International Data Compliance Policy (GDPR & Iranian Data Laws) Abtin Consulting Group

Abtin Consulting Group, recognizing the importance of personal data protection, is committed to conducting all data processing activities in full compliance with domestic laws of the Islamic Republic of Iran and relevant international regulations, including the EU General Data Protection Regulation (GDPR), the UK Data Protection Act (UK GDPR), and other global standards.

This policy provides a framework for the collection, use, transfer, and retention of personal data at both domestic and international levels.

Purpose
The purpose of this document is to ensure that all data operations at Abtin Consulting Group:

  • Adhere to the principles of transparency, lawfulness, and data minimization;
  • Utilize legal mechanisms such as Binding Corporate Rules (BCR) or Standard Contractual Clauses (SCC) for international transfers;
  • Comply with privacy regulations in Iran, including the 2023 Draft Personal Data Protection Law;
  • Respect the rights of all individuals (employees, clients, and users) worldwide.

Principles of International Compliance
Abtin is committed to the following principles in all activities:

  1. Lawfulness: All processing must have a legal basis (e.g., consent, contractual obligations, or legitimate interests).
  2. Transparency: Individuals must be informed about how their data is used.
  3. Proportionality/Necessity: Data is collected and used only to the extent necessary for the intended purpose.
  4. Security: Technical measures such as encryption, access controls, and audits are implemented.
  5. Accountability: All organizational units must be able to demonstrate compliance with documentation and evidence.

Cross-Border Data Transfers
When transferring personal data outside Iran, Abtin uses one of the following mechanisms:

  • Binding Corporate Rules (BCRs): For transfers within the group companies.
  • Standard Contractual Clauses (SCCs): For cooperation with international partners.
  • Informed Consent: Explicit consent from the data subject.

No data is transferred without ensuring a level of protection equivalent to or exceeding Iranian and EU standards.

Individual Rights at the International Level
All individuals, regardless of nationality or residence, have the right to:

  • Access their personal data
  • Request correction or deletion
  • Restrict processing
  • Receive a portable copy of their data
  • Object to processing or withdraw consent

Organizational Requirements
To maintain global data compliance, Abtin Consulting Group:

  • Appoints a Global Data Protection Officer (Global DPO)
  • Provides specialized training for managers and staff
  • Aligns international contracts with privacy provisions
  • Conducts periodic audits to ensure policy enforcement

Cooperation with Authorities
Abtin is committed to full cooperation with domestic and international authorities regarding the review, response, and reporting of data-related events.