You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ISO/IEC 27701:2019 - Privacy Information Management System (PIMS)
Repository
Privacy & Data Protection Skills
Skills Mapped
258 privacy skills
Last Updated
2026-03-15
Version
1.0
1. Standard Overview
1.1 What is ISO/IEC 27701?
ISO/IEC 27701:2019 specifies requirements and provides guidance for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS). It extends ISO/IEC 27001 (Information Security Management) and ISO/IEC 27002 (Security Controls) to include privacy-specific requirements for PII (Personally Identifiable Information) controllers and PII processors.
1.2 Standard Structure
Clause
Title
Scope
Clause 5
PIMS-Specific Requirements Relating to ISO/IEC 27001
Management system requirements extended for privacy
Clause 6
PIMS-Specific Guidance Relating to ISO/IEC 27002
Security controls adapted for privacy context
Clause 7
Additional ISO/IEC 27002 Guidance for PII Controllers
Controller-specific privacy guidance
Clause 8
Additional ISO/IEC 27002 Guidance for PII Processors
Processor-specific privacy guidance
Annex A
PIMS-Specific Reference Control Objectives and Controls (Controllers)
31 controls for PII controllers
Annex B
PIMS-Specific Reference Control Objectives and Controls (Processors)
18 controls for PII processors
Annex C
Mapping to ISO/IEC 29100
Privacy framework alignment
Annex D
Mapping to the General Data Protection Regulation
GDPR cross-reference
Annex E
Mapping to ISO/IEC 27018 and ISO/IEC 29151
Cloud privacy and PII protection
Annex F
Application to ISO/IEC 27001 and ISO/IEC 27002
Integration guidance
1.3 Key Concepts
PII Controller: Entity that determines the purposes and means of processing PII (equivalent to GDPR "data controller")
PII Processor: Entity that processes PII on behalf of a controller (equivalent to GDPR "data processor")
PII Principal: Individual whose PII is processed (equivalent to GDPR "data subject")
PIMS: Privacy Information Management System - the organizational framework for managing privacy
2. Annex A - PII Controller Controls Mapping
2.1 A.7.2 - Conditions for Collection and Processing
Controls governing the lawful basis, purpose limitation, consent, and contractual requirements for PII collection and processing.
Control
Title
Description
Mapped Skills
GDPR Article
A.7.2.1
Identify and document purpose
Document specific, explicit, and legitimate purposes for PII processing
ISO 27701 Annex D provides a mapping between the standard's clauses and GDPR Articles 5-49 (excluding Article 43). The following table maps GDPR articles to both ISO 27701 controls and repository skills.
South Africa's Protection of Personal Information Act
thailand-pdpa
5.2.1, A.7.2.3
Thailand Personal Data Protection Act
turkey-kvkk
5.2.1, A.7.3.1
Turkey's data protection law
uae-pdp-law
5.2.1, A.7.5.1
UAE data protection legislation
uk-aadc-implementation
A.7.3.10, A.7.4.4
UK Age Appropriate Design Code
uk-transfer-mechanisms
A.7.5.1
UK-specific transfer safeguards
6.4 US State Privacy Law Skills
Skill
Primary ISO 27701 Clause
Description
california-consumer-rights
A.7.3.6
CCPA/CPRA consumer access rights
ccpa-consumer-requests
A.7.3.6, A.7.3.9
CCPA data subject request handling
ccpa-cpra-compliance
A.7.3.1, A.7.3.5
California comprehensive compliance
ccpa-right-to-delete
A.7.3.8
California deletion rights
colorado-cpa-compliance
A.7.3.1
Colorado Privacy Act
connecticut-ctdpa
A.7.3.1
Connecticut data protection
cpra-opt-out-signals
A.7.3.4
CPRA opt-out preference signals
cpra-sensitive-pi
A.7.2.2
CPRA sensitive personal information
delaware-dppa
A.7.3.1
Delaware data privacy
iowa-consumer-privacy
A.7.3.1
Iowa consumer privacy
kentucky-kppa
A.7.3.1
Kentucky privacy protection
montana-mtdpa
A.7.3.1
Montana data protection
multi-state-compliance
5.2.1, A.7.3.1
Multi-state compliance framework
new-jersey-dpa
A.7.3.1
New Jersey data protection
oregon-ocpa-compliance
A.7.3.1
Oregon consumer privacy
state-law-applicability
5.2.1
State law threshold analysis
state-law-tracker
5.2.1
Monitoring state legislation
texas-tdpsa-compliance
A.7.3.1
Texas data privacy
vcdpa-compliance
A.7.3.1
Virginia consumer data protection
ca-breach-notification
Clause 6
California breach notification
6.5 Healthcare and HIPAA Skills
Skill
Primary ISO 27701 Clause
Description
42-cfr-part-2
A.7.2.2
Substance abuse records confidentiality
hipaa-baa-management
B.8.2.1, A.7.2.6
Business Associate Agreements
hipaa-breach-notification
Clause 6
HIPAA breach notification rule
hipaa-breach-notify
Clause 6
