EN 1090
European standard for execution of structural steel and aluminium
ISO 27701
International standard for privacy information management systems.
Quick Verdict
EN 1090 mandates CE marking for structural steel/aluminium in EU construction via FPC and execution classes, while ISO 27701 certifies voluntary PIMS for global PII privacy governance. Fabricators need EN 1090 for market access; data handlers adopt 27701 for compliance proof.
EN 1090
EN 1090 Execution of steel and aluminium structures
Key Features
- Risk-based Execution Classes (EXC1-EXC4) scaling controls
- Factory Production Control (FPC) certification by Notified Body
- CE marking for structural steel and aluminium components
- Welding quality management aligned with ISO 3834
- Full traceability from materials to finished structures
ISO 27701
ISO/IEC 27701:2025 Privacy Information Management
Key Features
- Establishes Privacy Information Management System (PIMS)
- PII controller and processor specific controls (Annex A/B)
- Risk-based PDCA cycle with DPIAs
- Mappings to GDPR and ISO 27001/27002
- Data subject rights and vendor management processes
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
EN 1090 Details
What It Is
EN 1090 is a harmonized European standard family (EN 1090-1, -2, -3) for the execution and conformity assessment of structural steel and aluminium components under the Construction Products Regulation (CPR). Its primary purpose is ensuring safe fabrication, assembly, and market placement via CE marking. It employs a risk-based approach through Execution Classes (EXC1-EXC4), scaling requirements by failure consequences, service conditions, and production complexity.
Key Components
- **EN 1090-1Conformity assessment, Factory Production Control (FPC), Declaration of Performance (DoP).
- **EN 1090-2/-3Technical rules for steel/aluminium (welding, tolerances, corrosion protection, inspection/NDT).
- Core principles: traceability, welding per ISO 3834, Notified Body certification, ongoing surveillance.
- Compliance model: FPC certification enabling CE marking.
Why Organizations Use It
Mandated for EU market access; reduces liability, ensures quality. Benefits include risk mitigation, rework reduction, market credibility. Builds stakeholder trust via certified performance declarations.
Implementation Overview
Phased: gap analysis, FPC development, personnel training (welding coordinators), NB audits. Applies to fabricators in construction; 6-12 months typical, with surveillance. Targets steel/aluminium producers geographically in EEA.
ISO 27701 Details
What It Is
ISO/IEC 27701:2025 is the international standard extending ISO/IEC 27001 for a Privacy Information Management System (PIMS). It provides requirements and guidance for managing personally identifiable information (PII) lifecycle, emphasizing accountability, risk management, and alignment with privacy laws like GDPR using a risk-based PDCA approach.
Key Components
- Clauses 4–10 for management system (context, leadership, planning, operation, evaluation, improvement).
- Annex A (PII controllers) and Annex B (PII processors) with privacy-specific controls.
- Mappings to GDPR, ISO 27002, and others.
- Certification via accredited bodies, often integrated with ISO 27001 audits.
Why Organizations Use It
- Mitigates regulatory fines, breach risks, and vendor exclusions.
- Builds trust, enables procurement differentiation, harmonizes multi-jurisdiction compliance.
- Reduces data footprint costs, provides audit-ready evidence.
Implementation Overview
- Phased: discover/scope, design/plan, implement/operate, validate/improve.
- Activities: PII inventory, risk assessments (DPIAs), DSR processes, training, vendor contracts.
- Suits all sizes/industries handling PII; voluntary certification over 6–12 months.
Key Differences
| Aspect | EN 1090 | ISO 27701 |
|---|---|---|
| Scope | Structural steel/aluminium execution & conformity | Privacy Information Management System (PIMS) |
| Industry | Construction, fabrication (EU/EEA focus) | All PII-processing sectors worldwide |
| Nature | Harmonized standard enabling CE marking | Voluntary PIMS certification standard |
| Testing | FPC certification, surveillance audits by Notified Bodies | Internal audits, certification body surveillance |
| Penalties | Market exclusion, no CE marking | Loss of certification, no legal penalties |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about EN 1090 and ISO 27701
EN 1090 FAQ
ISO 27701 FAQ
You Might also be Interested in These Articles...

TISAX Tabletop Exercises for ADAS Suppliers: Simulating Prototype IP Leaks and Ransomware in Hybrid Supply Chains (2025 Edition with Hero Scenario Visual)
Master TISAX 'Very High' tabletop exercises for ADAS suppliers with 2024 breach simulations like CAD leaks and ransomware. Get scripts, AAR templates, hybrid ti

Why the SEC Stepped In: The Investor-Driven Push for Cybersecurity Transparency
Discover why the SEC's 2023 cybersecurity rules treat cyber risks as material financial threats. Explore the 'stick and carrot' approach for standardized disclo

Practical Implementation Blueprint for Regulation S-K Item 106: Cybersecurity Governance and Risk Management Disclosures in 10-Ks
Step-by-step guide for Item 106 cybersecurity disclosures in 10-Ks: risk management, board oversight, Inline XBRL templates (Dec 2024 compliance). Templates for
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Check out these other Gradum.io Standards Comparison Pages
EPA vs ISO 31000
Discover EPA vs ISO 31000: Strict regs (CAA, CWA, RCRA) vs risk principles for resilience. Master compliance, governance & strategy. Integrate now for enterprise success!
CSL (Cyber Security Law of China) vs ISO 22301
CSL vs ISO 22301: China's Cybersecurity Law data localization & governance vs global BCMS resilience. Align for compliance, risk mitigation & China market dominance now!
ISO 50001 vs ISO 17025
Discover ISO 50001 vs ISO 17025: Energy mgmt for continual performance gains & cost savings vs lab competence for valid, impartial results. Align standards to your goals now!