Skip to main content

Data Privacy & Information Governance · Managed service

Managed Data Privacy Programme

Ongoing, senior-led privacy governance — so decisions, actions and evidence stay governed continuously, without building equivalent senior capability in-house.

Not occasional advice. An operating capability that keeps privacy risk in view, period after period.

View retained DPO & privacy-governance evidence — View Relevant Evidence

When this service fits

Privacy governance has outgrown ad-hoc support

  • No dedicated senior privacy capability

    Material privacy matters lack an experienced senior owner and independent challenge.

  • Privacy activity is hard to coordinate

    Data protection impact assessments (DPIAs), incidents, rights requests, policy actions and business change are handled inconsistently.

  • Multiple teams or jurisdictions

    Accountability, decisions and evidence need to stay coherent across the organisation.

  • Leadership needs better visibility

    Executives or the Board need a clear view of risk, open actions and decisions required.

  • External scrutiny is increasing

    Customers, regulators, auditors or procurement teams expect stronger evidence of privacy governance.

Service boundaries

Managed privacy programme or outsourced DPO?

Is this the same as an outsourced DPO?
No. A DPO provides independent oversight of compliance. The Managed Data Privacy Programme provides structured, ongoing privacy-governance capability. It can operate alongside an internal DPO or an IG-Smart-provided DPO, with responsibilities and decision rights kept clearly separated.
Do we need to appoint IG-Smart as our DPO?
No. The programme can operate with or without a formal IG-Smart DPO appointment. Where a designated DPO is also required, see our Fractional & Outsourced DPO Services.
Fractional & Outsourced DPO Services

What changes for your organisation

Privacy governance you can see, operate and evidence

  • Clear ownership

    Material privacy matters have accountable owners.

  • Decisions on record

    Advice, management decisions and rationale stay traceable.

  • Actions stay visible

    Open, overdue and escalated matters don’t disappear into email.

  • A usable leadership view

    Reporting focuses attention on material risk and decisions.

IG-Smart Managed Privacy Governance Cycle

A recurring governance cycle, not a one-off project

  1. Oversee

    Matters, risks and upcoming decisions stay visible.

  2. Advise

    Senior challenge and advice when decisions arise.

  3. Act

    Agreed activities, actions and escalations.

  4. Evidence

    Decisions, rationale and records maintained.

  5. Report

    Material position presented to leadership.

  6. Improve

    Priorities refreshed as risk and processing change.

Improve feeds the next period’s oversight.

How the programme starts

Mobilisation begins at the start of the engagement. The timetable, milestones and service cadence are agreed in writing for your organisation, rather than a fixed first-month schedule.

  1. Agree the operating model

    Governance, responsibilities, escalation routes, reporting requirements and service cadence.

  2. Review the starting position

    Existing privacy arrangements, current risks and priority matters.

  3. Establish the working records

    Establish or rationalise registers, decision records and oversight mechanisms; agree initial priorities.

  4. Move into recurring governance

    Oversee → Advise → Act → Evidence → Report → Improve.

What you receive

The working records of a governed privacy programme

The dashboards, registers and executive reporting that may support the programme.

Privacy Governance Dashboard · Q3 periodIllustrative data — not client data
Overall positionAmber — improving
Open privacy risks
7
▼ 2 vs last period
DPIAs open / closed
3 / 11
▲ 2 closed
Incidents under review
1
No change
Rights requests
14
▲ 3 this period

Privacy risk by severity

  • High2
  • Medium3
  • Low2

Evidence complete

82%

Overdue actions
4
Policy reviews due
2
Matters for escalation
2

Illustrative output

Privacy Governance Dashboard

Ongoing oversight

A recurring view of the privacy programme, so issues are seen and escalated before they become exposure.

What it helps you see

  • Current privacy-risk position and movement
  • DPIAs and assessments
  • Incidents and rights activity
  • Overdue actions and policy reviews
  • Evidence status
  • Matters requiring escalation

Likely format

Dashboard / reporting view · Supporting registers and evidence records · Executive PDF summary where agreed

Privacy Decision RegisterIllustrative data — not client data
Illustrative privacy decision register
RefMatterAdviceManagement decisionOwnerStatus
PD-14New analytics processingProceed after DPIA; minimise fieldsApproved with conditionsHead of ProductClosed
PD-15Support-record retentionShorten to agreed scheduleUnder considerationOperationsOpen
PD-16New international supplierTransfer assessment before contractEscalated to boardProcurementEscalated
PD-17Employee monitoring toolNot proportionate as proposedDeclinedHR directorClosed

+ Rationale+ Evidence ref+ Review date recorded for every entry

Illustrative output

Privacy Decision Register

Accountability & decisions

Every material privacy decision recorded with the advice given, management’s decision and its basis.

