

Information Security and Privacy Policy
1. History of Versions
| Date | Version | Author | Approved By | Comments |
|---|---|---|---|---|
| Previous 10 versions of this document (dated from 23 Jan 2019 to 29 Oct 2025) are archived as per the Document Retention Policy. New series begins again with Version 1.0. | ||||
| 27.04.2026 | 1.0 | Deepali Saxena | Senthil Kumar CR | The scope statement has been amended only to accommodate the name changes for 1Mentor, MoveON, and MoveIN. |
| 15.06.2026 | 1.1 | Deepali Saxena | Senthil Kumar CR |
Minor changes to content. Additional supporting statements to the Policy statement. Updating QSEM to QS Sector Intelligence |
2. Reference
| ISO 27001:2022 | ISO 27701: 2019 | GDPR |
|---|---|---|
| A.5.2 | 5.3.2 | GDPR Chapter IV and Chapter V |
| A.5.1 | 6.2.1.1 |
Table of contents
- Version History
- Reference
- Purpose
- Scope
- Information & Privacy Security Policy
- QS Organisation
- Understanding the organisation and its context
- People & Workplace
- Communication
- Control of documented information
- Information and privacy objectives and planning
- Operations
- Compliance
- Dealing with Personal data
- Dealing with Intellectual Property and Copyrights
- Compliance
- Commitment for ISMS & PIMS implementation
- Revisions
- Annex A: Measures based on suggestions from Commission Implementing Decision (EU) 2021/914 dated 4.6.2021
- Annex B: QS PIMS-specific reference control objectives and controls (PII Processors)
3. Purpose
This policy defines the framework for securing QS’s data, private information, and IT systems. It outlines the specific responsibilities, procedures, and controls required to protect our digital assets from unauthorized access, disclosure, alteration, or destruction.
The purpose of this policy is to ensure that all QS employees, contractors, and third-party users understand and adhere to best practices in information security and privacy data protection, in compliance with applicable laws, regulations, and industry standards.
The structural elements of this policy:
- Scope and Purpose: Clearly define the scope of the ISMS & PIMS.
- Information & Privacy security management system objectives such as confidentiality, integrity, and availability of information.
- Roles and responsibilities to identify key stakeholders and define their responsibilities in maintaining security.
- Change Management & Risk Assessment: Identify and assess potential risks and threats that could disrupt business operations, and the changes recently made should have traceability.
- Communication & Awareness: Establish a comprehensive communication plan to ensure timely provision of accurate communication to employees, customers, suppliers, and other stakeholders. Periodic organisation-wide awareness programs on various requirements of information security and privacy data protection.
4. Scope
This policy applies to all information assets, employees, contractors, temporary staff, suppliers, cloud service providers, business partners, and third parties that create, process, transmit, store, or manage QS information and personal data. This policy will be reviewed annually or when major changes occur.
Developed information and privacy security policies & procedures conform to information & privacy security best practices and are applicable within the entire QS.
5. Information & Privacy Security Policy
Information & privacy security policy outlines the QS approach to Information & Privacy Security Management System (ISMS & PIMS). It provides the guiding principles and responsibilities necessary to safeguard the security & privacy of the QS information systems.
QS is committed to a robust implementation of Information & Privacy Security Management. It aims to ensure the appropriate confidentiality, integrity, availability of data and protection of privacy as potentially affected by the processing of PII (Personally Identifiable Information).
The principles defined in this policy will be applied to all the physical and electronic information assets for which QS is responsible. QS is specifically committed to protection of privacy while processing PII, preserving the confidentiality, integrity, and availability of documentation and data supplied by, generated by, and held on behalf of third parties pursuant to the carrying out of work agreed by contract, in accordance with the requirements of data security and privacy standards ISO 27001 & ISO 27701, and applicable country specific legal/regulatory compliance requirements, specifically GDPR (EU 2016/679).
This policy may be supplemented with additional topic-specific policies in relation to commercial offers when appropriate. Country-specific data protection requirements – including GDPR requirements such as Data Processing Agreements (Art.28), Technical and Organisational Measures (Art.28 & 32), Inventory of data processing and Data Flow Diagrams, Transfer Impact Assessment (Art.46 Chapter V), the EDPB Recommendations 01/2020 on supplementary transfer measures, Data Protection Impact Assessments (Art.35), and Records of processing activities (Art.30) – are ensured through ISMS & PIMS procedures and controls, as per the Statement of Applicability.
