ISO/IEC 27701 · Lead Implementer
ISO/IEC 27701 Lead Implementer: Privacy Information Management System
Master the implementation and management of a privacy information management system (PIMS) based on ISO/IEC 27701, extending an existing ISMS to cover personal data.
- Trainer-Led

Extending an ISMS to cover personal data
Most organisations that need this course already have an ISO/IEC 27001 ISMS. ISO/IEC 27701 does not replace it: it adds the controller/processor-specific controls, consent handling and data subject rights processes a privacy programme needs on top.
By the end of this course
You should be able to map an organisation's personal data flows against its existing ISMS, determine where it acts as controller versus processor, and lead it to a PIMS certification-ready state.
What you will learn
- Understand the concepts, methods and techniques for implementing and managing a PIMS based on ISO/IEC 27701
- Interpret and implement the requirements of ISO/IEC 27701 in the context of your organisation
- Plan a PIMS implementation, including scope, controller and processor roles
- Extend an existing ISO/IEC 27001 ISMS to cover privacy-specific controls
- Monitor, measure and continually improve a PIMS
- Prepare an organisation for a PIMS certification audit
Course content
1. Fundamentals of privacy information management
Concepts, principles and the relationship between ISO/IEC 27701 and ISO/IEC 27001.
2. Initiating the PIMS
Organisational context, scope, and controller/processor role determination.
3. Privacy-specific controls
Additional controls for PII controllers and processors beyond ISO/IEC 27002.
4. Operation and data subject rights
Consent, access requests, and handling personal data across its lifecycle.
5. Performance evaluation and improvement
Monitoring, internal audit, management review and continual improvement.
6. Preparing for certification
Evaluating documentation and capability, and preparing for the certification audit.
Exam and certification
Open-book written exam delivered online through PECB Exams. Duration: 3 hours.
Your fee includes your first exam attempt and one free retake within 12 months. After passing, you can apply for the relevant PECB credential.
Related courses
ISO/IEC 27001 · ISO/IEC 27002
ISO/IEC 27001 Lead Implementer: Information Security Management System
- Duration
- 40 hours
- CPD credits
- 31
ISO 22301
ISO 22301 Lead Implementer: Business Continuity Management System
- Duration
- 40 hours
- CPD credits
- 31


