Information Security Policy: Version 18.2 – as at March 2026.
When this Policy is updated, the updated policy will be published on our website at: www.datazoo.com. The most current version of our Policy will always be the version published on our website and any previously downloaded or printed versions should not be relied upon. We will identify each version, include a publication date, and ensure that superseded versions continue to be available upon request from our GRC Team or Privacy and Data Protection Officer.
1. Introduction
1.1 Terms and Definitions
“we”, “us” and “our” refer to Data Zoo. “staff” and “users” means all of those who work under our control, including employees, contractors, interns etc.
1.2 Purpose and Scope
The aim of this top-level policy is to define the purpose, direction, principles, and basic rules for information security management. The purpose of this document is to summarise our security practices.
1.3 Users and Responsibilities
Users of this document are all our staff, as well as relevant external parties. Further details and explanations can be provided by the Data Zoo GRC Team on request. The ISMS Manager is responsible for all aspects of the implementation and management of these arrangements, unless noted otherwise. Managers and supervisors are responsible for the implementation of these arrangements within the scope of their responsibilities and must ensure that all staff under their control understand and undertake their responsibilities accordingly.
2. Compliance and Assurance
2.1. Leadership Commitment Data Zoo's leadership has clearly defined roles and responsibilities for managing privacy and security of data and information systems. To reinforce this commitment, the Senior Leadership Team actively participates in all information security related matters via multiple steering committees. This active involvement enhances awareness, provides strategic feedback and guidance, and ensures continuous oversight and effective management of information security. 2.2. Compliance Framework Data Zoo has established a compliance framework that enables the organisation to effectively identify and manage information security, privacy, and business risks. Data Zoo ensures the security and confidentiality of the Source Data that is supplied under the agreements from customers for the verification of their individuals. Data Zoo is ISO 27001:2022 certified; has been issued SOC 2 Type II report; adheres to relevant GDPR and CCPA/CPRA controls; and holds attestation for CSA STAR Level 2. Data Zoo Compliance can be viewed at: https://datazoo.com/compliance.
2.3 ISO 27001:2022 Certification
Data Zoo has designed, developed, and implemented comprehensive information security controls in its ISMS to establish, monitor and continually improve safeguards for the confidentiality, integrity, and availability of all physical and electronic information assets. The ISMS is aligned to the ISO 27001:2022 standard, which has been certified by a JAS-ANZ accredited body for the organizations. Certification can be viewed at: https://datazoo.com/compliance
2.4 SOC 2 Type 2 Reports
Data Zoo annually undergoes SOC 2 Type II audits for the relevant Security Trust Service Criteria (TSP). The scope and outcomes of these audits are outlined in a SOC 2 report issued to the organisation. A copy of the respective reports can be provided upon request.
2.5 CSA STAR Level-1 & Level-2
Data Zoo has successfully completed CSA STAR audits and holds annual attestations for CSA STAR Level-1 and Level-2. The CSA Registry entry can be accessed here: https://cloudsecurityalliance.org/star/registry/data-zoo
2.6 ESG Reporting
At Data Zoo, we are committed to creating and maintaining a sustainable business model that aligns with our values and prioritizes the well-being of our customers, the environment, and the communities in which we operate.
3. Risk and Information Security
3.1 Risk Assessment
We have implemented an ISO 31000-based Enterprise Risk Management Framework, conducting a proactive information security risk review across the organization. This review adheres to established criteria and is performed at least every 12 months or whenever significant changes occur. Directed by the FAR Committee, the review leverages both internal and, when necessary, external expertise. Data Zoo assesses and evaluates identified risks to determine their severity, probability, and controllability, assigning a relative Risk Index score. These scores are compared against approved criteria and risk appetite to identify and prioritise risks that require treatment. If a risk necessitates treatment or if there is a legal obligation, the ISMS Manager collaborates with the risk owner, the asset owner, and relevant experts to agree on appropriate mitigation methods. Following this consultation, a Risk Treatment Plan and a Corrective Action Plan are developed. The ISMS Manager and GRC Team maintain comprehensive records of the Enterprise Risk Management and information security risk assessment processes and their outcomes. Data Zoo continually reviews its risk assessment practices internally to ensure a pragmatic, business-led approach, adherence to best practices, and continuous improvement. Data Zoo integrates information security into every stage of the project lifecycle, with risk assessments, security requirements, awareness training, formal and informal consultation and regular audits. Security controls are continuously monitored, and post-project reviews ensure ongoing improvement and compliance with security standards.
