Privacy and Data Protection

Privacy credentials cover both the legal obligations of the GDPR and the management system practice of ISO/IEC 27701, the privacy information management extension to ISO/IEC 27001. This domain is aimed at data protection officers, privacy professionals, and anyone whose organization processes personal data at a scale that attracts regulatory attention — which, under the GDPR, is a lower threshold than many organizations expect.

Courses

7

Standards

2

Languages

9

From

€299

Who this is for

  • Data protection officers, whether appointed or in preparation
  • Privacy and legal professionals implementing GDPR compliance
  • Security managers extending an ISMS to cover privacy
  • Auditors assessing privacy information management systems

Standards in this category

GDPRISO/IEC 27701

Credential levels available

Certified Data Protection OfficerFoundationLead AuditorLead ImplementerTransition

Not sure which level fits your role, or what experience a designation requires? See the full certification-criteria reference →

Frequently asked questions

When is an organization required to appoint a Data Protection Officer?

Under the GDPR a DPO is mandatory for public authorities and bodies, for organizations whose core activities involve large-scale regular and systematic monitoring of individuals, and for those whose core activities involve large-scale processing of special category or criminal conviction data. Many organizations outside those categories appoint one voluntarily.

How does ISO/IEC 27701 relate to the GDPR?

ISO/IEC 27701 is a privacy information management standard that extends ISO/IEC 27001, giving organizations a certifiable framework for managing personal data. It maps usefully onto GDPR obligations and provides structured evidence of accountability, but certification is not itself GDPR compliance — the regulation applies regardless.

Should I take the GDPR course or ISO/IEC 27701?

Take the GDPR courses if your focus is the legal obligations — lawful basis, data subject rights, transfers, breach notification, and the DPO role. Take ISO/IEC 27701 if your focus is building an auditable privacy management system, particularly where an ISO/IEC 27001 system already exists.

Is the Certified Data Protection Officer credential recognized?

It is a PECB personal certification and is recognized internationally. The GDPR itself does not mandate any particular qualification for DPOs, requiring instead expert knowledge of data protection law and practice — which is what the credential evidences.

Do I need a legal background?

No. The courses cover the legal framework from the ground up and are routinely taken by security, IT and compliance professionals as well as lawyers.