I recently earned my certification as an ISO27701 Lead Auditor. The standard sets out requirements for a Privacy Information Management System which extends the existing information security framework to specifically cover data privacy.
Since March my remit has included data governance. Privacy and security overlap a lot in practice but they are not the same discipline, and the audit training made that distinction clearer.
