Training module

PII Processing: Context, Roles & Scope

Define PII processing context, determine controller and processor roles, and set practical PIMS scope boundaries under ISO/IEC 27701

Data ProtectionManagement System Manager
Modern office building at night with illuminated workspaces, symbolising PII processing context, controller and processor roles, and clearly defined scope boundaries for privacy governance under ISO/IEC 27701.

Who decides what in your PII processing — and where does your PIMS actually begin and end?

Define processing context, determine controller and processor roles, and establish defensible PIMS scope boundaries that reflect real operations.

Overview

What this module is about

A Privacy Information Management System only works if its foundations are defined with precision. Organisations must be clear about what constitutes PII processing in their environment, which roles apply, and where system boundaries sit across internal units and external parties.

This module focuses on the architectural front end of a PIMS: defining processing context in a maintainable way, determining controller and processor roles including joint arrangements, establishing internal accountability models, and formalising scope statements and boundary artefacts that reflect real operations and sourcing structures. The emphasis is on governance clarity that enables consistent decision-making, auditability, and long-term maintainability.

Audience

Who it is for

Management system implementers and coordinators

Executives and department heads accountable for management system performance

Those responsible for processes, policies, assets, risks and controls

Auditors seeking insight into management-side practice, not audit technique

Consultants working on management system design, governance or improvement

Decision supportIs this module for you?

It is a good fit if you…

need clarity on what counts as PII processing in practice.

want clean controller and processor role separation.

need defensible scope boundaries for a PIMS.

work across internal units or external parties.

support ISO/IEC 27701 implementation or oversight.

It may not be the best fit if you…

are looking for legal interpretation of privacy laws.

want execution guidance for DPIAs or data subject rights.

need detailed operational privacy controls.

already operate a stable, well-defined PIMS scope and role model.

Agenda

What is taught

8 parts
01Defining PII processing context in a way the organisation can maintain

How to describe real PII processing in terms of services, products, channels, locations, and data flows at a level that stays accurate as the organisation changes

02Determining the organization's role: controller, processor, joint roles

How to apply practical tests to determine who decides purposes and means versus who acts on instructions, including mixed-role scenarios with platforms, partners, and internal functions

03Internal accountability model for privacy roles

How to translate external role concepts into internal ownership, decision rights, escalation paths, and evidence expectations that actually work day to day

04External parties and boundary-setting

How to decide what sits inside the PIMS scope versus what is managed through interfaces with suppliers, sub-processors, partners, affiliates, customers, and how to document those choices

05PIMS scope statement and boundary artefacts

How to produce a scope statement that is operationally useful and support it with concrete boundary artefacts such as context maps, role registers, interface registers, and exclusion logs

06Keeping scope and roles up to date

How to define change triggers and lightweight review routines so scope, roles, and responsibilities remain credible without creating a parallel governance machine

07Technology as an enabler

How to use inventories, ticketing links, contract repositories, and AI-assisted summaries to keep processing context current while keeping human judgement in control

08Case-based workshop

Applying the learned concepts, methods, and approaches in a realistic case setting

Outcomes

Learning outcomes

01

Describe ISO/IEC 27701 expectations for processing context, roles and scope in a PIMS

02

Define a high‑level PII processing context that is usable for governance and maintenance

03

Determine and justify controller and processor roles for real‑world scenarios

Translate external role concepts into an internal accountability model that supports decisions and escalation

Produce a clear PIMS scope statement with boundaries, interfaces and exclusions

Identify typical scoping and role pitfalls and set up practical review triggers to keep roles and scope current

Materials

The content and the assessment

Written module

The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.

Exercises

Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.

On completion

The assessed exercises must be passed before the certificate is issued.

Scheduling

No public run of PII Processing: Context, Roles & Scope is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.

Module facts

Module ID
HAM-DP-S-01
Discipline
Data Protection
Download fact sheet (PDF, 5.0 MB) →

Case organisation

You work inside a company that already has the problem

Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.

Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.

Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes

Not a case study
Nothing is summarised for you; the evidence is where it would really be

It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after

It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions

Why it matters

Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.

How we teach →

Delivery & dates

How this module reaches you

Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.

No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.

Want this module scheduled?

We will tell you when the next run is scheduled, or run this module in-house with your own case material.

Not sure it is the right module?

Describe your context in a short message and we will tell you honestly.

No obligation

Tell us what would work and we will come back with dates, or with an in-house proposal if you would rather run this for a group on your own management system.
About PII Processing: Context, Roles & Scope · HAM-DP-S-01

No account needed. We reply personally, usually within a working day. Sending is not switched on yet, so write to us in the meantime: contact us.

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this module is the right one, or point you at a better fit.
About PII Processing: Context, Roles & Scope · HAM-DP-S-01

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.