Agent skill

Iso 27701 Pims

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides ISO 27701 Privacy Information Management System implementation extending ISO 27001/27002.

Apache-2.0Auto-check passedLegal & Compliance

Install Iso 27701 Pims

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill iso-27701-pims -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills iso-27701-pims --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/iso-27701-pims .claude/skills/iso-27701-pims && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iso-27701-pims
GitHub stars
301
Token cost
~4.7k tokens
SKILL.md length
2,136 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides ISO 27701 Privacy Information Management System implementation extending ISO 27001/27002.

  • Works in 9 steps: Prerequisite Assessment (Weeks 1-2) → Clause 5 Gap Analysis (Weeks 2-4) → Annex A/B Control Gap Analysis (Weeks 4-8) → …
  • Tasks that involve SOC 2 and security compliance
  • SKILL.md covers Overview, Standard Structure, Clause 5: PIMS-Specific… and Annex A: PII Controller Controls, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Iso 27701 Pims is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides ISO 27701 Privacy Information Management System implementation extending ISO 27001/27002. Covers Clause 5 PIMS-specific requirements, Clause 6 PIMS guidance for ISO 27002, Clause 7 PII controller guidance (Annex A), Clause 8 PII processor guidance (Annex B), gap assessment, and certification path. Keywords: ISO 27701, PIMS, privacy management system, ISO 27001 extension, certification, Annex A, Annex B.

Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve SOC 2 and security compliance
  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the iso-27701-pims skill to guide ISO 27701 Privacy Information Management System implementation extending ISO 27001/27002”
  • “/iso-27701-pims”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Prerequisite Assessment (Weeks 1-2)
  2. Clause 5 Gap Analysis (Weeks 2-4)
  3. Annex A/B Control Gap Analysis (Weeks 4-8)
  4. Clause 6 Gap Analysis (Weeks 4-8, parallel with Phase 3)
  5. Readiness (Months 1-3)
  6. Implementation (Months 3-9)
  7. Internal Audit and Management Review (Months 9-10)
  8. Certification Audit (Months 10-12)
  9. Surveillance and Recertification

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Iso 27701 Pims loads about 4.7k tokens when it runs, and up to ~7.4k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 2,136 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~4.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,136 words, ~4,688 tokens.

Download SKILL.mdSave it as .claude/skills/iso-27701-pims/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
iso-27701-pims
description
Guides ISO 27701 Privacy Information Management System implementation extending ISO 27001/27002. Covers Clause 5 PIMS-specific requirements, Clause 6 PIMS guidance for ISO 27002, Clause 7 PII controller guidance (Annex A), Clause 8 PII processor guidance (Annex B), gap assessment, and certification path. Keywords: ISO 27701, PIMS, privacy management system, ISO 27001 extension, certification, Annex A, Annex B.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-audit-certification
metadata.tags
iso-27701, pims, privacy-management, iso-27001, certification, controller-processor

ISO 27701 Privacy Information Management System Implementation

Overview

ISO/IEC 27701:2019 specifies requirements and provides guidance for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS) as an extension to ISO/IEC 27001:2022 and ISO/IEC 27002:2022. Published in August 2019, ISO 27701 is the first certifiable international standard for privacy management, providing a framework that maps to GDPR, LGPD, PIPA, APPI, and other data protection regulations. The standard transforms an existing Information Security Management System (ISMS) into a PIMS by adding privacy-specific requirements and controls applicable to PII controllers and PII processors.

Organizations such as Sentinel Compliance Group implement ISO 27701 to demonstrate accountability under Art. 5(2) GDPR, satisfy Art. 42 certification requirements, and provide contractual assurance to data subjects, customers, and supervisory authorities that privacy obligations are systematically managed.

Standard Structure

Clauses 5-8 Architecture
ClauseTitleExtendsApplicability
Clause 5PIMS-Specific Requirements Related to ISO/IEC 27001ISO 27001 Clauses 4-10All organizations
Clause 6PIMS-Specific Guidance Related to ISO/IEC 27002ISO 27002 ControlsAll organizations
Clause 7Additional ISO/IEC 27002 Guidance for PII ControllersAnnex A controlsPII controllers only
Clause 8Additional ISO/IEC 27002 Guidance for PII ProcessorsAnnex B controlsPII processors only
Annex APIMS-Specific Reference Control Objectives and Controls (Controllers)NormativePII controllers
Annex BPIMS-Specific Reference Control Objectives and Controls (Processors)NormativePII processors
Annex CMapping to ISO/IEC 29100InformativeAll organizations
Annex DMapping to the GDPRInformativeEU-operating organizations
Annex EMapping to ISO/IEC 27018 and ISO/IEC 29151InformativeCloud processors
Annex FHow to Apply ISO/IEC 27701 to ISO/IEC 27001 and ISO/IEC 27002InformativeAll organizations

