ISO 27701 certification — privacy information management in East Africa
ISO/IEC 27701 extends ISO 27001 into a Privacy Information Management System (PIMS). We help you build and certify a privacy programme that maps to data-protection law — including Uganda's Data Protection and Privacy Act and the GDPR — so you can prove to customers and regulators that personal data is handled responsibly.
Who ISO 27701 is for
Organisations that process personal data at scale — fintechs, health-tech, HR and payroll providers, marketing and data companies — and any business that already holds or is pursuing ISO 27001 and needs to demonstrate privacy compliance.
Why get certified
- Demonstrate compliance with the Data Protection & Privacy Act and GDPR
- Extend an existing ISO 27001 ISMS with minimal duplication
- Reassure customers that personal data is protected
- Reduce regulatory and reputational risk
What our ISO 27701 engagement covers
A complete engagement — from the first gap analysis to keeping you compliant year after year.
Privacy gap analysis
We benchmark your data-handling against ISO 27701 and applicable privacy law and prioritise the gaps.
Data mapping & records of processing
We map personal-data flows and build your records of processing activities.
PIMS controls & policies
We implement the ISO 27701 controls for controllers and/or processors and the required privacy policies.
Data subject rights & DPIA processes
We put in place processes for data-subject requests, consent, and data-protection impact assessments.
Certification audit preparation
We run mock audits and support you through the certification body's audit alongside your ISO 27001.
The road to ISO 27701
A clear, five-stage path. We stay with you through every stage.
Gap analysis
We assess your current controls against the standard and deliver a prioritised, practical action plan.
Implementation
We build the required policies, controls and evidence alongside your team — tailored to how you actually operate.
Internal audit & testing
We run internal audits and control testing to catch weaknesses before the assessor does.
Certification / assessment
We prepare you for, and support you through, the formal certification or assessment.
Maintain & improve
We keep you compliant through surveillance audits, re-assessments and continual improvement.
Request a ISO 27701 quote
Every engagement is fixed-scope — no open-ended billing. Because cost depends on your size, systems and current maturity, we prepare a tailored proposal after a short scoping call. Send us your details and we'll get back to you within 24 hours.
Request a quoteGet a free ISO 27701 consultation
Tell us where your organisation is today and we'll get back to you within 24 hours with a clear, practical next step — no obligation.
Request a quote
We'll be in touch within 24 hours.
ISO 27701 — frequently asked questions
Do we need ISO 27001 before ISO 27701?
Yes — ISO 27701 is an extension of ISO 27001, so you need an ISMS (either already certified or implemented in parallel). We commonly run the two together.
Does ISO 27701 make us GDPR compliant?
ISO 27701 is designed to map closely to GDPR and other privacy laws and is strong evidence of a well-run privacy programme, but certification is not a legal ruling. We align your PIMS to the specific laws that apply to you.
How long does ISO 27701 take?
As an extension it is usually faster than a standalone standard — often 2 to 4 months when built on top of an existing or in-progress ISO 27001 ISMS.