3.2 Ongoing Compliance and Assurance
Data Zoo conducts annual internal audits of its compliance framework to provide independent and objective assurance, enhancing operational effectiveness. The internal auditor prepares a detailed audit plan outlining the scope, objectives, and criteria. In collaboration with business unit heads, the auditor reviews processes against expected information security and privacy controls, performing technical compliance tests as needed to ensure systems align with policies, standards, and guidelines. Identified non-compliances are addressed through root cause analysis, corrective action planning, and follow-up, with oversight from the ISMS Manager to ensure effective resolution. Quarterly vulnerability assessments and penetration testing are conducted across all systems to maintain technical resilience. Aligned with the ISO 27001:2022 standard, Data Zoo undergoes annual external surveillance audits and recertification every three years. Additionally, we perform annual SOC 2 Type 2 audits for Trust Services Criteria (TSP) compliance and demonstrate adherence to CSA STAR Level 2 requirements.
3.3 Vulnerability Assessment and Penetration Testing
Data Zoo has formal Vulnerability and Penetration testing program, implemented with the goal of improving defensive IT security for Data Zoo’s infrastructure, systems, services, and applications. Penetration tests or vulnerability assessments at Data Zoo follow a formal methodology as per our Vulnerability Management Procedure; they are carefully planned, exercised with due caution, and are designed to be repeatable. Penetration and vulnerability testing is completed every quarter by industry recognised professionals, with any outcomes/recommendations actioned immediately. In addition, host scanning is conducted every three months.
3.4 Roles and Responsibilities
Data Zoo ensures adequate resources and clear role assignments to meet information security and compliance objectives, documented in Roles and Responsibilities Register. Data Zoo's Code of Conduct upholds professional and ethical standards, requiring staff to report risk or compliance concerns promptly for timely action.
3.5 Secure Development
The Data Zoo development team follows secure software practices throughout the lifecycle, implementing controls to prevent, detect, and respond quickly to security threats. Changes are managed through formal procedures, with version control ensuring consistency among developers. Modifications to third-party applications are minimal and strictly controlled. Secure system engineering principles are documented and applied to all implementations. Third-party acquisitions comply with the Data Zoo’s Supplier Management Policy.
4. Information Handling
4.1 Personally Identifiable Information (PII) Protection
At Data Zoo, we treat Personally Identifiable Information (PII) with the highest sensitivity. We use one-way hashing methods to protect transactional PII, following our Information Classification and Handling Policy and our Cryptographic Controls Policy. We comply with applicable data protection laws and, where relevant, incorporate GDPR principles. We process PII in accordance with applicable legal bases, regulatory requirements, and contractual obligations.
4.2 Data Destruction
The Data Retention and Disposal Policy outlines data destruction techniques and considerations. We dispose of all data when no longer required for business purposes and do not store customer PII unless instructed. By default, data is retained for up to 24 hours to support search summary reporting, which customers may disable upon request. After this period, personal information is no longer used or accessible in active systems; any residual data exists only within restricted system-level recovery environments for 48 hours and may only be accessed or restored in the event of a system incident or recovery scenario. Retired physical devices and media are securely removed, destroyed, and overwritten according to the company policy.
4.3 Data & Service Integrity
Data Zoo’s identity verification solution operates within a comprehensive and robust regulatory framework supported by stringent policies that promote trust in digital identity verification services, ensuring data protection, privacy, and accountability. We maintain the integrity of all our services and data sources through a rigorous quality assurance process, comprising both manual and automated testing.
Automated monitoring is conducted, which enables real-time system monitoring to ensure our services remain online and responsive. Customers can access this service via the Support Portal: https://help.datazoo.com/en/dz-knowledge-base. Manual testing involves regular checks against selected data sources to verify actual service input/output, performed using Postman Monitoring. This testing regime compares expected and actual results, with any discrepancies investigated by the support staff. The goal is to ensure consistent response structures and data formats. Data Zoo’s identity verification service is accessible through API, Batch, and Web Application interfaces.
