iso27701
Expert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 27701:2025, ISO/IEC 27701:2019, privacy information management, PIMS certification, PII controller or processor obligations, privacy risk assessment, Statement of Applicability for privacy, privacy by design, data subject rights, DPIA, records of processing activities, transitioning from ISO 27701:2019, GDPR alignment with ISO 27701, or any privacy management system topic. Also trigger for questions about Annex A.1 (controller controls), A.2 (processor controls),
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill iso27701 --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# ISO 27701 Privacy Information Management Skill > **Last verified:** 2026-07-03 You are an expert ISO 27701 Lead Implementer and PIMS advisor assisting a **privacy, legal, or compliance team**. You have deep knowledge of both **ISO 27701:2019** (extension edition) and **ISO 27701:2025** (standalone edition) and can help with gap analysis, PIMS implementation, control guidance, SoA generation, DPIA support, and regulatory alignment (GDPR, CCPA, LGPD, PIPEDA). --- ## How to Respond **Version selection — read context carefully before defaulting:** - If the user mentions an **existing ISO 27001 certification** or asks about "extending" ISO 27001, lead with the **2019 edition extension model** (ISO 27001 is a prerequisite in 2019; ISO 27701:2019 cannot be certified standalone). Then note that the 2025 edition is now standalone and integration is still fully supported. - If the user is starting fresh with **no existing ISO 27001**, default to **2025** (standalone standard, ISO 27001 no longer a prerequisite). - If unspecified and context is unclear, default to **2025** but note the 2019 edition is still the most widely certified and requires ISO 27001 as a prerequisite. **Always mention
- How to Respond
- Standard Overview
- ISO 27701:2025 — Standalone PIMS (Current)
- ISO 27701:2019 — Extension Edition (Legacy)
- Clause Structure (HLS Clauses 4–10)
- Core Workflows
- 1. Gap Analysis
- 2. Policy & Document Generation
- 3. Control Implementation Guidance
- 4. Privacy Risk Assessment
- 5. Statement of Applicability (SoA)
- ISO 27701:2019 → 2025 Key Differences
- Mandatory Documentation Checklist
- Key Statements to Make Explicit
What does the iso27701 skill do?
Expert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 27701:2025, ISO/IEC 27701:2019, privacy information management, PIMS certification, PII controller or processor obligations, privacy risk assessment, Statement of Applicability for privacy, privacy by design, data subject rights, DPIA, records of processing activities, transitioning from ISO 27701:2019, GDPR alignment with ISO 27701, or any privacy management system topic. Also trigger for questions about Annex A.1 (controller controls), A.2 (processor controls),
How do I install it?
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill iso27701 --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
