ISO 27001 implementation and certification readiness
From current state to a passed certification audit, with a fixed scope agreed before we start.
Sri Lanka’s Personal Data Protection Act No. 9 of 2022 brings its core obligations for controllers and processors into force on 1 January 2027. We assess where you stand, build the records, notices and procedures the Act requires, and align the work with ISO 27001 and ISO 27701 so the same evidence serves both.
We map what personal data you hold, where it flows, who processes it for you, and where you stand against Parts I and III of the Act.
A register of processing activities with lawful bases, retention periods and cross-border transfers.
Privacy notices, an internal data protection policy, a retention schedule, a data subject request procedure and a breach notification procedure with the Authority’s timelines built in.
Help deciding whether you must appoint a DPO, defining the role, and acting as an outsourced DPO adviser where that is appropriate.
Clauses for your vendors, and for your own client contracts where you act as a processor.
Where you run or plan an ISMS, we map the PDPA requirements onto it so one set of controls and evidence covers both.
From current state to a passed certification audit, with a fixed scope agreed before we start.
Independent internal audits, surveillance preparation and the 2013 to 2022 transition for companies that already hold ISO 27001.
Business impact analysis, continuity plans and exercises that prove the plans work. Certifiable to ISO 22301 if you need the certificate.
Forty-five minutes, no charge. We ask about your organisation, what is driving the project and what you already have in place, then send a written proposal with a fixed scope and fee.