What it helps you see

  • Matter and advice given
  • Management decision and rationale
  • Accountable owner
  • Evidence reference and review date
  • Status and escalation

Likely format

Spreadsheet / register · Extract for leadership reporting

DPIA Oversight LogIllustrative data — not client data
  • Customer portalDigital leadMedium
    1. Screen
    2. Assess
    3. Mitigate
    4. DPO input
    5. Approve

    Open actions: 0Review Q1

  • HR system replacementHR directorHigh
    1. Screen
    2. Assess
    3. Mitigate
    4. DPO input
    5. Approve

    Open actions: 4Target Oct

  • Marketing automationMarketingLow
    1. Screen
    2. Assess
    3. Mitigate
    4. DPO input
    5. Approve

    Open actions: 1Target Nov

Illustrative output

DPIA Oversight Log

Risk governance

Each DPIA tracked from screening to approval, so high-risk processing never proceeds unseen.

What it helps you see

  • Processing activity and business owner
  • Risk rating and current stage
  • Open actions
  • DPO input
  • Target and next review dates

Likely format

Tracker / register · Dashboard capture

Board Privacy Summary · Illustrative data — not client dataQuarter 3 · For decision
Overall privacy positionAdequate
Movement▲ Improving

Top three risks

  1. High-risk DPIA awaiting sign-off
  2. Supplier transfer assessment overdue
  3. One policy past review date

Significant events

  • One minor incident, closed; no notification required

Decisions required

  • Approve conditional go-live
  • Confirm retention change

Next period

  • Clear DPIA backlog
  • Refresh staff awareness

Illustrative output

Board Privacy Summary

Executive reporting

The privacy position in one view for leadership, with the decisions it needs to take.

What it helps you see

  • Overall position and movement
  • Top risks and significant events
  • Overdue and high-priority actions
  • Decisions required
  • Next-period priorities

Likely format

IG-Smart branded PDF · Board pack section

Illustrative structure — not a client document. Exact outputs and formats depend on the agreed scope.

Working together

Clear about who does what

IG-Smart

  • Senior privacy / Data Protection Officer (DPO) advice
  • Independent challenge
  • Governance oversight
  • Agreed managed activities
  • Escalation
  • Reporting

Your organisation

  • Business ownership
  • Operational decisions
  • Implementation
  • Timely information and evidence
  • Management risk acceptance
  • Accountable internal owners

Typical activities within scope

Governance
DPIA oversight · policy review · accountability records
Operational privacy
Rights requests · incidents · business change
Risk & assurance
Privacy risk · supplier privacy matters · transfers where applicable
Leadership
Escalation · reporting · action tracking

Scope, cadence and reporting rhythm are agreed in writing per engagement and refreshed as processing, risk and regulation change; not every activity applies to every organisation.

Core programme and separately scoped work

Core to every programme

  • Governance, oversight and structured programme management
  • Senior advice and independent challenge
  • Risk-based prioritisation
  • Management and board reporting

Scoped separately where required

  • Operational administration at scale
  • Extensive remediation delivery
  • Large implementation programmes
  • Specialist cyber, legal or international-transfer deep dives
  • Resource-heavy privacy-office execution

Scope, cadence and reporting rhythm are agreed in writing per engagement and refreshed as processing, risk and regulation change; not every activity applies to every organisation.

Urgent matters and incident interfaces

Urgent privacy and DPO advice can be provided within the agreed scope, including personal-data breach obligations, escalation, documentation, notification considerations and management decision-making. Any response-time commitment is agreed in writing for the engagement.

Technical containment, forensic investigation, malware eradication and system recovery remain with your organisation and its security providers unless separately and explicitly contracted. Privacy advice does not transfer operational incident-response responsibility to IG-Smart.

Relevant evidence

Direct retained DPO and privacy-governance evidence

Three retained or outsourced DPO engagements — each direct evidence for this service.