Clause 5: PIMS-Specific Requirements

5.2 Context of the Organization (extends ISO 27001 Clause 4)
5.2.1 Understanding the Organization and its Context

The organization shall determine external and internal issues relevant to privacy that affect its ability to achieve the intended outcomes of the PIMS. This includes:

  • Applicable privacy legislation and regulation (GDPR, CCPA/CPRA, LGPD, PIPA, APPI, PDPA)
  • Applicable judicial decisions and court orders
  • Applicable administrative regulations and standards
  • Contractual obligations related to PII processing
  • Organizational governance, policies, and procedures relevant to PII processing
  • Decisions regarding PII processing (particularly where the organization acts as both controller and processor for different processing activities)
5.2.2 Understanding the Needs and Expectations of Interested Parties

Interested parties specific to PIMS include:

Interested PartyPrivacy Expectations
Data subjects (PII principals)Lawful processing, transparency, rights exercise, data security
Supervisory authoritiesCompliance with applicable legislation, cooperation, breach notification
Customers (B2B)Contractual compliance, processor obligations, sub-processor management
EmployeesWorkplace privacy, monitoring transparency, data subject rights
Third-party processors/sub-processorsData processing agreement compliance, instruction adherence
Certification bodiesConformity with ISO 27701 requirements
5.2.3 Determining the Scope of the PIMS

The PIMS scope must define:

  • The types of processing performed (collection, storage, use, disclosure, deletion)
  • Whether the organization acts as PII controller, PII processor, or both
  • The categories of PII processed
  • The categories of PII principals affected
  • The organizational units, locations, and systems in scope
  • Third parties to whom PII is transferred
5.2.4 PIMS

The ISMS shall be extended to include privacy by addressing PII protection requirements in all ISMS processes, including risk assessment, risk treatment, policy, awareness, internal audit, management review, and continual improvement.

5.4 Planning (extends ISO 27001 Clause 6)
5.4.1.2 Privacy Risk Assessment

The organization shall implement a privacy risk assessment process that:

  1. Identifies risks to PII principals (not just to the organization) arising from loss of confidentiality, integrity, and availability of PII
  2. Considers privacy-specific threats: unauthorized access, unauthorized modification, unauthorized disclosure, unlawful processing, excessive data collection, failure to honor data subject rights, cross-border transfer without safeguards
  3. Assesses the likelihood and impact of each risk from the perspective of the PII principal
  4. Determines risk levels using a privacy-specific risk matrix
5.4.1.3 Privacy Risk Treatment

The risk treatment process shall select controls from:

  • ISO/IEC 27001 Annex A (information security controls)
  • ISO/IEC 27701 Annex A (PII controller controls) — when acting as controller
  • ISO/IEC 27701 Annex B (PII processor controls) — when acting as processor
  • Additional controls from other sources as needed

The Statement of Applicability (SoA) must be extended to include applicable Annex A and/or Annex B controls with justification for inclusion or exclusion of each control.

5.5 Support (extends ISO 27001 Clause 7)
5.5.1 Competence

Personnel performing privacy-related functions must demonstrate competence through:

  • Formal privacy training (CIPP/E, CIPM, CIPT, ISO 27701 Lead Implementer, ISO 27701 Lead Auditor)
  • Knowledge of applicable privacy legislation
  • Understanding of PII processing operations within their scope
  • Competence records maintained as documented information
5.5.2 Awareness

All persons doing work under the organization's control must be aware of:

  • The privacy policy
  • Their contribution to the effectiveness of the PIMS
  • The implications of not conforming with PIMS requirements
  • The potential consequences (including sanctions) of privacy violations

