iso27701

Guides ISO 27701 PIMS implementation, gap analysis, SoA generation, and GDPR alignment.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill iso27701-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iso27701
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/iso27701
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill iso27701-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Privacy, legal, and compliance teams struggle to interpret ISO/IEC 27701 requirements, choose between the 2019 extension edition and the 2025 standalone edition, and produce audit-ready PIMS documentation such as gap analyses, Statements of Applicability, DPIAs, and privacy policies. ## Core Features & Use Cases - Gap Analysis & Certification Readiness: Produces structured gap tables covering Clauses 4–10 and all applicable Annex A controls, with status, evidence needs, and remediation priorities. - PIMS Document Generation: Creates privacy policies, RoPA, DSR procedures, DPIA templates, and role-scoped Statements of Applicability mapped to controller (A.1), processor (A.2), and shared security (A.3) controls. - 2019 to 2025 Transition Support: Provides control-by-control mapping, transition audit steps, and a timeline toward the October 2028 deadline. - Use Case: A SaaS company acting as a PII processor asks for an SoA; the skill scopes it to A.2 plus A.3 (47 controls), generates the applicability table, and flags missing sub-processor authorization controls. ## Quick Start Ask the skill to perform an ISO 27701:2025 gap analysis for your organization, stating whether you act as a PII controller, processor, or both.

Frequently Asked Questions about iso27701

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an ISO 27701 gap analysis?

An ISO 27701 gap analysis covers all mandatory Clauses 4–10 plus applicable Annex A controls, rating each as Implemented, Partial, Not Implemented, or N/A with evidence needs and gap notes. First clarify your edition (2019 or 2025) and role as PII controller, processor, or both.

What is the difference between ISO 27701:2019 and ISO 27701:2025?

ISO 27701:2019 is an extension requiring ISO 27001 certification as a prerequisite, while ISO 27701:2025 is a standalone standard with its own Clauses 4–10 and 78 Annex A controls. Organizations certified under 2019 must transition to 2025 by October 2028.

Does ISO 27701 certification guarantee GDPR compliance?

No, ISO 27701 certification does not guarantee GDPR compliance and is not an approved Article 42 certification scheme in most EU member states. It provides strong evidence of Article 24 and 32 technical and organisational measures and accountability documentation under Article 5(2).

Can I certify ISO 27701 without ISO 27001?

Yes, under ISO 27701:2025, which is a standalone standard where ISO 27001 is optional though integration is supported. Under the 2019 edition, ISO 27001 certification is a mandatory prerequisite and standalone certification is not possible.

How many controls are in an ISO 27701 Statement of Applicability?

The SoA scope depends on your role: PII controllers cover A.1 plus A.3 (60 controls), processors cover A.2 plus A.3 (47 controls), and organizations acting as both cover all 78 controls. Each control needs an applicability decision, justification, and implementation status.

When is a DPIA required under ISO 27701?

A DPIA is required when processing is likely to result in high risk to individuals, especially systematic profiling with significant effects, large-scale special category data processing, systematic monitoring of public areas, or new technologies with untested privacy implications.