5.1. Approval
The Information and Privacy Security Policy has been developed by the compliance team and process owners, and reviewed and approved by management and the CISO (Chief Information Security Officer). This policy is communicated to all QS users who are likely to interact with the QS information system, and its application is mandatory.
5.2. Information Security and Privacy controls
The selected controls and their implementation status are listed in the Statement of Applicability.
6. QS Organisation
6.1. Senior Management
Strategic decisions and matters regarding the information security and privacy requirements for the information systems are managed by senior management. Our senior management demonstrates leadership and commitment concerning information & privacy security by:
- Ensuring the information & privacy security policy and objectives are established and compatible with QS’s strategic direction.
- Ensuring the integration of the information & privacy security management system requirements into the organisation’s processes.
- Ensuring that the resources needed for the information & privacy security management system are available.
- Communicating the importance of an effective information and privacy security management system, and of conforming to its requirements.
- Ensuring that the information & privacy security management system achieves its intended outcome(s).
- Directing and supporting people to contribute to the effectiveness of the information & privacy security management system.
- Promoting continual improvement and supporting other relevant management roles to demonstrate their leadership in their areas of responsibility.
6.2. Chief Information Security Officer (CISO)
Senior management appoints a CISO responsible for information systems security, cyber security and privacy. The CISO plans, coordinates, and monitors all activities related to information, cyber security & privacy. The role of the CISO includes:
- Leading and coordinating the actions of users associated with information system security, cyber security and privacy.
- Assisting and advising on risks, information security, cyber security & privacy measures during the development of new systems.
- Defining and proposing means of protection and actions required to achieve information security, cyber security & privacy objectives.
- Ensuring solutions are adapted to security & privacy issues and comply with policy requirements.
- Defining and consolidating reporting to senior management (Management Review Meeting – MRM).
- Responsibility for Information, cyber security & Privacy Security Management System implementation.
- Periodic review and updates of ISMS & PIMS processes to ensure efficiency and effectiveness of controls.
- Communicating regular updates on changes to legislation, internal ISMS/PIMS processes or methods to employees.
- Monitoring information, cyber security & privacy security incidents and taking appropriate action.
- Evaluating compliance with company processes through regular internal audits.
- Organising information & privacy security training for all employees.
- Organising security & privacy awareness campaigns to build a broad understanding of ISMS and PIMS requirements.
- Ensuring internal audits are periodically conducted and action items closed out.
- Maintaining appropriate contacts with relevant regulatory and legal authorities.
- Providing a vision to the organisation from an information, cyber security & privacy standpoint.
- Coordinating and facilitating the external audit process periodically.
- Participating in due diligence of suppliers and external partners before onboarding.
- Assessing and remediating critical vulnerabilities based on risk and defined service level targets.
6.3. Privacy Officer
The Privacy Officer supports the Data Protection Officer where required in providing and maintaining the necessary documentation as per ISO 27001 and ISO 27701, to demonstrate compliance with GDPR and other applicable country-specific privacy laws. Key responsibilities include:
- Informing and advising staff in their country of responsibility on obligations under GDPR and relevant local laws when processing personal data.
- Monitoring compliance with the Data Protection Policy and related internal documents, and informing the DPO of any non-compliance in a timely manner.
- Acting as the main point of contact for employees in their country of responsibility on matters of data protection.
- Executing and rolling out the data breach response and notification procedure, and informing the DPO accordingly.
- Ensuring training and awareness is delivered to staff involved in processing personal data in their country of responsibility.
In consultation with the Data Protection Officer, the following may also be considered, where they do not conflict with the responsibilities above:
- Reviewing/developing procedures and other controls for the protection of personal data.
- Establishing adequate controls to ensure and maintain the confidentiality, integrity, and availability of personal data.
- Contributing to business continuity and disaster recovery planning so personal data processing is considered.
6.4. Data Protection Officer
The Data Protection Officer assures that all necessary measures have been taken by QS pertaining to legal, regulatory, and contractual issues. Regarding information system security and privacy, the DPO’s mission is to:
- Keep up to date with judicial standards and jurisprudence, working with the CISO to communicate internal obligations related to information system security & privacy.