Annex A: PII Controller Controls

A.7 — Conditions for Collection and Processing
ControlDescriptionGDPR Mapping
A.7.2.1Identify and document purposeArt. 5(1)(b), Art. 13-14
A.7.2.2Identify lawful basisArt. 6(1), Art. 9(2)
A.7.2.3Determine when and how consent is to be obtainedArt. 7
A.7.2.4Obtain and record consentArt. 7(1)
A.7.2.5Privacy impact assessmentArt. 35
A.7.2.6Contracts with PII processorsArt. 28
A.7.2.7Joint PII controllerArt. 26
A.7.2.8Records related to processing PIIArt. 30
A.7.3 — Obligations to PII Principals
ControlDescriptionGDPR Mapping
A.7.3.1Determining and fulfilling obligations to PII principalsArt. 12-22
A.7.3.2Determining information for PII principalsArt. 13-14
A.7.3.3Providing information to PII principalsArt. 12
A.7.3.4Providing mechanism to modify or withdraw consentArt. 7(3)
A.7.3.5Providing mechanism to object to PII processingArt. 21
A.7.3.6Access, correction and/or erasureArt. 15-17
A.7.3.7PII controllers' obligations to inform third partiesArt. 19
A.7.3.8Providing copy of PII processedArt. 15(3), Art. 20
A.7.3.9Handling requestsArt. 12(3)-(4)
A.7.3.10Automated decision makingArt. 22
A.7.4 — Privacy by Design and Privacy by Default
ControlDescriptionGDPR Mapping
A.7.4.1Limit collectionArt. 5(1)(c)
A.7.4.2Limit processingArt. 5(1)(b)
A.7.4.3Accuracy and qualityArt. 5(1)(d)
A.7.4.4PII minimization objectivesArt. 25(2)
A.7.4.5PII de-identification and deletion at end of processingArt. 5(1)(e), Art. 17
A.7.4.6Temporary filesArt. 5(1)(e)
A.7.4.7RetentionArt. 5(1)(e)
A.7.4.8DisposalArt. 17
A.7.4.9PII transmission controlsArt. 32
A.7.5 — PII Sharing, Transfer, and Disclosure
ControlDescriptionGDPR Mapping
A.7.5.1Identify basis for PII transfer between jurisdictionsArt. 44-49
A.7.5.2Countries and international organizations to which PII can be transferredArt. 45
A.7.5.3Records of PII disclosure to third partiesArt. 30(1)(d)
A.7.5.4Notification of PII disclosure requestsArt. 19

Annex B: PII Processor Controls

B.8.2 — Conditions for Collection and Processing
ControlDescriptionGDPR Mapping
B.8.2.1Customer agreementArt. 28(3)
B.8.2.2Organization's purposesArt. 28(3)(a)
B.8.2.3Marketing and advertising useArt. 28(3)(a)
B.8.2.4Infringing instructionArt. 28(3) second subparagraph
B.8.2.5Customer obligationsArt. 28(3)
B.8.2.6Records related to processing PIIArt. 30(2)
B.8.3 — Obligations to PII Principals
ControlDescriptionGDPR Mapping
B.8.3.1Obligations to PII principalsArt. 28(3)(e)
B.8.3.2Information for PII principals—
B.8.4 — Privacy by Design and Default
ControlDescriptionGDPR Mapping
B.8.4.1Temporary filesArt. 28(3)(g)
B.8.4.2Return, transfer or disposal of PIIArt. 28(3)(g)
B.8.4.3PII transmission controlsArt. 32
B.8.5 — PII Sharing, Transfer, and Disclosure
ControlDescriptionGDPR Mapping
B.8.5.1Basis for PII transfer between jurisdictionsArt. 44-49
B.8.5.2Countries and international organizations to which PII can be transferredArt. 45, 46
B.8.5.3Records of PII disclosure to third partiesArt. 30(2)
B.8.5.4Notification of PII disclosure requests—
B.8.5.5Legally binding PII disclosuresArt. 28(3)(a)
B.8.5.6Disclosure of subcontractors used to process PIIArt. 28(2)
B.8.5.7Engagement of a subcontractor to process PIIArt. 28(2), (4)
B.8.5.8Change of subcontractor to process PIIArt. 28(2)

Gap Assessment Methodology

Show full SKILL.md (869 more words)Show less
Phase 1: Prerequisite Assessment (Weeks 1-2)

Before ISO 27701 implementation, verify that a functioning ISO 27001 ISMS is in place:

  1. ISO 27001 Certification Status: Confirm valid ISO 27001:2022 certification or at minimum a fully implemented ISMS with completed internal audit cycle
  2. Scope Alignment: Determine whether the PIMS scope aligns with the existing ISMS scope or requires expansion
  3. Documentation Baseline: Inventory existing ISMS policies, procedures, and records that will be extended
Phase 2: Clause 5 Gap Analysis (Weeks 2-4)

