Training Module
Operational Privacy Controls
Implement role-based privacy controls & data subject rights handling within an ISO/IEC 27701-aligned PIMS
Training module overview
ISO/IEC 27701 requires privacy controls to be defined, assigned, executed, and evidenced. The real challenge is not documenting controls, but making them work in daily operations.
This module focuses on implementing and sustaining operational privacy controls and data subject rights processes within a Privacy Information Management System (PIMS). Participants learn how to translate ISO/IEC 27701 role-based requirements for PII controllers and processors into workflows, ownership models, documented procedures, and reliable records.
The emphasis is on operational clarity: clear responsibilities, structured handoffs, consistent request handling, and traceable evidence that controls are functioning as intended.
Applicable environments
This module applies to organisations implementing or operating a Privacy Information Management System (PIMS) in line with ISO/IEC 27701. It focuses on how the standard’s requirements are interpreted and applied in practice within real organisational contexts.
The content is relevant for organisations seeking certification as well as for those using ISO/IEC 27701 as a reference framework to structure responsibilities, processes, and controls in the data protection domain.
Target audience
People involved in implementing, operating, or improving a PIMS aligned with ISO/IEC 27701
Executives and department heads accountable for the effectiveness and performance of a PIMS
Those responsible for processes, policies, IT systems, risks, and controls related to data protection
Auditors of ISO/IEC 27701 who want to deepen their understanding of management-side best practices (not audit technique)
Decision support
Is this module for you?
It is a good fit if you…
need to operationalise privacy controls across real workflows.
want clear role-based handling of data subject rights.
need consistent evidence for privacy controls in daily operation.
coordinate privacy execution across teams and suppliers.
support audit-ready, repeatable privacy operations in a PIMS.
If most of the points above apply, this module is likely a good fit.
It may not be the best fit if you…
are looking for privacy fundamentals or role definitions.
want DPIA methods or risk assessment logic.
expect legal interpretation or jurisdiction-specific guidance.
already run mature, stable operational privacy controls at scale.
Agenda
Operationalising ISO/IEC 27701 controls in a stand-alone PIMS
From control statements to workflows and evidence
Controller controls: operating patterns
Processor controls: operating patterns
Supplier and sub-processor interfaces
Data subject rights handling as a managed process
Special cases and failure modes
Sustaining operational controls over time
Technology as an enabler
Case-based workshop
Show detailed agenda...
Learning outcomes
Key outcomes
Operationalise ISO/IEC 27701 controls in a stand-alone PIMS
Design and run a structured data subject rights process
Establish and govern privacy control interfaces across roles and suppliers
Additional capabilities
Define proportionate, auditable evidence
Manage complex DSAR cases
Clarify controller and processor operating patterns
Maintain control effectiveness as environments change
Additional benefits
Learning materials
Slide deck
Participant workbook
Templates & tools
Practical, reusable artefacts to apply the module directly to your organisation.
Control register template
Control to workflow mapping sheet
Adjustable DSAR process
DSAR intake & triage checklist
DSAR documentation template
Supplier interface & assistance checklist
Confirmation
Certificate of completion
Module ID
HAM-DP-S-03
Discipline
ISO clause
8: Operation
Audience
Manager
Languages
English
Delivery
Live virtual
Duration
7 h
List price
CHF 550
Excl. VAT. VAT may apply depending on customer location and status.
Delivery & learning format
Virtual live teaching
This module is delivered live, with a strong focus on discussion, practical application, and direct interaction with the instructor.
Sessions work through realistic examples, clarify concepts in context, and apply methods directly to participants’ organisational realities.
Custom delivery options
For organisations with specific constraints or learning objectives, the module can be adapted in format or scope, including in-house delivery and contextualised case material.
For an optimal learning experience
Preparation guidance
This module is designed as part of a modular training approach. Topics are deliberately distributed across modules and are not repeated in full, in order to avoid unnecessary redundancy. Each module is self-contained and can be taken on its own. Where prior knowledge or experience is helpful, this is indicated below so you can decide whether any preparation is useful for you.
Assumed background
This module assumes participants can already work with core privacy concepts and can navigate their organisation’s processing reality.
Helpful background includes:
Basic privacy / data protection concepts and terminology (PII, processing, recipients, retention, disclosure)
Clarity on processing context, roles, and scope artefacts (at least at a high level)
Familiarity with internal workflows and systems where PII is handled (ticketing, CRM, HRIS, support tooling, shared drives)
Preparatory modules
Foundational modules (depending on background)
Useful if you are new to the underlying concepts or want a shared baseline before attending this module.
Supporting modules (optional)
Helpful if you want to deepen related skills, but not required to participate effectively.


