

INFORMATION AND PRIVACY SECURITY POLICY
1. Version History
| Date | Version | Author | Approved By | Comments |
| Previous 10 versions of this document (dated from 23Jan2019 to 29Oct2025) is archived as per the Document retention policy. New series begins again with Version 1.0 | ||||
| 27.04.2026 | 1.0 | Deepali Saxena | Senthil Kumar CR | The scope statement has been amended only to accommodate the name changes for 1Mentor, MoveON, and MoveIN. |
| 15.06.2026 | 1.1 | Deepali Saxena | Senthil Kumar CR | Minor changes to content. Additional supporting statements to the Policy statement. Updating QSEM to QS Sector Intelligence |
2. Reference
| ISO 27001:2022 | ISO 27701: 2019 | GDPR |
|---|---|---|
A.5.2 A.5.1 |
5.3.2 6.2.1.1 |
GDPR Chapter IV and Chapter V |
Table of contents
5. Information & Privacy Security Policy
5.2. Information Security and Privacy controls
6.2. Chief Information Security Officer (CISO)
7. Understanding the organisation and its context
8.1.1. Human Resource Security
10. Control of documented information
11. Information and privacy objectives and planning
12.2.1. Information security risk assessment
12.2.2. Information Security Risk Treatment
12.3. Management of Technical vulnerabilities
13.1. Compliance to legal, regulatory, and contractual obligation
13.2.1. Information Classification Labelling Policy
13.2.2. Asset Management Process
13.2.3. Clean Desk & Clear Screen
13.2.4. Mobile devices & Mobile Communication Services
13.2.5. Teleworking & Home Office Policy
13.2.6. Policy on Social Media
13.2.7. QS Supplier Security Policy (Managing Outsourced Services)
13.2.8. Information Security in Project Management
13.2.9. Information & Privacy Security Incident Management
13.2.10. Business Continuity Management System
14. Dealing with Personal data
15. Dealing with Intellectual Property and Copyrights
17. Commitment for ISMS & PIMS implementation
20. Annex B: QS PIMS-specific reference control objectives and controls (PII Processors)
3. Purpose
This policy defines the framework for securing QS’s data, private information, and IT systems. It outlines the specific responsibilities, procedures, and controls required to protect our digital assets from unauthorized access, disclosure, alteration, or destruction.
The purpose of this policy is to ensure that all QS employees, contractors, and third-party users understand and adhere to best practices in information security and privacy data protection, in compliance with applicable laws, regulations, and industry standards.
The structural elements of this policy:
Scope and Purpose: Clearly define the scope of the ISMS & PIMS
Information & Privacy security management system objectives such as such as confidentiality, integrity, and availability of information
Roles and responsibilities to identify key stakeholders and define their responsibilities in maintaining security.
Change Management & Risk Assessment: Identify and assess potential risks and threats that could disrupt business operations, and the changes recently made should have the traceability.
Communication & Awareness: Establish a comprehensive communication plan to ensure timely provision of accurate communication to employees, customers, suppliers, and other stakeholders. Periodic Organisation wide awareness programs on various requirements of information security and privacy data protection
4. Scope
This policy applies to all information assets, employees, contractors, temporary staff, suppliers, cloud service providers, business partners, and third parties that create, process, transmit, store, or manage QS information and personal data. This policy will be reviewed annually or when major changes occur.
Developed information and privacy security policies & procedures conforms to information & privacy security best practices and are applicable within the entire QS.
5. Information & Privacy Security Policy
Information & privacy security policy outlines the QS approach to Information & Privacy Security Management System (ISMS & PIMS). It provides the guiding principles and responsibilities necessary to safeguard the security & privacy of the QS information systems.
QS is committed to a robust implementation of Information & Privacy Security Management. It aims to ensure the appropriate confidentiality, integrity, availability of data and protection of privacy as potentially affected by the processing of PII (Personally Identifiable Information).
The principles defined in this policy will be applied to all the physical and electronic information assets for which the QS is responsible. QS is specifically committed to protection of privacy while processing PII (Personally Identifiable Information), preserving the confidentiality, integrity, and availability of documentation and data supplied by, generated by, and held on behalf of third parties pursuant to the carrying out of work agreed by contract in accordance with the requirements of data security and privacy standard ISO 27001 & ISO 27701 and applicable country specific legal/regulatory compliance requirements, specifically GDPR (EU 2016/679).
This policy may be supplemented with additional topic specific policies in relation to commercial offers when appropriate. Country Specific data protection requirements including GDPR requirements e.g., Data Processing Agreements (Art.28), Technical and Organisation Measures (Art.28 & 32), Inventory of data processing (including protection of privacy as potentially affected by the processing of PII (Personally Identifiable Information)) and Data Flow Diagrams ), Transfer Impact Assessment (Art.46 Chapter V), EDPB Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data, Data Protection Impact Assessment (Art.35), Records of processing activities (Art. 30) etc. shall be ensured through ISMS & PIMS procedures and controls, as per the Statement of Applicability.
