Training Module

Operational Privacy Controls

Implement role-based privacy controls & data subject rights handling within an ISO/IEC 27701-aligned PIMS

Secure physical access control gates in a corporate environment, representing operational privacy controls, role-based access, and practical data subject rights handling within an ISO/IEC 27701-aligned privacy management system.

Are your privacy controls lived or just documented?

This training module teaches how to embed ISO/IEC 27701 operational controls and data subject rights handling into workflows with clear ownership and evidence.

Secure physical access control gates in a corporate environment, representing operational privacy controls, role-based access, and practical data subject rights handling within an ISO/IEC 27701-aligned privacy management system.

Are your privacy controls lived or just documented?

This training module teaches how to embed ISO/IEC 27701 operational controls and data subject rights handling into workflows with clear ownership and evidence.

Secure physical access control gates in a corporate environment, representing operational privacy controls, role-based access, and practical data subject rights handling within an ISO/IEC 27701-aligned privacy management system.

Training module overview

ISO/IEC 27701 requires privacy controls to be defined, assigned, executed, and evidenced. The real challenge is not documenting controls, but making them work in daily operations.

This module focuses on implementing and sustaining operational privacy controls and data subject rights processes within a Privacy Information Management System (PIMS). Participants learn how to translate ISO/IEC 27701 role-based requirements for PII controllers and processors into workflows, ownership models, documented procedures, and reliable records.

The emphasis is on operational clarity: clear responsibilities, structured handoffs, consistent request handling, and traceable evidence that controls are functioning as intended.

Applicable environments

This module applies to organisations implementing or operating a Privacy Information Management System (PIMS) in line with ISO/IEC 27701. It focuses on how the standard’s requirements are interpreted and applied in practice within real organisational contexts.

The content is relevant for organisations seeking certification as well as for those using ISO/IEC 27701 as a reference framework to structure responsibilities, processes, and controls in the data protection domain.

Target audience

  • People involved in implementing, operating, or improving a PIMS aligned with ISO/IEC 27701

  • Executives and department heads accountable for the effectiveness and performance of a PIMS

  • Those responsible for processes, policies, IT systems, risks, and controls related to data protection

  • Auditors of ISO/IEC 27701 who want to deepen their understanding of management-side best practices (not audit technique)

Decision support

Is this module for you?

It is a good fit if you…

  • need to operationalise privacy controls across real workflows.

  • want clear role-based handling of data subject rights.

  • need consistent evidence for privacy controls in daily operation.

  • coordinate privacy execution across teams and suppliers.

  • support audit-ready, repeatable privacy operations in a PIMS.

If most of the points above apply, this module is likely a good fit.

It may not be the best fit if you…

  • are looking for privacy fundamentals or role definitions.

  • want DPIA methods or risk assessment logic.

  • expect legal interpretation or jurisdiction-specific guidance.

  • already run mature, stable operational privacy controls at scale.

Agenda

  • Operationalising ISO/IEC 27701 controls in a stand-alone PIMS

  • From control statements to workflows and evidence

  • Controller controls: operating patterns

  • Processor controls: operating patterns

  • Supplier and sub-processor interfaces

  • Data subject rights handling as a managed process

  • Special cases and failure modes

  • Sustaining operational controls over time

  • Technology as an enabler

  • Case-based workshop

Show detailed agenda...

Learning outcomes

Key outcomes

  • Operationalise ISO/IEC 27701 controls in a stand-alone PIMS

  • Design and run a structured data subject rights process

  • Establish and govern privacy control interfaces across roles and suppliers

Additional capabilities

  • Define proportionate, auditable evidence

  • Manage complex DSAR cases

  • Clarify controller and processor operating patterns

  • Maintain control effectiveness as environments change

Additional benefits

Learning materials

  • Slide deck

  • Participant workbook

Templates & tools

Practical, reusable artefacts to apply the module directly to your organisation.

  • Control register template

  • Control to workflow mapping sheet

  • Adjustable DSAR process

  • DSAR intake & triage checklist

  • DSAR documentation template

  • Supplier interface & assistance checklist

Confirmation

  • Certificate of completion

Module ID

HAM-DP-S-03

Discipline

ISO clause

8: Operation

Audience

Manager

Languages

English

Delivery

Live virtual

Duration

7 h

List price

CHF 550

Excl. VAT. VAT may apply depending on customer location and status.

Delivery & learning format

Virtual live teaching

This module is delivered live, with a strong focus on discussion, practical application, and direct interaction with the instructor.

Sessions work through realistic examples, clarify concepts in context, and apply methods directly to participants’ organisational realities.

Custom delivery options

For organisations with specific constraints or learning objectives, the module can be adapted in format or scope, including in-house delivery and contextualised case material.

Not sure if this module is right for you?

Send a short message and describe your context.

Not sure if this module is right for you?

Send a short message and describe your context.

For an optimal learning experience

Preparation guidance

This module is designed as part of a modular training approach. Topics are deliberately distributed across modules and are not repeated in full, in order to avoid unnecessary redundancy. Each module is self-contained and can be taken on its own. Where prior knowledge or experience is helpful, this is indicated below so you can decide whether any preparation is useful for you.