For each sub-clause of Clause 5, assess:

Assessment RatingCriteria
Fully ImplementedControl/requirement exists, is documented, implemented, and effective
Partially ImplementedControl/requirement exists but lacks documentation, full implementation, or evidence of effectiveness
Not ImplementedControl/requirement does not exist or is not addressed
Not ApplicableJustified exclusion documented in SoA

Specific gap analysis checklist:

  • Context analysis includes privacy-specific external and internal issues (5.2.1)
  • Interested parties include PII principals and supervisory authorities (5.2.2)
  • PIMS scope defines controller/processor roles per processing activity (5.2.3)
  • Privacy risk assessment addresses risks to PII principals (5.4.1.2)
  • Statement of Applicability includes Annex A/B controls (5.4.1.3)
  • Privacy-specific competence requirements are defined and tracked (5.5.1)
  • Privacy awareness program covers all persons under organizational control (5.5.2)
  • Internal audit scope includes PIMS-specific requirements (5.6)
  • Management review includes privacy performance indicators (5.7)
Phase 3: Annex A/B Control Gap Analysis (Weeks 4-8)

For organizations acting as PII controllers, assess all 31 Annex A controls. For PII processors, assess all 18 Annex B controls. For organizations acting in both roles, assess both annexes.

Gap Assessment Template:

Control ID: A.7.2.1
Control Title: Identify and document purpose
Current State: Purposes documented in privacy notice but not in processing register
Gap Description: Processing register lacks specific purpose documentation per activity
Risk Rating: Medium
Remediation Action: Update processing register template, populate for all activities
Owner: Data Protection Officer
Target Date: [date]
Phase 4: Clause 6 Gap Analysis (Weeks 4-8, parallel with Phase 3)

Assess the 34 privacy-specific modifications to ISO 27002 controls in Clause 6:

ISO 27002 ControlClause 6 ExtensionKey Addition
5.1 Policies for information security6.2.1.1Include PII protection policies
5.10 Acceptable use of information6.5.2.1Cover acceptable use of PII
5.12 Classification of information6.5.2.2PII classification criteria
5.13 Labelling of information6.5.2.3PII labelling requirements
5.34 Privacy and protection of PII6.5.3.1Operational PII handling
6.1 Screening6.6.2.1Privacy-related screening
6.2 Terms and conditions of employment6.6.2.2PII processing duties
6.4 Disciplinary process6.6.4Privacy violation consequences
8.10 Information deletion6.9.4.1PII deletion requirements
8.11 Data masking6.9.4.2PII masking/pseudonymisation

Certification Path

Step 1: Readiness (Months 1-3)
  1. Complete gap assessment (Phases 1-4 above)
  2. Develop remediation roadmap with prioritized actions
  3. Secure management commitment and budget
  4. Assign PIMS implementation team
Step 2: Implementation (Months 3-9)
  1. Extend ISMS documentation with PIMS-specific policies and procedures
  2. Implement Annex A/B controls per the remediation roadmap
  3. Conduct privacy risk assessments for all in-scope processing activities
  4. Update Statement of Applicability to include Annex A/B controls
  5. Deliver privacy-specific training to all personnel
Step 3: Internal Audit and Management Review (Months 9-10)
  1. Conduct PIMS-specific internal audit covering Clauses 5-8 and applicable Annex controls
  2. Document nonconformities and corrective actions
  3. Conduct management review with privacy-specific agenda items
  4. Verify closure of all major nonconformities
Step 4: Certification Audit (Months 10-12)
  1. Stage 1 Audit: Documentation review, scope confirmation, readiness assessment. The certification body reviews PIMS documentation, SoA, risk assessment, and policy framework. Typically 1-2 days on-site.
  2. Stage 2 Audit: Implementation verification, evidence sampling, interviews with key personnel. The auditor verifies that controls are not just documented but implemented and effective. Typically 3-5 days on-site depending on scope.
  3. Finding Resolution: Address any nonconformities identified during Stage 2. Major nonconformities must be resolved before certification; minor nonconformities must have accepted corrective action plans.
Step 5: Surveillance and Recertification
  • Surveillance Audits: Conducted annually (Year 1 and Year 2) to verify continued conformity
  • Recertification Audit: Full audit in Year 3 before certificate expiry
  • Scope Changes: Notify the certification body if significant changes affect the PIMS scope
Certification Bodies

Accredited certification bodies for ISO 27701 include BSI, SGS, TUV, Bureau Veritas, DNV, LRQA, and Schellman. The certification body must hold accreditation from a national accreditation body (e.g., UKAS, ANAB, DAkkS) specifically for ISO 27701 audits.

