Privacy, information security and standards are often presented as paperwork, checklists or formal requirements. In practice they are about understanding what an organisation does, which information it uses, which risks exist, which procedures are needed, and how people can keep working in a careful and repeatable way.
The aim is to make requirements understandable, prepare useful documentation, set up workable procedures, and make the connection between daily work, technical systems and formal obligations visible. The point is not paperwork for its own sake, but records and habits that match the real work.
The AVG/GDPR asks practical questions. Which personal data do you collect? Why do you collect it? Who receives it? How long is it kept? How is it protected? What happens when someone asks to inspect, correct or delete their data? Which systems, websites, forms, mailboxes, cloud services, processors and backups are involved?
We help make these questions understandable and workable. This can include reviewing forms, website plugins, analytics, embedded services, customer records, mailboxes, cloud folders, backups, access rights, processor relationships, privacy text and retention choices. The goal is not to create paperwork for its own sake, but to make the real data handling clear enough to manage responsibly.
Good privacy and security documentation should describe what actually happens. A privacy statement, processing overview, retention list, procedure or security measure is only useful when it matches the real systems, real accounts and real working habits of the organisation.
Part of the work is therefore to compare documents with practice. Which data is collected through the website? Where do form submissions go? Who has access to the mailbox? Which backups exist? Which external parties are involved? Which procedures are already followed informally but not written down? Which documents are too vague, outdated or copied from somewhere else?
Some organisations need to prepare for certification, an audit, a supplier assessment, a customer questionnaire or a more formal review of their quality management or information security. This may involve standards such as ISO 9001 for quality management or ISO 27001 for information security management.
Within the foundation there is board-level auditing expertise for ISO 9001 and ISO 27001. This can be used to help set up the documents, procedures, records and working habits needed to prepare for an audit or certification process. The work can include explaining the structure of a management system, identifying missing procedures, reviewing existing documentation, preparing evidence, and making sure the chosen approach fits the size and reality of the organisation.
Certification itself is performed by an appropriate external certification body or audit party. Our role is preparation and guidance: helping you understand what is being asked, what evidence is needed, which procedures must be in place, and how the documentation can remain useful after the audit is finished.
Procedures should help people work consistently. They should not be so large or abstract that nobody uses them. Depending on the organisation, useful procedures may cover access management, backups, updates, incident handling, customer data, document control, supplier selection, complaints, changes, onboarding, offboarding, risk assessment or periodic review.
We can help write or improve these procedures in a way that connects to actual daily work. That means looking at who does what, which systems are used, which decisions need to be recorded, how exceptions are handled, and how the procedure can be followed without creating unnecessary administrative burden.
Privacy, quality and information security are not only legal or administrative topics. They also depend on technical choices: accounts, passwords, two-factor authentication, administrator roles, server access, website updates, mail authentication, backups, logging, file sharing, cloud services, CMS plugins, themes, forms and third-party scripts.
Where relevant, we look at how technical systems support or undermine the intended procedure. A policy may say that access is limited, but the website, mailbox, shared folder or social media account may tell a different story. Making these differences visible is often the first step towards a setup that is easier to maintain and explain.
Audit preparation often requires evidence. It is not enough to say that something is done carefully; it must be possible to show how it is done, when it was reviewed, who is responsible, and where the relevant records are kept.
We can help identify which evidence already exists and which records still need to be created. This can include policies, procedures, access lists, backup checks, incident records, supplier overviews, processing records, risk assessments, change logs, training notes, review minutes and examples of completed work. The aim is to make the organisation understandable to itself first, and then easier to explain to an auditor, customer or partner.
Sometimes the immediate need is not a full certification process, but a customer, supplier, funder or partner asking questions about privacy, security, quality or data handling. These questions may arrive as a checklist, contract appendix, security questionnaire, processor agreement or informal request.
We can help interpret what is being asked, gather the relevant facts, write careful answers and identify where the organisation should improve before giving commitments. This helps avoid vague promises, copied answers or statements that do not match the actual technical and organisational situation.
Not every organisation needs the same level of documentation, controls or formal certification. A small website, a local activity, a webshop, a care-related project, a technical supplier and an organisation handling sensitive personal data all have different risks and obligations.
Part of the work is learning what applies to the situation. Which requirements are legal obligations? Which are customer or supplier requirements? Which are good practice? Which controls are proportionate? Which documents are necessary now, and which would only add complexity without improving the work?
Some situations require specialised legal advice or formal representation. This can be the case when there is a dispute, enforcement risk, contractual conflict, formal complaint, regulatory investigation or a need for a legal opinion.
Our role is practical and educational: helping to understand the technical and organisational situation, prepare useful documentation, improve procedures, gather evidence, explain choices, and make privacy, quality and information security easier to manage. Where legal advice or accredited certification is needed, the appropriate external professional or certification body should be involved.
The result may be a clearer privacy statement, a processing overview, better access documentation, improved procedures, audit preparation notes, an evidence file, a supplier overview, a risk register, incident handling steps, cleaner website data flows, or a practical plan for ISO 9001 or ISO 27001 preparation.
The common thread is understanding and control. People and organisations should know which information they handle, which obligations apply, which procedures are followed, which evidence exists, and how the work can remain careful, explainable and maintainable over time.