QS ISMS & PIMS Policy
We, at QS shall continuously strive to enhance competitiveness of our customers with a range of value-added products and provide world class support to the Institutions at large by adopting a process approach to excellence.
This shall be enabled by implementing an Information & Privacy Security Management System (ISMS & PIMS), with the involvement and contribution of relevant stakeholders for:
QS implements security by design, privacy by design, defence in depth, least privilege, segregation of duties, secure development, and continuous monitoring principles.
Ensuring enhanced customer experience by meeting all their requirements.
Proactively protecting & ensuring security & privacy of PII (Personally Identifiable Information) data and information assets through effective risk management process.
Establishing measurable objectives and monitoring them periodically for achievement.
Fulfilling compliance obligations to applicable country specific privacy laws and regulations.
Adopting privacy by design and by default in all development and operational activities.
Ensuring changes are managed efficiently and communicated.
Creating awareness and clarity about information security and privacy data protection requirements to all employees, external suppliers and partners.
Continually improving the implemented systems (ISMS & PIMS).
5.1. Approval
The Information and privacy security policy have been developed by compliance team, process owners, reviewed & approved by management & CISO (Chief Information Security Officer). This policy Is communicated to all QS users that are likely to interact with the QS information system, and its application is mandatory.
5.2. Information Security and Privacy controls
The selected controls and their implementation status are listed in the Statement of Applicability.
6. QS Organisation
6.1. Senior Management
Strategic decisions and matters regarding the information security and privacy requirements for the information systems are managed by senior management. Our Senior management demonstrates leadership and commitment concerning information & privacy security by:
Ensuring the information & privacy security policy and objectives are established and are compatible with the strategic direction of QS.
Ensuring the integration of the information & privacy security management system requirements into the Organisation’s processes.
Ensuring that the resources needed for the information & privacy security management system are available.
Communicating the importance of effective information security management system & privacy security management system and of conforming to its requirements.
Ensuring that the information & privacy security management system achieves its intended outcome(s)
Directing and supporting persons to contribute to the effectiveness of the information & privacy security management system
Promoting continual improvement and supporting other relevant management roles to demonstrate their leadership as it applies to their areas of responsibility.
6.2. Chief Information Security Officer (CISO)
Senior management appoints a CISO responsible for the information systems security, cyber security and privacy. The CISO plans, coordinates, and monitors all activities related to Information, cyber security & privacy. The role of the CISO is as follows:
Lead and coordinate the actions of the group of users associated with information system security, cyber security and privacy.
Assist and advise about risks, information security, cyber security & privacy measures to be implemented during the development of new systems.
Define and propose means of protection and actions required to achieve information security, cyber security & privacy objectives.
Ensure that solutions are adapted to the issues of security & privacy and comply with the requirements of the information, cyber security & privacy security policy.
Define and consolidate reporting to senior management (Management Review Meeting- MRM)
Responsible for Information, cyber security & Privacy Security Management System implementation
Makes periodical review and updates on ISMS & PIMS process to ensure the efficiency and effectiveness of information, cyber security & privacy security controls
Communicating Regular updates on changes to legislation, internal ISMS and PIMS process or methods to employees
Monitoring Information, cyber security & Privacy Security Incidents and take appropriate actions
Evaluating compliance with the company processes through regular Internal Audits
Organisation of information & privacy security trainings for all employees
Organising security & privacy awareness campaigns to enhance the security & privacy culture and develop a broad understanding of the ISMS and PIMS requirements
Ensuring that internal audits are periodically conducted, and action items are taken to closure.
Appropriate contacts with relevant authorities (regulatory, legal) must be maintained.
Providing a vision to the organisation from an information security, cyber security & privacy standpoint.
Coordinate and facilitate the external audit process periodically.
Participate in any due diligence of suppliers and external partners before onboarding them.
Critical vulnerabilities shall be assessed and remediated based on risk and defined service level targets.
6.3. Privacy Officer
Privacy Officer shall Support the Data Protection Officer where required in providing and maintaining the necessary documentation as per ISO 27001 and ISO 27701, to demonstrate compliance with the GDPR, and other applicable country specific privacy laws. Key responsibilities include:
Informing and providing expert advice to all members of staff in his/her respective country of responsibility regarding their obligation to comply with the provisions of the GDPR and relevant country specific local laws and regulations when processing personal data.
Monitoring compliance with the Data Protection Policy and any other internal documents relating to data protection in his/her respective country of responsibility and informing the Data Protection Officer of any non-compliance in a timely manner.
