Privacy information management

Make privacy a managed capability.

Turn privacy commitments into defined responsibilities, practical controls and evidence through a Privacy Information Management System.

Discuss ISO 27701 / PIMS

Designed for your context

The right support
for the decision ahead.

For personal information controllers and processors strengthening privacy management or exploring certification and Philippine Privacy Mark readiness.

What we deliver

Scope tailored to your organisation

PIMS gap assessment

Review privacy management against the applicable ISO/IEC 27701 edition and certification scope.

PII inventory & data flows

Identify personal information, processing purposes, systems, transfers and accountable owners.

Privacy risk assessment

Assess risks to individuals and establish appropriate treatment actions.

Policies, procedures & controls

Develop the PIMS framework and controller/processor controls.

NPC integration

Map relevant Philippine privacy obligations into the management system.

Audit preparation

Support internal audit, corrective actions and certification-body preparation.

Tangible outputs

Leave with more
than recommendations.

  • PIMS scope and gap assessment
  • Personal-information inventory
  • Privacy risk assessment
  • Policies and control evidence
  • Audit-readiness plan

A clear path to progress

  1. 01

    Define scope and applicable criteria

  2. 02

    Map data and assess privacy risk

  3. 03

    Implement and document controls

  4. 04

    Audit and prepare

Philippine context & engagement boundaries

Confirm the applicable standard edition, certification route and current NPC Philippine Privacy Mark criteria before committing to prerequisites or eligibility. Advisory readiness support is not certification or NPC approval.

Questions worth asking

How is the engagement scoped?

We start with your priorities, operating context and current capabilities. The proposal sets out deliverables, responsibilities, dependencies and acceptance criteria.

Can this connect with other Gardoce services?

Yes. Related advisory, security, architecture and implementation work can be coordinated, with each workstream’s scope and ownership made explicit.

Every engagement starts with a clear scope, agreed responsibilities and practical outcomes.

Start with a conversation

What needs to move
forward in your organisation?

Tell us the decision, risk or operational challenge you are facing. We will help define a sensible next step.

Discuss your priorities