ISO/IEC 29100:2024 - PRIVACY
FRAMEWORK

Overview
ISO/IEC 29100 provides a high-level framework for protecting the Personally Identifiable Information (PII) that is within Information and Communication Technology systems (ICT). This privacy framework provided by ISO/IEC 29100 applies not only to organizations but also for persons using the ICT, which do require privacy controls in order to process the PII.
This privacy framework is intended to help organizations to define their PII related requirements for the safeguarding of privacy within an Information and Communication Technology system (ICT). This can be executed by specifying a common privacy terminology, defining the actors and their roles in processing PII and referencing familiar privacy principles.
Benefits of ISO 29100 Certification
Developed the necessary expertise to support an organization in implementing and managing a Privacy Framework based on ISO/IEC 29100
Gained a thorough understanding of how to design, build and lead organizations privacy programs covering business processes, ICT systems and services, through the use of best practices
Acquired the necessary expertise in privacy governance, specifically in personally identifiable information governance
Improved the capacity for analysis of privacy incident management
ISO 29100 Foundation (FD):
The ISO/IEC 29100 Foundation training course enables you to gain knowledge on the fundamentals of designing, implementing, operating, and maintaining Information and Communication Technology (ICT) systems that handle and protect Personally Identifiable Information (PII).
After completing this course, participants can sit for the exam. Once participants meet the pass mark, he/she will be given an “SandBP Certified ISO 29100 Foundation” credential. An SandBP Foundation Certificate shows that the participants have understood the fundamental methodologies, requirements, framework and management approach.
ISO 29100 Manager (MG)
I.T. Privacy manager training enables you to develop the necessary expertise to support an organization in designing, implementing, operating and maintaining Information and Communication Technology (ICT) systems that handle and protect Personally Identifiable Information (PII). During this training course, you will also have the opportunity to support an organization in improving privacy programs through the use of best practices and spur innovative solutions that enable the protection of PII within ICT systems.
After mastering all the necessary concepts of ISO 29100, participants can sit for the exam. Once participants meet the pass mark, he/she will be given “SandBP Certified ISO 29100 I.T. Privacy Manager” credential. By holding a SandBP Manager Certificate, the participant can be able to demonstrate that he/she has the practical knowledge and professional capabilities to implement ISO 29100 in an organization.
- Introduction to ISO/IEC 29100 and initiation of a Privacy Framework
- Plan the implementation of a Privacy Framework
- Implementation of a Privacy Framework
- Privacy Framework monitoring, measurement, continuous improvement and evaluation
- Certification Exam
- PRE-REQUISITE: A fundamental understanding of ISO/IEC 27032 and comprehensive knowledge of Cybersecurity
Terms of Certification
Candidates who score 70% and above in the examination will be issued an SANDBP certificate.
In case you do not meet the pass mark, you can retake the exam for FREE after the first attempt while subsequent retakes would come at a cost.
Criteria for Suspending and Withdrawing the Scope of Certification
SANDBP reserves the right to suspend or revoke certifications for reasons including fraud, deceit, or submission of inaccurate data.
Process:
Certificate holders will be notified by certified mail if evidence of charges is found.
They may present their defense in writing to the certification board.
The board will review the case and decide to uphold or deny the suspension/revocation.
Causes for Suspension/Withdrawal:
Improper use of certificates/logos
Malpractices
Providing false information
Ineligibility for applied examinations
Voluntary suspension requests
Recertification Process
Recertification ensures that certified individuals maintain their knowledge and skills in line with the latest standards and practices. It is a critical process that reaffirms the competency of certified professionals, allowing them to stay current with evolving industry standards.
Criteria for Recertification:
Transition Exam:
- Individuals must take and pass a transition exam when there is a change in the current version of the certification standard.
- The transition exam focuses on the updates and changes in the new version of the standard, ensuring that certified individuals are knowledgeable about the latest requirements and practices.
Adherence to Code of Ethics:
Certified individuals must adhere to a code of ethics, demonstrating professionalism and integrity in their practice. Any violations of the code of ethics may result in the suspension or revocation of certification
Payment of Recertification Fees:
Payment of the required recertification fees is necessary to process and validate the renewal of certification.
Introduction
To maintain the integrity and fairness of our examinations, specific guidelines have been established for proctoring. These rules apply to all candidates and must be adhered to strictly. Failure to comply may result in disqualification or other disciplinary actions.
General Requirements
Technology Setup
- Device: Use a desktop or laptop with a working webcam and microphone. Mobile phones or tablets are not permitted unless explicitly allowed.
- Internet: Ensure a stable internet connection with sufficient bandwidth to stream video and audio continuously.
- Browser: Use the designated browser as specified by the exam platform.
- Power Backup: Ensure your device is fully charged and/or connected to a reliable power source.
Environmental Setup
- Location: Choose a quiet, well-lit room with minimal distractions.
- Background: Ensure the background is plain and free of any clutter or distractions.
- Privacy: No other person is allowed in the room during the examination.
Pre-Exam Procedures
Present a valid government-issued photo ID or institution-approved identification document. Ensure that no unauthorized materials (e.g., books, notes, or electronic devices) are present.
During the Exam
Behavior Guideline
- Focus on the Screen: Avoid looking away from the screen for extended periods.
- No Assistance: You are prohibited from receiving help from anyone or any external resource.
Prohibited Items
- Electronic devices such as mobile phones, tablets, smartwatches, and earphones.
- Books, notes, or any other study material unless explicitly permitted.
Proctor Interaction
- Follow all instructions given by the proctor.
- If contacted for clarification or rule enforcement, respond promptly and cooperatively.
- Inform the proctor immediately in case of technical issues.
Post-Exam Procedures
Submission
- Ensure your exam responses are submitted within the designated time.
- Do not close the exam window or disconnect until you receive confirmation that your submission is successful.
Feedback
- Report any technical issues or concerns to the designated support team immediately aƜer the exam.
Violations and Consequences
Examples of Violations
- Using unauthorized materials or devices.
- Attempting to impersonate another candidate.
- Engaging in suspicious behavior (e.g., frequent movement, talking).
- Disconnecting intentionally without justification.
Consequences
- Warnings for minor infractions.
- Disqualification of the exam attempt for major violations.
Support and Troubleshooting
Contact the technical support team in case of any issues with logging in, connectivity, or proctoring tools. (support@sandbp.net)

FREE
- Level : Foundation
- Duration: 4-6 Days
- Exam Duration : 2 hours
- Retake Exam: Yes
- Passing Score: 70%

$170
- Level : Manager
- Duration: 4-6 Days
- Exam Duration : 2 hours
- Retake Exam: Yes
- Passing Score: 70%