Skip to main content

Data Privacy & Information Governance

Managed Information Governance

Ongoing, senior-led information governance for organisations that need records, information risk and accountability managed consistently — not revisited only when an audit arrives.
Information governance operating model
  1. Information assets
  2. Ownership
  3. Lifecycle
  4. Controls
  5. Assurance
  6. Leadership

Ongoing information-governance capability, not a periodic clean-up — with defined-scope work available where the operating model or baseline first needs to be established.

Best suited to regulated, multi-entity, multi-site or public-sector-facing organisations that need information governance to operate consistently across teams, records and systems.

Senior-led by Michael Abtar, CEO and Founder · LLB (Hons), PG.Dip.Law, Cert. DPO

When organisations engage us

Signals that it is time to act

  1. Information governance relies on one person or goodwill
  2. Records, retention and information-asset ownership are unclear
  3. Information risks are not reported to senior leadership
  4. Audit, contract or assurance requirements keep recurring
  5. Several business units handle information differently
  6. Incidents or near misses reveal gaps in control

What the service covers

Outcomes the service is built to deliver

IG framework and accountability
Defined roles, committees and reporting lines for information governance.
Information assets and risk
Oversight of information-asset registers, owners and information-risk management.
Records and retention governance
Governance of records management and retention so information is kept, and disposed of, deliberately.
Policy and procedure maintenance
Keeping IG policies and procedures current and consistently applied.
Incident and issue governance
Clear routes for information incidents, lessons learned and escalation.
Leadership reporting
Regular, evidenced reporting on information risk and progress.

How we deliver

Assess → Build → Manage → Assure → Improve

  1. Assess

    Baseline IG maturity, risks and evidence.

  2. Build

    Agree the IG model, priorities and reporting rhythm.

  3. Manage

    Run ongoing oversight, advice and issue governance.

  4. Assure

    Evidence control and progress for leadership and auditors.

  5. Improve

    Refresh priorities as the organisation and risks change.

Scope boundaries

Included, and separately scoped where required

Included in the core service

  • IG oversight and structured programme management
  • Senior advice and challenge
  • Risk-based prioritisation
  • Leadership and committee reporting

Separately scoped where required

  • Large-scale records remediation or migration
  • Operational administration at scale
  • Specialist cyber or legal deep dives
  • Major implementation programmes

What you receive

Outputs you can picture before you engage

Generic structures showing the shape of typical outputs. Content is agreed with each client.

Illustrative structure — not a client document

Example content shown for illustration only.

Information asset ownership register

AssetOwnerClassificationRetentionLast review
Customer recordsCustomer Services DirectorConfidentialPer approved retention scheduleReview date set
HR filesHR DirectorRestrictedPer approved retention scheduleReview date set
Finance ledgersFinance DirectorConfidentialCurrent schedule appliesReview date set

Relevant evidence

Relevant evidence

  • Named client · Healthcare / NHS

    NHS England

    Strategic data-privacy and data-sharing advisory

    National privacy-by-design framework · multiple national workstreams

    View the evidence: NHS England
  • Named client · Higher Education / Research

    UCL

    IG audit, improvement plan, training and physical-security audit

    Helped shape and focus the final DSPT submission

    View the evidence: UCL
  • Named client · Financial Services

    AIG

    Supplier data-governance audit

    Nationwide supplier audit

    View the evidence: AIG

Explore all case studies →Request Relevant Evidence →

Portrait of Michael Abtar, CEO and Founder of IG-Smart.

Service lead

Michael Abtar · CEO and Founder

LLB (Hons), PG.Dip.Law, Cert. DPO

Governance, risk and assurance specialist with more than 18 years' experience spanning privacy, cyber resilience, AI governance, digital transformation, healthcare and complex regulated organisations.

Experience includes governance and assurance work involving more than 100 million consumer records.

View profile

Investment

Scoped to requirement

Delivered as a managed & retained service. Scope, deliverables, assumptions and fees are agreed in writing before work begins.

Talk to a Senior Practitioner How engagements & investment work

Fees reflect factors such as

  • Organisational scale and complexity
  • Number of entities and jurisdictions
  • Scope of retained responsibility
  • Existing maturity
  • Volume of remediation support
  • Required availability
  • Assurance and reporting requirements

Questions

Frequently asked questions

How does this differ from an IG assessment?

An assessment is a defined-scope review of where you stand. Managed Information Governance provides continuing oversight and support so improvements are sustained.

Does it cover data protection?

It covers the governance that data protection depends on. Where formal DPO oversight or a privacy programme is needed, it can be combined with those services with responsibilities kept distinct.

Can it support NHS assurance requirements?

Yes, it can support the governance behind NHS requirements. Where a DSPT submission needs dedicated readiness or assurance work, that is scoped as NHS DSPT Readiness & Assurance.