Data Protection and Information Security Policy – Abtin Consulting Group
At Abtin Consulting Group (“the Company” or “we”), data protection and information security are integral parts of our professional commitments to clients, colleagues, and business partners.
The purpose of this policy is to define the principles, framework, and technical and organizational requirements to ensure the confidentiality, integrity, and availability of information across all our business processes.
This document aligns with the laws of the Islamic Republic of Iran, international regulations including the EU General Data Protection Regulation (GDPR), and ISO 27001 and ISO 27701 standards.
Scope
This policy applies to:
- Permanent employees, contractors, and consultants of Abtin Consulting Group
- All units, offices, and subsidiaries, both domestic and international
- Third parties with access to the Company’s information (e.g., IT service providers or data processors)
Fundamental Principles of Data Protection
All activities related to the collection, storage, transfer, or processing of data must adhere to the following principles:
- Lawfulness and Transparency:
All data processing must be based on a clear legal basis, fair, and transparent. - Purpose Limitation:
Data shall only be collected for specific, legitimate purposes and must not be used for incompatible objectives. - Data Minimization:
Only data essential for the intended purpose shall be collected. - Accuracy and Updating:
Personal data must be accurate and kept up-to-date when necessary. - Security and Confidentiality:
Technical and organizational measures must prevent unauthorized access, disclosure, alteration, or destruction of information. - Storage Limitation:
Data shall only be retained as long as necessary for the processing purpose. - Accountability and Compliance:
All employees and managers must demonstrate evidence of compliance with this policy.
Data Protection Management Framework
To effectively implement this policy, Abtin Consulting Group has established the following structure:
- Data Protection Officer (DPO): Responsible for overseeing compliance with internal and international regulations.
- Information Security Committee: Comprising representatives from IT, Legal, HR, and Operations departments.
- Training and Awareness Program: Regular courses for staff on cybersecurity threats, privacy, and data management.
- Periodic Audits: Internal and external reviews conducted according to ISO 27001 and ISO 27701 standards.
Information Security
The Company is committed to implementing the following security measures:
- Data encryption in transit and at rest
- Multi-factor authentication (MFA) for sensitive systems
- Role-based access control (RBAC)
- Continuous network and system monitoring
- Regular penetration testing and vulnerability assessment
- Business continuity and disaster recovery planning (BCP/DRP)
International Data Transfers
When transferring data outside Iran, the Company ensures that:
- Data is only transferred to countries with adequate protection levels
- Otherwise, Standard Contractual Clauses (SCC) or Binding Corporate Rules (BCR) are used
- Users are informed of such transfers and their explicit consent is obtained
Individual Rights
In accordance with Iranian law and global standards, individuals whose data is processed by Abtin have the following rights:
- Access to their data
- Request correction or deletion of data
- Restrict or object to processing
- Receive a portable copy of their data
- File complaints with the DPO or competent authorities
Incident Reporting and Management
All security incidents or data breaches must be reported to the DPO within 72 hours of discovery.
The IT department is responsible for technical analysis, documentation, and implementing corrective actions.
Continuous Training and Compliance
All employees must complete annual information security training.
The Company reviews and updates its policies and security procedures at least once every 12 months.