Skip to content
Security / Governance, Risk & Compliance

ISO/IEC 27701 Lead Implementer (ISO/IEC 27701 Lead Implementer).

ISO/IEC 27701 Lead Implementer training allows you to develop the knowledge necessary to support your organization in establishing, implementing, managing, monitoring and maintaining a Privacy Information Management System (PIMS) based on the requirements of ISO/IEC 27701 and the guidelines of ISO/IEC 27552. During this training, you will also gain an in-depth understanding of PIMS best practices and learn how to manage and process data to ensure privacy and compliance with various data protection regimes. Once you have mastered all the necessary concepts of Privacy Information Management Systems, you can take the exam and apply for the PECB Certified ISO/IEC 27701 Lead Implementer certification.

Issues

  • Privacy Information Management System (PIMS).

  • ISO/IEC 27701 standard

  • ISO/IEC 27552

  • Privacy management

  • Data protection

  • Data protection regimes

  • Data processing

  • Privacy compliance

  • Privacy best practices

  • Compliance monitoring

  • Privacy audits

  • Continuous improvement

Benefits

  • Understand the operation of the Privacy Information Management System (PIMS) based on ISO/IEC 27701.
  • Master the concepts, approaches, methods and techniques for implementing and managing PIMS
  • They will learn how to interpret the requirements of ISO/IEC 27701 in the specific context of the organization
  • They will gain the knowledge to professionally advise organizations on best practices for managing privacy information

Who is this training for?

Privacy and data protection managers and consultants
Data Protection Officers (DPOs).
Compliance and information security specialists
Those responsible for maintaining compliance with data protection regimes

Prerequisites

  • Basic knowledge of data protection and privacy
  • Knowledge of standards from the ISO/IEC 27000 family (preferred)
  • Experience in working with management systems
  • Analytical and project management skills

Training program

01

Day 1: Introduction to ISO/IEC 27701 and PIMS Fundamentals

  • Introduction to ISO/IEC 27701 — objectives, scope, structure, relationship with ISO/IEC 27001 and ISO/IEC 27002
  • Privacy Information Management System (PIMS) — concepts, ISMS extension, PDCA cycle
  • Data protection regulations — GDPR, national legislation, sector-specific requirements, international transfers
  • Organizational context — role as controller and/or processor, data flow mapping
  • Leadership and privacy policy — management commitment, PIMS policy, roles (DPO)
  • Exercises: organizational context analysis, role identification (controller/processor), data flow mapping
02

Day 2: PIMS Requirements and Privacy Controls

  • Controls for data controllers (Annex A) — legal bases, consent, transparency, data subject rights
  • Controls for data processors (Annex B) — controller instructions, sub-processors, breach notification
  • Privacy Impact Assessment (PIA/DPIA) — methodology, criteria, privacy risk identification, remedial measures
  • Privacy by Design and Privacy by Default — principles, implementation in business processes and IT systems
  • Records of processing activities — GDPR Art. 30 requirements, structure, maintenance, documentation
  • Exercises: conducting a Privacy Impact Assessment (PIA), developing records of processing activities
03

Day 3: PIMS Implementation and Data Subject Rights Management

  • Data subject rights management — access, rectification, erasure, portability, objection, profiling
  • Consent management — mechanisms for obtaining, withdrawing, documenting consent, preference management
  • Data breach management — detection, assessment, notification (72h), and documentation procedures
  • International data transfers — legal bases, Standard Contractual Clauses (SCC), Binding Corporate Rules (BCR)
  • Privacy training and awareness — program for building a data protection culture, team competencies
  • Exercises: designing a data subject rights handling procedure and breach management process
04

Day 4: Monitoring, Audit, and PIMS Continuous Improvement

  • Compliance monitoring — privacy KPIs, metrics, PIMS internal audits, management review
  • Nonconformity management — identification, root cause analysis, corrective actions, DPO reporting
  • PIMS continuous improvement — lessons learned, PIA updates, adaptation to regulatory changes
  • PIMS integration with ISMS — shared controls, extended objectives, integrated audit
  • PIMS certification preparation — certification requirements, cooperation with the certification body
  • Exercises: designing a privacy audit program, PIMS maturity analysis
05

Day 5: PECB Exam Preparation

  • ISO/IEC 27701 requirements summary — review of key PIMS concepts and controls
  • Global regulations — GDPR, CCPA, LGPD, APPI, comparison of requirements and approaches
  • Case studies — PIMS implementation analysis in organizations of various scales and industries
  • PECB certification preparation — exam format, question types, passing strategies
  • Practice exam — PECB Certified ISO/IEC 27701 Lead Implementer exam simulation
  • PECB certification exam (optional) — written exam leading to PECB Certified ISO/IEC 27701 Lead Implementer certificate

Delivery Methods

Online

  • Convenience of participating from anywhere
  • Interactive live sessions with trainer
  • Materials available for 30 days
  • No travel costs

On-site

  • Direct contact with trainer and group
  • Intensive hands-on workshops
  • Networking with other participants
  • Full focus on learning

Frequently asked questions

What are the prerequisites for this training?

For ISO/IEC 27701 Lead Implementer (ISO/IEC 27701 Lead Implementer). we recommend: Basic knowledge of data protection and privacy; Knowledge of standards from the ISO/IEC 27000 family (preferred); Experience in working with management systems.

What is the format and duration of this training?

The training lasts 5 days and is available in online and on-site format. Sessions run from 9:00 AM to 4:00 PM. We can also customize the schedule to fit your team's needs.

Who is this training designed for?

This training is designed for: Privacy and data protection managers and consultants; Data Protection Officers (DPOs).; Compliance and information security specialists.

Kamil Gabryszewski
Kamil Gabryszewski Opiekun szkolenia

Request a quote

Funding Options

Check funding options for your company

Up to 80%

Development Services Database

Up to 80% funding for SMEs from EU funds

Check availability
Up to 100%

National Training Fund

Up to 100% funding for employers

Learn more

Trusted by

We train teams at Poland's largest companies

ING Bank - EITT client
mBank - EITT client
PKO Bank Polski - EITT client
PZU - EITT client
Allianz - EITT client
T-Mobile - EITT client
KGHM - EITT client
PGE - EITT client
IKEA - EITT client
InPost - EITT client
Leroy Merlin - EITT client
ZUS - EITT client

Interested in this training?

Contact us - we'll prepare an offer tailored to your organization's needs.

500+ experts
2500+ trainings available
ISO 9001 quality certified
Request Training
Call us +48 22 487 84 90