Close your
ISO 27001 & PDPA
gaps — only what's missing
Assess once, see exactly what's missing, then pick the modules you need — from documentation to technical controls to ongoing management. Led by a certified ISO 27001 Lead Auditor, with specialist PDPA partners.
ISO 27001
ISO 29110
PDPA-aligned
Lead Auditor-led
฿5M
of data breaches
originate from insiders
2022
PDPA in full
force since
ISO 27001
increasingly required
by enterprise buyers
1 path
ISO + PDPA together
shared controls
-----Our Approach
Pay only for the gaps you have
No need to start from zero. We assess what you already have and what's missing, then you take only the modules you need. GWPDPA splits delivery into two clear layers.
Policy & Governance
The policy and legal backbone — ISMS, policies, RoPA, DPIA, data-subject rights, lawful basis, and DPO. Delivered with specialist PDPA partners under Greenwill's quality control.
ISO 27001 Clauses 4–10 · Annex A org controls | PDPA ม.23–37
Technical Controls
The real controls that make compliance more than paperwork — data classification & protection, access control, encryption, backup, and monitoring. Delivered directly by Greenwill on a proven stack.
Stack: M365 Purview · Entra ID · FortiPAM · FortiGate · Nakivo/Veeam · Zabbix
-----How it works
Your compliance path in 4 steps
Start by knowing what's missing, then close the gaps in priority order.
01
Assess
A combined ISO 27001 + PDPA gap assessment — a clear report of what you have, what's missing, plus a roadmap.
Starts with Module M0
02
Choose
Pick only the modules the report flags as gaps. Pay for what you need — no all-or-nothing bundle.
Based on real gaps
03
Implement
Build the documentation, policies, and real technical controls — Greenwill's team with PDPA partners.
Track A · B · C
04
Manage
Monitor, review periodically, prep surveillance audits, and stay compliant on an ongoing retainer.
Track D · Recurring
-----Service Modules
Pick only what you're missing
Every module is available on its own. Start with the assessment (M0), then build on the results.
Compliance Gap Assessment
Assess ISO 27001 and PDPA together in one pass. Delivers a gap report, a roadmap, and the exact menu of modules you actually need.
M0 · ASSESS
ISO 27001 / ISMS
ISMS scope, risk assessment, SoA, documentation, internal audit, and certification readiness.
TRACK A · ISO 27001
PDPA (Governance & Legal)
Privacy policy suite, RoPA, DPIA, DSAR procedures, awareness training, and DPO-as-a-Service.
TRACK B · PDPA
Technical Data Protection
Data classification/DLP, access control & PAM, encryption, backup, and security monitoring.
TRACK C · CONTROLS
Managed Compliance
Ongoing: monitoring, periodic reviews, surveillance-audit prep, and a vCISO + vDPO retainer.
TRACK D · MANAGED
Not sure where to start?
Let the M0 assessment answer that — see the full picture before you commit budget.
* ISO 27001 & PDPA controls overlap heavily — doing them together costs less than separately.
-----Why Greenwill
An advisor that did it first
We don't just advise — we hold these standards ourselves and run the controls every day.
We're ISO-certified
Greenwill holds ISO/IEC 27001 and ISO/IEC 29110 — we practice exactly what we implement for clients.
Lead Auditor-led
Led by a CQI/IRCA ISO 27001 Lead Auditor — we see your program through a real auditor's eyes.
Tech + legal in one
Partners handle the legal layer, we handle the technical controls — all under one contract.
Thai team, 20+ years
20+ years in IT, a local Thai team that stays close and understands the Thai business context.
---------- Get Started
Ready to see your gaps?
Start with a readiness assessment and get a clear roadmap of what to do first —
no commitment required.
01
Book a consult
A short call to understand your context and scope.
02
Get your gap report
See what you have and lack, with a module menu and priorities.
03
Choose & start
Pick the gap modules and start closing them within your budget.