  • Named client · Life Sciences / Pharmaceutical

    Glenmark Pharmaceuticals

    Retained external DPO service

    Retained external DPO · Global remit

    View the evidence: Glenmark Pharmaceuticals
  • Named client · Security Services & Technology

    Banham Group

    Defined-scope assessment → retained managed DPO service

    Gap analysis → implementation support → outsourced DPO since 2020

    View the evidence: Banham Group
  • Named client · Healthcare / NHS

    accuRx

    Retained DPO and NHS IG support

    Retained DPO services · privacy and NHS information-governance support during growth

    View the evidence: accuRx

Client perspective

“IG Smart quickly enabled AIMIA to reach GDPR readiness and implementation of the ‘privacy by design’ framework in a highly efficient and time-effective manner.”

Richard PeakePresident & COO, AIMIA Loyalty Solutions – Asia PacificGlobal data privacy management programme
View AIMIA evidence — AIMIA Loyalty Solutions – Asia Pacific case study

Your IG-Smart team

Who provides this capability

Senior-led support from relevant IG-Smart privacy, information-governance and programme specialists. Engagement responsibilities, escalation routes, continuity arrangements and any urgent-response expectations are agreed in writing for the service.

  • Subject-matter expert

    Michael Abtar

    LLB (Hons), PG.Dip.Law, Cert. DPO

    Senior governance and privacy-assurance perspective, with executive oversight of the programme.

    View profile
  • Subject-matter expert

    Shaista Peart

    BA (Hons), CIPP/E

    Privacy and information-governance specialist supporting operational and DPO requirements.

    View profile
  • Client & programme contact

    Julia Andrade

    Coordinates scope, practitioners, delivery and stakeholder communication.

    View profile

Questions buyers ask

Before you engage

Is this the same as an outsourced DPO?

No. A DPO provides independent oversight of compliance. The Managed Data Privacy Programme provides structured, ongoing privacy-governance capability. It can operate alongside an internal DPO or an IG-Smart-provided DPO, with responsibilities and decision rights kept clearly separated.

Do we need to appoint IG-Smart as our DPO?

No. The programme can operate with or without a formal IG-Smart DPO appointment. Where a designated DPO is also required, see our Fractional & Outsourced DPO Services.

Fractional & Outsourced DPO Services

Can it work alongside our internal privacy team?

Yes. Scope is agreed around the capability you already have, so the programme strengthens your team rather than duplicating it. Engagement responsibilities, escalation routes and reporting cadence are agreed in writing around the organisation’s existing roles and priority matters.

Who stays accountable for decisions?

Your organisation. IG-Smart advises, challenges, oversees and escalates; business ownership, operational decisions, implementation and risk acceptance remain with your management.

What is not included?

Operational administration at scale, extensive remediation, large implementation programmes and specialist deep dives are scoped separately where required, so the core programme stays focused on governance, oversight and reporting.

What are the fees based on?

Fees reflect organisational size and complexity, entities and jurisdictions, processing complexity, operating cadence, reporting requirements and existing internal capability. Scope, deliverables, assumptions and fees are agreed in writing before work begins. Any material work outside the agreed scope, including additional on-site requirements or travel where applicable, is discussed and agreed with you before additional charges are incurred. Engagement structure, delivery location and any commitment or response terms are agreed for your service; there is no universal package implied here.

Investment

Scoped to requirement

Delivered as an ongoing managed or retained service, depending on scope. Scope, deliverables, assumptions and fees are agreed in writing before work begins.

The fee depends on

  • Organisational size and complexity
  • Entities and jurisdictions
  • Processing complexity and regulatory environment
  • Operating cadence and volume of privacy activity
  • Reporting requirements
  • Existing internal capability

Senior privacy capability without building equivalent capability in-house. The level of oversight, operating support and reporting is tailored to your organisation; any subsequent change to scope or cost is agreed before additional charges are incurred.

Procurement or supplier-assurance review?

Visit our Trust Centre

Ready to move forward?

Choose the route that matches where you are.

Not sure which service applies? Find the Right Service

  • Still defining the requirement

    Talk to a Senior Practitioner

    Discuss the requirement, risk, scope and the right engagement model with an experienced practitioner.

    Talk to a Senior Practitioner
  • Defined scope, RFP or tender

    Submit a Requirement

    Share a defined requirement, RFP, tender, statement of work or existing scope for senior review.

    Submit a Requirement
  • Procurement or supplier assurance

    Prepare for Procurement Review

    Access company, security and assurance information for supplier review, with controlled evidence available on request.

    Open Trust Centre

Know the service, but not sure what we need to scope it?

A few questions about your organisation so the first conversation starts in the right place. This is not an audit.