GDPR is a law; ISO 27001 is a voluntary standard. GDPR governs how organisations handle personal data, backed by fines of up to 4% of annual global turnover or 20 million euros, whichever is higher [1]. ISO 27001 is an international standard for building an information security management system (ISMS), and nobody can fine you for not having one. They solve related but different problems, and in practice most organisations that take either seriously end up needing elements of both.
Scope
UK GDPR (the retained EU regulation, tailored by the Data Protection Act 2018) tells you what you must do with personal data: lawful basis for processing, data subject rights, breach notification within 72 hours, data protection impact assessments, and appointing a Data Protection Officer where required [1]. It applies to every organisation that processes personal data of people in the UK, regardless of where the organisation is based.
ISO/IEC 27001:2022 tells you how to manage information security across your entire organisation [2]. It covers all information, not just personal data: source code, financial records, trade secrets, customer lists, employee files. The standard requires you to assess risks to that information and implement controls to treat those risks, documented in a Statement of Applicability (SoA). A certification body (CB) then audits you against the standard and, if you pass, issues a certificate valid for three years.
The simplest way I explain it to founders: GDPR is the driving law, ISO 27001 is the advanced driving course. You need to obey the law regardless, but the course gives you a structured way to prove you are a competent driver.
Side-by-side comparison
| Dimension | UK GDPR | ISO/IEC 27001:2022 |
|---|---|---|
| What it is | UK law (retained EU regulation) | International voluntary standard |
| Published by | European Parliament / UK Parliament | ISO and IEC (International Electrotechnical Commission) |
| Scope | Personal data of UK/EEA individuals | All information assets in the defined ISMS scope |
| Enforcement | ICO fines up to £17.5m or 4% of global turnover [3] | No legal enforcement; market and contractual pressure |
| Certification | No official GDPR certification scheme in the UK yet | Third-party certification by an accredited CB |
| Breach notification | Mandatory: 72 hours to the ICO, without undue delay to data subjects if high risk [1] | Not mandatory by the standard itself, but Annex A control 5.24 covers incident reporting, and most ISMS policies include breach notification procedures |
| Geographic reach | UK (and EU GDPR for EEA) | International: 96,709 certificates in 130+ countries at end-2024 [4] |
| Ongoing obligations | Continuous compliance; no expiry | 3-year certificate cycle: Stage 1, Stage 2, two surveillance audits, then recertification [2] |
| Cost of non-compliance | Fines, enforcement notices, reputational damage | Loss of certificate, contractual consequences, lost deals |
| Who it applies to | Any organisation processing personal data of UK individuals | Any organisation that chooses to adopt it |
Overlap
The overlap is substantial, and it sits mostly in GDPR Article 32: "security of processing" [1]. Article 32 requires controllers and processors to implement "appropriate technical and organisational measures" to ensure a level of security appropriate to the risk. It explicitly mentions pseudonymisation, encryption, the ability to ensure confidentiality, integrity, availability and resilience, and regular testing of security measures.
That language maps almost directly onto an ISO 27001 ISMS. If you have done a proper risk assessment under Clause 6.1.2, selected controls from Annex A, and can demonstrate they are working through internal audits (Clause 9.2) and management reviews (Clause 9.3), you have built exactly the kind of evidence Article 32 asks for [2].
In my experience, about 70% of the work an organisation does for ISO 27001 also satisfies GDPR's security requirements. The remaining 30% is GDPR-specific: lawful basis documentation, data subject access request procedures, data protection impact assessments, records of processing activities, and the relationship with your Data Protection Officer. An ISMS does not cover those unless you deliberately extend its scope.
ISO 27001 gaps for GDPR
I have audited organisations that assumed their ISO 27001 certificate meant they were GDPR compliant. It does not, and here is why:
- Lawful basis for processing. ISO 27001 does not ask why you process personal data or whether you have consent, legitimate interest, or another lawful basis. That is a GDPR-only requirement under Articles 6 and 9 [1].
- Data subject rights. The right to access, erasure, portability, and objection are not addressed by any Annex A control. You need separate procedures.
- Records of processing activities (ROPA). Article 30 requires a structured register of processing activities. Your ISMS asset register is not the same thing, even if it overlaps.