Data Zoo’s identity verification service is provided via API, Batch, and Web Application. API & Web: All transaction logs have PII de-identified. For search summary reports, PII is retained for up to 24 hours to support customer access for reporting purposes. Customers may opt out of the 24-hour retention period by submitting a formal request. If a customer opts out, the search summary reports will not be stored or made available. Batch: All transaction logs have PII de-identified. For search summary reports, PII is retained for up to 24 hours to support customer access for reporting purposes. Customers may opt out of the 24-hour retention period by submitting a formal request. If a customer opts out, the search summary reports will not be stored or made available. All customer files received for batch processing and returned with verification results via SFTP are automatically deleted from our system within 72 hours of delivery. |
4.4 Data Life Cycle Management
We prioritise privacy throughout the data lifecycle. We ensure that the data acquisition processes capture all necessary data for transactions. Non-PII transaction logs are stored securely and optimally to minimise storage and maximise access speed. Once securely stored, data is discovered, classified, and categorised based on regulatory requirements, business value, criticality, and sensitivity according to the Information Classification and Handling Policy. Unneeded data is destroyed per the Data Disposal Policy. See the table below for a summary of Data Life Cycle stages.
Table 4.4.1 – Data Life Cycle Management
Stage | Protection Procedure |
|---|---|
Collection/Transmission | Data is transferred via SOAP and/or RESTful web service calls via HTTPS. |
Use | All Customer PII is hashed after the completion of the transaction so that it can never be reidentified. |
Retention | We do not retain any customer PII, except where search summary reports are stored for up to 24 hours to support customer access for reporting purposes. This retention is optional and can be disabled upon formal request. |
Destruction | Data is destroyed when no longer needed. |
4.5 Asset Management
All critical assets related to information and processing facilities are listed in the Information Asset Inventory. Each asset is assigned an owner and classified per Information Classification and Handling Policy. The Acceptable Use Policy outlines the requirements for asset usage, which all staff must follow. We ensure proper handling of information assets according to their classification.
5. Access Controls
5.1 Access Control Policies
We manage access risks as per the Access Control Policy, granting access based on the principle of ‘Least Privilege’. Access provisioning and de-provisioning follow formal procedures, and periodic reviews ensure integrity as outlined in Periodic Access Review Plan.
5.2 System Access Control
Access to Data Zoo services is secured with individual credentials, including username and password, as per the Password Policy. Passwords are stored using a Password Manager integrated with Data Zoo's Mobile Device Management program. Accounts lock after five failed login attempts and can be reset via support assistance.
6. Information Security Incident Management
6.1 Incident Management and Response
Data Zoo has implemented a formal Incident Management Policy to ensure a consistent and effective approach to the management of information security incidents. The incident management procedure is introduced to employees during induction and is included in the Information Security Awareness Training. All staff and suppliers are required to promptly report any suspected information security events via the designated reporting channels. The responsible team collaborates to complete an Incident Report Form. We mandate that all malfunctions and anomalous system events involving classified information be reported as information security events, as they may indicate a security attack or actual security breach. When an information security event is reported, the IMT assesses whether it should be classified as an incident and, if necessary, takes immediate remedial action to mitigate the threat. The details of the incident, remedial action taken, and outcome are recorded in a formal register for improvement and audit purposes. Figure 6.1.1 summarises the incident management workflow and response procedure.

6.2. Data Breach Notifications
In the event of a security incident involving a personal data breach, the Privacy and Data Protection Officer must be notified immediately. We will ensure that all relevant parties and organizations are informed in accordance with legal, contractual, and regulatory obligations, within the required timeframes as set out in privacy and data protection legislation, regulations, and contractual agreements. To support this process, we have established a Data Breach Notification Policy. The Privacy and Data Protection Officer, in collaboration with the ISMS Manager, will work with the IMT to ensure that any notifiable data breaches are communicated to the appropriate supervisory and regulatory authorities, as well as internal and external stakeholders. A comprehensive list of the supervisory and regulatory bodies is included in the Data Breach Notification Policy. The reporting threshold for an eligible data breach varies across jurisdictions and countries. As a global organisation, we adhere to best practices to meet these timeframes and evaluate security incidents against the relevant thresholds established by applicable data protection and privacy laws, and supervisory authorities pertinent to the personal data involved.
