"The structure, the practice exams, the instructor — all top tier. Passed first try."
Course Outline
What the programme covers, module by module.
Module 1: Introduction to ISO 27018
- ISO 27018 overview
- Purpose and scope
- Cloud privacy concepts
- Public cloud environments
- Personally identifiable information
- Key terminology
Module 2: Cloud Computing & Privacy Fundamentals
- Cloud computing concepts
- Cloud service models
- Cloud deployment concepts
- Privacy considerations
- Shared responsibilities
- Cloud data risks
Module 3: PII Roles & Responsibilities
- PII principals
- PII controllers
- PII processors
- Cloud service providers
- Organisational responsibilities
- Accountability
Module 4: Privacy Principles
- Consent and choice
- Purpose legitimacy
- Collection limitation
- Data minimisation
- Use and retention
- Privacy compliance principles
Module 5: PII Collection & Processing
- PII collection
- Processing instructions
- Lawful processing awareness
- Purpose limitations
- Processing records
- Responsible data handling
Module 6: Data Classification & Handling
- Identifying PII
- Data classification
- Sensitive information
- Handling requirements
- Storage considerations
- Information protection
Module 7: Access Control
- Access control principles
- User access
- Authentication
- Authorisation
- Privileged access
- Access reviews
Module 8: Cryptography & Data Protection
- Encryption concepts
- Data at rest
- Data in transit
- Key management awareness
- Secure communication
- Protection mechanisms
Module 9: Data Location & Transfer
- Data location awareness
- Cross-location processing
- Data transfers
- Transfer controls
- Cloud infrastructure considerations
- Customer transparency
Module 10: Transparency & Customer Communication
- Transparency principles
- Privacy notices
- Processing information
- Customer communication
- Changes to services
- Information accessibility
Module 11: PII Disclosure & Third Parties
- PII disclosure
- Disclosure requests
- Third-party access
- Subcontractors
- Subprocessor considerations
- Disclosure records
Module 12: Data Retention & Deletion
- Retention requirements
- Retention periods
- Data return
- Secure deletion
- Media disposal
- Data lifecycle management
Module 13: Privacy & Security Incident Management
- Privacy incidents
- Security incidents
- Incident identification
- Incident escalation
- Customer communication
- Incident documentation
Module 14: Monitoring, Logging & Accountability
- Activity logging
- Monitoring access
- Audit trails
- Accountability records
- Reviewing activities
- Control effectiveness
Module 15: Cloud Privacy Risk Management
- Privacy risk identification
- Cloud privacy threats
- Vulnerabilities
- Risk assessment
- Risk treatment concepts
- Reviewing privacy risks
Module 16: Maintaining & Improving Cloud Privacy
- Reviewing privacy controls
- Performance monitoring
- Internal reviews
- Improvement opportunities
- Updating practices
- Continual improvement
Who it's for & what's included
Pick a delivery method to see exactly who it suits and everything you receive.
Classroom
Best for learners who want face-to-face tuition and to network with peers in person.
Everything you get
- ✓ Live instructor on-site
- ✓ Printed workbook & materials
- ✓ Group exercises & case studies
Online Instructor-Led
Best for learners who want a live instructor and a fixed schedule, without the travel.
Everything you get
- ✓ Live instructor via video call
- ✓ Digital workbook & resources
- ✓ Session recordings
Self-Paced
Best for self-motivated learners who need maximum flexibility around work and life.
Everything you get
- ✓ On-demand video lessons
- ✓ Interactive quizzes
- ✓ 24/7 access on any device
Course Overview
The ISO 27018 Cloud Data Privacy Foundation course provides working professionals with foundational knowledge for protecting personally identifiable information in public cloud environments. Learners explore ISO 27018 principles, cloud privacy roles, PII processing, consent, transparency, access controls, data lifecycle management, disclosure, subcontractors, security incidents, accountability, monitoring, and continual privacy improvement.