HIPAA breach notification procedures
hipaa-deidentification
A.7.4.5
Safe Harbor and Expert Determination
hipaa-employee-training
Clause 6
Privacy and security training
hipaa-interoperability
A.7.4.9
Health data exchange requirements
hipaa-minimum-necessary
A.7.4.1
Minimum Necessary Standard
hipaa-mobile-health
A.7.4.9
Mobile health application privacy
hipaa-phi-inventory
A.7.2.8
PHI data inventory
hipaa-privacy-rule
A.7.3.1
HIPAA Privacy Rule requirements
hipaa-research-privacy
A.7.2.3
Research data consent requirements
hipaa-risk-analysis
A.7.2.5
Risk analysis per Security Rule
hipaa-security-rule
Clause 6, A.7.4.9
Technical safeguards
hitech-act-privacy
A.7.3.1
HITECH Act privacy provisions
pia-health-data
A.7.2.5
Health data impact assessments
telehealth-privacy
A.7.4.9
Telehealth-specific privacy controls
edtech-privacy-assessment
A.7.2.5
Educational technology privacy
6.6 Cookie and Tracking Skills
Skill
Primary ISO 27701 Clause
Description
analytics-cookie-consent
A.7.2.3, A.7.2.4
Analytics cookie consent management
cnil-compliant-cookies
A.7.2.3
CNIL cookie compliance
cnil-cookie-banner
A.7.3.3
CNIL-compliant cookie banners
cookie-audit
A.7.2.8, A.7.4.2
Comprehensive cookie audit
cookie-consent-ab-audit
A.7.2.4
A/B testing of consent flows
cookie-consent-testing
A.7.2.4
Consent mechanism testing
cookieless-alternatives
A.7.4.5
Privacy-preserving analytics alternatives
cookie-lifetime-audit
A.7.4.7
Cookie retention audit
cross-jurisdiction-cookies
A.7.5.2
Multi-jurisdiction cookie compliance
eprivacy-essential-cookies
A.7.2.3
ePrivacy Directive cookie classification
google-consent-mode-v2
A.7.2.4
Google Consent Mode implementation
gpc-cookie-integration
A.7.3.4
Global Privacy Control integration
server-side-tracking
A.7.4.5
Server-side tracking privacy
tcf-v2-implementation
A.7.2.4
IAB Transparency & Consent Framework
6.7 Vendor and Processor Management Skills
Skill
Primary ISO 27701 Clause
Description
cloud-provider-assessment
A.7.2.6
Cloud processor risk assessment
dpa-drafting
A.7.2.6, B.8.2.1
Data Processing Agreement drafting
gdpr-dpa-art28
A.7.2.6, B.8.2.1
Art. 28 compliant processor agreements
saas-vendor-inventory
A.7.2.6
SaaS vendor data inventory
sub-processor-management
B.8.5.6, B.8.5.7, B.8.5.8
Sub-processor lifecycle management
vendor-breach-cascade
B.8.5.6
Vendor breach notification cascade
vendor-cert-acceptance
A.7.2.6
Vendor certification acceptance criteria
vendor-monitoring-program
B.8.5.6
Ongoing vendor monitoring
vendor-privacy-audit
A.7.2.6
Vendor privacy audit program
vendor-privacy-due-diligence
A.7.2.6, B.8.5.7
Pre-engagement privacy due diligence
vendor-risk-scoring
A.7.2.6
Vendor risk scoring methodology
vendor-termination-data
B.8.4.2
Data handling at vendor termination
6.8 NIST, SOC2, and Framework Skills
Skill
Primary ISO 27701 Clause
Description
nist-pf-communicate
A.7.3.3
NIST Privacy Framework - Communicate
nist-pf-control
A.7.4.1-A.7.4.9
NIST Privacy Framework - Control
nist-pf-govern
Clause 5
NIST Privacy Framework - Govern
nist-pf-identify
A.7.2.1, A.7.2.8
NIST Privacy Framework - Identify
nist-pf-protect
A.7.4.9, Clause 6
NIST Privacy Framework - Protect
nist-privacy-identify
A.7.2.1
NIST privacy identification
soc2-privacy-audit
Clause 5, A.7.2.5
SOC 2 privacy trust criteria audit
apec-cbpr-cert
A.7.5.1
APEC Cross-Border Privacy Rules certification
iso-27701-pims
All clauses
Direct ISO 27701 PIMS implementation
preparing-iso-31700-certification
A.7.4.1-A.7.4.4
ISO 31700 Privacy by Design
6.9 Employment and HR Privacy Skills
Skill
Primary ISO 27701 Clause
Description
background-check-privacy
6.3.1.1
Pre-employment screening privacy
byod-privacy-policy
6.3.2.1
BYOD privacy controls
employee-biometric-data
A.7.2.2
Employee biometric data processing
employee-dsar-response
A.7.3.6
Employee data subject requests
employee-health-data
A.7.2.2
Employee health data processing
employee-monitoring-dpia
A.7.2.5
Employee monitoring DPIA
employee-surveillance-dpia
A.7.2.5
Workplace surveillance assessment
employment-consent-limits
A.7.2.3
Employment consent limitations
hr-system-privacy-config
6.6.2.2
HR system privacy configuration
remote-work-monitoring
A.7.2.5
Remote work monitoring privacy
whistleblower-data
A.7.2.2
Whistleblower data protection
workplace-email-privacy
6.3.2.1
Workplace email monitoring
7. ISO/IEC 27701:2025 (Edition 2) Updates
ISO/IEC 27701:2025 was published as a significant revision of the 2019 edition. Organizations with existing ISO 27701:2019 certification must transition by 2028.
