Skip to main content
GDPR & privacy

ISO 27701 Foundation

ISO 27701 Foundation. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBFoundation2 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Individuals involved in information security and privacy management who want a structured introduction to ISO/IEC 27701
  • Those seeking foundational knowledge of privacy information management system processes and principles
  • Professionals considering a career in privacy information management
  • Individuals responsible for personally identifiable information within their organisations
  • Information security team members who need to understand how privacy requirements integrate with existing security controls

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Experienced privacy officers or PIMS implementers seeking advanced implementation or audit guidance, who would benefit more from a lead-level programme
  • Those requiring deep legal analysis of specific privacy regulations rather than a standards-based management overview
  • Professionals looking for technical privacy engineering skills rather than a management system framework introduction

What you'll be able to do

  • 1Describe the fundamental concepts and principles of a privacy information management system as defined in ISO/IEC 27701
  • 2Identify the relationship between ISO/IEC 27701, ISO/IEC 27001, ISO/IEC 27002, and applicable regulatory frameworks
  • 3Explain the approaches, methods, and techniques used to implement and manage a privacy information management system
  • 4Distinguish the roles of PII controllers and PII processors within a privacy management context
  • 5Recognise how a PIMS supports compliance with privacy-related legal and regulatory obligations

Day by day

Day 1Introduction to Privacy Information Management System Concepts as Specified in ISO/IEC 27701
  • Foundational Privacy and PIMS Concepts

    Participants are introduced to key privacy terminology and the core principles that underpin a privacy information management system as described in ISO/IEC 27701.

  • Structure of ISO/IEC 27701 and Its Extensions

    The session examines how ISO/IEC 27701 extends ISO/IEC 27001 and ISO/IEC 27002 to incorporate privacy-specific controls and requirements.

  • Regulatory and Standards Landscape

    Participants explore how ISO/IEC 27701 aligns with major privacy regulatory frameworks, helping organisations demonstrate accountability for PII protection.

By end of day

  • Articulate what a privacy information management system is and why it matters to your organisation
  • Explain how ISO/IEC 27701 builds upon ISO/IEC 27001 to address privacy requirements
Day 2Privacy Information Management System Implementation Approaches and Exam Preparation
  • PIMS Implementation and Management Approaches

    This module covers the standards-based methods and practical techniques used to establish, operate, and maintain a privacy information management system.

  • PII Controller and PII Processor Obligations

    Participants examine the distinct obligations that ISO/IEC 27701 assigns to organisations acting as PII controllers versus those acting as PII processors.

  • Exam Competency Domain Review

    Facilitators review the two competency domains assessed in the PECB ISO/IEC 27701 Foundation exam to support participant readiness.

By end of day

  • Identify the practical steps involved in establishing a PIMS within an existing information security management system
  • Distinguish your organisation's role as a PII controller or processor and understand the corresponding ISO/IEC 27701 requirements

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

The exam fully meets the requirements of the PECB Examination and Certificate Programme. It covers the following competency domains:

  • Domain 1: Fundamental principles and concepts of a privacy information management system (PIMS)
  • Domain 2: Privacy information management system (PIMS)

In case candidates fail the exam, they can retake it within twelve months following the initial exam for free.

*Note: This applies only to candidates who have attended the training course.

After successfully completing the exam, you can apply for the credential shown on the table below.

The certificate requirements for the ISO/IEC 27701 Foundation are:

  • Certificate and examination fees are included in the price of the training course.
  • Training material containing over 200 pages of information and practical examples will be distributed.
  • An attestation of course completion worth 14 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free.

Why should you attend?

The ISO/IEC 27701 Foundation training course is designed to help participants understand the basic concepts and principles of a Privacy Information Management System (PIMS) based on ISO/IEC 27701. Moreover, during this training course, students will learn more on the structure of the standard including its requirements, guidance and controls on the protection of the privacy of Personally Identifiable Information (PII) principals and the relationship of the standard with ISO/IEC 27001 and ISO/IEC 27002.

After completing this training course, you can sit for the exam and, if you successfully pass it, you can apply for the “PECB Certificate Holder in ISO/IEC 27701 Foundation” certificate. A PECB Foundation certificate proves that you have comprehended the fundamental methodologies, requirements, guidelines, framework and managerial approach.

Educational approach

  • Lecture sessions are complemented by discussions questions and examples
  • The exercises include multiple-choice quizzes and essay-type exercises
  • Exercise questions and quizzes are similar to the certificate exam

Prerequisites

None

Buyers always ask

What is the difference between completing the training, passing the exam, and holding a certificate?+

Completing the two-day training means you have attended the programme. Passing the PECB examination is a separate step that tests your knowledge of the two defined competency domains.

Obtaining the ISO/IEC 27701 Foundation certificate requires meeting the credential requirements set out in PECB's Certification Rules and Policies in addition to passing the exam. Cyber Academy delivers the training; the examination and certification are managed independently by PECB.

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

Which competency domains does the ISO/IEC 27701 Foundation exam cover?+

According to PECB, the exam covers two domains: fundamental principles and concepts of a privacy information management system, and the privacy information management system itself. For details on exam format and available languages, refer to the List of PECB Exams on the PECB website.

Does a participant need prior knowledge of ISO/IEC 27001 to benefit from this course?+

Prior knowledge of ISO/IEC 27001 is not listed as a formal requirement. However, because ISO/IEC 27701 extends ISO/IEC 27001 and ISO/IEC 27002, participants who already have some familiarity with those standards will find it easier to understand how privacy controls integrate with information security management.

Participants without that background can still gain valuable foundational knowledge about privacy management principles and the PIMS framework.

How does the ISO/IEC 27701 Foundation course relate to regulatory frameworks such as the GDPR?+

ISO/IEC 27701 is designed to complement rather than replace specific privacy regulations. The training covers how the standard aligns with regulatory frameworks, helping participants understand how a PIMS can support an organisation's broader compliance obligations. It does not provide legal advice or a definitive interpretation of any specific regulation.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.