Act as the main point of contact for employees in his/her respective country of responsibility and will cooperate with all members of staff on matters of data protection.
Takes the necessary steps in his/her respective country of responsibility to execute and roll-out data breach response and notification procedure which specifies the process and procedures for reporting personal data breaches and takes the necessary measures to inform the Data Protection Officer accordingly.
Ensures that training and awareness is available and delivered to all members of staff involved in the processing of personal data in his/her respective country of responsibility.
The following responsibilities can be considered, in consultation Data Protection Officer, if they do not conflict with the key activities listed above:
Review/develop procedures and other controls for the protection of personal data.
Establish adequate controls to ensure and maintain the confidentiality, integrity, and availability of personal data.
Contribute to the business continuity and disaster recovery planning process to ensure that personal data processing is considered.
6.4. Data Protection Officer
The Data Protection Officer assures that all necessary measures have been taken by the QS pertaining to legal, regulatory, and contractual issues. Regarding information system security and privacy, the mission of the DPO is to:
Keep up to date with judicial standards and jurisprudences, in collaboration with the CISO to communicate and state internal obligations related to information system security & privacy
Ensure compliance with legal, regulatory, and contractual provisions concerning information system security & privacy.
In collaboration with the CISO, identify and maintain legal, regulatory, and contractual obligations.
Document and update the procedures used to meet legal, regulatory, and contractual obligations.
Ensure, in collaboration with personnel concerned, the integration of information security & privacy requirements in contracts with all service providers or external partners.
Proceed with regular review of contracts.
Establish legal references.
Monitors compliance with GDPR, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits
Cooperates with the supervisory authority
Contact point for the supervisory authority on issues relating to processing, including the prior consultation and to consult, where appropriate, about any other matter
The DPO plays a supporting role to the various entities. Therefore, the DPO may be consulted when or if further information is required.
Ensures to have due regard to the risk associated with processing operations, considering the nature, scope, context, and purposes of processing.
The Data Protection Officer shall perform duties independently, report to senior management, and shall not receive instructions regarding the exercise of those duties.
6.5. Line Managers
Managers are responsible for the administration and review of access and authorisation of users to their services. With the assistance of CISO, assure that their teams are aware of information system guidelines and security & privacy policies.
7. Understanding the organisation and its context
An overview of QS products is addressed in the QS Business Summary.
QS has determined the external and internal issues that are relevant to its purpose & its strategic direction, and which act on its ability to achieve the intended outcomes of the ISMS & PIMS. QS monitors & periodically reviews the information about these external and internal issues or when there is a change.
8. People & Workplace
People & Workplace management shall apply the security & privacy rules during the processes of the arrival, employment and departure of employees according to ISO 27001 Control “A.6 – People Controls ” and ISO 27701 control “ 6.4. – Human Resource Security”.
8.1. Users
Users must comply with all security & privacy rules which are communicated to them and report, as quickly as possible, any security and privacy incidents, to their Line manager and CISO for further actions.
8.1.1. Human Resource Security
To ensure that employees and contractors understand their responsibilities and are suitable for the roles for which they are considered.
Terms and conditions of employment: The contractual agreements with employees and contractors shall state their and the organisation’s responsibilities for information security.
9. Communication
QS has determined the need for internal and external communications relevant to the information security management system and the privacy information management system. The referenced document addresses the below points along with identifying the reporting lines for any escalation.
what to communicate
when to communicate
with whom to communicate
who shall communicate
how communication would take place
10. Control of documented information
All ISMS & PIMS documents (policies, procedures, and guidelines) and records are created, maintained, and controlled in accordance with the defined processes and guidelines. Periodic reviews and Approvals are taken as appropriate to all documents.
A document is also released to govern information lifecycle management and archive of information, with emphasis on “Business records,” both internal and external.
11. Information and privacy objectives and planning
QS has established information, cyber & privacy security objectives at relevant functions and levels to maintain and continually improve the ISMS & PIMS and its performance. The information & privacy security objectives are.
Are consistent with the information security and privacy policy.
Are measurable.
Consider applicable information security and privacy requirements, and results from risk assessment and risk treatment.
are monitored.
communicated
are updated as appropriate.
While planning to achieve its information security and privacy objectives, the Organisation shall determine:
what will be done
what resources will be required
who will be responsible
when it will be completed and
how the results will be evaluated
12. Operations
12.1. Change Management
We aim to prevent malfunctioning of the information system as part of the implementation of changes on platforms (application and system updates, changes in infrastructure, architecture) while maintaining the responsiveness of teams. Information security and privacy is an integral part of the entire project lifecycle. Risk Management process is invoked to support the change management process.
12.2. Risk management
12.2.1. Information security risk assessment
QS has defined and implemented an information security and privacy risk assessment process that:
Establishes and maintains information & privacy security risk criteria
Ensures that repeated information security & privacy risk assessments produce consistent, valid, and comparable results
Identifies the information & privacy security risks
Analyses the information & privacy security risks
Evaluates the information & privacy security risks
Identifies Mitigating actions that will be tracked in the risk register
12.2.2. Information Security Risk Treatment
QS also has defined and implemented an information security and privacy risk treatment process to:
Select appropriate information & privacy security risk treatment options, taking account of the risk assessment results.
Determine all controls that are necessary to implement the information & privacy security risk treatment option(s) chosen.
Compare the controls determined in the point (b) with those in the Statement of Applicability and verify that no necessary controls have been omitted
Produce a Statement of Applicability that contains the necessary controls (point b and c) and justification for inclusions, whether they are implemented or not, and the justification for exclusions of controls
Formulate an information & privacy security risk treatment plan
Obtain risk owners’ approval of the information & privacy security risk treatment plan and acceptance of the residual information & privacy security risks
12.3. Management of Technical vulnerabilities
Using a risk-based approach, technical vulnerabilities are evaluated and updated regularly to guard against attacks by correcting known vulnerabilities in systems and applications. Vulnerability Management comprises of planning, implementation and operation of vulnerability management, patch Management, threat intelligence, configuration management, monitoring activities and web filtering.
Periodic third-party internal and third-party penetration testing is conducted to assess and analyse the risk of any new vulnerabilities for remediation.
The third-party penetration testing largely covers:
Web Application Security Assessment
Web Service Security Assessment
Security Configuration Review
12.4. Antivirus Protection
QS safeguards its information system against viruses, malicious code attack, Cyber-attack protecting vulnerable systems from these threats, as well as information system input and output.
The QS staff systems are equipped with antivirus software; the software provider updates the antivirus databases periodically after reviewed with QS corporate IT. Configuration of the antivirus software is managed by the QS corporate IT support-helpdesk. Users cannot change the configuration or uninstall the antivirus.
12.5. Backups
In the event of incidents affecting the availability or integrity of assets, we ensure to protect against data loss. Safeguard mechanisms are in place for all systems and data including backups (Application configuration, Application source code, Application logs, Access logs, Database logs, configuration files, code, product databases supporting Client data). Business continuity plans are in place and regularly evaluated.
12.6. Monitoring and Logging
All critical functions and systems are monitored by Infrastructure support along with data traceability. The Visualising tool used to manage log reports and are reviewed regularly.
All the systems and equipment are synchronised to a unique time source. Logs are analysed by the Infrastructure Head based on abnormality and the legal retention period of logs is consistent with the law. The log reports are stored in protected areas.
12.7. Disposal
All computer equipment containing business information is discarded using a secure erasure process. Paper documents containing sensitive and/ or confidential information are destructed using a Paper shredder as per our information & privacy security Policy. Procedures are established for secure disposal of information security assets. A data retention policy is established for normal working. In case of client data, applicable contractual and legal/regulatory requirements are ensured.
13. Compliance
13.1. Compliance to legal, regulatory, and contractual obligation
We respect legal, regulatory, contractual, requirements and adopt applicable standards.
The key drivers and mechanism include the following:
Local legal and regulatory compliance requirements (E.g., for GDPR, these include related data processing agreements and standard contractual clauses as per European Council, & Commission decision C (2021) 3972 final dated 4.6.2021 and related EDPB guidelines).
Obligations under standard contracts or conditions of service offerings with suppliers/Sub Processors
Obtaining and maintaining certifications recognised for information security management system ISO/IEC 27001, privacy information management system ISO/IEC 27701, Cyber risk, etc.
Compliance is ensured through:
Up to date legal, contractual, and regulatory requirements and measures as per European Council, & Commission decision C (2021) 3972 final dated 4.6.2021 and related EDPB guidelines.
Observation of any developments in the legal, regulatory, contractual, and standards framework.
Procedures and their implementation to satisfy legal, regulatory, contractual and standards, Communication channels in place concerning the developments of the framework.
Monitoring mechanisms can include audit indicators, penetration testing, and vulnerability tests, updates to these tests, and scheduled periodic reviews.
Action plan for identified non-conformities during audits.
Due to their impact or potential impact on QS’s ability to consistently provide products & services that meet customer & applicable statutory & regulatory requirements, the QS has detailed applicable Legal, Regulatory and Contractual Requirements to avoid breaches of legal, statutory, regulatory or contractual obligations related to information security & privacy requirements.
13.2. Security Practices
QS adopts the information, cyber security & privacy practices by defining information, cyber & privacy security controls applicable to the entire information system of QS. Additional information & privacy security measures identified through risks analysis, legal, regulatory, and/or contractual concerns and/or specific standards will be addressed accordingly. Statement of applicability -is established for the applicable controls required for the context of various products that enable Software as a Service (SaaS) offering. Security & privacy controls and best practices are to be considered and implemented as appropriate to the risk level.
13.2.1. Information Classification Labelling Policy
To handle business information according to the identified security and privacy classification QS established Information classification & labelling policy to protect the QS data against unauthorised access, unauthorised change, unintentional breach and data loss. Further, employ a comprehensive security and privacy awareness.
13.2.2. Asset Management Process
QS has established asset management process to issue, track, maintain, return all types of assets (hardware & software) and associated assets to prevent loss, damage, theft or compromise.
13.2.3. Clean Desk & Clear Screen
QS has adopted a Clean Desk and Clear Screen Policy for all workstations including Laptops and Desktops. This will ensure that all sensitive and confidential information, whether on paper, or on a storage device or hardware device, is properly locked away or kept secure from unauthorised use or disposed when not in use.
13.2.4. Mobile devices & Mobile Communication Services
QS has established Mobile Devices & Mobile Communication Services Policy is to establish clear guidelines for the appropriate use, security, and management of mobile devices and communication services within QS.
13.2.5. Teleworking & Home Office Policy
QS has adopted Teleworking & Home Office policy is to establish clear guidelines and expectations for QS employees who work remotely, either full-time or part-time.
13.2.6. Policy on Social Media
QS Has established policy on social media to guide QS employees on responsible online behaviour, handle social media official platforms or channels to protect the QS’s reputation, ensure legal compliance, reduce risks associated with inappropriate or unauthorized posts
13.2.7. QS Supplier Security Policy (Managing Outsourced Services)
QS has established the rules for its vendors and partners. Considering that QS solutions entail the processing of protected data in what concerns personal data and data included in the data forms of the universities.
Suppliers processing QS information or personal data shall be subject to risk assessment, contractual security requirements, periodic review and ongoing monitoring.
13.2.8. Information Security in Project Management
QS ensure to assess information & cyber security risks related to QS business projects and deliverables in project management throughout the project life cycle.
13.2.9. Information & Privacy Security Incident Management
QS has established Information, cyber & Privacy Security Incident Management process to ensure effective and timely response to security and privacy incidents, including communication on information security and privacy events.
13.2.10. Business Continuity Management System
QS has established Business continuity policy to ensure the organisation’s objectives can continue to be met during disruption and ensure the availability of information and other associated assets during disruption.
14. Dealing with Personal data
We have the important responsibility of protecting the personal and sensitive personal data of our clients or prospects and our employees by respecting their rights.
QS Student Recruitment, QS 1Mentor, QS MoveON, and QS MoveIN have established and maintain the following control measures to ensure the confidentiality, integrity, and protection of information and personal data.
ISO 27001 and ISO 27701 Controls adopted and implemented per the Statement of Applicability
Applicability [refer to Annex B for PIMS-specific reference control objectives and controls (PII Processors)].
Technical and Organisational Measures as required by GDPR and as per European Council, & Commission decision C (2021) 3972 final dated 4.6.2021 (refer Annex A)
Strong Firewall and Anti-virus: using multiple layers of security software thus making unauthorised access to client data more difficult
Access control: Purpose based access provision as per a strong password policy, which ensures changing of passwords to key software systems and immediate access revocation in cases when an employee exit
Processing information ethically: Being transparent about data collection and usage and adhering to information handling policies
Regular compliance checks against applicable country specific regulations like GDPR by third-party.
Data management: Adding value by collecting and managing client data responsibly and strategically, as per contractual and legal/regulatory obligations
Supplier management: Ensuring suppliers / sub processors fulfil information security and privacy [including protection of privacy as potentially affected by the processing of PII (Personally Identifiable Information)] through implementation of applicable controls, ensuring the customer value chain is compliant.
Training and Education: Training stakeholders on ISMS, PIMS, GDPR and Cyber security to enhance the focus on how to manage personal data and maintain information confidentiality & privacy.
QS supports the rights of data subjects, including access, rectification, erasure, restriction, portability and objection rights where applicable.
PIMS-specific reference control objectives and control (PII Processors) steps (refer Annex B) are ensured at QS Student Recruitment, QS 1Mentor, QS MoveON, and QS MoveIN through the Data Processing Agreement (DPA) and Standard Contractual Clauses (SCC) – where ever its applicable, to protect personal data in cases of cross border transfer.
15. Dealing with Intellectual Property and Copyrights
We respect Intellectual Property and Copyrights when using software subject to license. The licensed software concerning the information system used within QS are defined and maintained as part of our Information asset inventory.
The licensing agreements are maintained under the responsible license owner. Requests for installing license software are handled through proper approval workflow. Regular checks are carried out on the information system to ensure consistency between licensing agreements and current installations.
16. Compliance
QS respects legal, regulatory, contractual, requirements and adopt applicable standards. Compliance team owns the QS Information & Privacy security policy Internal audit and reports the same to CISO. Any person, who fails to comply with the QS Information & Privacy security policy and legal compliance requirements, shall be subject to appropriate QS disciplinary action.
17. Commitment for ISMS & PIMS implementation
As per the Management Commitment, ISMS and PIMS implementation and continual improvement will be supported with adequate resources to achieve all objectives set in this Policy, as well as satisfy all identified requirements.
18. Revisions
Revisions to this document will be made annually or whenever deemed necessary.
19. Annex A: Measures based on suggestions from Commission Implementing Decision (EU) 2021/914 dated 4.6.2021.
| # | Measures | QS Measures |
|---|---|---|
| 1 | Measures of pseudonymisation and encryption of personal data | Personal data is accessible only through secure login and critical data fields are encrypted. All services provided as part of SaaS are accessible only through TLS encrypted communication (or SSH for special packages). The certificates used are checked as part of server maintenance. Hashed passwords for are used for authentication. Anonymisation is in place in for personal data in production environment. This also ensures that personal data in development environment is also protected when it resides in production environment. Pseudonymisation is not deemed required, given the context of QS offerings to fulfil contractual obligations, and hence not implemented. |
| 2 | Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services | ISMS & PIMS based on ISO 27001 & ISO 27701 is established and implemented, with procedures & controls to ensure identification, authentication, authorisation, and accountability. Regular risk management periodic reviews with C, I & A analysis, are conducted to ensure current controls to address the changing threats & vulnerabilities. |
| 3 | Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident | Technical & Organisational Measures (TOM) are in place as per Art. 28 of GDPR. Enough redundancy is built for availability of applications/ server/ software so that if the primary equipment fails, alternate resource can take over operational activities. physical location of project server is planned so that the server is easily accessible from alternate site during disaster scenario The backup data of critical project server is accessible from alternate location, if required, the recovery of data on to another server is possible in the event of a physical or technical incident. The installable versions of software required is also made accessible in such situations. |
| 4 | Processes for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures to ensure the security of the processing | QSIP (MoveON & MoveIN) and QSSR, QSEM (1Mentor) is currently ISO 27001 & ISO 27701 certified, the requirements for the certification are verified during regular audits. As part of ISMS and PIMS review, periodic review of TOM with respective data Sub-processors, and thereby compliance to applicable regulations and any changes are checked. |
| 5 | Measures for user identification and authorisation | Procedures are documented for identification, authentication, authorisation, and accountability of information systems. Access to systems is restricted and no access is given to guest or anonymous accounts. For Data Access, differentiated access rights based on profiles and roles are defined according to business requirement and least privilege concept. |
| 6 | Measures for the protection of data during transmission | The data is transferred only over HTTPS to the datacentre we have hosted the application with. QS has enabled encryption for HTTPS traffic. Once the data enters the data centre internal network it is protected with Firewall and iPS protocol. The selected custom fields in the database are stored encrypted by our product. The backups are created with read-only permission and kept in secured backup server. SAML based SSO is implemented, and API access is via secured certificate/key |
| 7 | Measures for the protection of data during storage | Data is securely hosted at dedicated data centres. Once data enters the data centre internal network it is protected with Firewall and iPS protocol. Authentication, encryption, and passwords policies are defined and implemented. The database Is encrypted. The backups are created with read-only permission and kept in secured backup server. Regular checks of the application logs are conducted by the internal team. |
| 8 | Measures for ensuring physical security of locations at which personal data are processed | Technical and Organisational Measures audit being conducted with Data centres on regular intervals and need basis. Regular fire drills are conducted, and equipment is under preventive maintenance. From infrastructure points we have Firewall, IDS and DDOS protection and layered networks. Datacentres have the following measures in place: * Access control policy in place * ISO/IEC 27001, ISO/IEC 27017, and DSS compliance certified * Anti-DDoS: highly resilient Layer 4-7 DDoS protection built into the network |
| 9 | Measures for ensuring events logging | Events logging is done using Industry standard logging tools. Protection of log files against unauthorized access is ensured. |
| 10 | Measures for ensuring system configuration, including default configuration | Initial product configuration (default) is provided when Institutions are onboarded, and further configuration changes are managed and done by Institutions. For Infrastructure configuration: VM Backups is in place and periodic Server hardening, and OS patching is tested and implemented. |