7.1 Key Structural Changes
Change
2019 Edition
2025 Edition
Independence
Extension of ISO 27001/27002 (cannot stand alone)
Standalone management system standard
Structure
Clauses 5-8 extending ISO 27001/27002
Clauses 4-10 following ISO Harmonized Structure
Annex A
Separate Annex A (Controllers) and Annex B (Processors)
Consolidated Annex A with A.1 (Controllers), A.2 (Processors), A.3 (Shared)
Annex B
18 processor controls
Merged into consolidated Annex A.2 (21 processor controls)
No dedicated skill for handling unlawful controller instructions
Consider adding a processor instruction compliance skill
B.8.5.4-B.8.5.5 (Legal disclosures)
Limited coverage for government access request handling
Consider dedicated law enforcement request handling skill
ISO 27701:2025 A.3 (Shared controls)
New shared controls category not yet explicitly addressed
Update skills to reflect 2025 consolidated Annex A structure
9. Implementation Guidance
9.1 Using This Mapping for ISO 27701 Certification
Scope Definition: Use skills mapped to Clause 5.2.3 (data-inventory-mapping, data-flow-mapping) to establish the PIMS scope
Gap Assessment: Cross-reference your organization's current state against the controls using gdpr-gap-analysis and privacy-maturity-model
Controller Implementation: Implement Annex A controls using the mapped skills in Section 2
Processor Implementation: If acting as a processor, implement Annex B controls using skills in Section 3
Documentation: Use ROPA skills (controller-ropa-creation, processor-ropa-creation) and audit skills (gdpr-compliance-audit, internal-privacy-audit) to maintain evidence
Continuous Improvement: Leverage continuous-compliance, privacy-metrics-dashboard, and privacy-program-metrics for ongoing monitoring
ISO/IEC 27701:2019 - Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management
ISO/IEC 27701:2025 - Privacy information management system (standalone standard, Edition 2)
ISO/IEC 27001:2022 - Information security management systems - Requirements
ISO/IEC 27002:2022 - Information security controls
ISO/IEC 29100:2011 - Privacy framework
ISO/IEC 27018:2019 - Code of practice for protection of PII in public clouds
ISO/IEC 29151:2017 - Code of practice for PII protection
ISO 31700-1:2023 - Consumer protection - Privacy by design for consumer goods and services
10.2 Regulatory References
GDPR - Regulation (EU) 2016/679 - General Data Protection Regulation
CCPA/CPRA - California Consumer Privacy Act / California Privacy Rights Act
HIPAA - Health Insurance Portability and Accountability Act (US)
LGPD - Lei Geral de Protecao de Dados (Brazil)
PIPL - Personal Information Protection Law (China)
PIPEDA - Personal Information Protection and Electronic Documents Act (Canada)
APPI - Act on the Protection of Personal Information (Japan)
10.3 Implementation Resources
BSI Group - ISO/IEC 27701 Implementation Guide
NQA - ISO 27701 Annex A Controls Analysis
ISMS.online - ISO 27701 Clause-by-Clause Reference
Schellman - How to Prepare for ISO 27701:2025
IAPP - ISO Updates Standard on Managing Privacy Compliance Programs
Glocert International - ISO 27701:2025 Transition Guide
This mapping document is maintained as part of the Privacy & Data Protection Skills repository. For the latest updates to ISO 27701 controls and skill mappings, consult the individual skill directories and their associated standards references.