- Data Protection Impact Assessments. Article 35 requires a DPIA for high-risk processing. ISO 27001's risk assessment methodology is related but not equivalent.
- International data transfers. The rules on transferring personal data outside the UK (adequacy decisions, standard contractual clauses, binding corporate rules) are pure GDPR territory.
GDPR gaps for ISO 27001
The reverse gap is equally real, because GDPR focuses exclusively on personal data. If your crown jewels are proprietary source code, financial models, or intellectual property that does not qualify as personal data, GDPR has nothing to say about protecting them, whereas ISO 27001 covers the lot.
GDPR also has no audit cycle, no structured improvement loop, and no requirement for an independent external assessment, which means you can be GDPR compliant without ever having anyone check. ISO 27001, by contrast, forces the discipline of internal audits, management reviews, and a CB audit at least annually.
ISO 27701: the bridge
ISO/IEC 27701:2019 is a privacy extension to ISO 27001 [5]. It maps privacy controls onto the ISMS framework, adding specific requirements for PII controllers and PII processors. If you already have ISO 27001, bolting on 27701 gives you a structured privacy management system that covers most of what GDPR asks for on the security and privacy-by-design side.
No UK certification body currently issues a standalone "GDPR certificate" (the ICO has not approved any certification scheme under Article 42), but an ISO 27701 certificate is the closest thing the market has to a recognised privacy credential [5]. I expect this to become more common as the ICO develops its certification framework.
Sequencing
If you are a UK tech company selling to enterprise customers, start with ISO 27001. It unblocks sales, and the ISMS you build will cover most of your GDPR Article 32 obligations as a side effect. Then layer in the GDPR-specific elements (ROPA, DPIA process, data subject request procedures) on top.
If you handle large volumes of sensitive personal data (healthtech, fintech, adtech), consider running both in parallel. The risk assessment you do for ISO 27001 Clause 6.1.2 should already be capturing personal data risks, so extending it to cover GDPR-specific scenarios is incremental, not a separate project.
At Calibre, we audit the ISO 27001 side. We cannot advise on your GDPR compliance (that would be an impartiality breach under ISO/IEC 17021-1 [6]), but we see plenty of organisations where the ISMS and the privacy programme are maintained as one integrated system, and that is usually the sensible approach.
FAQ
No. ISO 27001 demonstrates you have appropriate security measures in place, which covers Article 32. It does not address lawful basis, data subject rights, international transfers, or DPIAs. You need both.
No. ISO 27001 is voluntary. The ICO enforces UK GDPR and the Data Protection Act 2018. However, holding ISO 27001 can be used as evidence of "appropriate technical and organisational measures" if the ICO investigates a breach [3].
Not exactly. ISO 27701 is a privacy management standard that maps onto GDPR requirements, but it is not an ICO-approved GDPR certification scheme. It is the closest market equivalent and may gain formal recognition as the ICO's certification framework develops [5].
The DPO requirement comes from GDPR Article 37, not from ISO 27001. You need a DPO if you are a public authority, if your core activities require large-scale systematic monitoring, or if you process special category data at scale [1]. ISO 27001 does require defined information security roles (Clause 5.3), but that is not the same thing.
In practice, about 70% of the work overlaps, mainly around security measures, incident management, access control, and risk assessment. The non-overlapping 30% is GDPR-specific: lawful basis, data subject rights, ROPA, DPIAs, and international transfer mechanisms.
Sources
- 1.UK Government. (2018). "Data Protection Act 2018 / UK GDPR". legislation.gov.uk. https://www.legislation.gov.uk/ukpga/2018/12/contents/enacted
- 2.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection. Information security management systems. Requirements". https://www.iso.org/standard/27001
- 3.Information Commissioner's Office. (2026). "Taking action - our powers and penalties". ICO. https://ico.org.uk/action-weve-taken/
- 4.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
- 5.ISO/IEC. (2019). "ISO/IEC 27701:2019 Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management". https://www.iso.org/standard/71670.html
- 6.ISO/IEC. (2015). "ISO/IEC 17021-1:2015 Conformity assessment - Requirements for bodies providing audit and certification of management systems". https://www.iso.org/standard/61651.html
- 7.Department for Science, Innovation and Technology. (2026). "Cyber Security Breaches Survey 2025/2026". GOV.UK. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026

