
Useful information about this course and its structure
Generic information about the concept of privacy and how it shoud be regarded in the context of our society
Definitions for key privacy concepts used throughout the course, including PII processing, PII principlals, PII processors and PII controllers
A short presentation of 11 key principles that should be considered in the design of any privacy programme
General information about ISO/IEC 27701, including its history, its structure and its relationship with ISO/IEC 27001 and ISO/IEC 27002
A presentation of the relationship between ISO/IEC 27701 and the GDPR including similarities and differences
Details about the certification of organizations for their PIMS according to ISO/IEC 27701 and the certification of individuals as evidence of competence in the field of privacy information management
Generic information about the management system requirements in ISO/IEC 27701:2025
About the identification of internal and external issues that make up the context of the organization and can have an impact on the PIMS
About the needs and expectations of stakeholders and their identification
Generic requirements about the establishment, implementation, maintenance and continual improvement of the PIMS
About the content of the privacy policy and its implementation
About the assignment and communication of roles and responsibilities relevant for privacy protection
Information about the privacy risk assessment, including methodology and its application
More details about the process of risk assessment, including risk identification, analysis and evaluation
About the options available for treating privacy risks and their implementation through controls
Two key documents of the privacy information management system, the SoA (Statement of Applicability) and the Risk treatment plan
Requirements for the privacy objectives and how to plan for their achievement
The organization must identify and provide the resources needed for the PIMS
Details about the process to ensure competence for those who work for the organization and may impact its privacy performance
The organization must ensure adequate privacy awareness for employees and other parties that may affect its privacy performance
The internal and communications relevant for privacy information management must be effective
What the PIMS documentation shall include and how this documentation can vary from one organization to another
Create, update, and control documented information with clear titles, issue or revision dates, and author ownership; ensure format and media, review, approval, version control, access, and retention and disposal.
General aspects about establishing and controlling the processes of the PIMS
The organization must conduct privacy impact assessments at planned intervals and in case of significant changes and implement the risk treatment plan
The privacy performance and the PIMS must be monitored and measured with adequate KPIs
The oragnization shall conduct internal audits of the PIMS at planned intervals
Top management must review the PIMS regularly to ensure its continuing suitability, adequacy and effectiveness
How the organization's privacy performance and the PIMS can be improved continually
About the process to manage nonconformities and address their root causes with corrective actions
A recapitulation of the management system requirements in ISO/IEC 27701:2025
Generic information about the controls for PII controllers in ISO/IEC 27701
The organization must have a clear identification of the purpose for PII processing
All processing of personal data must have a legal basis that is clearly identified
About the process for obtaining consent from PII principals
How consent must be recorded and which are the requirements to ensure that consent from PII principals is valid
The organization must determine whehter a Privacy Impact Assessment is required and conduct the assessment
There should be written agreements signed with all PII processors engaged by the organization
The organization must clarify responsibilities whenever there are multiple PII controllers participating in the processing of personal data
About keeping records of PII processing the demonstrate compliance
The organization must have a very good understanding of its obligations towards PII principals
The information that should be provided to PII principals must be clearly identified
The organization should provide information to PII principals in accessible and easy to understand form
PII principals should be able to withdraw or modify consent for PII processing
The organization should make available to individuals a mechanism to object to personal data processing
PII principals should be provided with access to their PII, including options to correct or erase personal data
The organization must identify its obligations in relation to informing third parties relevant for data processing
Whenver possible the organization should be able to provide PII principals with a copy of their PII
There should be a process in place to handle requests from PII principals including complaints
Whenver decisions are made based solely on automated PII processing the organization should follow the provisions of the relevant legislation
The collection of PII must be limited to what is strictly necessary to achieve the intended processing purpose
The organization must limit the processing of PII to the minimum that is strictly necessary considering the processing purpose
PII must remain accurate over time to prevent processing errors
The organization must define and pursue PII minimization objectives, such as PII de-identification
Whenver PII is no longer needed it should be de-identified and deleted according to procedures
The organization must ensure that temporary files are removed when no longer necessary
There should be rules in place for the retention of PII. The organization must document retention schedules
The organization must dipose of PII securely when no longer needed
The organization must have clear rules for PII transmission to prevent data interception
There should be a clear documented legal basis for transferring PII between jurisdictions
The organization must identify the countries and international organizations where PII can be transferred as part of normal operations
There should be a record of PII transfers kept for traceability and accountability reasons
The organization must maintain records of PII disclosures to third parties
A recapitulation of the privacy controls for PII controllers in ISO/IEC 27701:2025
General aspects about the privacy controls that PII processors should implement as part of the PIMS
There should be a contract with every customer for which the organization processes PII and the responsibilities of each party must be documented in the contract
The organization must be be aware of the processing purpose and support its customer in fulfilling their obligations
The PII processor must not use PII processed for a customer for marketing and advertising unless proper consent has been obtained from PII principals
The PII processor should notify its customer whenever a processing instruction does not comply with legal requirements
The PII processor must support its customer in meeting their obligations
The PII processor should keep adequate records in relation to PII processing
The PII processor should support its customer in meeting their obligations toward PII principals
The PII processor must ensure that temporary files do not become a source of PII disclosure
The PII processor must return, transfer or dispose of PII when no longer needed, in accordance with the customer's requirements
The PII processor must submit PII transmitted over a network to adequate controls as agreed with its customer
There should be a solid legal basis for transferring PII between jurisdictions
The PII processor must document the list of countries and international organizations to which PII can be transferred and make this list available to customers
Maintain detailed records of every personal information disclosure to third parties, noting data, recipients, dates, whether routine or legally required, and the source and issuing authority for traceability.
