitor new legislation, amendments, regulatory developments, and enforcement activity. Relevant changes should be evaluated for their effect on existing controls, contracts, notices, systems, and employee responsibilities.

This approach allows businesses to maintain one privacy management structure without assuming that every state follows identical rules.

ISO 27701 Certification as Evidence of Privacy Accountability

ISO 27701 certification provides independent evidence that a privacy information management system has been audited against the applicable requirements of the standard within a defined scope. It can demonstrate that an organization has established formal processes for privacy governance, risk management, and continual improvement.

Certification is not a legal determination that an organization complies with every applicable US state privacy statute. Its relevance depends on the certified scope, the applicable edition of ISO 27701, the organization's processing activities, and the legal obligations that apply to those activities.

Role of an Independent Certification Body

An independent certification body evaluates whether an organization's privacy management system conforms to the applicable requirements of the relevant standard within the agreed certification scope. The audit examines documented arrangements and evidence that the system operates as required.

Organizations seeking ISO 27701 certification should consider the certification body's competence, impartiality, applicable accreditation status, and scope of certification services. These factors are relevant when selecting a certification body that can evaluate the organization's privacy management system.

An independent certification audit is distinct from legal advice or a jurisdiction-by-jurisdiction legal determination. Organizations remain responsible for identifying applicable laws and meeting their statutory obligations.

ISO 27701 Certification Audit Stages

The certification process generally involves defining the proposed scope, evaluating the management system against the applicable standard, examining evidence of its operation, and addressing any nonconformities identified during the audit.

Depending on the applicable certification arrangements, the process may include reviewing documented information, examining operational evidence, interviewing relevant personnel, and evaluating privacy controls within the certification scope.

Organizations pursuing certification to ISO/IEC 27701:2025 should confirm the applicable requirements and audit arrangements with their chosen certification body. Businesses transitioning from the 2019 edition should also verify the relevant transition provisions and deadlines rather than assuming that previous arrangements remain unchanged.

Maintaining Certification Through Surveillance Audits

Maintaining certification requires continued conformity with the applicable certification requirements. Surveillance audits and subsequent recertification activities take place according to the relevant certification programme to evaluate whether the management system continues to meet the standard.

Organizations should maintain accurate records, monitor privacy risks, review changes in processing activities, address audit findings, and evaluate the effectiveness of corrective actions.

Changes to organizational structure, processing scope, technology, vendors, and applicable laws may affect the privacy management system. These changes should be reviewed to determine whether additional controls or modifications to the certified scope are necessary.

Business Benefits of an ISO 27701-Based Privacy Program

A unified privacy management system can establish more consistent privacy practices across departments, business units, and customer relationships. Its value depends on how effectively the organization integrates the system into daily operations and maintains it as business activities and legal obligations evolve.

Stronger Trust with Enterprise Customers and Partners

Enterprise customers increasingly examine how vendors collect, use, retain, and protect personal information. A documented privacy management system and an appropriately scoped ISO 27701 certificate can provide evidence of structured privacy governance and independent assessment.

This can be relevant to procurement reviews, vendor risk evaluations, contractual discussions, and business relationships involving personal information. However, customers may still require separate questionnaires, contractual commitments, regulatory evidence, or additional assessments according to their requirements.

Organizations should describe their certification accurately, including the applicable standard edition and scope. Certification should not be presented as proof of compliance with every privacy law or as a guarantee that privacy incidents cannot occur.

Reduced Duplication Across Multi-State Compliance Efforts

A shared privacy management framework can reduce duplicated work by establishing common records, policies, risk management activities, and accountability arrangements. Teams can use the same core privacy inventory and governance structure for multiple legal obligations where requirements overlap.

For example, one processing inventory can inform vendor oversight, privacy notice reviews, retention decisions, and risk evaluations. A common request management platform can also reduce administrative duplication while applying different legal rules where required.

Organizations can measure performance through indicators such as request completion times, overdue actions, vendor review status, privacy incident trends, policy review completion, and the closure of identified nonconformities. These measures provide insight into the consistency and operational effectiveness of the privacy program.

Readiness for New and Amended State Privacy Laws

US state privacy laws continue to evolve through legislative amendments, regulatory activity, and enforcement developments. Organizations operating across multiple states should maintain a process for identifying relevant changes and evaluating their impact on existing privacy practices.

An ISO 27701-based program can establish clear ownership for legal change monitoring, risk reviews, policy updates, and management oversight. When a new obligation becomes applicable, the organization can evaluate it against existing controls and determine whether additional procedures, contractual changes, disclosures, or technical measures are necessary.

The benefit comes from having a repeatable management process, not from assuming that certification automatically covers future legal requirements.

Common Challenges When Using ISO 27701 for US State Privacy Compliance

One of the main challenges is the difference between a management system standard and a legal compliance obligation. ISO 27701 establishes requirements for privacy information management, but state laws determine the specific rights, duties, exemptions, and enforcement provisions that apply to an organization.

Another challenge is determining which laws apply. Applicability may depend on the nature of the business, the information processed, consumer locations, processing thresholds, revenue criteria, and statutory exemptions. Organizations should not assume that every state privacy law applies to every business operating nationally.

Maintaining accurate data inventories can also be difficult. Personal information may be spread across customer relationship management systems, websites, mobile applications, cloud platforms, marketing tools, human resources systems, and external service providers. Incomplete inventories can affect privacy notices, retention controls, consumer request handling, and risk evaluations.

Vendor relationships create additional complexity. Organizations must distinguish between controller and processor activities, review contractual requirements, and maintain appropriate oversight of third parties that process personal information. A vendor's certification does not automatically remove the customer's own legal responsibilities.

Finally, legal requirements change over time. Organizations need a reliable method for monitoring relevant amendments, evaluating their effects, updating procedures, and retaining evidence of decisions. Legal review may be necessary when obligations are unclear or when processing activities raise complex questions about applicability.

A successful unified privacy program therefore combines ISO 27701-based governance with a current legal obligations register, operational controls, clear ownership, and periodic review of applicable laws.

Elevate Your Privacy Management With ISO/IEC 27701:2025. Demonstrate Privacy Accountability Through INTERCERT Certification.

Next Steps for Organizations Adopting ISO 27701

Organizations considering ISO 27701 for multi-state privacy compliance should begin by identifying the personal information they process and the purposes for which it is used. They should establish which business units, systems, vendors, and processing activities fall within the intended privacy management system scope.

The next step is to determine which US state privacy laws and other applicable requirements affect those activities. This evaluation should consider statutory applicability criteria, exemptions, consumer rights, notice requirements, contractual duties, data protection assessment obligations, and rules concerning sensitive personal information.

Organizations can then map these obligations to their privacy management processes, identify areas where additional controls are necessary, assign responsibilities, and establish measurable performance indicators. Existing information security and risk management processes can be coordinated with the privacy program where appropriate.

Before pursuing certification, organizations should confirm the applicable ISO 27701 edition, define the certification scope, evaluate the relevant standard requirements, and establish the evidence needed to demonstrate that the privacy management system operates as intended.

INTERCERT provides independent certification and audit services for organizations seeking to demonstrate conformity with applicable management system standards. Organizations considering ISO 27701 certification can discuss the relevant standard edition, certification scope, and audit arrangements with INTERCERT.

A unified privacy program based on ISO 27701 can establish a consistent foundation for managing privacy across US states. Its effectiveness depends on combining that foundation with accurate legal mapping, operational accountability, and ongoing attention to jurisdiction-specific requirements.

Frequently Asked Questions

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved