Data Protection & Privacy Policy

Rozmith — Ethics & Compliance Policy Suite

Document owner
Data Protection Officer
Approved by
Rozmith Executive Leadership Team
Version
1.0
Effective date
1 July 2026
Next review date
1 July 2027 (annual)
Applies to
All Rozmith personnel processing personal data of any individual, in any jurisdiction

1. Purpose

This policy governs how Rozmith collects, uses, shares, retains, and protects personal data of clients, client end users, employees, and other individuals. It implements ISO/IEC 27001:2022 Annex A 5.34 (privacy and protection of PII) and underpins the SOC 2 Privacy criteria (P1–P8) and Confidentiality criteria (C1).

2. Principles

Rozmith applies the highest common standard across its jurisdictions — in practice, GDPR-level principles globally: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Privacy notices are provided at or before collection (SOC 2 P1.1), and consent is obtained where required (P2.1).

3. Core Requirements

  • Records of Processing Activities (RoPA) are maintained for all processing, identifying purpose, lawful basis, categories, recipients, transfers, and retention.
  • Data Protection Impact Assessments (DPIAs) are mandatory for high-risk processing and for new products or significant changes (supports SOC 2 CC3.4 and P-series criteria).
  • Privacy by design and by default applies to all systems and services (UK GDPR Art. 25; mirrored in the Macedonian LPDP).
  • Data subject / consumer rights requests (access, rectification, deletion, portability, objection, opt-out) are logged and fulfilled within statutory deadlines: one month under UK GDPR and the Macedonian LPDP (extendable); 45 days under most US state privacy laws (e.g., CCPA), extendable once.
  • Retention schedules are documented per data category; data is securely disposed of at end of life (Annex A 8.10; SOC 2 P4.2, P4.3, C1.2).
  • Processors and sub-processors must be bound by written data processing agreements meeting UK GDPR Art. 28, LPDP equivalents, and US state-law service-provider/processor requirements (see Vendor Policy).
  • Rozmith does not share or sell consumer personal information (including phone numbers) to third parties or affiliates for marketing or lead generation.

4. Jurisdiction-Specific Requirements

4.1 United Kingdom

  • Rozmith complies with the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (DUAA), whose main data protection provisions commenced 5 February 2026. The Information Commissioner's Office (ICO) is the supervisory authority; Rozmith pays the ICO data protection fee.
  • DUAA changes Rozmith applies: the new 'recognised legitimate interests' lawful basis may be relied on only after DPO assessment; the broadened research provisions and revised subject-access 'stop the clock' rules are reflected in the rights-handling procedure.
  • From 19 June 2026, individuals have a statutory right to complain directly to Rozmith as controller; Rozmith provides a complaints form, acknowledges within 30 days, and responds without undue delay, with escalation rights to the ICO.
  • PECR governs marketing and cookies; fines for PECR breaches now align with UK GDPR maximums (up to £17.5m or 4% of global turnover).
  • International transfers from the UK rely on adequacy regulations, the ICO's International Data Transfer Agreement (IDTA), or the UK Addendum to EU SCCs, with transfer risk assessments.

4.2 North Macedonia

  • Rozmith complies with the Law on Personal Data Protection (LPDP), which is closely aligned with the EU GDPR. The supervisory authority is the Personal Data Protection Agency (AZLP).
  • Rozmith complies with the Agency's Rulebook on the security of personal data processing adopted 25 December 2024 and in effect since 1 July 2025, including documented technical and organisational measures, periodic risk assessment, and review and updating of those measures.
  • A Data Protection Officer is designated and notified to the Agency where required; processing documentation is maintained in Macedonian where required for regulator inspection.
  • Cross-border transfers of personal data from North Macedonia are permitted to EU/EEA states and adequate jurisdictions; other transfers require appropriate safeguards or Agency approval as set out in the LPDP. Transfers to the UK and US are executed with safeguards (contractual clauses) and recorded in the RoPA.
  • Employee monitoring and biometric/video surveillance in the Skopje office follow the LPDP's specific video-surveillance provisions, including signage and documented decisions.

4.3 United States

  • There is no single federal comprehensive privacy law; as of 2026, twenty states have comprehensive privacy statutes in effect, including California (CCPA as amended by CPRA), Virginia, Colorado, Connecticut, Texas, and, newly effective in 2026, Indiana, Kentucky, and Rhode Island. Rozmith assesses applicability annually against each statute's thresholds and tracks new laws (e.g., Oklahoma and Alabama, effective 2027).
  • Where applicable, Rozmith honours consumer rights (access, deletion, correction, portability), opt-outs of sale/sharing and targeted advertising (including universal opt-out signals such as Global Privacy Control where mandated), and data minimisation duties.
  • Rozmith does not sell personal data. Service-provider and contractor contracts contain the restrictions required by the CCPA and analogous laws.
  • Several states' cure periods have expired or are expiring in 2026, so violations may be enforced immediately; privacy compliance is therefore verified quarterly.
  • Sectoral laws are applied when in scope for client engagements: HIPAA (as business associate), GLBA, FERPA, COPPA, and the FTC Act §5. State breach notification laws in all 50 states are addressed in the Incident Response Plan.

5. International Data Transfers

All cross-border data flows are mapped in the RoPA. UK→US and UK→North Macedonia transfers use the IDTA/UK Addendum with transfer risk assessments; North Macedonia→UK/US transfers use LPDP-compliant safeguards; intra-group transfers are governed by an intercompany data transfer agreement.

6. Breach Response

Suspected personal data breaches must be reported immediately to the DPO and handled under the Incident Response Plan, including 72-hour regulator notification assessments for the ICO (UK GDPR) and the Macedonian Agency (LPDP), and US state notification obligations. See Incident Response Plan section 6.

7. Training, Audit, and Governance

All personnel complete privacy training at hire and annually; roles with significant personal data access receive enhanced training. The DPO reports to the Executive Leadership Team quarterly. Privacy controls are tested in internal audits, the annual SOC 2 examination (where the Privacy category is in scope), and ISO 27001 audits.

8. Framework Mapping

Policy sectionSOC 2 TSC (2017)ISO/IEC 27001:2022
Notice and consentP1.1, P2.1, P3.1, P3.2Annex A 5.34
Collection, use, retention, disposalP4.1–P4.3, C1.1, C1.2Annex A 5.32–5.34, 8.10
Rights requests and accessP5.1, P5.2Annex A 5.34
Disclosure to third parties; transfersP6.1–P6.7Annex A 5.14, 5.19–5.23
Quality and accuracyP7.1Annex A 5.34
Complaints and monitoringP8.1Clauses 9.1, 10.1
DPIAs and changeCC3.4Clause 6.1; Annex A 5.8