ISO 27701 certification in Angola
ISO 27701 extends ISO 27001 to personal data protection. We prepare the organisation to process data with verifiable controls.

What ISO 27701 is
ISO 27701 adds privacy requirements to the information security management system: controller and processor roles, basis for processing, records of processing activities, data subject rights, transfers and data breach notification.
It assumes an implemented ISO 27001 system, since it extends its controls rather than replacing them.
How we prepare the certification
- 01AssessmentReview of the current situation against the standard's requirements and identification of the gaps to close.
- 02Scope and contextDefinition of the certification scope, interested parties and applicable legal requirements.
- 03Process and risk mapProcess design, assignment of owners and assessment of the associated risks and opportunities.
- 04DocumentationPolicy, procedures, instructions and records written for the actual operation, not generic templates.
- 05Training and roll-outTeam training and day-to-day roll-out of the system, with evidence of real use.
- 06Internal auditInternal audit run by network auditors, recording non-conformities and corrective actions.
- 07Pre-auditSimulation of the certification audit and closure of the final gaps, ahead of the independent DQS audit.
Preparing and certifying are separate functions
Export Lab handles the assessment, system design, documentation, training and internal audit. The certification audit is conducted independently by DQS. That separation is what makes the certificate credible to clients, regulators and international partners.
Cost and timeline: what makes them vary
We do not publish list prices for ISO 27701, because the effort is not the same in two different organisations. The investment always has two separate components: preparation, delivered by Export Lab, and the certification audit, billed by the certification body.
What drives cost: Number of processing activities and systems involved, whether an ISO 27001 ISMS is already in place (a practical prerequisite), controller and processor roles, data transfers, and the maturity of the processing inventory.
What drives the timeline: Drivers are the processing inventory, processor contracts, data subject request procedures, and the time needed to demonstrate them working in practice.
After the initial assessment, scope, schedule and price are presented in writing, before any commitment.
What your company gains
- Personal data processing mapped and justified.
- Data subject requests answered by procedure.
- Data breaches with a defined response plan.
Frequently asked questions
- Who needs ISO 27701?
- Organisations processing significant volumes of personal data — banking, insurance, healthcare, telecoms, human resources, digital platforms — and providers processing data on behalf of clients.
- Is ISO 27701 mandatory in Angola?
- ISO 27701 is voluntary. Applicable personal data protection obligations come from law; the standard structures how to meet and evidence them, and does not remove the need for legal assessment of those obligations.
- How much does ISO 27701 certification cost?
- There is no list price. The figure follows from scope and starting point — specifically: Number of processing activities and systems involved, whether an ISO 27001 ISMS is already in place (a practical prerequisite), controller and processor roles, data transfers, and the maturity of the processing inventory. Preparation and the certification audit are billed separately, the latter by the certification body.
- How long does ISO 27701 implementation take?
- We do not quote fixed timelines before the assessment. Drivers are the processing inventory, processor contracts, data subject request procedures, and the time needed to demonstrate them working in practice. A realistic schedule is set out in the proposal.
- Who issues the certificate? Does Export Lab also certify?
- No. Export Lab prepares and implements; the ISO 27701 certification audit is conducted independently by DQS. Whoever prepares cannot certify, and that separation is what gives the certificate value with clients and regulators.
- What happens after certification?
- It extends the ISO 27001 certificate and follows the same three-year cycle with annual DQS audits. The processing inventory, data subject request handling and impact assessment for new processing are kept live.
- Can ISO 27701 be certified without ISO 27001?
- Not on its own: ISO 27701 is a privacy extension to the information security management system. In practice, either ISO 27001 is already certified, or both are implemented and audited together.
Network specialists
Tell us your company's challenge and we identify, within the network, the specialist with the right profile in Information Security and ISO 27701.