What you'll learn:
- What is a PIMS and what it should include
- The requirements of ISO/IEC 27701:2025
- The controls that PII controllers and processors should implement
- The information security controls that should be part of a PIMS
- Key privacy concepts and principles
ISO/IEC 27701 is the international standard for privacy information management systems (PIMS) — and with its 2025 revision, it became a standalone standard, no longer just a privacy extension to ISO/IEC 27001. It defines the management system requirements and privacy controls for any organization that processes personally identifiable information (PII), whether as a PII controller, a PII processor, or both — regardless of size, sector or jurisdiction.
Data privacy is not just an IT issue; it is a business imperative. According to IBM's Cost of a Data Breach report, the average breach now costs over $4.4 million, and privacy regulation keeps tightening worldwide — the EU's GDPR, California's CCPA/CPRA, and dozens of national laws. ISO/IEC 27701 is the globally recognized framework that helps organizations structure their response to all of them.
Course structure
The course takes you from fundamentals to implementation in five sections:
Introduction to privacy — core concepts and definitions, privacy principles, and the position of ISO/IEC 27701 within the ISO/IEC 27000 series
Management system requirements — a deep dive into the PIMS requirements: context of the organization, leadership, planning, support, operation, performance evaluation and continual improvement
Controls for PII controllers — a detailed breakdown of the 31 privacy controls for organizations that determine the purposes and means of processing: obligations toward PII principals, privacy by design and by default, conditions for collecting and processing personal data, and requirements for sharing and transferring PII
Controls for PII processors — the specific controls for organizations that process personal data on behalf of, and according to the instructions of, their customers
Information security controls — 29 controls protecting personal data, including information classification and labelling, cryptography, incident management, access rights, backups, logging, and secure development of software and systems
What you can do with this knowledge
Launch or advance a career as a privacy consultant or Data Protection Officer (DPO)
Participate in internal and external PIMS audits
Extend an existing ISO/IEC 27001 information security management system (ISMS) to cover privacy — or implement a PIMS on its own, as the 2025 revision now allows
Lead the implementation of a PIMS in your organization
Understand precisely how ISO approaches the processing of personally identifiable information
Who this course is for
Privacy professionals, DPOs and aspiring DPOs building standards-based expertise
Information security professionals and ISO/IEC 27001 practitioners adding privacy to their scope
Compliance and legal teams structuring GDPR and multi-jurisdiction privacy compliance
Consultants and auditors working with privacy information management systems
Organizations and professionals transitioning from the previous edition of ISO/IEC 27701
By the end of the course you will understand what a PIMS is, how its requirements and controls fit together, and how to apply ISO/IEC 27701 in practice — for your organization or your career.