Skip to main content

Data Privacy & Information Governance

Managed Data Privacy Programme

A managed privacy-governance programme for organisations that need structured, ongoing privacy capability — whether or not a formal DPO appointment is part of the engagement.
Privacy governance cycle
  1. Processing change
  2. Risk / DPIA
  3. Decision
  4. Action
  5. Oversight
  6. Reporting

Ongoing privacy governance, not one-off advice — with defined-scope assessment or remediation available where a baseline needs to be established first.

Senior-led by Michael Abtar, CEO and Founder · LLB (Hons), PG.Dip.Law, Cert. DPO

When organisations engage us

Signals that it is time to act

  1. Privacy obligations are growing faster than in-house capacity
  2. DPIAs, rights requests and incidents are handled inconsistently
  3. The board needs regular, evidenced privacy reporting
  4. A DPO is in place but the wider privacy programme has no owner
  5. Multiple entities, jurisdictions or suppliers complicate compliance
  6. Audit, procurement or regulator scrutiny is approaching

What the service covers

Outcomes the service is built to deliver

Governance and accountability
A clear privacy governance structure, defined roles and a documented accountability framework.
Policy and control framework
Support to maintain policies, notices and controls as processing and regulation change.
Processing governance
Oversight of records of processing and how new or changed processing is assessed.
DPIA, risk and issue governance
Structured handling of DPIAs, privacy risks and issues, with clear escalation.
Rights, incident and escalation governance
Defined routes for rights requests, personal-data incidents and decisions that need senior attention.
Executive, board and regulator-ready reporting
Regular reporting that gives leadership an evidenced view of privacy risk and progress.
Prioritised improvement planning
A risk-based roadmap so effort goes where it reduces most exposure.
Ongoing senior advisory support
Access to senior practitioner judgement as questions arise.

How we deliver

Assess → Build → Manage → Assure → Improve

  1. Assess

    Baseline current privacy governance, risk and evidence.

  2. Build

    Agree the governance model, priorities and reporting rhythm.

  3. Manage

    Run the programme: oversight, advice, issue and risk governance.

  4. Assure

    Evidence progress for leadership, auditors and regulators.

  5. Improve

    Refresh priorities as processing, risk and regulation change.

Scope boundaries

Included, and separately scoped where required

Included in the core service

  • Governance, oversight and structured programme management
  • Senior advice and independent challenge
  • Risk-based prioritisation
  • Management and board reporting

Separately scoped where required

  • Operational administration at scale
  • Extensive remediation delivery
  • Large implementation programmes
  • Specialist cyber, legal or international-transfer deep dives
  • Resource-heavy privacy-office execution

What you receive

Outputs you can picture before you engage

Generic structures showing the shape of typical outputs. Content is agreed with each client.

Illustrative structure — not a client document

Example content shown for illustration only.

Privacy decision register

RefDecisionRationaleOwnerStatus
D-01Approve new analytics processingDPIA complete; residual risk acceptedHead of ProductClosed
D-02Extend retention for support recordsLegal basis reviewedOperations leadOpen
D-03New international supplierTransfer assessment pendingProcurementEscalated

Relevant evidence

Relevant evidence

  • Named client · Healthcare / NHS

    accuRx

    Retained DPO and NHS IG support

    Retained DPO services · privacy and NHS information-governance support during growth

    View the evidence: accuRx
  • Named client · Security Services & Technology

    Banham Group

    Defined-scope assessment → retained managed DPO service

    Gap analysis → implementation support → outsourced DPO since 2020

    View the evidence: Banham Group
  • Named client · Life Sciences / Pharmaceutical

    Glenmark Pharmaceuticals

    Retained external DPO service

    Retained external DPO · EU & LATAM remit

    View the evidence: Glenmark Pharmaceuticals

Explore all case studies →Request Relevant Evidence →

Portrait of Michael Abtar, CEO and Founder of IG-Smart.

Service lead

Michael Abtar · CEO and Founder

LLB (Hons), PG.Dip.Law, Cert. DPO

Governance, risk and assurance specialist with more than 18 years' experience spanning privacy, cyber resilience, AI governance, digital transformation, healthcare and complex regulated organisations.

Experience includes governance and assurance work involving more than 100 million consumer records.

View profile

Investment

Scoped to requirement

Delivered as a managed & retained service. Scope, deliverables, assumptions and fees are agreed in writing before work begins.

Talk to a Senior Practitioner How engagements & investment work

Fees reflect factors such as

  • Organisational scale and complexity
  • Number of entities and jurisdictions
  • Scope of retained responsibility
  • Existing maturity
  • Volume of remediation support
  • Required availability
  • Assurance and reporting requirements

Questions

Frequently asked questions

Is this the same as an outsourced DPO?

No. A DPO provides independent oversight of compliance. This programme provides structured, ongoing privacy governance capability. It can run alongside a DPO — internal, or provided by IG-Smart — with decision rights kept clearly separated.

Do we need to appoint IG-Smart as our DPO?

No. The programme can operate with or without a formal DPO appointment. Where a designated DPO is also required, see our Outsourced & Fractional DPO Services.

Can it work alongside our internal privacy team?

Yes. Scope is agreed around the capability you already have, so the programme strengthens your team rather than duplicating it.

What is not included?

Operational administration at scale, extensive remediation, large implementation programmes and specialist deep dives are scoped separately where required, so the core programme stays focused on governance, oversight and reporting.

Next step

Need ongoing privacy governance — or still defining the model?

Not sure what applies?Find the Right Service