- Ensure compliance with legal, regulatory, and contractual provisions concerning information system security & privacy.
- Identify and maintain legal, regulatory, and contractual obligations, in collaboration with the CISO.
- Document and update the procedures used to meet those obligations.
- Ensure the integration of information security & privacy requirements into contracts with service providers or external partners.
- Proceed with regular review of contracts and establish legal references.
- Monitor compliance with GDPR and other data protection provisions and internal policies, including assignment of responsibilities, awareness-raising, staff training, and related audits.
- Cooperate with the supervisory authority and act as its contact point on processing matters, including prior consultation.
- Play a supporting role to the various entities, and be consulted when further information is required.
- Have due regard to the risk associated with processing operations, considering their nature, scope, context, and purposes.
- Perform duties independently, report to senior management, and receive no instructions regarding the exercise of those duties.
6.5. Line Managers
Managers are responsible for the administration and review of access and authorisation of users to their services. With the assistance of the CISO, they assure that their teams are aware of information system guidelines and security & privacy policies.
7. Understanding the organisation and its context
An overview of QS products is addressed in the QS Business Summary. QS has determined the external and internal issues relevant to its purpose and strategic direction, and which affect its ability to achieve the intended outcomes of the ISMS & PIMS. QS monitors and periodically reviews this information, or reviews it when there is a change.
8. People & Workplace
People & Workplace management applies security & privacy rules during the arrival, employment, and departure of employees, in line with ISO 27001 Control “A.6 – People Controls” and ISO 27701 control “6.4 – Human Resource Security”.
8.1. Users
Users must comply with all security & privacy rules communicated to them, and report any security and privacy incidents as quickly as possible to their line manager and the CISO for further action.
8.1.1. Human Resource Security
This ensures that employees and contractors understand their responsibilities and are suitable for the roles they are considered for. Contractual agreements with employees and contractors state their and the organisation’s responsibilities for information security.
9. Communication
QS has determined the need for internal and external communications relevant to the information security management system and the privacy information management system. This covers, along with identifying reporting lines for escalation:
- What to communicate
- When to communicate
- With whom to communicate
- Who shall communicate
- How communication would take place
10. Control of documented information
All ISMS & PIMS documents (policies, procedures, and guidelines) and records are created, maintained, and controlled in accordance with defined processes and guidelines. Periodic reviews and approvals are carried out for all documents.
A separate document governs information lifecycle management and the archiving of information, with an emphasis on internal and external business records.
11. Information and privacy objectives and planning
QS has established information, cyber & privacy security objectives at relevant functions and levels to maintain and continually improve the ISMS & PIMS and its performance. These objectives:
- Are consistent with the information security and privacy policy.
- Are measurable.
- Consider applicable information security and privacy requirements, and results from risk assessment and risk treatment.
- Are monitored, communicated, and updated as appropriate.
While planning to achieve its information security and privacy objectives, the organisation determines:
- What will be done
- What resources will be required
- Who will be responsible
- When it will be completed
- How the results will be evaluated
12. Operations
12.1. Change Management
We aim to prevent malfunctioning of the information system during the implementation of changes to platforms (application and system updates, changes in infrastructure and architecture) while maintaining team responsiveness. Information security and privacy are integral to the entire project lifecycle, and the Risk Management process supports change management.
12.2. Risk management
Information security risk assessment
QS has defined and implemented an information security and privacy risk assessment process that:
- Establishes and maintains information & privacy security risk criteria.
- Ensures repeated risk assessments produce consistent, valid, and comparable results.
- Identifies, analyses, and evaluates information & privacy security risks.
- Identifies mitigating actions that are tracked in the risk register.
Information Security Risk Treatment
QS has also defined and implemented an information security and privacy risk treatment process to:
- Select appropriate risk treatment options, taking account of risk assessment results.
- Determine all controls necessary to implement the chosen risk treatment option(s).
- Compare determined controls with those in the Statement of Applicability, verifying none have been omitted.
- Produce a Statement of Applicability with justification for inclusions and exclusions of controls.
- Formulate an information & privacy security risk treatment plan.
- Obtain risk owners’ approval of the treatment plan and acceptance of residual risks.
12.3. Management of Technical vulnerabilities
Using a risk-based approach, technical vulnerabilities are evaluated and updated regularly to guard against attacks by correcting known vulnerabilities in systems and applications. Vulnerability management comprises planning, implementation and operation of vulnerability management, patch management, threat intelligence, configuration management, monitoring activities, and web filtering.
