Skip to content
All posts

DataEQ Achieves ISO/IEC 27001:2022 Certification

DataEQ, a global customer data intelligence business, has achieved ISO/IEC 27001:2022 certification, the international standard for information security management systems (ISMS). It was awarded by SANCERT, an ISMS certification body accredited by SANAS, and underscores DataEQ's commitment to information security, risk management, and operational maturity.

"This is a significant milestone for the business and highlights our continued commitment to global data protection standards."

Nic Ray — Chief Executive Officer, DataEQ

DataEQ’s ISO/IEC 27001:2022 certification covers the Information Security Management System supporting the design, development, hosting and delivery of its cloud-based platforms: Analyse, Engage and Good Outcomes. The scope includes the people, processes, technologies and information assets used to securely collect, process, analyse and manage data across these services.

This confirms that DataEQ has established a structured, risk-based approach to protecting the confidentiality, integrity and availability of information. This includes appropriate safeguards for both publicly available data and non-public information, such as direct messages, client-provided data and internal operational information.

DataEQ will maintain the certification through ongoing surveillance audits, ensuring its information security practices continue to evolve alongside its platforms and client requirements.

"Achieving this certification has been a company-wide effort, and I am incredibly proud of what our teams have accomplished. For us, this is about building good security practices into the way we work and continuing to improve them over time. Certification is an important step, but it is not the end of the journey. In the coming months, we will also begin working towards ISO/IEC 42001 certification, supporting our wider business strategy and our commitment to using AI responsibly."

Meg Holtzhausen — Head of Operations & Data Compliance, DataEQ

The certification followed an independent assessment of DataEQ’s Information Security Management System. This included a review of its security governance, risk-management processes, policies, operational procedures and supporting controls.

The assessment considered how DataEQ manages information security across its business, including access management, employee responsibilities, supplier risk and incident response. It also reviewed how security controls are monitored and improved over time.

This is particularly important for DataEQ’s clients across the UK, Africa and the Middle East, including large organisations and businesses operating in regulated industries. These clients need confidence that the companies handling their data have established security practices and can provide evidence of how information security risks are managed.

ISO/IEC 27001:2022 gives clients assurance that DataEQ has implemented a recognised and structured approach to information security. It supports DataEQ’s wider data protection responsibilities under frameworks such as the GDPR and POPIA, while giving clients and their risk teams clear, independently verified information to support their own supplier assessments.