Visão Geral
O curso ISO 27701 Privacy Management tem como objetivo capacitar profissionais na implementação, manutenção e melhoria de um Sistema de Gestão de Informações de Privacidade (PIMS – Privacy Information Management System), com base na norma ISO/IEC 27701. O treinamento aborda práticas de proteção de dados pessoais, governança de privacidade e conformidade com regulamentações como LGPD e GDPR, integrando-se ao Sistema de Gestão de Segurança da Informação (SGSI).
Conteúdo Programatico
Module 1 – Introduction to Privacy Information Management (PIMS)
- Overview of ISO/IEC 27701 standard
- Relationship with ISO/IEC 27001 and ISO/IEC 27002
- Privacy principles and concepts
- Personally Identifiable Information (PII) fundamentals
- Roles: PII Controller and PII Processor
Module 2 – PIMS Requirements and Framework
- Structure of ISO/IEC 27701
- Extension of ISO/IEC 27001 requirements
- Organizational context for privacy
- Leadership and governance in privacy
- Scope definition for PIMS
Module 3 – Privacy Risk Management
- Identifying privacy risks
- Privacy impact assessment (PIA/DPIA)
- Risk analysis and evaluation
- Risk treatment strategies
- Integration with ISMS risk management
Module 4 – Controls for PII Controllers
- Control objectives for PII controllers
- Consent and lawful basis management
- Data subject rights handling
- Data minimization and purpose limitation
- Third-party data sharing controls
Module 5 – Controls for PII Processors
- Processor obligations and responsibilities
- Data processing agreements
- Instructions from controllers
- Data protection measures
- Incident handling and breach notification
Module 6 – Data Lifecycle Management
- Data collection and classification
- Storage and protection of PII
- Data retention and deletion
- Data transfer (cross-border considerations)
- Data anonymization and pseudonymization
Module 7 – Compliance and Legal Frameworks
- Overview of GDPR requirements
- Overview of LGPD requirements
- Mapping ISO 27701 with regulations
- Audit and compliance verification
- Documentation and evidence management
Module 8 – Monitoring, Audit, and Continuous Improvement
- Performance evaluation of PIMS
- Internal audits for privacy
- Management review
- Continuous improvement practices
- Incident response and lessons learned