Periodic internal and third-party penetration testing is conducted to assess and analyse the risk of new vulnerabilities for remediation. Third-party penetration testing largely covers:
- Web Application Security Assessment
- Web Service Security Assessment
- Security Configuration Review
12.4. Antivirus Protection
QS safeguards its information systems against viruses, malicious code, and cyber-attacks, protecting vulnerable systems as well as information system input and output. QS staff systems are equipped with antivirus software, which is updated periodically after review with QS corporate IT. Configuration of the antivirus software is managed by QS corporate IT support – users cannot change the configuration or uninstall it.
12.5. Backups
In the event of incidents affecting the availability or integrity of assets, we protect against data loss through safeguard mechanisms for all systems and data, including backups (application configuration, source code, application logs, access logs, database logs, configuration files, code, and product databases supporting client data). Business continuity plans are in place and regularly evaluated.
12.6. Monitoring and Logging
All critical functions and systems are monitored by Infrastructure Support along with data traceability, using a visualising tool to manage log reports that are reviewed regularly. All systems and equipment are synchronised to a unique time source. Logs are analysed by the Infrastructure Head based on abnormality, retained consistent with legal requirements, and stored in protected areas.
12.7. Disposal
All computer equipment containing business information is discarded using a secure erasure process. Paper documents containing sensitive and/or confidential information are destroyed using a paper shredder as per this policy. Procedures are established for the secure disposal of information security assets, and a data retention policy is established for normal working – with applicable contractual and legal/regulatory requirements ensured for client data.
13. Compliance
13.1. Compliance to legal, regulatory, and contractual obligation
We respect legal, regulatory, and contractual requirements and adopt applicable standards. Key drivers and mechanisms include:
- Local legal and regulatory compliance requirements (for GDPR, including related data processing agreements and standard contractual clauses as per European Council & Commission decision C(2021) 3972 final dated 4 June 2021, and related EDPB guidelines).
- Obligations under standard contracts or conditions of service offerings with suppliers/sub-processors.
- Obtaining and maintaining recognised certifications for information security management (ISO/IEC 27001), privacy information management (ISO/IEC 27701), cyber risk, and more.
Compliance is ensured through:
- Up-to-date legal, contractual, and regulatory requirements and measures.
- Observation of developments in the legal, regulatory, contractual, and standards framework.
- Procedures and their implementation to satisfy legal, regulatory, contractual and standards requirements, with communication channels in place.
- Monitoring mechanisms including audit indicators, penetration testing, vulnerability tests, and scheduled periodic reviews.
- Action plans for identified non-conformities during audits.
Due to their impact, or potential impact, on QS’s ability to consistently provide products & services that meet customer and applicable statutory & regulatory requirements, QS has detailed applicable legal, regulatory and contractual requirements to avoid breaches of obligations related to information security & privacy.
13.2. Security Practices
QS adopts information, cyber security & privacy practices by defining controls applicable to its entire information system. Additional measures identified through risk analysis, legal, regulatory, and/or contractual concerns, and/or specific standards, are addressed accordingly. A Statement of Applicability is established for the applicable controls required for the products that enable Software as a Service (SaaS) offerings.
13.2.1. Information Classification Labelling Policy
QS has established an Information Classification & Labelling Policy to handle business information according to its identified security and privacy classification, protecting QS data against unauthorised access, unauthorised change, unintentional breach and data loss, supported by comprehensive security and privacy awareness.
13.2.2. Asset Management Process
QS has established an asset management process to issue, track, maintain, and return all types of assets (hardware & software) and associated assets, to prevent loss, damage, theft or compromise.
13.2.3. Clean Desk & Clear Screen
QS has adopted a Clean Desk and Clear Screen Policy for all workstations, including laptops and desktops, ensuring sensitive and confidential information – whether on paper, storage device, or hardware – is properly locked away, kept secure, or disposed of when not in use.
13.2.4. Mobile devices & Mobile Communication Services
QS has established a Mobile Devices & Mobile Communication Services Policy to set clear guidelines for the appropriate use, security, and management of mobile devices and communication services within QS.
13.2.5. Teleworking & Home Office Policy
QS has adopted a Teleworking & Home Office Policy to establish clear guidelines and expectations for QS employees who work remotely, full-time or part-time.