The PII processor must notify its customer about any requests to disclose PII
The PII processor must reject all non-binding PII disclosure requests and inform its customer before disclosing any PII to third parties
The PII processor must disclose to its customer all subcontractors used to process PII
The PII processor must have an established process for engaging a subcontractor to process PII and inform its customer before the subcontractor starts processing PII
The customer must be informed about any changes of subcontractors and have the right the object to the change
A recapitulation of the privacy controls for PII processors in ISO/IEC 27701:2025
Tailor information security requirements in supplier agreements for PII processing, establishing measures and audit provisions. Ensure subcontractors uphold encryption at rest and in transit.
Managers and information owners regularly verify that policies for processing PII are followed, supporting a two-layer accountability with independent reviews.
Enforce clear desk and clear screen rules from ISO 27701 to minimize printed PII and secure unattended devices, reducing the risk of accidental data disclosure.
Manage storage media containing PII across its lifecycle, from acquisition to disposal, according to the organization's classification scheme. Encrypt removable media storing PII and document use, transfers, and disposal procedures.
Learn how to securely dispose of or repurpose equipment containing PII by validating data removal, applying secure wiping or cryptographic erasure, and removing labels before disposal or reuse.
Logging supports accountability, incident detection, and forensic analysis by recording who accessed PII, what actions occurred, when, and enforcing retention, de-identification, and integrity controls.
Explore how ISO 27701 integrates privacy by design and privacy by default into the secure development lifecycle, emphasizing pii processing, risk assessments, controls, and privacy checkpoints.
Identify, specify, and approve security requirements for PII processing in internal and external applications before use, including encryption, strong authentication, and access controls, derived from risk, obligations, and stakeholder expectations.
Embed privacy by design into system architectures for PII processing, applying least privilege, defense in depth, and fail securely to minimize data risks.
Explore how ISO 27701's test information control safeguards personal data by prioritizing synthetic data for testing and, when real PII is necessary, applying production-level protections.
Navigate ISO/IEC 27701’s privacy information management system, its 78 controls, and the controller‑vs‑processor roles, now as a standalone standard with implications for security practices.
ISO/IEC 27701 is the international standard for privacy information management systems (PIMS) — and with its 2025 revision, it became a standalone standard, no longer just a privacy extension to ISO/IEC 27001. It defines the management system requirements and privacy controls for any organization that processes personally identifiable information (PII), whether as a PII controller, a PII processor, or both — regardless of size, sector or jurisdiction.
Data privacy is not just an IT issue; it is a business imperative. According to IBM's Cost of a Data Breach report, the average breach now costs over $4.4 million, and privacy regulation keeps tightening worldwide — the EU's GDPR, California's CCPA/CPRA, and dozens of national laws. ISO/IEC 27701 is the globally recognized framework that helps organizations structure their response to all of them.
Course structure
The course takes you from fundamentals to implementation in five sections:
Introduction to privacy — core concepts and definitions, privacy principles, and the position of ISO/IEC 27701 within the ISO/IEC 27000 series
Management system requirements — a deep dive into the PIMS requirements: context of the organization, leadership, planning, support, operation, performance evaluation and continual improvement
Controls for PII controllers — a detailed breakdown of the 31 privacy controls for organizations that determine the purposes and means of processing: obligations toward PII principals, privacy by design and by default, conditions for collecting and processing personal data, and requirements for sharing and transferring PII
Controls for PII processors — the specific controls for organizations that process personal data on behalf of, and according to the instructions of, their customers
Information security controls — 29 controls protecting personal data, including information classification and labelling, cryptography, incident management, access rights, backups, logging, and secure development of software and systems
What you can do with this knowledge
Launch or advance a career as a privacy consultant or Data Protection Officer (DPO)
Participate in internal and external PIMS audits
Extend an existing ISO/IEC 27001 information security management system (ISMS) to cover privacy — or implement a PIMS on its own, as the 2025 revision now allows
Lead the implementation of a PIMS in your organization
Understand precisely how ISO approaches the processing of personally identifiable information
Who this course is for
Privacy professionals, DPOs and aspiring DPOs building standards-based expertise
Information security professionals and ISO/IEC 27001 practitioners adding privacy to their scope
Compliance and legal teams structuring GDPR and multi-jurisdiction privacy compliance
Consultants and auditors working with privacy information management systems
Organizations and professionals transitioning from the previous edition of ISO/IEC 27701
By the end of the course you will understand what a PIMS is, how its requirements and controls fit together, and how to apply ISO/IEC 27701 in practice — for your organization or your career.