7. Change Management
7.1 Change Management Procedures
Data Zoo has established procedures to address risks associated with changes in systems and business circumstances. All changes are governed by the Change Management Policy, which mandates that changes be assessed according to their operational risk profile to ensure compliance with all relevant procedures. Whether related to code development, architecture, or infrastructure, each change must undergo an appropriate level of testing to ensure a high probability of success without adversely affecting production functionality. Changes identified as presenting an unacceptable level of risk will be denied. Additionally, all changes must be properly logged along with any supporting documentation and necessary approvals. This creates a comprehensive audit trail, which can be referenced if any questions arise about the process.
7.2 Security in Change Management
Data Zoo assesses security requirements for each change request by evaluating the risk, likelihood, mitigation needed, and risk severity. The Quality Assurance team creates and follows an information security testing plan for significant changes in our systems, applications, or network before releasing them to production. The plan tests the design and operation of security controls identified in the change request assessment. All testing occurs in a non-production environment and requires approval from relevant committee before deployment.
8. System Security
8.1 Cloud Security
Data Zoo’s cloud servers are secured with a Next-Gen Firewall and IPS to block real-time threats. The cloud provider manages access, logging, and monitoring. Additionally, Cloudflare's DNS service adds security and ensures continuity through load balancing and failover. The application uses an n-tier architecture with data stored in a trust zone behind a DMZ. Access requires a username and password meeting industry-standard strength.

8.2 Backup and Recovery
Backup copies of information, software, and system images are created and tested regularly following a formal Backup and Restore Policy. The extent, frequency, and retention period of backups are based on business requirements, security needs, the importance of the information for ongoing operations, and legal or audit obligations. Automated backup solutions undergo thorough testing before implementation and at regular intervals afterward. Data restores are performed only by qualified, authorised personnel. Backups are stored at multiple, geographically dispersed locations. Data Zoo's backup data is managed under the same logical and physical security controls as other data to ensure its confidentiality, availability, and integrity.
8.3 Logging & Monitoring
Event logs of user activities, exceptions, faults, and security events are produced, stored, and reviewed regularly. Logging facilities and information are protected from tampering and unauthorized access. System administrator and user activities are logged and reviewed per formal procedures. All system clocks are synchronized to a single reference time source. Real-time insights and alerts allow continuous monitoring. PII in transaction logs is one-way hashed to prevent reidentification. Startup and shutdown logs are kept for each device. Security events are logged using an SIEM system. Sophos antivirus logs are retained and monitored regularly for quality control and security purposes.
8.4. Test Data Management
Test data and environments are separate from production. The testing environment is not a sandbox but specifically created for service testing. Test data comes from a new source, compiled by the Quality assurance team when testing starts. Security and permissions are managed by the Quality Assurance Team in coordination with other Data Zoo teams.
9. Device Security
9.1 Mobile Device Management (MDM)
All employee machines are enrolled in a centralised MDM program managed by a third-party provider to ensure they meet all required technical compliance controls according to the Mobile Device Management Policy. All Data Zoo devices must have an asset tag and a label indicating the classification associated with the equipment, if applicable. Employees are restricted from installing or removing applications from their machines without IT approval, and all updates to operating systems, anti-virus software, and other applications are tracked and enforced remotely. Additionally, all Data Zoo employee mobile phones used for work purposes must be enrolled in the MDM program, enforcing necessary technical controls such as passcode complexity and automatic screen locking, and ensuring all Data Zoo information is protected within a “secure bubble” on the device. Employees cannot transfer or copy information of any kind (text, images, screenshots, etc.) outside of the Data Zoo “secure bubble” on their mobile phone into personal applications or documents. The MDM program supports remote deletion of all Data Zoo information and applications from the device in cases of compromise or non-compliance. All devices enrolled in the MDM program have encryption technically enforced. Staff must not use personal devices for work purposes without written authorisation from the business unit head.
