How much does ISO 27701 Lead Implementer training cost in Australia?
$849 + GST self-paced, or $928 + GST with guided eLearning. Both include the official PECB examination voucher and two attempts — PECB’s own course documentation states that the training fee includes a first exam attempt and one free retake within 12 months — plus 12 months of myPECB access and over 450 pages of course material. There is no separate ISO 27701 exam cost. The course carries 31 CPD credits and is equivalent to a five-day classroom course. All ISO 27701 training through Aegentra Academy is official PECB certification training, with the exam cost included in the course price rather than billed separately.
What is on the ISO 27701 Lead Implementer exam?
80 multiple-choice questions across 7 competency domains, open book, 3 hours, 70% to pass. The seven domains follow the implementation lifecycle: fundamental principles and concepts of a PIMS; initiation of the PIMS implementation; planning the implementation; implementing the PIMS; monitoring and measurement; continual improvement; and preparing for a PIMS certification audit.
Scenario-based items are still multiple-choice — there is no essay paper at this level. Being open book, you may use the standard, the course materials and your own notes, which makes retrieval speed the real constraint rather than memorisation. Candidates who fail usually knew the content but could not find it quickly enough; build an index into your notes before you sit.
What does the Lead Implementer credential qualify you for?
One exam, four credential tiers, awarded on the experience you can attest to:
- Provisional Implementer — on passing, no experience required
- Implementer — 2 years of professional experience, 1 in privacy management, plus 200 hours of PIMS project activity
- Lead Implementer — 5 years, 2 in privacy management, plus 300 hours
- Senior Lead Implementer — 10 years, 7 in privacy management, plus 1,000 hours
Above all of them sits PECB Certified ISO/IEC 27701 Master, which requires 20 years of professional experience with 10 in a leadership role, 5,000 hours of combined audit and project activity, and passing both the ISO/IEC 27701 exam and the Lead Auditor exam. Almost no provider publishes that tier exists.
Can you implement ISO 27701 without ISO 27001?
Yes, since the October 2025 revision. ISO/IEC 27701:2025 is a stand-alone management system standard — PECB states the 2025 edition introduces a stand-alone PIMS, no longer requiring ISO/IEC 27001-based security management. Guidance telling you otherwise is describing the 2019 edition.
That changes the first decision in any implementation. Standalone suits an organisation whose obligation is privacy-driven — a health service, a marketing business, a government supplier — and which has no commercial reason to certify information security separately. Integrated suits anyone already holding ISO 27001, because clauses 4 to 10 are shared and the PIMS extends the existing scope instead of duplicating it.
Either way the control work is the same shape. Annex A is now one consolidated annex of 78 controls: Table A.1 for PII controllers (31 controls), Table A.2 for PII processors (18), and Table A.3 shared security controls (29). Your Statement of Applicability declares which apply, and the answer depends on your role in each processing activity — most organisations are both. Annex B carries the matching implementation guidance.
How does a PIMS satisfy the Australian Privacy Act and GDPR at once?
This is the practical reason Australian organisations implement it. The Privacy Act 1988 and its 13 Australian Privacy Principles set the domestic obligation; the GDPR applies to anyone processing EU personal data. Building separate compliance programmes for each is duplicated effort.
A PIMS gives you one system that produces evidence for both. APP 11 (security of personal information) is answered by the Table A.3 shared security controls; APP 8 (cross-border disclosure) by the transfer register; APP 12 and APP 13 (access and correction) by the PII principal rights process. The same records answer GDPR accountability. Our free APP mapping below sets out all thirteen.
Free documents to build the PIMS alongside the course
These are the artefacts a Lead Implementer actually produces — published in full, free, no email required.
If the organisation needs the PIMS built rather than a person trained, that is our governance and compliance practice. For what organisational certification costs, see the ISO 27701 certification guide for Australia. Auditing one is the Lead Auditor track.