Training for managers/representatives/inspectors responsible for data protection/privacy in the company, preparing them to perform this function based on the latest edition of the PN-EN ISO 27701:2019 standard.
Training duration: 2 days / 16 hours
Confirmation document: "Manager of the Personal Data Protection Management System (ISO/IEC 27701:2019)" Certificate„
This is a two-day (16-hour) practice-oriented training during which:
During the training, in addition to understanding the model based on the ISO 27701 standard, you will practice selected tools useful in implementing a Personal Data Protection Management System. The trainer will advise you on what mistakes to avoid and what to pay attention to.
Who might benefit from participating in the training?:
Module I: INTRODUCTION TO THE TRAINING TOPIC
1) Introduction:
2) Introduction to ISO 27701:
Module II: DISCUSSION OF SPECIFIC PERSONAL DATA PROTECTION MANAGEMENT SYSTEM REQUIREMENTS RELATED TO ISO/IEC 27001
1) Organizational Context
2) Understanding the needs and expectations of stakeholders
3) Information security policy
4) Risk assessment
Module III: DISCUSSION OF GUIDELINES ON SPECIFIC REQUIREMENTS OF A PERSONAL DATA PROTECTION MANAGEMENT SYSTEM RELATED TO ISO/IEC 27002
1) Information security policy
2) Organization of information security
3) Human Resource Security
4) Asset Management
5) Access control
6) Cryptography
7) Physical and environmental security
8) Safe operation
9) Communication security
10) Acquisition, development and maintenance of systems
11) Supplier Relationships
12) Information Security Incident Management
13) Information security aspects in business continuity management
14) Compliance
Module IV: PERSONAL DATA PROTECTION – OVERVIEW OF ADDITIONAL ISO/IEC 27002 GUIDELINES FOR CONTROLLERS
1) General guidelines
2) Conditions of collection and processing
3) Obligations towards persons responsible for identifying PII persons
4) Risk Assessment: Privacy by Design and Privacy by Default
5) Protection of personal data - sharing, transferring and disclosing information
Module V: PERSONAL DATA PROTECTION – OVERVIEW OF ADDITIONAL ISO/IEC 27002 GUIDELINES FOR PROCESSORS
1) General guidelines
2) Conditions for the receipt and processing of personal data
3) Obligations towards clients
4) Privacy by design, Privacy by default
5) Sharing, Transferring, and Disclosure of PII
Module VI: TRAINING SUMMARY AND EXAMINATION
Training summary - effectiveness evaluation.
Exam – lasts 30 minutes and consists of two parts: a single-choice test and a descriptive part during which the recommendations of the standard and the tool must be applied.