9.2 Acceptable Use of Devices and Secure Employee Behaviour
Data Zoo staff must ethically use Data Zoo devices, systems, and Internet access in compliance with all laws. Upon onboarding, employees must acknowledge the Acceptable Use Policy, Code of Conduct, and Disciplinary Policy. Information Security Awareness training emphasises personal responsibility for security and privacy. Employees should screen lock their devices when away, both in and out of authorised offices or teleworking spaces. Devices should not be left unattended in public places, vehicles, or with unauthorised persons. Employees must remain vigilant to protect our IT systems and report any suspicious equipment or persons to their manager immediately.
9.3. Infrastructure
Data Zoo uses cloud services and data centres, to host its applications. The infrastructure is configured to maximise security, following system-specific requirements and regularly updated standard operating procedures. Access to Cloud resources is granted based on the principle of least privilege, with all users required to use two-factor authentication. Access is monitored for suspicious activity, which is reported and investigated. Firewalls and network security parameters protect all traffic. Regular backups are secured, and the security of Cloud resources is reviewed for compliance with relevant laws and regulations.
10. Physical Security
10.1 Physical Security and Environmental Security
Data Zoo operates from multiple physical locations, including Sydney, Gold Coast, Melbourne, New Zealand, and New York. All office sites are secured with 24-hour surveillance. Access is restricted to authorized personnel only, who must use keys to enter. Guests are required to register at reception and must be escorted at all times within our offices. The shared office space is locked down after 5:00 pm, and access outside of office hours is granted through a registered fingerprint system. To safeguard against potential threats such as fire, flood, earthquakes, explosions, civil unrest, and other natural or man-made disasters, Data Zoo has implemented comprehensive physical security measures and contingency plans. These protections are regularly reviewed and updated to ensure effectiveness. As previously mentioned under "Device Security," mobile assets such as laptop computers are secured through enrolment and management. The API is deployed on the Cloud Platforms, which feature multi-layered security models including safeguards such as custom-designed electronic access cards, alarms, vehicle access barriers, perimeter fencing, metal detectors, biometric systems, and laser beam intrusion detection on the data centre floor.
10.2 Data Centres
All data is stored on secure servers, employing firewalls and advanced encryption to protect all data and applications. Databases are equipped with built-in security measures that prevent unauthorized access from malicious actors. All transactions are logged by user and IP address. Data Zoo’s cloud-based servers are globally distributed, ensuring minimal cross-border information transfer and processing within legal jurisdictions. Data Zoo’s servers are located in Australia, New Zealand, Singapore, Canada, the United States, and the European Union.
Databases are backed up daily. There is failover capability between multiple servers within each data centre, as well as automated failover processes between data centres should an entire data centre go offline. Procedures are established to monitor and test the failover sites as required to ensure redundancy capacity remains effective. Frequent synchronization activities ensure identical configuration and account management across all servers, thereby eliminating downtime when traffic is re-routed between servers and data centres. For more information on how we manage data centre security or for technical specifications, please contact your account representative or reach out to us via info@datazoo.com.
Databases are backed up multiple times a day. There is failover capability between multiple servers within each data centre, as well as automated failover processes between data centres should an entire data centre go offline. Procedures are established to monitor and test the failover sites as required to ensure redundancy capacity remains effective. Frequent synchronization activities ensure identical configuration and account management across all servers, thereby eliminating downtime when traffic is re-routed between servers and data centres. For more information on how we manage data centre security or for technical specifications, please contact your account representative or reach out to us via info@datazoo.com.
11. Network Security
Data Zoo does not have an internal network at most office locations, with the exception being the North Sydney head office. The North Sydney network is using industry-standard security equipment including next gen firewall and industry best practices of network segregation and WPA2 for all Wi-Fi access points, with a Guest network that is monitored and separate from the internal network. The shared office network security is managed by building management, safeguarding system information. Security details for all network services are specified in agreements. Information services, users, and systems are segregated on networks. Onsite, staff use WPA2-enterprise encrypted Wi-Fi provided by building management. Offsite, staff uses private protected Wi-Fi or Personal Hotspots. All staff IPs accessing Data Zoo infrastructure are registered and whitelisted. Internet use, including email and web, can be monitored as needed.
