At K2 X Border, we only collect, process and transfer personal data to our third-party suppliers and partners if it is necessary for the purpose of performing the specific services requested by our clients.
We carry out the intra-group cross-border transfer of personal data. To regulate this, we have an intra-group data transfer agreement, which incorporates the following:
In order to ensure privacy across our developed solutions and operational processes, we have implemented several controls in line with our ISO 27001, SOC 2 and Cyber Essentials Plus certifications:
We encrypt all sensitive data both in transit and at rest, using industry-standard encryption algorithms.
We have strict access controls and authentication mechanisms in place. Only authorised personnel who have a legitimate need-to-know argument have access to sensitive data. Additionally, we enforce strong password policies and regularly review access permissions to mitigate the risk of unauthorised access.
We mandate regular privacy training and awareness programmes for all employees, ensuring that our people understand the importance of data privacy and are equipped to handle data securely and responsibly.
We have established and robust data protection policies in place. We have appointed a dedicated Data Protection Officer, plus we carry out regular compliance assessments to ensure adherence to relevant data privacy laws.
We enforce data minimisation principles, only collecting and retaining the minimum amount of data necessary to fulfil our business purpose. This reduces the overall level of risk exposure.
We have implemented rigorous incident response and breach notification procedures. In the event of a data breach or privacy incident, we have protocols in place to promptly assess the situation, mitigate the impact, and notify affected parties in accordance with legal requirements.