There is, generally, no direct legal requirement as such. Organisations choose whether or not to implement the requirements of ISO 27001 based upon the benefits that would be gained by doing so.
However, you should pay close attention to any contractual obligations you may have for protecting the information of clients and other stakeholders.
There is an increasing trend where customers require third party suppliers to implement or certify to ISO 27001, thus making it a legal requirement, by way of a contract.

How do You Identify and Then Manage Your ISMS Scope?
When managing the security of your organisation’s information assets, you will need to consider the scope of what you are doing.
URM’s blog explores ISO 27001 Clause 9.1, what it requires and practical guidance on how to implement this Clause in full conformance with the Standard.
URM’s blog explores five key actions organisations can take to strengthen their ISO 27001 information risk management processes.
URM’s blog explains the risk management requirements in ISO 27001, including identifying ISMS risk, risk assessment and treatment, documentation and more

