Home / Consulting / ISO 27701
Information Security & Data Protection

ISO 27701 certification — privacy information management in East Africa

ISO/IEC 27701 extends ISO 27001 into a Privacy Information Management System (PIMS). We help you build and certify a privacy programme that maps to data-protection law — including Uganda's Data Protection and Privacy Act and the GDPR — so you can prove to customers and regulators that personal data is handled responsibly.

Who ISO 27701 is for

Organisations that process personal data at scale — fintechs, health-tech, HR and payroll providers, marketing and data companies — and any business that already holds or is pursuing ISO 27001 and needs to demonstrate privacy compliance.

Why get certified

  • Demonstrate compliance with the Data Protection & Privacy Act and GDPR
  • Extend an existing ISO 27001 ISMS with minimal duplication
  • Reassure customers that personal data is protected
  • Reduce regulatory and reputational risk

What our ISO 27701 engagement covers

A complete engagement — from the first gap analysis to keeping you compliant year after year.

Privacy gap analysis

We benchmark your data-handling against ISO 27701 and applicable privacy law and prioritise the gaps.

Data mapping & records of processing

We map personal-data flows and build your records of processing activities.

PIMS controls & policies

We implement the ISO 27701 controls for controllers and/or processors and the required privacy policies.

Data subject rights & DPIA processes

We put in place processes for data-subject requests, consent, and data-protection impact assessments.

Certification audit preparation

We run mock audits and support you through the certification body's audit alongside your ISO 27001.

The road to ISO 27701

A clear, five-stage path. We stay with you through every stage.

01

Gap analysis

We assess your current controls against the standard and deliver a prioritised, practical action plan.

02

Implementation

We build the required policies, controls and evidence alongside your team — tailored to how you actually operate.

03

Internal audit & testing

We run internal audits and control testing to catch weaknesses before the assessor does.

04

Certification / assessment

We prepare you for, and support you through, the formal certification or assessment.

05

Maintain & improve

We keep you compliant through surveillance audits, re-assessments and continual improvement.

Request a ISO 27701 quote

Every engagement is fixed-scope — no open-ended billing. Because cost depends on your size, systems and current maturity, we prepare a tailored proposal after a short scoping call. Send us your details and we'll get back to you within 24 hours.

Request a quote

Get a free ISO 27701 consultation

Tell us where your organisation is today and we'll get back to you within 24 hours with a clear, practical next step — no obligation.

Accredited consultants and practising auditors
Case studies from real East African industry
Fixed-scope proposals — no open-ended billing

Request a quote

We'll be in touch within 24 hours.

ISO 27701 — frequently asked questions

Do we need ISO 27001 before ISO 27701?

Yes — ISO 27701 is an extension of ISO 27001, so you need an ISMS (either already certified or implemented in parallel). We commonly run the two together.

Does ISO 27701 make us GDPR compliant?

ISO 27701 is designed to map closely to GDPR and other privacy laws and is strong evidence of a well-run privacy programme, but certification is not a legal ruling. We align your PIMS to the specific laws that apply to you.

How long does ISO 27701 take?

As an extension it is usually faster than a standalone standard — often 2 to 4 months when built on top of an existing or in-progress ISO 27001 ISMS.