13.2.6. Policy on Social Media
QS has established a policy on social media to guide employees on responsible online behaviour and handling of official platforms or channels, protecting QS’s reputation, ensuring legal compliance, and reducing risks associated with inappropriate or unauthorized posts.
13.2.7. QS Supplier Security Policy (Managing Outsourced Services)
QS has established rules for its vendors and partners, given that QS solutions entail the processing of protected data, including personal data included in university data forms. Suppliers processing QS information or personal data are subject to risk assessment, contractual security requirements, periodic review and ongoing monitoring.
13.2.8. Information Security in Project Management
QS ensures information & cyber security risks related to business projects and deliverables are assessed in project management throughout the project life cycle.
13.2.9. Information & Privacy Security Incident Management
QS has established an Information, Cyber & Privacy Security Incident Management process to ensure effective and timely response to security and privacy incidents, including communication on information security and privacy events.
13.2.10. Business Continuity Management System
QS has established a Business Continuity Policy to ensure the organisation’s objectives can continue to be met during disruption, and to ensure the availability of information and other associated assets during disruption.
14. Dealing with Personal data
We have an important responsibility to protect the personal and sensitive personal data of our clients, prospects, and employees by respecting their rights. QS Student Recruitment, QS 1Mentor, QS MoveON, and QS MoveIN have established and maintain control measures to ensure the confidentiality, integrity, and protection of information and personal data, including:
- ISO 27001 and ISO 27701 controls adopted and implemented per the Statement of Applicability (see Annex B for PIMS-specific reference control objectives and controls for PII Processors).
- Technical and Organisational Measures as required by GDPR and per European Council & Commission decision C(2021) 3972 final dated 4 June 2021 (see Annex A).
- Strong Firewall and Anti-virus: multiple layers of security software making unauthorised access to client data more difficult.
- Access control: purpose-based access provision under a strong password policy, ensuring regular password changes to key systems and immediate access revocation on employee exit.
- Processing information ethically: transparency about data collection and usage, adhering to information handling policies.
- Regular compliance checks against applicable country-specific regulations such as GDPR, carried out by third parties.
- Data management: collecting and managing client data responsibly and strategically, per contractual and legal/regulatory obligations.
- Supplier management: ensuring suppliers/sub-processors fulfil information security and privacy requirements through implementation of applicable controls, ensuring the customer value chain is compliant.
- Training and Education: training stakeholders on ISMS, PIMS, GDPR and cyber security to strengthen personal data management and information confidentiality & privacy.
- QS supports the rights of data subjects, including access, rectification, erasure, restriction, portability and objection rights, where applicable.
PIMS-specific reference control objectives and controls for PII Processors (see Annex B) are ensured at QS Student Recruitment, QS 1Mentor, QS MoveON, and QS MoveIN through the Data Processing Agreement (DPA) and Standard Contractual Clauses (SCC), where applicable, to protect personal data in cases of cross-border transfer.
15. Dealing with Intellectual Property and Copyrights
We respect Intellectual Property and Copyrights when using licensed software. Licensed software used within the QS information system is defined and maintained as part of our information asset inventory. Licensing agreements are maintained under the responsible licence owner, and requests to install licensed software go through a proper approval workflow. Regular checks are carried out to ensure consistency between licensing agreements and current installations.
16. Compliance
QS respects legal, regulatory, and contractual requirements and adopts applicable standards. The compliance team owns the QS Information & Privacy Security Policy internal audit and reports to the CISO. Anyone who fails to comply with this policy or applicable legal compliance requirements is subject to appropriate QS disciplinary action.
17. Commitment for ISMS & PIMS implementation
As per the Management Commitment, ISMS and PIMS implementation and continual improvement are supported with adequate resources to achieve the objectives set out in this policy and satisfy all identified requirements.
18. Revisions
Revisions to this document will be made annually or whenever deemed necessary.
