Cianaa Training

ISO 27701 Training: Privacy Information Management Courses

Build practical ISO 27701 competency with expert-led training covering Privacy Information Management System (PIMS) implementation, privacy risk management, and integration with ISO 27001.

ISO/IEC 27701:2025
GDPR + ANZ Privacy Acts
Privacy & security practitioners
GDPR-mapped
Standard ISO/IEC 27701:2025
Privacy Information Management
Extends ISO 27001 with Annex A + B
31
Controllers (A)
18
Processors (B)
GDPR
EU Regulation
ANZ
Privacy Acts
Aligned to GDPR + AU + NZ Privacy Acts
Privacy practitioners
Security + privacy expertise combined
Trusted by privacy teams across ANZ
About This Course

ISO 27701 Training from Cianaa

ISO/IEC 27701:2025 — now a standalone standard in its latest edition — addresses Privacy Information Management, providing a structured framework for managing personal data in compliance with privacy regulations including GDPR, the Australian Privacy Act, and New Zealand’s Privacy Act 2020. As privacy obligations grow more demanding, organisations need teams who can implement and operate a credible Privacy Information Management System (PIMS).

Cianaa’s ISO 27701 training is delivered by professionals with both information security and privacy expertise. Our courses are designed for teams already familiar with ISO 27001 who need to extend their ISMS to cover privacy, as well as privacy professionals new to the ISO standards model.

Course highlights

  • Covers ISO/IEC 27701:2025 in full
  • Addresses integration with ISO 27001 ISMS
  • Covers PII controller and processor requirements
  • Aligned to GDPR, Australian Privacy Act, and NZ Privacy Act 2020
  • Delivered by privacy and information security practitioners
  • Available on-site, live virtual, or public cohort
  • Certificate of completion for all participants
Training Paths

Four certification paths — choose by role and depth.

2-Day · Awareness

Foundation

  • PIMS concept & ISO 27701 structure
  • Privacy regulation overview
  • Annex A + B at a high level
  • Privacy terminology
For: Anyone needing PIMS awareness
Format: Virtual or on-site
Enquire about Foundation
3-Day · Auditing

Internal Auditor

  • Plan combined ISMS+PIMS audits
  • Privacy audit techniques
  • Nonconformity & CAR management
  • Evidence gathering for PIMS
For: Internal Auditors, Privacy Compliance
Format: Virtual / on-site / public
Enquire about Internal Auditor
5-Day · Certification

Lead Auditor

  • Lead combined 27001/27701 audits
  • IRCA-aligned methodology
  • Stage 1 + Stage 2 audit process
  • Regulatory mapping checks
For: Lead Auditor Candidates, consultants
Format: Public cohort or on-site
Enquire about Lead Auditor
Course Modules

What This Training Covers

Our ISO 27701 training modules cover the full PIMS framework — from extending ISO 27001 through to controller/processor requirements and regulatory mapping.

ISO 27701 Structure & Purpose

Relationship to ISO 27001, the PIMS concept, and how ISO 27701 maps to global privacy regulations.

PII Controller Requirements

Extended ISO 27001 controls for organisations acting as PII controllers — consent, purpose limitation, and data subject rights.

PII Processor Requirements

Controls for organisations processing PII on behalf of controllers — contracts, instructions, and sub-processor management.

Privacy Risk Assessment

Extending the ISO 27001 risk process to cover privacy risks, privacy impact assessments, and regulatory exposure.

Annex A & B Controls

Detailed coverage of the ISO 27701 Annex A (controller) and Annex B (processor) privacy-specific control sets.

Integration with ISO 27001

How to extend an existing ISMS to incorporate PIMS requirements without duplicating governance structures.

Privacy Governance

Privacy policies, privacy notices, data retention schedules, and accountability frameworks.

Regulatory Mapping

How ISO 27701 maps to GDPR, Australian Privacy Act, and NZ Privacy Act 2020 obligations.

Certification Preparation

ISO 27701 audit process, combined 27001/27701 certification, evidence requirements, and common findings.

Delivery Options

How This Training Is Delivered

Cianaa offers flexible delivery options to suit your team’s schedule, size, and location.

On-Site Classroom

Instructor-led training delivered at your premises. Ideal for teams of 6+ who benefit from group discussion and hands-on exercises in a shared environment.

Live Virtual

Instructor-led sessions delivered online via video conference. Fully interactive with Q&A, breakout exercises, and real-time engagement with the trainer.

Public Scheduled Courses

Join a scheduled open cohort alongside participants from other organisations. Ideal for individuals or small teams who want to learn alongside peers from different sectors.

Who Should Attend

Who Is This Training For?

ISO 27701 training is relevant for privacy, security, compliance, and risk professionals involved in implementing or operating a PIMS.

Data Protection Officers (DPOs)

DPOs using ISO 27701 to build a structured, auditable privacy management programme.

Privacy & Compliance Teams

Professionals managing privacy obligations under GDPR, Australian Privacy Act, or NZ Privacy Act.

Information Security Managers

ISMS managers extending their ISO 27001 programme to incorporate privacy management requirements.

IT & Data Engineering Teams

Technical staff implementing privacy-by-design and privacy controls in systems and data pipelines.

Legal & Risk Professionals

Lawyers and risk managers working on data protection compliance, vendor contracts, and breach response.

Internal Auditors

Auditors developing competency to assess PIMS effectiveness as part of combined ISMS/PIMS audit programmes.

FAQ

Frequently Asked Questions

Do we need ISO 27001 before implementing ISO 27701?
ISO 27701 is designed as an extension to ISO 27001 — it requires an existing ISMS as its foundation. You don’t need to be ISO 27001 certified before starting ISO 27701, but you do need an operational ISMS in place. Our training covers how to implement both together for organisations starting from scratch.
Does ISO 27701 certification demonstrate GDPR compliance?
ISO 27701 is explicitly designed to be mappable to GDPR — and the standard includes a GDPR mapping in its normative annexes. However, ISO 27701 certification is not a formal legal determination of GDPR compliance. It demonstrates you have systematic controls in place that align with GDPR obligations.
Is this course suitable for Australian and New Zealand organisations?
Yes. Our training specifically covers how ISO 27701 maps to the Australian Privacy Act 1988 (APP framework) and the New Zealand Privacy Act 2020, making it particularly relevant for organisations operating in the Asia-Pacific region.
Can we combine ISO 27701 certification with ISO 27001?
Yes — ISO 27701 certification is typically achieved through a combined audit with ISO 27001, conducted by the same certification body. This is the most efficient approach and is how most organisations pursue ISO 27701. Our training prepares teams for this combined audit process.
★ Official PECB Partner

Certified Through PECB

Cianaa delivers ISO/IEC 27701 training as a partner of PECB, a globally recognized certification body. Our courses follow the official PECB curriculum, and your credential is issued and recognized worldwide.

View on PECB ↗
Ready when you are

Build Your Privacy Management Competency

Enquire about ISO 27701 training for your team — from PIMS awareness through to implementation and certification preparation.

No obligation · ANZ-based team · Response within 1 business day

Other training your team might need

See all training →
ISO 27001

Information Security Management

The ISMS foundation that ISO 27701 extends — required base for PIMS implementation.

View course
PCI DSS

Payment Card Security

PCI DSS v4.0 training for teams handling cardholder data — complements privacy programmes.

View course
All courses

Browse Cianaa Training

Explore Cianaa’s full training catalogue across cybersecurity, ISO standards, and compliance.

View all training