12. Business Continuity and Disaster Recovery
Data Zoo has a comprehensive Business Continuity and Disaster Recovery (BC&D) Plan that outlines procedures to maintain, restore, and recover core services during a disaster. Oversight of the plan is managed by the ERBC, which ensures its ongoing effectiveness and alignment with organisational needs. The plan's resilience is regularly validated through scheduled tests, including tabletop exercises and technical recovery simulations, ensuring readiness and continuous improvement.
13. Legal and Regulatory Compliance
13.1 Cross Border Transfer of Information
Data Zoo’s policies are designed to safeguard information both within internal databases and during customer access. System access is electronically monitored, creating an auditable record of who accessed data, what was accessed, and when. When required by business processes, data remains within the country of origin for processing, ensuring compliance with local regulations. Only the necessary verification results are transmitted back to our systems, maintaining data security and minimising exposure.
13.2 Insurance
Data Zoo holds insurance policies for Public Liability, Product Liability, Professional Indemnity, and Cybersecurity. These policies are subject to review on an as-needed basis or at a minimum annually. We require our contracting counterparts to maintain equivalent insurance coverage in order to comply with industry standards and manage shared risks.
14. Client Information Security Requirements
All Clients or Customers using Data Zoo Systems and Services, are expected to implement and maintain minimum information security requirements, as set forth in our Master Services Agreement.
At a minimum the Client shall:
• Use Data Zoo Systems and Services solely for legitimate, lawful business purposes. • Ensure compliance with all applicable laws, regulations, and rules, including privacy laws and those governing the use, protection, and disclosure of Personal Information. • Implement, regularly review, and maintain a documented access control policy to manage user access rights to Data Zoo Systems and Services. Staff access should be role-specific and periodically reviewed to ensure it remains appropriate. The Client may log all network activity and ensure that all personally identifiable information (PII) is transmitted securely. • Provide Data Zoo with audit rights to verify compliance with material obligations under the contractual terms. Data Zoo may conduct a Client Due Diligence audit via a security questionnaire. The Client shall supply any necessary documentation or records to facilitate this process. • Safeguard Data Zoo’s Intellectual Property with reasonable security measures and notify Data Zoo immediately upon discovering any unauthorized use of its Systems, Services, or data. • Where applicable, protect confidential information with at least the same degree of care used to protect its own confidential information, ensuring reasonable administrative, physical, technical, and organizational measures are in place to prevent unauthorized access, alteration, disclosure, or destruction. • Comply with applicable privacy and data protection laws related to the storage or transmission of confidential information. • Return or destroy any confidential information upon Data Zoo’s request within ten (10) days.
15. Supplier Due Diligence
Data Zoo implements stringent measures to ensure that our data sources are externally verified and certified for reliability, accuracy, and legal compliance. All data source suppliers ("Suppliers") undergo thorough due diligence, including an annual vendor risk management review, which incorporates a security questionnaire.
Suppliers are required to comply with this policy, both generally and specifically, and must implement the technical and organizational measures outlined below to safeguard the Services and Data Zoo Data, ensuring an appropriate level of security commensurate with the associated risks.
If a Supplier processes, stores, or transmits Data Zoo Data that is classified as "Confidential" or "Personal Confidential," additional data protection controls may be necessary to ensure the data's security.