19. Annex A: Measures based on suggestions from Commission Implementing Decision (EU) 2021/914 dated 4.6.2021
| # | Measures | QS Measures |
|---|---|---|
| 1 | Measures of pseudonymisation and encryption of personal data | Personal data is accessible only through secure login, and critical data fields are encrypted. All services provided as part of SaaS are accessible only through TLS-encrypted communication (or SSH for special packages). Certificates are checked as part of server maintenance, and hashed passwords are used for authentication. Anonymisation is applied to personal data in the production environment, which also protects personal data in the development environment. Pseudonymisation is not deemed required given the context of QS offerings and contractual obligations, and is therefore not implemented. |
| 2 | Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services | ISMS & PIMS based on ISO 27001 & ISO 27701 is established and implemented, with procedures & controls for identification, authentication, authorisation, and accountability. Regular risk management reviews with confidentiality, integrity & availability analysis address changing threats and vulnerabilities. Access to systems is restricted, with no guest or anonymous accounts; differentiated access rights are defined by profile and role using the least-privilege principle. Data is transferred only via secure networks with firewalls and anti-virus installed, with IPSEC, TLS and SSH protocols in place for remote access; portable data storage media are prohibited. Regular data backups are taken and stored – at least three copies across two different storage types, with at least one copy offsite – alongside periodic server hardening and OS patching. Power backup covers power failures, and periodic system/equipment maintenance is implemented. Availability is monitored continuously per contract, and business continuity plans for processes and services are implemented and tested frequently. |
| 3 | Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident | Technical & Organisational Measures (TOM) are in place per GDPR Art. 28. Sufficient redundancy is built for the availability of applications, servers, and software so that alternate resources can take over if primary equipment fails. Project servers are physically located for easy accessibility from an alternate site during a disaster scenario. Backup data for critical project servers is accessible from an alternate location, and recovery onto another server is possible in the event of a physical or technical incident; installable versions of required software are also made accessible in such situations. |
| 4 | Processes for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures to ensure the security of the processing | QSIP (MoveON & MoveIN) and QSSR/QSEM (1Mentor) are currently ISO 27001 & ISO 27701 certified, with certification requirements verified during regular audits. As part of ISMS and PIMS review, TOMs are periodically reviewed with respective data sub-processors, checking compliance with applicable regulations and any changes. |
| 5 | Measures for user identification and authorisation | Procedures are documented for identification, authentication, authorisation, and accountability of information systems. Access is restricted with no guest or anonymous accounts; differentiated access rights are defined by profile and role according to business requirement and the least-privilege concept. |
| 6 | Measures for the protection of data during transmission | Data is transferred only over HTTPS to the data centre hosting the application, with encryption enabled for HTTPS traffic. Once data enters the data centre’s internal network it is protected with firewall and IPS protocols. Selected custom database fields are stored encrypted by our product. Backups are created with read-only permission and kept on a secured backup server. SAML-based SSO is implemented, and API access is via secured certificate/key. |
| 7 | Measures for the protection of data during storage | Data is securely hosted at dedicated data centres. Once data enters the internal network it is protected with firewall and IPS protocols. Authentication, encryption, and password policies are defined and implemented; the database is encrypted. Backups are created with read-only permission and kept on a secured backup server, and application logs are regularly checked by the internal team. |
| 8 | Measures for ensuring physical security of locations at which personal data are processed | Technical and Organisational Measures audits are conducted with data centres at regular intervals and on a need basis. Regular fire drills are conducted, and equipment undergoes preventive maintenance. Infrastructure includes firewall, IDS, DDoS protection, and layered networks. Data centres maintain an access control policy, hold ISO/IEC 27001, ISO/IEC 27017, and PCI DSS-aligned compliance certification, and provide highly resilient Layer 4–7 anti-DDoS protection built into the network. |
| 9 | Measures for ensuring events logging | Events logging is performed using industry-standard logging tools, with protection of log files against unauthorised access ensured. |
| 10 | Measures for ensuring system configuration, including default configuration | Initial (default) product configuration is provided when institutions are onboarded, with further configuration changes managed by institutions. For infrastructure configuration, VM backups are in place, and periodic server hardening and OS patching are tested and implemented. |
| 11 | Measures for internal IT and IT security governance and management | A structured IT governance mechanism is implemented and regularly reviewed with top management at the Management Review Meeting (MRM). Process owners are involved in planning, implementing, and monitoring ISMS and PIMS processes. All employees are responsible for the secure handling of information, especially personal data, within the scope of their tasks. Access to IT applications and systems is periodically reviewed, and security and privacy training is provided to all employees. |
