info@nexoprivacy.com +254 768200243 Mon - Sat | 24 Hours
HomeSolutions

Privacy & security programmes, end-to-end.

From the first gap assessment through certification, day-to-day operations and crisis response - one team accountable for the entire programme.

Assessments & advisory

Know exactly where you stand - and what to do next.

Every engagement starts with an honest, prioritised view of your current posture. No 200-page slide decks - just a clear plan with owners, dates and dollar values.

Privacy Impact Assessments

Privacy Impact Assessments

DPIAs, TIAs and PIAs for new products, vendors and cross-border data flows - built around your engineering reality.

Discuss this
Security & Surface Scans

Security & Surface Scans

External attack-surface and configuration scans, cookie & tracker audits, SSL/TLS reviews and dark-web monitoring.

Discuss this
Compliance Gap Analyses

Compliance Gap Analyses

Honest readiness reviews against GDPR, CCPA, ISO 27001, SOC 2, PCI DSS or your framework of choice.

Discuss this
Programmes

Build the programme. Run the programme.

A privacy or security programme isn't a project - it has a heartbeat. We design it, hand-hold it through certification, and stay on board to keep it healthy.

Programme delivery

GDPR & UK GDPR readiness

Lawful-basis mapping, RoPA, DPIAs, DSAR workflows, transfer mechanisms (SCCs/IDTAs/TIAs), DPO support and ICO engagement.

CCPA / CPRA programmes

Consumer-rights pipelines, “Do Not Sell or Share” signals, sensitive-PI handling, service-provider agreements, CPPA readiness.

ISO/IEC 27001 & 27701 certification

ISMS & PIMS design, Statement of Applicability, Annex A controls, internal audit, certification body liaison.

SOC 2 Type I & Type II

Trust Services Criteria mapping, control design and operating-effectiveness evidence, auditor-ready dataroom.

PCI DSS v4.0

Scoping, SAQ / RoC support, ASV-scan readiness, segmentation reviews, customised-approach guidance.

Kenya DPA, 2019 readiness

ODPC registration, DPIAs, data-subject-rights, operator agreements and cross-border safeguards for Kenyan and pan-African operations.

Virtual DPO & vCISO retainers

Senior privacy and security leadership on retainer - fractional support that scales with your stage.

Incident response

When the worst happens, who do you call?

Our 24×7 incident-response retainer gives you a privacy lawyer, an analyst and a communications lead on a single call - with regulator-notification templates ready to file.

Full catalogue

Everything in one place.

Privacy by Design reviews

Embed privacy controls into product, data and engineering before they ship.

Policy & notice drafting

Plain-English privacy notices, internal policies and standards your teams will actually read.

Records of Processing (RoPA)

A living RoPA that doesn’t need an annual panic to keep up to date.

Vendor & DPA management

One vendor inventory, one DPA template set, one renewal calendar.

Privacy & security training

Role-based training that moves the needle on behaviour - and stays evidenced.

Breach & incident response

Retainers, runbooks, regulator drafts and crisis-comms support.

DPO & CISO outsourcing

Named officers for as long as you need them.

Cloud & SaaS security

Tenancy hardening, IAM reviews, M365 & Google Workspace baselines.

Attack-surface monitoring

Continuous visibility into your external posture and shadow assets.

Common questions

What every prospective client asks first.

Don't see your question? Ask us directly - usually a same-day reply.

How long does a GDPR or ISO 27001 readiness programme take?

For a mid-sized SaaS business we typically reach certification readiness in 12-16 weeks for ISO 27001 and 8-12 weeks for GDPR. We hit early wins inside the first month so the business feels progress straight away.

Do you support multiple frameworks at once?

Yes - and we recommend it. We map GDPR, CCPA, ISO 27001, ISO 27701, SOC 2 and Kenya DPA onto a single control set so you don't pay for the same control five times.

Can you act as our Data Protection Officer or CISO?

Absolutely. Our virtual DPO and vCISO retainers give you a named officer, board reporting, regulator engagement and day-to-day decision support - at a fraction of the cost of a full-time hire.

How do you price engagements?

Fixed-fee for defined programmes (assessment, certification readiness, incident response) and monthly retainers for ongoing operations. We share a clear scope and pricing in our first proposal - no surprises later.

Do you serve organisations outside Kenya?

Yes - the majority of our work is international, with clients across the EU, UK, US, Middle East and Asia-Pacific. We have local language and regulatory know-how across each major region.

Let's design your programme

Talk to a privacy & security strategist.

30 minutes, no obligation. We will share a high-level plan you can take to your board the same week.