Skip to main content
Image coming soon

Sources and specific examples on hand when peers push back

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Sources and specific examples on hand when peers push back

Build unshakable rationale for privacy and compliance decisions using ISO 27701 as your foundation

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior digital marketing practitioner operating at the intersection of data use, compliance, and cross-functional scrutiny

Who this is not for

Entry-level marketers looking for GDPR basics or checklist compliance; this is for those already making real-world decisions under regulatory scrutiny

What you walk away with

  • Reference specific ISO 27701 clauses when defending data collection architecture
  • Map privacy controls directly to marketing campaign structures
  • Deploy audit-ready documentation that anticipates reviewer questions
  • Explain the 'why' behind data minimisation in tracking workflows
  • Turn compliance artefacts into repeatable templates across initiatives

The 12 modules (with all 144 chapters)

Module 1. The anatomy of a defensible decision
Break down real marketing compliance decisions into their ISO 27701-aligned components: purpose limitation, consent scope, and data lifecycle boundaries.
12 chapters in this module
  1. Defining defensibility in practice
  2. Mapping decision to clause
  3. Identifying reviewer hotspots
  4. Documenting intent at inception
  5. Aligning with legal disclosure timelines
  6. Avoiding over-collection by design
  7. Consent architecture patterns
  8. Third-party data flow mapping
  9. Retention triggers and rules
  10. Audit trail expectations
  11. Cross-border data movement flags
  12. Scenario rehearsal: live campaign launch
Module 2. Clause grounding: Purpose Limitation (ISO 27701 Section 8.2)
Anchor data handling choices in the original intent, with examples from abandoned campaigns and consent revalidation cycles.
12 chapters in this module
  1. What purpose limitation means
  2. How intent is documented
  3. Valid changes to purpose
  4. Re-consent thresholds
  5. Campaign expansion boundaries
  6. User expectation alignment
  7. Historical data reuse limits
  8. Purpose drift red flags
  9. Vendor purpose audits
  10. Logging purpose decisions
  11. Review cycle triggers
  12. Case study: abandoned cart flow
Module 3. Justifying data minimisation in tracking stacks
Show how specific tags, pixels, and IDs align with ISO 27701’s data minimisation principle using documented necessity assessments.
12 chapters in this module
  1. Tracking vs. necessity
  2. Identifying non-essential data
  3. Pixel-by-pixel review
  4. Cookie categorisation standards
  5. Consent management alignment
  6. Downstream use constraints
  7. Anonymisation thresholds
  8. Pseudonymisation in practice
  9. Retention by data class
  10. Data sharing boundaries
  11. Vendor compliance checks
  12. Audit rehearsal: tag inventory review
Module 4. Consent architecture and ISO 27701 compliance
Build systems where consent mechanisms map directly to processing activities, with clear evidence trails for each user cohort.
12 chapters in this module
  1. Consent as a legal basis
  2. Granular opt-in design
  3. Consent logging standards
  4. Withdrawal mechanisms
  5. Proof of consent storage
  6. Timing of consent requests
  7. Pre-checked box pitfalls
  8. Age verification integration
  9. Bulk communication rules
  10. Consent refresh cycles
  11. Jurisdictional variation handling
  12. Case study: email re-engagement campaign
Module 5. Vendor accountability under ISO 27701
Evaluate third-party partners using ISO 27701 criteria, with documented assessments for data processing agreements.
12 chapters in this module
  1. Processor vs. controller distinction
  2. Data Processing Agreement essentials
  3. Sub-processor disclosure rules
  4. Right to audit clauses
  5. Breach notification timelines
  6. Security control expectations
  7. Cross-border transfer mechanisms
  8. Onboarding checklist
  9. Ongoing monitoring rhythm
  10. Exit data handling
  11. Penetration test sharing
  12. Vendor incident response alignment
Module 6. Data subject rights workflows
Design DSAR processes that are ISO 27701-compliant and operationally feasible within marketing timelines.
12 chapters in this module
  1. DSAR scope definition
  2. Access request handling
  3. Correction procedures
  4. Deletion boundaries
  5. Portability formats
  6. Automated decision explanation
  7. Response timeline compliance
  8. Identity verification steps
  9. Marketing suppression sync
  10. Data map usage in fulfilment
  11. Third-party coordination
  12. Audit trail generation
Module 7. Data Protection Impact Assessments