Table 15.1. Supplier Technical and Organisational Security Measures
Area | Description |
|---|---|
Information Security & Data Privacy | The Supplier shall ensure that Information Security and Data Privacy are managed according to international information security, cyber security and data privacy standards, laws and regulations (e.g. ISO/IEC 27000 family; SOC2; GDPR; CCPA) throughout the entire supply chain. |
Information Security Risk Management | The Supplier shall ensure that: 1. A Risk Management methodology, with regular risk assessments, that provides for the identification, treatment and documentation of substantive risks and vulnerabilities that may impact Data Zoo Data must be maintained 2. The Supplier shall implement measures to secure Data Zoo Data by: a) Restricting access to Data Zoo Data only on a need-to-know basis b) Restricting access to systems that process or store Data Zoo Data (both at rest and in transit); c) Enforcing strict access control mechanisms; and d) Enacting, where the Supplier works with service providers, on such service providers substantially the same security requirements as described in this document to protect Data Zoo Data. |
Physical Security | Physical Security controls acceptable for the type of data involved must be put into operation; at any supplier location where Data Zoo Data is stored or processed. The Supplier shall ensure that all Data Zoo Data is safe from unauthorized physical access, damage, interference, loss, or theft. In this regard, the supplier shall log access to system processing Data Zoo data, restrict access based on a need-to-know basis, lock the server rooms (if any), use the video surveillance were permitted by law, secure the equipment used to store, process and transmit Data Zoo data including wireless access points, gateways, handheld devices, networking/communications hardware, and telecommunication lines. |
Access Control and system infrastructure Control | 1. The Supplier shall at minimum take all practical steps to restrict anyone other than authorized individuals from accessing Data Zoo Data in any way or for any purpose not authorized by contract and the Agreement. 2. The Supplier shall document and implement procedures and policies ensuring the Supplier has sufficient protections against malware and viruses; critical System and data backup; logging and monitoring; logs retention for no less than 18 months or, where the Supplier allows the Data Zoo to download the logs, for no less than 3 months; and technical vulnerability management. 3. The Supplier shall have arrangements to protect the security of Data Zoo Data by limiting the purposes for which Data Zoo Data may be used and confirming such purposes are permitted by the Agreement. 4. The Supplier shall grant access to individuals on a need-to-know basis 5. The Supplier shall periodically conduct access review (in no less than 12 months) 6. The Supplier shall ensure that any system where Data Zoo Data are processed is secure by design. 7. The Supplier shall have a formal change management process that embodies the principle of segregation of duties. |
Incident Management and Communication of Incidents | 1. The Supplier should have a formal Incident Management Process and related procedures in place. 2. If a disclosure, outbreak, violation or another breach of the agreement herein (an “Incident”) occurs, Data Zoo must be informed without undue delay regarding any security breaches that might have an impact on Data Zoo Data, or the provided services stated in the underlying contract. |
Data Retention & Transmission | 1. If applicable and authorized by contract/Agreement, the Supplier shall: 2. Document and enforce measures to protect Data Zoo data during transmission by applying measures to secure data in transit. 3. Not store Data Zoo Data on removable media (e.g., USB flash drives, thumb drives, memory sticks, tapes, CDs, or external hard drives) except for backup, business continuity, disaster recovery, and data interchange purposes as allowed and required under a contract between the Supplier and Data Zoo. 4. At no additional charge to Data Zoo, upon Data Zoo’s request or upon the termination of the Agreement, destroy all of Data Zoo’s Confidential Information and Personal Information, including electronic, hard, and secured backup copies as provided for in the Agreement or, if not provided for in the Agreement, within thirty calendars (30) days after the soonest of: (a) expiration or termination of the Agreement, (b) Data Zoo’s request for the deletion/de-identification of Personal Information and Confidential Information, or (c) the date when Vendor no longer needs Personal Information and Confidential Information to perform services and products under the Agreement. 5. Dispose of Personal Information and Data Zoo Data in a manner that ensures the information cannot be reconstructed into a usable format. |
Business Continuity and Disaster Recovery | The Supplier shall, at a minimum: 1. Develop, operate, manage, and revise business continuity plans for each location and disaster recovery plans for each core technology in order to minimize the impact for Data Zoo to the Supplier’s service or products. Such plans shall include named resources specific to Business Continuity and Disaster Recovery functions, established recovery time objectives and recovery point objectives, back-up of critical data and systems, record protection and contingency plans commensurate with the requirements of the Agreement, store such plans securely off-site and ensure such plans are available to the Supplier as needed. 2. Adequately review and adjust its Business Continuity Plan to address additional or emerging threat sources or scenarios and provide Data Zoo with a high-level summary of plans and testing within a reasonable timeframe upon request. |
Standards, Best Practices, Regulations, and Laws | In the event the Supplier processes, accesses, views, stores, or manages Personal Information or Confidential Information pertaining to Data Zoo personnel, partners, Affiliates, Data Zoo clients; or Data Zoo client employees, contractors, subcontractors, or suppliers; the Supplier shall employ Technical and Organisational Security Measures no less strict than is required by applicable global, regional, country, state, and local guidelines, regulations, directives, and law. |
Modification | Data Zoo reserves the right to update or modify these Information Security Requirements from time to time by posting the latest version on Data Zoo’s website. Unless the Supplier provides written notification objecting to such updates or modifications within thirty (30) days of posting, the Supplier will be deemed to have accepted these changes. |
16. Policy Communication
The GRC Team ensures all Data Zoo Staff, as well as appropriate external parties, are familiar with this Policy.