Assumed background

This module assumes participants can already work with core privacy concepts and can navigate their organisation’s processing reality.

Helpful background includes:

  • Basic privacy / data protection concepts and terminology (PII, processing, recipients, retention, disclosure)

  • Clarity on processing context, roles, and scope artefacts (at least at a high level)

  • Familiarity with internal workflows and systems where PII is handled (ticketing, CRM, HRIS, support tooling, shared drives)

Preparatory modules

Foundational modules (depending on background)

Useful if you are new to the underlying concepts or want a shared baseline before attending this module.

Data Protection Principles

Privacy roles, obligations & controls in organisations, aligned with common national and international data protection requirements

7 h

Data Protection Principles

Privacy roles, obligations & controls in organisations, aligned with common national and international data protection requirements

7 h

Operational Control

Establish and run operational control with clear operating criteria, checks, records & deviation handling

7 h

Operational Control

Establish and run operational control with clear operating criteria, checks, records & deviation handling

7 h

Supporting modules (optional)

Helpful if you want to deepen related skills, but not required to participate effectively.

PII Processing: Context, Roles & Scope

Define PII processing context, determine controller and processor roles, and set practical PIMS scope boundaries under ISO/IEC 27701

7 h

PII Processing: Context, Roles & Scope

Define PII processing context, determine controller and processor roles, and set practical PIMS scope boundaries under ISO/IEC 27701

7 h

Governance Design

Define clear roles, decision rights, governance mechanisms & escalation paths in management systems

7 h

Governance Design

Define clear roles, decision rights, governance mechanisms & escalation paths in management systems

7 h

Continuous learning

Follow-up modules

After completion of this module, the following modules are ideal to further deepen your competence. If you are looking for a structured learning path, modules can also be taken as part of a professional track.

Continuous learning

Follow-up modules

After completion of this module, the following modules are ideal to further deepen your competence. If you are looking for a structured learning path, modules can also be taken as part of a professional track.

Privacy Risk & Impact Assessment (DPIA)

Assess privacy risks, reason about impacts, and document DPIAs within an ISO/IEC 27701-aligned PIMS

Duration

7 h

List price

CHF 550

View module

Privacy Risk & Impact Assessment (DPIA)

Assess privacy risks, reason about impacts, and document DPIAs within an ISO/IEC 27701-aligned PIMS

Duration

7 h

List price

CHF 550

View module

Privacy Risk & Impact Assessment (DPIA)

Assess privacy risks, reason about impacts, and document DPIAs within an ISO/IEC 27701-aligned PIMS

Duration

7 h

List price

CHF 550

View module

Policy Management

Design coherent, auditable policy frameworks that align with strategy, scale across entities, and stay current without excess bureaucracy

Duration

7 h

List price

CHF 550

View module

Policy Management

Design coherent, auditable policy frameworks that align with strategy, scale across entities, and stay current without excess bureaucracy

Duration

7 h

List price

CHF 550

View module

Policy Management

Design coherent, auditable policy frameworks that align with strategy, scale across entities, and stay current without excess bureaucracy

Duration

7 h

List price

CHF 550

View module

Monitoring & Measurement

Design and run monitoring activities and measurement methods to generate reliable performance data for evaluation and improvement

Duration

7 h

List price

CHF 550

View module

Monitoring & Measurement

Design and run monitoring activities and measurement methods to generate reliable performance data for evaluation and improvement

Duration

7 h

List price

CHF 550

View module

Monitoring & Measurement

Design and run monitoring activities and measurement methods to generate reliable performance data for evaluation and improvement

Duration

7 h

List price

CHF 550

View module

Performance Evaluation

Evaluate monitoring and measurement results, interpret trends and deviations, and summarise conclusions to support management decisions

Duration

7 h

List price

CHF 550

View module

Performance Evaluation

Evaluate monitoring and measurement results, interpret trends and deviations, and summarise conclusions to support management decisions

Duration

7 h

List price

CHF 550

View module

Performance Evaluation

Evaluate monitoring and measurement results, interpret trends and deviations, and summarise conclusions to support management decisions

Duration

7 h

List price

CHF 550

View module

Improvement Management

Build disciplined corrective action and continual improvement through root cause analysis, action planning, implementation & effectiveness verification

Duration

7 h

List price

CHF 550

View module

Improvement Management

Build disciplined corrective action and continual improvement through root cause analysis, action planning, implementation & effectiveness verification

Duration

7 h

List price

CHF 550

View module

Improvement Management

Build disciplined corrective action and continual improvement through root cause analysis, action planning, implementation & effectiveness verification

Duration

7 h

List price

CHF 550

View module

Office scene with people standing, walking and sitting

Ready to improve your management systems?

We support continuous improvement by embedding ISO requirements into everyday practice and daily operations.

Office scene with people standing, walking and sitting

Ready to improve your management systems?

We support continuous improvement by embedding ISO requirements into everyday practice and daily operations.

Office scene with people standing, walking and sitting

Ready to improve your management systems?

We support continuous improvement by embedding ISO requirements into everyday practice and daily operations.