| 11 | Measures for internal IT and IT security governance and management | Structured IT Governance mechanism is implemented and regularly reviewed with top management in the MRM. Process Owners are involved in planning, implementing, and monitoring the ISMS and PIMS processes. Within the scope of their tasks, all employees are responsible for the secure handling of information especially personal data. Access to IT applications and systems are periodically reviewed. Security and Privacy training is provided to all employees. |
| 12 | Measures for certification/assurance of processes and products | QS Information Security Management System is certified against ISO 27001 and ISO 27701. Risk management is ongoing to determine weakness and risks, as well as for learning from incidents/ corrective measures. Audits are regularly carried out by internal and external auditors for regular evaluations of information security practices. The corrective action plans for the audit findings have the responsibilities and deadlines assigned. With support from CISO and top management, the audit findings and other related continuous improvement actions are facilitated to closure and reviewed for effectiveness. |
| 13 | Measures for ensuring data minimisation | Mandatory data fields are advised by Institutions, thereby ensuring data minimisation by design. Configuration is possible as per instructions provided by Institutions. Personal data is collected and maintained by Institutions. |
| 14 | Measures for ensuring data quality | Standard practices in Form design are established, with appropriate validation to ensure data quality at point of collection. European Student Identifier is used to identify and validate students at various touchpoints. Communication regarding changes / deletion of data types is promptly reconciled with Institutions. Demo and user validation in some cases are conducted to ensure alignment with client data quality requirements. Login Access to forms is restricted |
| 15 | Measures for ensuring limited data retention | Data retention is ensured as per the contractual terms with the Institution. Individual’s data retention/erasure/deletion is based on Institutions request. Thus, Institutions can specify retention period for specific records under service agreements, and the same will be implemented. Personal data shall not be retained longer than necessary for the purposes for which it was collected, unless required by legal, regulatory or contractual obligations. |
| 16 | Measures for ensuring accountability | CISO and Data Protection Officer are appointed. Process owners are assigned for the ISMS and PIMS processes and unique usernames, with multi factor authentication are provided for system users. Contracts with Data Centres, along with DPA and regular TOM audits are established. Security and privacy training is provided to all employees at the time of joining and regular refresher training also provided. Periodic reviews and updates as required by ISMS & PIMS e.g., access rights to personal data, compliance to applicable regulations and changes to regulations are in place. DPIA is in place and updated regularly. Data inventory and related processing activities are available and regularly reviewed. |
| 17 | Measures for allowing data portability and ensuring erasure | As per contractual requirements, support can be provided for data portability and erasure. Data can be exported in a standard readable format, on request of the Institution, thereby ensuring data portability. |
20. Annex B: QS PIMS-specific reference control objectives and controls (PII Processors)
| Annex B Clause # | Title | Control | QS undertakes through the Data Processing Agreement: |
|---|---|---|---|
| B.8.2 Conditions for collection and processing Objective: To determine and document that processing is lawful, with legal basis as per applicable jurisdictions, and with clearly defined and legitimate purpose. |
|||
| B.8.2.1 | Customer agreement | The Organisation shall ensure, where relevant, that the contract to process PII addresses the Organisation’s role in providing assistance with the customer’s obligations, (taking into account the nature of processing and the information available to the Organisation). | where relevant, QS contracts with customers and suppliers to process PII, addresses QS ’s role in providing assistance with the customer’s obligations, (taking into account the nature of processing and the information available to QS). |
| B.8.2.2 | Organisation’s purposes | The Organisation shall ensure that PII processed on behalf of a customer are only processed for the purposes expressed in the documented instructions of the customer. | to ensure that PII processed on behalf of a customer are only processed for the purposes expressed in the documented instructions of the customer. |
| B.8.2.3 | Marketing and advertising use | The Organisation shall not use PII processed under a contract for the purpose of marketing and advertising without establishing that prior consent was obtained from the appropriate PII principal. The Organisation shall not make providing such consent a condition for receiving the service. | as a processor, does not use PII processed under a contract for the purpose of marketing and advertising without establishing that prior consent was obtained from the appropriate PII principal. QS privacy policy ensures that it shall not make such consent a condition for providing the service |
| B.8.2.4 | Infringing instruction | The Organisation shall inform the customer if, in its opinion, a processing instruction infringes applicable legislation and/or regulation. | to inform the customer if, in its opinion, a processing instruction infringes applicable legislation and/or regulation. |
| B.8.2.5 | Customer obligations | The Organisation shall provide the customer with the appropriate information such that the customer can demonstrate compliance with their obligations. | to provide the customer with the appropriate information such that the customer can demonstrate compliance with their obligations. |
