There is, generally, no direct legal requirement as such. Organisations choose whether or not to implement the requirements of ISO 27001 based upon the benefits that would be gained by doing so.
However, you should pay close attention to any contractual obligations you may have for protecting the information of clients and other stakeholders.
There is an increasing trend where customers require third party suppliers to implement or certify to ISO 27001, thus making it a legal requirement, by way of a contract.

5 Must-Dos of Effective ISO 27001 Risk Management
URM’s blog explores five key actions organisations can take to strengthen their ISO 27001 information risk management processes.
URM’s blog explains the risk management requirements in ISO 27001, including identifying ISMS risk, risk assessment and treatment, documentation and more
URM’s blog explains how to meet ISO 27001 Clause 10.2, including finding nonconformities, performing root cause analysis, implementing corrective actions & more
URM’s blog explains ISO 27001 communications requirements, their links to interested parties, & how both can be addressed through a single framework.

