Gwirio Gwirio
Solutions

Privacy & Compliance

Know what information you are allowed to process

More data does not necessarily create more value.

In the digital age, every additional piece of personal information an organisation collects, copies and retains can create additional privacy, security and compliance risk.

Gwirio helps organisations understand what information they are processing, why they have it, what gives them the right to process it, and whether that right still exists.

The objective is not simply to manage consent or produce compliance documentation.

It is to give an organisation a current, evidence-based view of its information-processing position — and help reduce the risk created by information it does not need or cannot justify processing.

Why

An organisation can know exactly who a person is and still not have the right to process all the information it holds about them.

Identity answers:

Who is this person?

Privacy and information rights also require organisations to answer:

Why do we have this information?

Are we allowed to process it?

What can we use it for?

How long can we keep it?

What evidence supports that?

What happens when that right expires or is withdrawn?

Digital systems make this harder because information is easily copied.

Information provided for one purpose can move into databases, applications, analytics platforms, backups and archives. A company may therefore continue processing or retaining information long after the original reason for collecting it has changed or disappeared.

Privacy regulation is increasingly pushing organisations towards data reduction, purpose limitation, risk management and demonstrable accountability.

Gwirio helps organisations address these requirements through evidence attached to the information and the rights governing its use.

What Gwirio provides

Consent Management

Gwirio can manage consent as a verifiable record, rather than simply a checkbox in an application.

This can include what was consented to, when consent was provided, its purpose, relevant conditions and whether it has subsequently been withdrawn or expired.

Information Certificates

Gwirio can create certificates that provide context around information, including its source, purpose, processing rights, consent, permitted use and lifecycle.

This allows organisations to maintain evidence about why information exists and how it may be used.

Processing Rights

Gwirio helps establish the basis on which information is being processed and whether that basis remains valid.

Where consent is required, the organisation can establish whether valid consent exists. Where another lawful basis is being relied upon, the organisation can maintain the evidence supporting that basis.

Information & Data Reduction

Gwirio can help identify information that is no longer required, cannot be adequately justified or presents unnecessary privacy risk.

The principle is simple: if you do not need the information, do not keep it.

Compliance Assessment

Gwirio can assess the information an organisation is processing against its defined purposes, rights, consent and other relevant conditions.

This provides a more practical view of compliance based on the information actually being processed, rather than relying only on policies and procedures.

Compliance Reporting

Gwirio can provide a report outlining an organisation's current state of privacy compliance, identifying areas where evidence, consent, processing rights or information lifecycle requirements need attention.

This gives management a clearer view of where privacy risk exists and what needs to be addressed.

How it works

Establish the information
Understand what information is being processed and the relevant person, organisation or system it relates to.
↓
Establish the purpose
Record why the information was collected and the purpose for which it may be processed.
↓
Establish the right
Determine what gives the organisation the right to process the information.
↓
Maintain the evidence
Maintain consent, information certificates and other relevant evidence supporting the processing.
↓
Monitor the lifecycle
Track changes to consent, processing rights, purpose, retention and expiry.
↓
Assess the position
Assess the information being processed against the rights and conditions governing its use.
↓
Report and act
Identify areas of risk and provide a current view of the organisation's compliance position.
Information→Purpose→Right→Evidence→Lifecycle→Assessment→Report

What value does this provide?

Know your actual compliance position

Move beyond policies and declarations to understand the state of the information actually being processed.

Reduce unnecessary data

Identify information that is no longer required or cannot be adequately justified.

Reduce privacy risk

Less unnecessary information means less information that can be exposed, misused, breached or retained incorrectly.

Maintain evidence

Keep evidence of consent, processing rights, purpose and other conditions associated with information.

Respond faster

Produce a current compliance view without having to reconstruct the organisation's position manually every time a review or audit occurs.

Improve accountability

Provide management with a clearer understanding of where privacy and information-processing risks exist and why.

Where it can be used

Consent management

Manage consent across customer, employee, partner and other information-processing activities.

Customer information

Establish whether the organisation still has a valid basis for processing information about its customers.

Marketing

Establish whether information can be used for a particular marketing purpose and whether the relevant consent or processing basis remains valid.

Data sharing

Establish the rights and conditions associated with providing information to another organisation.

Legacy data

Identify information that has accumulated over time without a clear continuing purpose or processing basis.

Regulatory compliance

Provide an evidence-based view of the organisation's privacy position and identify areas requiring attention.

AI and analytics

Establish whether information being provided to AI systems, analytics platforms or automated processes can legitimately be used for that purpose.

The practical difference

Traditional privacy compliance often asks:

Do we have the right policies and processes?

Gwirio adds the question:

Do the information we are actually processing and the evidence supporting that processing match those policies and processes?

That distinction matters.

An organisation may have a well-written privacy policy while still holding information for which it cannot readily demonstrate a valid purpose, consent or processing right.

Gwirio helps connect the policy and the evidence to the information itself.

Know your position

Gwirio can work with an organisation to assess a defined set of information and establish:

  • what information is being processed;
  • why it was collected;
  • what gives the organisation the right to process it;
  • what consent has been provided;
  • whether that consent remains valid;
  • what information may no longer be necessary;
  • where processing or retention creates additional risk; and
  • what evidence is available to support the organisation's position.

The result is a clearer, evidence-based view of the organisation's privacy compliance position.

The objective is not to collect more information about compliance.

It is to understand the information you already process, reduce what you do not need, and be able to demonstrate why the information you retain and process is justified.

Discuss a Privacy & Compliance assessment