Privacy
Privacy by design
The platform is designed from the ground up around data protection principles – aligned with the GDPR and beyond.
We build DataNXT with regulatory compliance and data protection at the core of the platform architecture. This page sets out which standards we are working towards and where we currently stand.
Targeted, not certified. The standards named on this page describe our target state. At this point there are no completed external certifications or audit reports. We label each item accordingly and update this page as assessments complete. Please do not use these statements as evidence of certification in procurement or tender processes.
Privacy
The platform is designed from the ground up around data protection principles – aligned with the GDPR and beyond.
Regulation
We are developing the policies, procedures, and technical controls needed to meet financial services regulation and industry standards.
Operations
Ongoing monitoring, regular assessments, and improvement processes maintain the standard rather than reaching it once.
In preparation
Requirements for data protection, data subject rights, and cross-border data transfers.
In preparation
Controls for security, availability, processing integrity, confidentiality, and privacy.
In preparation
An information security management system (ISMS) following international best practice.
In preparation
Cloud-specific security controls and guidance for providers and their customers.
In preparation
Protection of privacy in cloud computing environments and handling of personally identifiable information.
In preparation
Readiness for financial services regulatory requirements and industry-specific obligations.
Analysis of applicable regulations and industry standards to define our compliance requirements.
Designing the platform architecture with built-in compliance controls, security measures, and privacy safeguards.
Creating the policies, procedures, and documentation that support the compliance framework.
Implementing the controls and testing them thoroughly to demonstrate effectiveness and reliability.
Engaging external auditors and certification bodies to validate the implementation.
Ongoing monitoring, assessment, and improvement of our compliance posture.
We answer questions about regulatory readiness and data protection practice – and say plainly what is not finished yet.