Professional track
Data Protection Manager
Develop the capability to implement, manage and continuously improve an effective Privacy Information Management System aligned with ISO/IEC 27701
Make data protection a managed capability, not a reactive obligation
By integrating privacy governance, risk-based controls and lifecycle thinking into normal management processes, this track shows how data protection becomes operationally effective and sustainable.
Overview
What this track is about
A modular training programme for professionals managing data protection in practice. Learn to establish and operate an ISO/IEC 27701–aligned Privacy Information Management System that embeds accountability across the data lifecycle.
The Data Protection Manager Track is designed for professionals who are responsible for establishing and maintaining a structured approach to data protection within their organisation through a Privacy Information Management System (PIMS). Rather than focusing on legal texts or isolated compliance activities, the programme addresses data protection as a management system that integrates governance, risk management and operational control across the personal data lifecycle.
Audience
Who it is for
The Data Protection Manager Track prepares professionals to design, implement, operate, and improve Privacy Information Management Systems (PIMS) aligned with ISO/IEC 27701.
Practitioners, implementers, and consultants involved in the design, implementation, or extension of privacy information management systems (PIMS) aligned with ISO/IEC 27701
Individuals with responsibility for introducing or expanding privacy management capabilities , e.g. when building on an existing ISMS
Current or aspiring privacy managers, PIMS managers, or system owners responsible for operating and steering a privacy information management system
Members of privacy, data protection, or information governance teams who play an active role in shaping, evolving, and continually improving privacy management practices
Outcomes
Learning outcomes
4 capability areas. Each is assessed on the case organisation before the credential is issued, not on a multiple-choice paper.
Design a PIMS that actually works
Translate data protection requirements (e.g. GDPR) and ISO/IEC 27701 into practical, organisation-specific governance and processes
Integrate data protection coherently into the organisation’s existing management systems
Take ownership of data protection governance
Define roles, responsibilities and decision rights for data protection
Position data protection clearly within management and operational decision-making
Manage data protection risks, performance and improvement
Identify and assess data protection risks before they lead to incidents or compliance issues
Define monitoring and indicators that provide management with meaningful data protection information
Lead audits and continual improvement with confidence
Prepare and support internal and external data protection audits and assessments professionally
Use audit results, incidents and performance data to drive targeted improvements
Professional positioning
Establish a recognised competence profile as Data Protection Manager in ISO/IEC 27701-based organisations
Take responsibility for the implementation of a new PIMS or the coordination of an existing system
Act as a competent counterpart to senior management, clients, auditors and certification bodies
Credentials
Scalable credential model
Halderstone tracks follow a two-credential model that mirrors their modular structure. Both are awarded without expiry.
Core credential
Diploma in Management System Management
Cross-domain management system foundation: the 19 core modules
Applicable across every ISO standard we teach
Reusable across every further specialisation in the same role
Specialisation credential
Halderstone Certified Data Protection Manager
Domain competence in data protection
Translation of generic management system concepts to data protection management
Aligned with ISO/IEC 27701 requirements
Registered credentials
Once the specialisation credential is held, a Registered credential can be applied for. These confirm verified professional experience alongside the qualification, and keep it current through periodic reassessment.
Registered credentials: Halderstone Certified Data Protection Manager
The following Registered credentials can be applied for:
Registered Associate Manager in Data Protection Management
Registered Professional Manager in Data Protection Management
Registered Lead Manager in Data Protection Management
Registered Senior Lead Manager in Data Protection Management
Application requires meeting the experience requirements for the respective level.
For employers
How Halderstone credentials translate into capability signals in hiring, role design and professional practice, including what each one does and does not evidence.
Track price
CHF 9,500
All 23 modules, the capstone and the examination
No VAT is charged.
Start with a single module at any time · credited in full if you continue
Bought from us before? Sign in to see the modules you already hold.
Track facts
- Track ID
- HAT-DP-M
- Discipline
- Data Protection
- ISO standard
- ISO/IEC 27701
- Target audience
- Management System Manager
Modular approach
The core carries into every discipline
The 19 core modules are the same in every manager track. Completing them here means they are never repeated, never re-assessed and never paid for again, which is what makes a second track short and why most of this one is not about data protection.
