Skip to main content

How to become an ISO 27701 Lead Implementer in Australia

By Harry Sidhu — ISO 27001 Lead Implementer · Director and Principal Consultant, Aegentra · Published 25 July 2026 · Updated 26 August 2026

Privacy became a job title in Australia before it became a standard anyone could certify against on its own. This guide covers the credential behind it — the PECB Lead Implementer pathway for ISO/IEC 27701: the tiers, the experience and PIMS project hours each one needs, the exam, the cost, and the roles it opens.

To become a PECB Certified ISO/IEC 27701 Lead Implementer you complete the official ISO 27701 Lead Implementer training, pass the PECB exam — 80 multiple-choice questions across seven competency domains, open book, three hours, 70% to pass — then meet the experience tier you are claiming: five years of professional experience with two in privacy management, plus 300 hours of PIMS project activity for the full Lead Implementer credential. The entry tier, Provisional Implementer, needs only the exam. Aegentra Academy is an official PECB authorised training partner and runs the course for $849 + GST self-paced or $928 + GST with eLearning, with the exam voucher and a free 12-month retake included.

What an ISO 27701 Lead Implementer actually is

ISO/IEC 27701:2025 is the international management-system standard for privacy — and since the October 2025 revision it is stand-alone, no longer requiring an ISO 27001 ISMS underneath it. A Lead Implementer is the person who builds and runs that system: the records of processing, the privacy policy, the risk assessment, the Statement of Applicability, the 78 Annex A controls, and the audit readiness. The detail on the standard itself is in our ISO 27701 certification guide; this page is about the individual credential and the career behind it.

Two clarifications. First, the Lead Implementer builds the system and the Lead Auditor assesses it — separate credentials, separate career tracks. Second, a great deal of published guidance still describes the 2019 edition, which required ISO 27001 first and split the controls across Annex A and Annex B. Neither is true of the 2025 edition, where Annex A is one consolidated annex of 78 controls across three tables and Annex B is implementation guidance.

The step-by-step pathway

  1. Get the management-system grounding. If you have never run a management system, start with ISO 27701 Foundation — 40 questions, one hour, closed book, no prerequisites. If you already hold an ISO 27001 implementer credential, skip it; clauses 4 to 10 share the same Annex SL spine.
  2. Take the official Lead Implementer course. The official PECB course teaches you to establish and maintain a PIMS end to end — organisational context, PIMS scope, gap analysis, privacy policy, privacy risk assessment and treatment, the Statement of Applicability, control selection and implementation, monitoring, and preparation for the certification audit. PECB supplies over 450 pages of material.
  3. Sit and pass the PECB exam. 80 multiple-choice questions across seven competency domains, open book, three hours, 70% to pass. Scenario items are still multiple-choice — there is no essay paper. Being open book, retrieval speed matters more than memorisation.
  4. Log your experience and PIMS project hours. PECB counts years of professional experience with a minimum specifically in privacy management, and hours of hands-on PIMS project activity, separately. Keep a running log with dates, the organisation, the deliverable and the hours.
  5. Sign the Code of Ethics and apply for your tier. Every tier requires signing the PECB Code of Ethics and submitting an application with references. PECB verifies the claim and issues a digital credential a procurement team can verify independently.
  6. Maintain it, and know where the ladder goes. Maintained through CPD credits. Above Senior Lead Implementer sits PECB Certified ISO/IEC 27701 Master — 20 years of professional experience with 10 in a leadership role, 5,000 hours of combined audit and project activity, and passing both the ISO/IEC 27701 and Lead Auditor exams.

Aegentra Academy is an official PECB authorised training partner and delivers the ISO 27701 Lead Implementer course online and self-paced. Foundation-level grounding is available through the ISO 27701 Foundation course.

Credential tiers and the experience each one needs

“Lead Implementer” is the third rung of a four-tier ladder. All four sit the same exam; what separates them is the professional experience and the hours of hands-on PIMS work you can evidence.

Credential tierTotal experienceIn privacy managementPIMS project hours
Provisional ImplementerNoneNoneNone
Implementer2 years1 year200 hours
Lead Implementer5 years2 years300 hours
Senior Lead Implementer10 years7 years1,000 hours

Above these sits PECB Certified ISO/IEC 27701 Master — 20 years of professional experience with 10 in a leadership role, 5,000 hours of combined audit and project activity, and passing both the ISO/IEC 27701 and Lead Auditor exams. Confirm current criteria on the official PECB ISO/IEC 27701 page.

What counts as PIMS project hours

Two things are counted separately. Professional experience is your years of work, with a minimum specifically in privacy management. Project activity hours are hands-on hours doing the PIMS work itself — the part people underestimate and then cannot evidence later.

