Who needs it
It suits organisations that process personal data as controllers or processors. Uganda, Kenya and Rwanda each have a data protection law in force.
The steps
- A gap assessment compares current practice with the requirements.
- Top management approves the scope, the policy and the objectives.
- Personal data flows are mapped and roles as controller or processor are set out.
- Processes run long enough to produce evidence for the auditor.
- An internal audit and a management review are completed.
- Stage 1 and Stage 2 audits by the certification body lead to the certificate.
Cost drivers
Headcount, the number of sites and the scope of the system drive most of the cost. Existing practice matters, because every gap takes staff time and outside support to close. Audit days are set by the certification body from headcount and complexity under accreditation rules. The volume and sensitivity of personal data processed shape the controls needed. Surveillance audits follow in each of the two years after certification.
Timeline
Time depends on size, scope and readiness. Small organisations with sound practice often finish in four to six months. Larger or multi-site organisations commonly need nine to twelve months. A certificate runs for three years before recertification.
Certification
Certificates are issued by certification bodies accredited to ISO/IEC 17021-1. Your implementer and your auditor are always different, so the audit stays independent.