| B.8.2.6 | Records related to processing PII | The Organisation shall determine and maintain the necessary records in support of demonstrating compliance with its obligations (as specified in the application contract) for the processing of PII carried out on behalf of a customer. | to determine and maintain the necessary records in support of demonstrating compliance with its obligations (as specified in the contract) for the processing of PII carried out on behalf of a customer. |
| B.8.3 Obligations to PII principals Objectives: To ensure that PII principals are provided with the appropriate information about the processing of their PII, and to meet any other applicable obligations to PII principals related to the processing of their PII. |
|||
| B.8.3.1 | Obligations to PII principals | The Organisation shall provide the customer with the means to comply with its obligations related to PII principals. | to provide the customer with the means to comply with its obligations related to PII principals. |
| B.8.4 Privacy by design and privacy by default Objective: To ensure that processes and systems are designed such that the collection and processing of PII (including use, disclosure, retention, transmission, and disposal) are limited to what is necessary for the identified purpose. |
|||
| B.8.4.1 | Temporary files | The Organisation shall ensure that temporary files created as a result of the processing of PII are disposed of (e.g., erased or destroyed) following documented procedures within a specified, documented period. | along with Technical and Organisational Measures, Acceptable Use of IT Systems policy, and Employee Declaration, to ensures that temporary files created as a result of the processing of PII are disposed of (e.g., erased or destroyed) following documented procedures within a specified, documented period. |
| B.8.4.2 | Return, transfer or disposal of PII | The Organisation shall provide the ability to return, transfer and/or disposal of PII in a secure manner. It shall also make its policy available to the customer. | along with Technical and organisational measures and its Privacy Policy, to provide the ability to return, transfer and/or disposal of PII in a secure manner. It shall also make its policy available to the customer. |
| B.8.4.3 | PII transmission controls | The Organisation shall subject PII transmitted over a data-transmission network to appropriate controls designed to ensure that the data reaches its intended destination. | along with Technical and organisational measures, to subject PII transmitted over a data-transmission network to appropriate controls designed to ensure that the data reaches its intended destination. |
| B.8.5 PII sharing, transfer and disclosure Objectives: To determine whether and document when PII is shares, transferred to other jurisdictions or third parties and/or disclosed in accordance with applicable obligations. |
|||
| B.8.5.1 | Basis for PII transfer between jurisdictions | The Organisation shall inform the customer in a timely manner of the basis for PII transfer between jurisdictions and of any intended changes in this regard, so that the customer has the ability to object to such changes or to terminate the contract. | to inform the customer in a timely manner of the basis for PII transfer between jurisdictions and of any intended changes in this regard, so that the customer has the ability to object to such changes or to terminate the contract. Inventory of data processing ( including protection of privacy as potentially affected by the processing of PII(Personally Identifiable Information)) and Data Flow Diagrams, where applicable, shall be maintained. Transfer Impact Analysis (TIA) is undertaken only in cases where cross border transfers of personal data of EU data subjects outside Europe is involved as applicable under the purview of GDPR. |
| B.8.5.2 | Countries and international Organisations to which PII can be transferred | The Organisation shall specify and document the countries and international Organisations to which PII can possibly be transferred. | To list, specify and document the countries and international Organisations to which PII can possibly be transferred |
| B.8.5.3 | Records of PII disclosure to third parties | The Organisations shall record disclosures of PII to third parties, including what PII has been disclosed, to whom and when. | To record disclosures of PII to third parties, including what PII has been disclosed, to whom and when. |
| B.8.5.4 | Notification of PII disclosures requests | The Organisation shall notify the customer of any legally binding requests for disclosure of PII. | To notify the customer of any legally binding requests for disclosure of PII. |
| B.8.5.5 | Legally binding PII disclosures | The Organisation shall reject any requests for PII disclosures that are not legally binding, consult the corresponding customer before making any PII disclosures that are authorized by the corresponding customer. | To reject any requests for PII disclosures that are not legally binding, consult the corresponding customer before making any PII disclosures that are authorized by the corresponding customer. |
| B.8.5.6 | Disclosure of sub-contractors used to process PII | The Organisation shall disclose any use of subcontractors to process PII to the customer before use. | To disclose any use of subcontractors to process PII to the customer before use. |
| B.8.5.7 | Engagement of a subcontractor to process PII | The Organisation shall only engage a subcontractor to process PII according to the customer contract. | To only engage a subcontractor to process PII according to the customer contract. |
| B.8.5.8 | Change of subcontractor to process PII | The Organisation shall, in the case of having general written authorisation, inform the customer of any intended changes concerning the addition or replacement of subcontractors to process PII, thereby giving the customer the opportunity to object to such changes. | In the case of having general written authorisation, inform the customer of any intended changes concerning the addition or replacement of subcontractors to process PII, thereby giving the customer the opportunity to object to such changes. |



