A tailored course, built for your situation
Sources and specific examples on hand when peers push back
Build unshakable rationale for privacy and compliance decisions using ISO 27701 as your foundation
Who this is for
Senior digital marketing practitioner operating at the intersection of data use, compliance, and cross-functional scrutiny
Who this is not for
Entry-level marketers looking for GDPR basics or checklist compliance; this is for those already making real-world decisions under regulatory scrutiny
What you walk away with
- Reference specific ISO 27701 clauses when defending data collection architecture
- Map privacy controls directly to marketing campaign structures
- Deploy audit-ready documentation that anticipates reviewer questions
- Explain the 'why' behind data minimisation in tracking workflows
- Turn compliance artefacts into repeatable templates across initiatives
The 12 modules (with all 144 chapters)
- Defining defensibility in practice
- Mapping decision to clause
- Identifying reviewer hotspots
- Documenting intent at inception
- Aligning with legal disclosure timelines
- Avoiding over-collection by design
- Consent architecture patterns
- Third-party data flow mapping
- Retention triggers and rules
- Audit trail expectations
- Cross-border data movement flags
- Scenario rehearsal: live campaign launch
- What purpose limitation means
- How intent is documented
- Valid changes to purpose
- Re-consent thresholds
- Campaign expansion boundaries
- User expectation alignment
- Historical data reuse limits
- Purpose drift red flags
- Vendor purpose audits
- Logging purpose decisions
- Review cycle triggers
- Case study: abandoned cart flow
- Tracking vs. necessity
- Identifying non-essential data
- Pixel-by-pixel review
- Cookie categorisation standards
- Consent management alignment
- Downstream use constraints
- Anonymisation thresholds
- Pseudonymisation in practice
- Retention by data class
- Data sharing boundaries
- Vendor compliance checks
- Audit rehearsal: tag inventory review
- Consent as a legal basis
- Granular opt-in design
- Consent logging standards
- Withdrawal mechanisms
- Proof of consent storage
- Timing of consent requests
- Pre-checked box pitfalls
- Age verification integration
- Bulk communication rules
- Consent refresh cycles
- Jurisdictional variation handling
- Case study: email re-engagement campaign
- Processor vs. controller distinction
- Data Processing Agreement essentials
- Sub-processor disclosure rules
- Right to audit clauses
- Breach notification timelines
- Security control expectations
- Cross-border transfer mechanisms
- Onboarding checklist
- Ongoing monitoring rhythm
- Exit data handling
- Penetration test sharing
- Vendor incident response alignment
- DSAR scope definition
- Access request handling
- Correction procedures
- Deletion boundaries
- Portability formats
- Automated decision explanation
- Response timeline compliance
- Identity verification steps
- Marketing suppression sync
- Data map usage in fulfilment
- Third-party coordination
- Audit trail generation
- When a DPIA is required
- High-risk processing flags
- DPIA vs. Legitimate Interest Assessment
- Stakeholder consultation steps
- Risk mitigation mapping
- Data flow diagramming
- Third-party risk inclusion
- Retention period justification
- Breach likelihood scoring
- Public interest balancing
- Approved template usage
- Case study: influencer data campaign
- What constitutes a breach
- Internal reporting triggers
- 72-hour clock rules
- Marketing data exposure scenarios
- Customer notification thresholds
- Regulator communication templates
- Media response coordination
- Data loss vs. unauthorised access
- Forensic support needs
- Post-breach review requirements
- Temporary suspension protocols
- Re-engagement after resolution
- Retention period justification
- Campaign-specific timelines
- Automated deletion triggers
- Archival vs. erasure
- Legal hold exceptions
- Proof of deletion records
- Cross-system sync
- Vendor disposal validation
- Data minimisation review
- Auditor access to logs
- Year-end review process
- Case study: seasonal campaign wrap-up
- Translating marketing needs
- Security control trade-offs
- Legal threshold discussions
- Incident escalation paths
- Policy exception requests
- Control testing participation
- Audit preparation meetings
- Risk appetite conversations
- Budget justification using risk
- Training needs identification
- Cross-team playbook alignment
- Shared documentation standards
- Common auditor questions
- Evidence collection rhythm
- Control mapping templates
- Interview preparation
- Gap identification method
- Remediation tracking
- Vendor evidence requests
- System access logs
- Policy version control
- Training completion records
- Third-party attestations
- Pre-audit rehearsal
- Post-campaign compliance review
- Lessons learned integration
- New technology assessment
- Pilot programme governance
- Stakeholder feedback loops
- Control adaptation process
- Benchmarking against peers
- Privacy by design updates
- Team training refresh
- Policy alignment checks
- External standard updates
- Annual ISO 27701 review
How this maps to your situation
- When launching a new tracking campaign
- Before a vendor contract renewal
- During internal compliance audits
- After a data subject request surge
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: 12 weeks of deliberate, part-time engagement (30-45 minutes per module) to build durable, referenceable knowledge
How this compares to the alternatives
Unlike generic GDPR courses, this focuses on ISO 27701 as a defensible framework for marketing decisions, with real campaign examples and audit-grade documentation templates
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.