Build DPIAs that are decision-enabling, not box-ticking, with marketing-specific risk patterns.
12 chapters in this module
  1. When a DPIA is required
  2. High-risk processing flags
  3. DPIA vs. Legitimate Interest Assessment
  4. Stakeholder consultation steps
  5. Risk mitigation mapping
  6. Data flow diagramming
  7. Third-party risk inclusion
  8. Retention period justification
  9. Breach likelihood scoring
  10. Public interest balancing
  11. Approved template usage
  12. Case study: influencer data campaign
Module 8. Breach preparedness and communication
Prepare marketing-adjacent breach playbooks aligned with ISO 27701’s incident response expectations.
12 chapters in this module
  1. What constitutes a breach
  2. Internal reporting triggers
  3. 72-hour clock rules
  4. Marketing data exposure scenarios
  5. Customer notification thresholds
  6. Regulator communication templates
  7. Media response coordination
  8. Data loss vs. unauthorised access
  9. Forensic support needs
  10. Post-breach review requirements
  11. Temporary suspension protocols
  12. Re-engagement after resolution
Module 9. Retention and disposal by design
Embed ISO 27701 retention rules into campaign lifecycle planning, from launch to archive.
12 chapters in this module
  1. Retention period justification
  2. Campaign-specific timelines
  3. Automated deletion triggers
  4. Archival vs. erasure
  5. Legal hold exceptions
  6. Proof of deletion records
  7. Cross-system sync
  8. Vendor disposal validation
  9. Data minimisation review
  10. Auditor access to logs
  11. Year-end review process
  12. Case study: seasonal campaign wrap-up
Module 10. Cross-functional alignment with legal and security
Lead discussions using ISO 27701 language that resonates with compliance and IT teams.
12 chapters in this module
  1. Translating marketing needs
  2. Security control trade-offs
  3. Legal threshold discussions
  4. Incident escalation paths
  5. Policy exception requests
  6. Control testing participation
  7. Audit preparation meetings
  8. Risk appetite conversations
  9. Budget justification using risk
  10. Training needs identification
  11. Cross-team playbook alignment
  12. Shared documentation standards
Module 11. Audit preparation with evidence depth
Assemble documentation that anticipates reviewer questions, avoiding last-minute scrambles.
12 chapters in this module
  1. Common auditor questions
  2. Evidence collection rhythm
  3. Control mapping templates
  4. Interview preparation
  5. Gap identification method
  6. Remediation tracking
  7. Vendor evidence requests
  8. System access logs
  9. Policy version control
  10. Training completion records
  11. Third-party attestations
  12. Pre-audit rehearsal
Module 12. Defensible evolution of marketing practices
Continuously improve data use while maintaining compliance through structured review and iteration.
12 chapters in this module
  1. Post-campaign compliance review
  2. Lessons learned integration
  3. New technology assessment
  4. Pilot programme governance
  5. Stakeholder feedback loops
  6. Control adaptation process
  7. Benchmarking against peers
  8. Privacy by design updates
  9. Team training refresh
  10. Policy alignment checks
  11. External standard updates
  12. Annual ISO 27701 review

How this maps to your situation

  • When launching a new tracking campaign
  • Before a vendor contract renewal
  • During internal compliance audits
  • After a data subject request surge

Before vs. after

Before
Decisions questioned without clear reference points, relying on general best practices
After
Every choice anchored in ISO 27701 with specific examples and documented rationale

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: 12 weeks of deliberate, part-time engagement (30-45 minutes per module) to build durable, referenceable knowledge

If nothing changes
Continuing to rely on informal justification increases exposure to scrutiny and slows campaign approvals

How this compares to the alternatives

Unlike generic GDPR courses, this focuses on ISO 27701 as a defensible framework for marketing decisions, with real campaign examples and audit-grade documentation templates

Frequently asked

Is this relevant if my company isn’t certified in ISO 27701?
Yes. The course teaches how to apply its logic to strengthen your decisions, whether or not your organization is formally certified.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will I get templates I can use immediately?
Yes. Each module includes downloadable, customisable templates and real-world examples aligned to ISO 27701 clauses.
$199 one-time. 12 weeks of deliberate, part-time engagement (30-45 minutes per module) to build durable, referenceable knowledge.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours