consultancy · data governance
Privacy that you demonstrate, not just declare.
We turn your legal framework into daily operation: auditable records, real controls, and measurable data governance, the foundation any safe AI adoption depends on.
sec. 01 · problem
A policy in a drawer protects no one, and won't survive an audit.
Privacy isn't solved with isolated documents. Real data governance is a set of processes, controls, evidence and measurable operations that run continuously, so that when a regulator, a client or your own board asks, you can show how personal data is handled, who can access it, and what your AI systems actually do with it.
sec. 02 · the pillars
What holds data governance up.
Talent
Role-based capability across legal, IT, business and data teams.
Culture
Data-driven and privacy-aware, from leadership down.
Data & AI
Catalog, lineage, quality and protection, extended to AI.
Platform
Continuous operation and evidence, see Pharus Privacy.
sec. 03 · our services
Make governance run day to day.
Data-Protection Technical Package
RoPA, DPIAs, data-subject-rights handling, lawful bases, risk matrix and remediation plan.
Auditable Records of Processing
Activities with flows, owners, categories, lawful bases and evidence.
Privacy Operations (PrivacyOps)
Ongoing management of requests, consents, breaches and third parties.
Data Governance
Catalog, lineage, roles, access, policies, quality and PII protection.
Role-Based Training
Practical paths for leadership, legal, IT, business, marketing and data teams.
Privacy-by-Design for AI
Extending governance to prompts, outputs and agent data flows.
sec. 04 · method
How the engagement runs.
Diagnose
Gap assessment and data mapping.
Design
Policies, controls, RoPA and roles.
Implement
PrivacyOps, tooling and an evidence vault.
Operate & Improve
Continuous monitoring, DSAR handling and audit readiness.
From diagnosis to daily operation, with the evidence to prove it.
sec. 05 · deliverables
What the engagement leaves you.
- Records of Processing (RoPA)
- DPIA set
- DSAR / rights procedure
- Risk matrix & remediation plan
- Data catalog & lineage
- Governance policy set
- Training plan
sec. 06 · platform
Operated on Pharus Privacy.
Compliance under Chilean law. For organizations operating in Chile, we adapt the engagement to Ley 21.719 (personal-data protection) and Ley 21.663 (cybersecurity framework), including ARSOP rights handling, Acceso, Rectificación, Supresión, Oposición, Portabilidad, alignment to the PROA Framework, and CertiProf-referenced practices. Delivered with our Chilean partners.
Outside Chile, the same engagement maps to GDPR and your local data-protection and cybersecurity law.
sec. 07 · questions
Frequently asked
By default the engagement is jurisdiction-neutral and maps cleanly to GDPR. We adapt it to your local data-protection and cybersecurity law, including Chile's Ley 21.719.
Yes. For organizations in Chile we adapt to Ley 21.719 and Ley 21.663, ARSOP rights handling and the PROA Framework, delivered with our Chilean partners. See the regional addendum below.
It's the foundation any safe AI adoption depends on. We extend governance to prompts, outputs and agent data flows, privacy-by-design for AI.
A Record of Processing Activities, an auditable inventory of how personal data is handled, with flows, owners, categories, lawful bases and evidence. We build and keep it live.
Yes. We operate this governance on Pharus Privacy, which keeps records live and generates continuous regulatory evidence, advisory and tooling in one.
next step
Let's find your first win.
Tell us how your team works today and what's slowing it down. We'll point you to the right starting line. For most teams, that's a one-day AI Ignite workshop.
next step
Book a technical consultation.
Tell us your regulatory context and where your data lives. We'll map the gap between policy and daily operation, and the evidence you'll need when someone asks.