  • Determining controller vs processor role — Working out, per processing activity, whether the organisation decides the purpose (controller) or acts on instruction (processor). Most organisations are both, and this decides which Annex A table applies.
  • Building the Records of Processing Activities — Documenting every activity with purpose, lawful basis, PII categories, recipients, cross-border transfers, retention and owner. The artefact an auditor opens first, and usually the largest block of hours.
  • Privacy risk assessment and treatment — Assessing risk to PII principals rather than only to the organisation, scoring it against defined criteria, and producing a treatment plan somebody accountable has signed.
  • Drafting the Statement of Applicability — Deciding which of the 78 Annex A controls apply across Table A.1 (controller), Table A.2 (processor) and Table A.3 (shared security), with a scope-based justification for every exclusion.
  • Implementing the privacy controls — Collection notices, consent and opt-out handling, PII principal access and correction, cross-border transfer safeguards, retention schedules and defensible disposal.
  • Mapping to the Privacy Act and GDPR — Cross-walking the PIMS to the 13 Australian Privacy Principles and, where EU data is processed, to GDPR accountability — so one system answers both.
  • Internal audit preparation and management review — Building the audit programme, preparing evidence, supporting the auditor, and packaging performance data into a management review leadership can decide on.

Why the role is growing in Australia

No Australian law names ISO 27701. Demand arrives through the Privacy Act, some enterprise procurement processes, and the 2025 revision itself.

  • The Privacy Act 1988 and the 13 APPs — The Act sets the obligation and the Australian Privacy Principles set the detail — APP 1 transparent management, APP 8 cross-border disclosure, APP 11 security, APP 12 and APP 13 access and correction. None names ISO 27701, but all assume the documented, repeatable method a PIMS produces.
  • Privacy questions in some enterprise procurement processes — Privacy-specific questions are now standard in vendor questionnaires: what personal information do you hold, where does it go, who are your sub-processors, how do you handle access requests. Buyers increasingly ask for a framework behind the answers.
  • The 2025 revision made it stand-alone — Until October 2025, adopting ISO 27701 meant committing to an ISO 27001 ISMS first. The second edition removed that, opening the standard to organisations whose obligation is privacy-driven rather than security-driven.
  • Cross-border operation and GDPR — Organisations processing EU personal data need accountability evidence under GDPR alongside their Australian obligations. A PIMS produces both from one system.

Jobs and indicative salaries in Australia

Indicative Australian ranges from public privacy, GRC and risk salary guides — a market guide, not a quote:

RoleIndicative range (AUD)
Privacy Analyst$100,000 – $135,000
Privacy Officer$120,000 – $160,000
Data Protection Officer$145,000 – $195,000
Privacy & Compliance Manager$150,000 – $200,000
Head of Privacy$185,000 – $245,000

Frequently asked questions

Do I need ISO 27001 before ISO 27701?

No — and since the October 2025 revision that is true of the standard itself, not just the credential. ISO/IEC 27701:2025 is a stand-alone management system standard; PECB states the 2025 edition introduces a stand-alone PIMS, no longer requiring ISO/IEC 27001-based security management. Guidance telling you otherwise is describing the superseded 2019 edition.

What is on the exam?

80 multiple-choice questions across seven competency domains, open book, three hours, 70% to pass. The domains follow the implementation lifecycle: fundamental principles and concepts of a PIMS; initiation; planning; implementation; monitoring and measurement; continual improvement; and preparing for a PIMS certification audit. Scenario items are still multiple-choice.

How much does the course cost in Australia?

Aegentra Academy runs the official PECB ISO 27701 Lead Implementer course for $849 + GST as self-study and $928 + GST with eLearning. Both include the official PECB exam voucher and one free retake within 12 months — PECB states the training fee includes a first exam attempt and one retake — so there is no separate exam fee.

Are we a PII controller or a PII processor?

Almost certainly both, and it is decided per processing activity. You are a controller for your own employee records, recruitment and marketing. You are a processor for data your customers put into your platform. The determination selects which Annex A table applies: Table A.1 for controllers (31 controls), Table A.2 for processors (18), and Table A.3 shared security controls (29) which apply either way.

Lead Implementer or Lead Auditor — which should I take?

Take Lead Implementer if you will build the PIMS; take Lead Auditor if you will assess someone else’s. Both exams are 80 questions over seven domains, but the domains differ: implementation phases versus audit phases.

Can my company get certified to ISO 27701, or only individuals?

Both, and they are separate things. Individuals earn a professional credential. Organisations get certified by building a PIMS and passing an audit by an accredited certification body — and since the 2025 revision that certificate can stand alone or extend an existing ISO 27001 certificate.

Ready to start? Aegentra Academy runs the official PECB ISO 27701 Lead Implementer course for $849 + GST, exam voucher and free retake included. If your organisation needs the PIMS built rather than a person trained, that is our ISO 27701 implementation service.