Privacy & data protection
Privacy stopped being a legal department problem some years ago. These certifications cover the management system that operationalizes it and the regulatory expertise that keeps you defensible.
A management system, and the law it has to satisfy
ISO/IEC 27701 gives you the operating structure. GDPR and its regional cousins give you the obligations. Doing one without the other is how organizations end up with excellent documentation and an enforcement action anyway.
Privacy information management
The extension to ISO/IEC 27001 that turns an ISMS into a privacy management system.
Where it connects
Privacy leans on the information security family — most 27701 candidates hold 27001 first.
27701 assumes 27001
ISO/IEC 27701 is written as an extension, not a standalone standard. You can take the training without prior 27001 certification, but the content will keep referring to controls and clauses you're meeting for the first time. If you're starting from zero, 27001 Foundation first is the shorter road.
-
Extension, not replacement27701 builds on the ISMS you already have rather than duplicating it
-
Recognized DPO credentialPECB's GDPR certification maps to the Data Protection Officer role defined in Article 37
-
Multi-jurisdiction realityContent covers GDPR in depth with the concepts that transfer to PIPEDA and similar regimes
-
Cross-functional cohortsPrivacy work spans legal, security and engineering — group bookings put them in the same room
Foundation to Lead — pick the one that matches the job
Not every standard offers every level, but where they exist the ladder is consistent. Choose by the work you'll do, not by which title sounds most senior.
Three ways to take any course
Same accreditation, same exam, same certificate. The difference is how much structure and instructor access you want along the way.
Self-study
Course materials and exam voucher, worked at your own pace. The lowest-cost route, and a reasonable one if you already work in the subject.
Browse self-studyeLearning
Recorded instruction with structured modules and assessments. Fits around a working week without needing fixed dates.
Browse eLearningLive online
Scheduled cohorts with a practising instructor you can question in real time. The format most people pass first time with.
See upcoming datesEvery course in this category
5 courses. Current pricing, delivery formats, languages and the full session calendar are on each course page.
Before you enrol
Not formally for the training or the exam. Practically, yes — 27701 is an extension standard and the material assumes you know how an ISMS is structured. If 27001 is unfamiliar, take its Foundation course first. It's two days and it makes the 27701 content land properly.
Yes, for two reasons. GDPR applies extraterritorially to anyone processing EU residents' data, which catches most Canadian firms with any European customers. And the concepts — lawful basis, data subject rights, DPIAs, breach notification — are the template most newer privacy laws have copied.
Foundation is for people new to 27701. Transition is for people already certified against the earlier revision who need to update. Take Transition only if you already hold the previous credential.
The Lead Implementer course is built around exactly that: scoping, gap analysis, risk treatment, and the evidence a certification body will ask for. If you want hands-on help rather than training, our privacy impact assessment service is a separate engagement.
Privacy programme or privacy paperwork?
Tell us whether you're building a management system, preparing for certification, or filling a DPO role. We'll say which of these five courses actually gets you there.