17. Breach of Policy
We will take all necessary measures to remedy any breach of this policy including the use of our disciplinary or contractual processes where appropriate.
18. Records
Records retained in support of this procedure are listed in the ISMS Document Control and Improvements Register and controlled according to this ISMS Document Control Procedure.
19. Glossary
Confidentiality – characteristic of the information by which it is available only to authorised persons or systems.
Integrity – characteristic of the information by which it is changed only by authorised persons or systems in an allowed way.
Availability – characteristic of the information by which it can be accessed by authorised persons when it is needed.
Information Security – preservation of confidentiality, integrity, and availability of information.
Information Security Management System (ISMS) – part of overall management processes that take care of planning, implementing, maintaining, reviewing, and improving the information security.
AML: Refers to “Anti-Money Laundering”.
API: Refers to “Application Programming Interface”.
Audit Scope: Refers to which areas are included and which are excluded from the audit.
Audit Objectives: Refers to the purpose of the audit and what it should achieve.
Audit Criteria: Refers to which Clauses, Controls, and Policies are to be audited.
Batch: Refers to a batch process of identity verifications.
CDR: Refers to “Consumer Data Right”.
Data Zoo Data: Refers to either:
(a) the data that the verification subject, or a person acting on their behalf, provides to Data Zoo for identity verification purposes. Data Zoo provides this data to the Supplier, or permits the Supplier to access, in connection with the Agreement; or
(b) the Supplier creates or collects in connection with the Agreement; or
(c) is derived from the data listed in (a) and (b).
DMZ: A DMZ Network is a perimeter network that protects and adds an extra layer of security to an organization’s internal local-area network from untrusted traffic.
GDPR: Refers to the European Union’s “General Data Protection Regulation 2016/679”.
CCPA: Refers to the US “California Consumer Privacy Act”.
CPRA: Refers to the US "California Privacy Rights Act".
IDU / IDU System: Refers to Data Zoo’s Electronic Identity Verification platform, encapsulating all access points such as our SOAP and REST API, and Web-Application Interface.
Hashing: Refers to the de-identification of personally identifiable information in a way that it cannot be reconstructed.
ISMS: Refers to Information Security Management System.
JAS-ANZ: Joint Accreditation System of Australia and New Zealand. (About us | JAS ANZ (jas-anz.org))
Machine: Refers to Data Zoo Employee Laptops.
MDM: Refers to “Mobile Device Management”.
OS: Refers to “Operating System”.
PII: Refers to Personally Identifiable Information. That is any information that can potentially identify an individual (including instances of inference, etc).
SOC / SOC 2 / SOC 3: Refers to “Service Organisational Control”.
Source Data: Refers to the personal information provided by clients to Data Zoo for the purposes of Identity Verification.
Supplier: Refers to the person/organisation providing the Services to the Data Zoo under the Agreement.
System and Services: Data Zoo identity verification services and systems used in provision of these services.
REFERENCES
Legislation / Standards | Policies | |
|---|---|---|
Privacy Act (1988) | Acceptable Use Policy | Information Asset Inventory |
General Data Protection Regulation 2016/679 | Access Control Policy | Information Classification and Handling Policy |
California Consumer Privacy Act 2019 | Backup and Restore Policy | Mobile Device Management Policy |
California Privacy Rights Act 2020 | Business Code of Conduct | Pandemic BCP |
Consumer Data Right Act 2019 | Business Continuity & Disaster Recovery Plan | Password Policy |
ISO 27001:2022 | Change Management Policy | Periodic Access Review Plan |
Corrective Action Plan | Risk Treatment Plan | |
Cryptographic Controls Policy | Roles and Responsibilities Register | |
Data Breach Notification Policy | Vulnerability Management Procedure | |
Data Disposal Policy | Vulnerability & Penetration Assessment Summary | |
Disciplinary Policy | Teleworking Policy | |
Incident Management Policy |