Skip to content
IjyaLabs logo
IjyaLabs
Beta — under testing and trial. Do not use for live compliance decisions, statutory submissions, or regulatory reliance. Readiness preparation only, not a certification or audit.
🔏
BetaISO/IEC 27701:2025

ISO/IEC 27701 Privacy Readiness

Privacy Information Management System (PIMS) readiness for Controllers, Processors, and dual-role organisations. RoPA builder, DPIA trigger evaluation, multi-law gap view across GDPR, India DPDP, CCPA, and 5 more jurisdictions.

2025
Published edition
3
Roles
10
Control domains
8
Jurisdictions
Free
Sampler + RoPA
₹0
To start

This is a thematic privacy-readiness catalogue, not a clause-by-clause ISO/IEC 27701:2025 mapping. Validate applicable requirements against a licensed standard before an audit or certification programme.

Before you start — what to have ready for ISO 27701

Gather these first. Every one of them is something the assessment will ask for, and finding them mid-way is where an assessment stalls.

Decide your scope first

This module works out which controls apply to you from your answers, so complete the scope step first. Starting without it assesses a population you did not choose.

  • Which systems, services and locations are in scope — write this down before you answer anything.
  • Who owns each area, so an answer about it is somebody’s to give.
  • The period the evidence should cover, where the framework opines on a period rather than a moment.

Gather these documents

What ISO 27701 is assessed against. Find them before you start — the assessment reads what you upload, not what you tell it.

  • Privacy Information Management System (PIMS) policy
  • Record of Processing Activities (RoPA)
  • Data Processing Agreements with processors and sub-processors
  • Privacy notices given to data subjects
  • Data subject rights procedure (access, correction, deletion)
  • Personal data breach response procedure
  • DPIA / privacy risk assessments

Have the right people

Who needs to be involved, and what changes if it is only you.

  • Someone who can find the documents — usually whoever owns the control day to day.
  • A second person to review what was uploaded, if you want reviewed coverage. They must not be the person who submitted or attached that evidence: no one reviews their own work.
  • One person can complete the whole assessment. Reviewed coverage will read zero, and that is accurate rather than a fault.
  • A reviewer’s acceptance is what raises a control from partial to proven, and every workspace has that during the open beta. It becomes something a plan includes once there is anything to buy.

Prepare the files

Upload only what the assessment needs. You are responsible for removing or masking personal and sensitive data that a control does not require — do it before you upload. A RoPA and DPIAs describe processing of real people's data. Remove actual data-subject records — names, contact details, identifiers — and keep only the description of the processing itself.

  • Upload digital documents only — a Word file, a spreadsheet, or a PDF with real text. A photograph or a scanned paper has no readable text, so it cannot be assessed or prove a control.
  • A scan or a photograph has no text to read, so it cannot prove a control. Export the original instead.
  • The same file cannot be uploaded twice to one library — it is recognised by its contents, not its name.
  • Upload the document itself, not a summary of it. A summary is your description of the evidence, not the evidence.
  • A document that is not about this framework will be accepted and matched against nothing. It still counts against your library, so it is worth checking before you send it.

Know what you will get

So the result is what you expected when you started.

  • You get a readiness position derived from the evidence you upload, and a list of where the gaps are.
  • You do not get an audit, an opinion, or a certification. Only a licensed auditor, an accredited certification body, or the relevant regulator can give you those.
  • Controls you upload nothing for are reported as UNEXAMINED — not as failed. That distinction is deliberate.
  • A document can support a control without proving it. Supporting evidence raises a control to partial; reaching proven takes evidence a second person independently reviewed and accepted.
2025
Published edition
ISO/IEC 27701:2025
3
Roles covered
Controller, Processor, Both
8
Jurisdictions
GDPR, DPDP, CCPA, UK, BR, SG
₹0
Free sampler
No account needed
Catalogue scope. Thematic privacy-readiness catalogue; no clause-by-clause mapping is represented. Use this tool to identify privacy-management work. Validate applicable ISO/IEC 27701:2025 requirements against a licensed copy before an audit or certification programme.
Relationship to ISO/IEC 27001. ISO/IEC 27701 is a privacy extension to an information security management system. Under the 2025 edition it is not a hard prerequisite to hold ISO/IEC 27001 first — the PIMS requirements can be established alongside, or on top of, your existing security management system. In practice most of the security foundation a PIMS relies on is the same, so an organisation already running an ISMS has less to build.

Which role applies to you?

Controller

Determines purposes and means of PII processing

SaaS, e-commerce, healthcare apps collecting customer data

Processor

Processes PII on behalf of a controller

Cloud hosting, payroll SaaS, data analytics providers

Both

Controller for own operations + processor for clients

Most SaaS companies — typical and fully supported

5-step assessment journey

1

Profile

Organisation details, jurisdictions in scope, role determination (Controller / Processor / Both)

2

RoPA

Document processing activities, legal basis, data subjects, retention, and cross-border transfers

3

DPIA

Automatic DPIA trigger evaluation per activity. Track completion status for high-risk processing

4

Assessment

Score privacy controls 0–3. Evidence cap and critical finding detection applied automatically

5

Results

Readiness level, critical findings, domain heatmap, priority gap register, and JSON export

6

Evidence Library

Upload documents once — each is checked against every control that applies to your declared role. Answers are a claim; uploaded evidence is what produces a proof-backed position

Multi-jurisdiction coverage

GDPR (EU/EEA)India DPDP Act 2023CCPA/CPRA (California)UK GDPRLGPD (Brazil)PDPA (Singapore)Privacy Act (Australia)PIPL (China)
Important: This platform provides a self-assessed readiness indicator. It does not constitute ISO/IEC 27701 certification, legal advice, or a regulatory determination. Role classification (Controller / Processor) is a recommendation requiring confirmation by qualified legal counsel or a DPO. Certification requires independent Stage 1 and Stage 2 audits by a UKAS, NABCB, or equivalent accredited certification body.