Core modules
Manager capabilities across disciplines
19 modules · shared by every manager track
Awarded as the Diploma in Management System Management: the credential you keep whichever discipline you specialise in.
Specialisation · 3–5 modulesHighlighted: this track
A second manager track is 3–5 modules, not 23
Its specialisation modules, a capstone and an exam, whenever you want them, with no time limit on the core you completed here.
Curriculum
How the modules fit together
Every module is self-contained. There is no fixed order and no schedule: take them in whatever sequence your work makes useful, at whatever pace you can sustain. The grouping below is how we would sequence them if you have no reason to do otherwise.
Core
Shared with every manager track. Complete them once and they count towards any further qualification in the same role.
Data Protection Management
These modules carry the same management system work into ISO/IEC 27701. The method does not change; the material does. What is at stake, which controls are proportionate and which obligations bind are specific to the standard, and so are the judgements that go with them. The aim is a system the organisation runs, not one it maintains for the certificate.
The capstone engagement
Practical application of the learned PIMS competencies
Demonstrates ability tackle a concrete data protection management challenge in a real-world scenario
Based on case proposed by the candidate or provided by Halderstone
The final examination
Confirms solid and actionable understanding of data protection management principles $
Assesses the ability to design, implement and manage a PIMS based on ISO/IEC 27701 requirements
Covers all core and specialization modules of the track
Method
How you learn it
Two things separate knowing a standard from being able to run a management system to it: what is trained, and what it is trained on.
Practical reflexes, not topics covered
Every module is built around practical reflexes rather than around a list of topics. A practical reflex is what a practitioner asks and does without being prompted, under pressure: whether an owner can actually act, whether an exposure is being accepted or merely tolerated, whether the criteria in use can carry the decisions they are asked to carry, and then the move that follows from the answer. Topics can be listed after a course; reflexes show up in the next review, the next escalation and the next signature. Each one is developed in the written module, practised on the case organisation’s own material, and assessed in graded exercises that must be passed before the certificate is issued.
Three examples from this track’s modules:
Real ownership and escalation
Test whether a named owner actually holds the authority and the resources to act, keep risk, control and treatment ownership apart, and recognise when an exposure needs escalating as a decision request rather than another status update.
Residual exposure and explicit acceptance
See where exposure is being carried rather than treated, accept that an organisation may run exposure deliberately to pursue its objectives, and insist that such acceptance is named, dated, reasoned and signed instead of arriving by inertia.
Risk criteria and acceptance authority
Design impact, likelihood and acceptance criteria proportionate to the organisation's size and decision needs, with named acceptance authority, escalation thresholds and a review cadence, and recognise the defects that make a framework unusable: scales that cannot be compared across units, criteria without decision consequence, and rules copied from elsewhere that nobody applies consistently.
Trained on one organisation
Exercises run on Northstar Integrated Services AG, a Zurich company that provides digital operations platforms and managed operational services to organisations in healthcare, the public sector, industry and energy.
One organisation, carried across modules
Northstar has a management system with the wear of a real one. Authority is not always where the org chart puts it. The founder stepped off the board years ago and teams still seek his signal on the calls that matter. The decision log he kept personally faded out during a growth phase and nothing replaced it. You work that organisation rather than a tidy example, and the exercises are marked on what you did with it.
It has a timeline
Governance changes as the company grows, suppliers move through their lifecycle, and modules travel into earlier windows as well as later ones
Nothing resets between modules
The state you leave the organisation in is the state the next module finds it in
Why it matters
Judgement cannot be trained on tidy examples, and it cannot be trained on a fresh one each week. Because the modules work the same organisation, they compound into one continuous engagement rather than a series of disconnected courses.
Related track
The same discipline, the other role
The same discipline is taught from the auditor’s side as well. That track rests on a different core and carries its own specialisation modules, capstone and examination, so the two qualifications are earned separately.
Track price
CHF 9,500
23 modules, the capstone and the examination
Getting it signed off
Most people pay for this from a training budget. This page is written to be forwarded to whoever approves it: what the qualification covers, what it costs and what it changes in the role are all on it. If your approver needs something the page does not answer, ask us.
Not sure this is the one?
Start with a single module and have it credited in full later. If the work is assessing other people’s systems rather than running your own, the auditor track is the one. Tell us the situation and we will say which, honestly.