GDPR Alignment via Annex D

Annex D (informative) provides a detailed mapping between ISO 27701 controls and GDPR articles. Key mappings:

GDPR ArticleISO 27701 Control(s)
Art. 5 (Principles)A.7.2.1, A.7.2.2, A.7.4.1-A.7.4.9
Art. 6 (Lawfulness)A.7.2.2
Art. 7 (Consent)A.7.2.3, A.7.2.4, A.7.3.4
Art. 13-14 (Information)A.7.3.2, A.7.3.3
Art. 15-22 (Data subject rights)A.7.3.1, A.7.3.5-A.7.3.10
Art. 25 (DPbD)A.7.4.1-A.7.4.5
Art. 28 (Processor)A.7.2.6, B.8.2.1-B.8.2.6
Art. 30 (Records)A.7.2.8, B.8.2.6
Art. 32 (Security)Clause 6 controls
Art. 33-34 (Breach)6.13.1.1, 6.13.1.5
Art. 35 (DPIA)A.7.2.5
Art. 44-49 (Transfers)A.7.5.1-A.7.5.4, B.8.5.1-B.8.5.8

Implementation at Sentinel Compliance Group

Sentinel Compliance Group extended its existing ISO 27001:2022 certified ISMS to ISO 27701 over a 12-month period:

  • Scope: All customer data processing operations across EU and APAC regions, covering 47 processing activities as both PII controller (23 activities) and PII processor (24 activities)
  • Gap Assessment Results: 22 of 31 Annex A controls partially implemented; 14 of 18 Annex B controls partially implemented; 7 Clause 5 gaps identified
  • Key Remediation Items: Privacy risk assessment methodology (5.4.1.2), data subject rights response procedures (A.7.3), sub-processor change management (B.8.5.7-B.8.5.8)
  • Certification Outcome: Achieved dual ISO 27001 + ISO 27701 certification via BSI, with zero major nonconformities at Stage 2 audit
  • Ongoing: Annual surveillance audits, quarterly privacy risk reviews, continuous improvement through corrective action tracking

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/iso-27701-pims of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Iso 27701 Pims next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iso 27701 Pims compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iso 27701 Pims this skillmukul975/Privacy-Data-Protection-Skills301—~4.7kAutomated safety check: PassApache-2.0
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4.2kAutomated safety check: PassMIT
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    946 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Iso 27701 Pims

What does Iso 27701 Pims do?

Guides ISO 27701 Privacy Information Management System implementation extending ISO 27001/27002. Iso 27701 Pims is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides ISO 27701 Privacy Information Management System implementation extending ISO 27001/27002.

When should I use Iso 27701 Pims?

Iso 27701 Pims fits situations like: tasks that involve SOC 2 and security compliance; tasks that involve Privacy and GDPR.

How do I install Iso 27701 Pims in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill iso-27701-pims -a claude-code`. Or copy the skill folder (skills/privacy/iso-27701-pims in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/iso-27701-pims in your project. Claude Code loads it when a task matches its description.

How do I install Iso 27701 Pims in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill iso-27701-pims -a codex`. Or copy the skill folder (skills/privacy/iso-27701-pims in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/iso-27701-pims in your project. Codex loads it when a task matches its description.

Can I use Iso 27701 Pims in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill iso-27701-pims -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iso-27701-pims, .gemini/skills/iso-27701-pims, .github/skills/iso-27701-pims and .opencode/skills/iso-27701-pims in your project.

What does Iso 27701 Pims need to run?

Going by SKILL.md and its folder, Iso 27701 Pims needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Iso 27701 Pims access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Iso 27701 Pims safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Iso 27701 Pims use?

Iso 27701 Pims is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Iso 27701 Pims use?

About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Iso 27701 Pims?

Skills that share tags, products or a category with Iso 27701 Pims: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Audit Report (harness/harness-skills, 115 stars), Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Security Compliance (sangrokjung/claude-forge, 852 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iso 27701 Pims?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.