You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A practical, audit-ready implementation toolkit for ISO/IEC 27701:2025 Privacy Information Management Systems — extending ISO 27001:2022 and ISO 27002:2022 with privacy-specific controls for PII controllers and PII processors. Updated for the 2025 edition with expanded Annex A/B controls, enhanced DPIA requirements, joint-controller provisions, and full alignment to ISO 27001:2022 (HLS/Annex SL).
Updated: April 2025 | Standard Version: ISO/IEC 27701:2025 | Replaces: ISO/IEC 27701:2019
What This Toolkit Contains
All 10 PIMS clauses with implementation templates (extending ISO 27001:2022 Clauses 4–10)
Full PIMS Gap Assessment covering all updated Annex A/B controls (aligned to ISO 27002:2022 structure)
Privacy Risk Register with PII-specific risk methodology (aligned to ISO 27005:2022)
Data Protection Impact Assessment (DPIA) template — enhanced per 27701:2025 requirements
Statement of Applicability (SoA) for all updated Annex A and Annex B controls
PII Controller controls — Annex A (ISO 27701:2025, aligned to ISO 27002:2022)
PII Processor controls — Annex B (ISO 27701:2025, aligned to ISO 27002:2022)
Privacy Notice, Consent Management, and Data Subject Rights procedures
Legal & Regulatory Requirements Register (GDPR, UAE PDPL, UK GDPR, CCPA, HIPAA, India DPDPA)
Worked examples for a fictional organisation (Nexus Financial Services Ltd)
GRC automation scripts (Python)
Cross-mapping to GDPR Articles, NIST Privacy Framework 1.0, ISO 29100:2011, and ISO 31700
Key Changes: ISO/IEC 27701:2025 vs. 2019
Area
2019 Edition
2025 Edition
Base standard
ISO 27001:2013
ISO 27001:2022 (HLS/Annex SL)
Control structure
Annex A (31) + Annex B (18) = 49
Expanded, aligned to ISO 27002:2022 (93-control structure)
Privacy by Default
Embedded in Annex A
Standalone control — explicit requirement
Joint Controllers
Limited guidance
Dedicated provisions and responsibilities
DPIA triggers
General guidance
Prescriptive threshold criteria
Consent management
Basic provisions
Granular consent lifecycle controls
Cross-border transfers
Reference to safeguards
Explicit transfer impact assessment (TIA) requirements
Terminology
"PII" primary
"Personal data" and "PII" harmonised
ISO 29100 alignment
Referenced
Deeper integration of 11 privacy principles
ISO 31700 (PbD)
Not referenced
Explicitly cross-referenced for Privacy by Design
Audit requirements
General PIMS audit
Specific privacy audit criteria and competence
Repository Structure
#
Folder / File
Contents
—
README.md
This file — full index and navigation guide
—
00-IMPLEMENTATION-GUIDE.md
How to use this toolkit; PIMS implementation roadmap (2025 edition)
—
TRANSITION-GUIDE-2019-TO-2025.md
Transition guide: ISO 27701:2019 → 2025 — new controls, changes, gap analysis
1
01-GAP-ASSESSMENT/
Updated PIMS gap assessment checklist (2025 controls)
Conditions for collection/use, obligations to data subjects, privacy notices, consent lifecycle, DSARs, Privacy by Default, joint controller provisions
B — Clauses B.8
PII Processors
Processor-specific obligations, sub-processor management, PII return/deletion, transfer safeguards, audit rights
Supplementary Resources — Now in Dedicated Folders
All supplementary files have been reorganised into two dedicated folders for easier navigation:
ISO/IEC 29100:2011 — Privacy framework and 11 privacy principles alignment
ISO/IEC 31700:2023 — Privacy by Design standard cross-reference
UK GDPR / DPA 2018 — Post-Brexit UK data protection alignment
CCPA / CPRA — California Consumer Privacy Act alignment
Version History
Version
Date
Changes
2.2
April 2025
Comprehensive audit and fix — replaced incorrect placeholder content in 11 files with correct docs; completed THIRD-PARTY-PRIVACY-ASSESSMENT.md; fixed all ISO/IEC 27701:2019 body/footer refs to 2025; fixed dpia_risk_scorer.py version refs
2.3
April 2025
Final deep audit — fixed wrong content in GAP-ASSESSMENT-SCORING-GUIDE (was showing checklist, now proper scoring guide PIMS-SCR-001); updated ISO/IEC 27701:2019 → 2025 in 17 additional files (body text, footer citations, document titles, contributing guidelines) — all 63 files now fully consistent with 2025 edition
2.4
April 2025
Readiness gap-fill — added 11 new files: 13-SCRIPTS/README.md (quickstart + sample CSVs); 5 NFS worked examples (ROPA, DSR log, Third-Party Assessment, Consent Record, Internal Audit); India DPDPA 2023 alignment guide; NIST Privacy Framework 1.0 mapping; Certification Readiness Checklist; Privacy Governance Templates (DPO letter + Board report); Consent Withdrawal Form
2.1
April 2025
Fixed file reference errors — Annex A/B now correctly reference ANNEX-A-PII-CONTROLLER-CONTROLS.md and ANNEX-B-PII-PROCESSOR-CONTROLS.md
2.0
April 2025
Updated to ISO/IEC 27701:2025 — HLS alignment, expanded controls, DPIA enhancements, TIA, joint controller provisions, ISO 31700 cross-reference
1.0
2024
Initial release — ISO/IEC 27701:2019 edition
Maintained by Ankit Uniyal — ISO 27001 Lead Auditor | GRC Lead
A practical implementation toolkit for ISO/IEC 27701:2025 PIMS — updated for 2025 edition, aligned to ISO 27001:2022, covering all Annex A/B controls, DPIA, TIA, Privacy by Default, joint controllers, GDPR/UAE PDPL cross-mapping, and Python GRC automation scripts.