ISO/IEC 27701:2025 – Privacy Management Step by Step

Build a certifiable Privacy Information Management System (PIMS) using the ISO 27701:2025 standalone standard

This course contains the use of Artificial Intelligence.

What you’ll learn

  • Implement a complete PIMS aligned to all ISO 27701:2025 clauses and controls.
  • Conduct privacy risk assessments, DPIAs, Transfer Impact Assessments, and FRIAs for AI.
  • Design privacy governance structures with named executive accountability.
  • Build multi-jurisdictional privacy policies and procedures from scratch.
  • Manage data subject rights across GDPR, AI Act, and global privacy regulations.
  • Establish a PII inventory, data mapping, and classification framework.
  • Audit your PIMS, manage findings, and drive continuous improvement.
  • Prepare for standalone or integrated ISO 27701:2025 PIMS certification.

Course Content

  • Introduction –> 2 lectures • 13min.
  • Foundations & Context –> 3 lectures • 17min.
  • Scope & Leadership –> 2 lectures • 13min.
  • PII Discovery & Classification –> 2 lectures • 11min.
  • PII Lifecycle Management –> 3 lectures • 17min.
  • Privacy Risk Management –> 3 lectures • 21min.
  • Impact Assessments –> 2 lectures • 10min.
  • Privacy Operations –> 2 lectures • 11min.
  • Data Subject Rights & Consent –> 2 lectures • 6min.
  • Auditing & Findings –> 2 lectures • 9min.
  • Monitoring & Incident Management –> 2 lectures • 13min.
  • Advanced Topics & Certification –> 3 lectures • 25min.

ISO/IEC 27701:2025 – Privacy Management Step by Step

Requirements

This course contains the use of Artificial Intelligence.

Privacy is no longer optional. With over 144 countries having data protection laws, GDPR fines exceeding €5.5 billion, and the EU AI Act in full effect, organizations need a systematic, certifiable approach to privacy management.

ISO/IEC 27701:2025 is the international standard for Privacy Information Management Systems (PIMS). In October 2025, it was elevated to a standalone certifiable standard — organizations can now achieve PIMS certification independently, without ISO 27001.

This course takes you step by step through a complete PIMS implementation using a realistic model company — DataTrust Solutions, a SaaS provider operating across 4 countries and processing data for 12,000+ customer organizations.

 

What You Will Build

  • A scoped, leadership-accountable Privacy Information Management System
  • A comprehensive PII inventory, data map, and classification framework
  • Privacy risk assessments, DPIAs, Transfer Impact Assessments, and FRIA for AI
  • Multi-jurisdictional privacy policies, data subject rights procedures, and consent frameworks
  • An internal audit programme and privacy incident management process
  • A full certification readiness checklist for ISO 27701:2025

Course Highlights

  • Covers all 12 implementation steps across 12 sections and 28 lectures (~9 hours)
  • Real-world case study: DataTrust Solutions faces GDPR, AI Act, cross-border transfers, and more
  • Covers both standalone and integrated (with ISO 27001:2022) PIMS paths
  • Includes AI and privacy management, multi-jurisdictional compliance, and breach management
  • Aligned to ISO 27701:2025, GDPR, EU AI Act, and global privacy frameworks
  • Prepares you for external certification audit under ISO 27706:2025
Get Tutorial