Privacy and Data Protection
Privacy credentials cover both the legal obligations of the GDPR and the management system practice of ISO/IEC 27701, the privacy information management extension to ISO/IEC 27001. This domain is aimed at data protection officers, privacy professionals, and anyone whose organization processes personal data at a scale that attracts regulatory attention — which, under the GDPR, is a lower threshold than many organizations expect.
Courses
7
Standards
2
Languages
9
From
€299
Who this is for
- Data protection officers, whether appointed or in preparation
- Privacy and legal professionals implementing GDPR compliance
- Security managers extending an ISMS to cover privacy
- Auditors assessing privacy information management systems
Standards in this category
Credential levels available
Not sure which level fits your role, or what experience a designation requires? See the full certification-criteria reference →
All privacy and data protection courses€299–€850
ISO/IEC 27701
Transition
EN
2 exam attempts includedISO/IEC 27701
Lead Implementer
EN, UA, ES +2 more
2 exam attempts includedISO/IEC 27701
Lead Auditor
EN
2 exam attempts includedISO/IEC 27701
Foundation
EN, CZ
2 exam attempts includedGDPR
Foundation
EN, DE, FR
2 exam attempts includedGDPR
Certified Data Protection Officer
EN, UA, ES +4 more
2 exam attempts includedGDPR
Certified Data Protection Officer
EN, FR
2 exam attempts includedFrequently asked questions
When is an organization required to appoint a Data Protection Officer?
Under the GDPR a DPO is mandatory for public authorities and bodies, for organizations whose core activities involve large-scale regular and systematic monitoring of individuals, and for those whose core activities involve large-scale processing of special category or criminal conviction data. Many organizations outside those categories appoint one voluntarily.
How does ISO/IEC 27701 relate to the GDPR?
ISO/IEC 27701 is a privacy information management standard that extends ISO/IEC 27001, giving organizations a certifiable framework for managing personal data. It maps usefully onto GDPR obligations and provides structured evidence of accountability, but certification is not itself GDPR compliance — the regulation applies regardless.
Should I take the GDPR course or ISO/IEC 27701?
Take the GDPR courses if your focus is the legal obligations — lawful basis, data subject rights, transfers, breach notification, and the DPO role. Take ISO/IEC 27701 if your focus is building an auditable privacy management system, particularly where an ISO/IEC 27001 system already exists.
Is the Certified Data Protection Officer credential recognized?
It is a PECB personal certification and is recognized internationally. The GDPR itself does not mandate any particular qualification for DPOs, requiring instead expert knowledge of data protection law and practice — which is what the credential evidences.
Do I need a legal background?
No. The courses cover the legal framework from the ground up and are routinely taken by security, IT and compliance professionals as well as lawyers.