| 12 | Measures for certification/assurance of processes and products | The QS Information Security Management System is certified against ISO 27001 and ISO 27701. Risk management is ongoing to determine weaknesses and risks and to learn from incidents and corrective measures. Audits are regularly carried out by internal and external auditors, with corrective action plans assigned responsibilities and deadlines; findings and continuous-improvement actions are facilitated to closure and reviewed for effectiveness with support from the CISO and top management. |
| 13 | Measures for ensuring data minimisation | Mandatory data fields are advised by institutions, ensuring data minimisation by design. Configuration follows instructions provided by institutions, and personal data is collected and maintained by institutions. |
| 14 | Measures for ensuring data quality | Standard practices in form design are established, with appropriate validation to ensure data quality at the point of collection. The European Student Identifier is used to identify and validate students at various touchpoints. Communication regarding changes or deletion of data types is promptly reconciled with institutions, with demo and user validation conducted in some cases to ensure alignment with client data quality requirements, and login access to forms restricted. |
| 15 | Measures for ensuring limited data retention | Data retention is ensured per contractual terms with the institution. Individual data retention, erasure, or deletion is based on institution requests, so institutions can specify a retention period for specific records under service agreements. Personal data is not retained longer than necessary for the purposes for which it was collected, unless required by legal, regulatory, or contractual obligations. |
| 16 | Measures for ensuring accountability | A CISO and Data Protection Officer are appointed, with process owners assigned for ISMS and PIMS processes and unique usernames with multi-factor authentication provided for system users. Contracts with data centres, along with DPAs and regular TOM audits, are established. Security and privacy training is provided to all employees at onboarding, with regular refresher training. Periodic reviews and updates are made as required – for example, access rights to personal data and compliance with applicable and changing regulations. A DPIA is in place and updated regularly, and data inventory and related processing activities are available and regularly reviewed. |
| 17 | Measures for allowing data portability and ensuring erasure | As per contractual requirements, support can be provided for data portability and erasure. Data can be exported in a standard, readable format at the request of the institution, ensuring data portability. |
20. Annex B: QS PIMS-specific reference control objectives and controls (PII Processors)
| Clause # | Title | Control | QS undertakes through the Data Processing Agreement |
|---|---|---|---|
| B.8.2 — Conditions for collection and processing. Objective: to determine and document that processing is lawful, with legal basis as per applicable jurisdictions, with a clearly defined and legitimate purpose. | |||
| B.8.2.1 | Customer agreement | The Organisation shall ensure, where relevant, that the contract to process PII addresses the Organisation’s role in providing assistance with the customer’s obligations (taking into account the nature of processing and the information available to the Organisation). | Where relevant, QS contracts with customers and suppliers to process PII address QS’s role in providing assistance with the customer’s obligations, taking into account the nature of processing and information available to QS. |
| B.8.2.2 | Organisation’s purposes | The Organisation shall ensure that PII processed on behalf of a customer is only processed for the purposes expressed in the customer’s documented instructions. | QS ensures that PII processed on behalf of a customer is only processed for the purposes expressed in the customer’s documented instructions. |
| B.8.2.3 | Marketing and advertising use | The Organisation shall not use PII processed under a contract for marketing and advertising purposes without establishing that prior consent was obtained from the appropriate PII principal, and shall not make providing such consent a condition for receiving the service. | As a processor, QS does not use PII processed under a contract for marketing and advertising purposes without establishing prior consent from the appropriate PII principal. QS’s privacy policy ensures such consent is not made a condition of providing the service. |
| B.8.2.4 | Infringing instruction | The Organisation shall inform the customer if, in its opinion, a processing instruction infringes applicable legislation and/or regulation. | QS informs the customer if, in its opinion, a processing instruction infringes applicable legislation and/or regulation. |
| B.8.2.5 | Customer obligations | The Organisation shall provide the customer with the appropriate information such that the customer can demonstrate compliance with their obligations. | QS provides the customer with appropriate information so the customer can demonstrate compliance with their obligations. |
| B.8.2.6 | Records related to processing PII | The Organisation shall determine and maintain the necessary records in support of demonstrating compliance with its obligations (as specified in the contract) for the processing of PII carried out on behalf of a customer. | QS determines and maintains the necessary records to support demonstrating compliance with its contractual obligations for processing PII on behalf of a customer. |
| B.8.3 — Obligations to PII principals. Objective: to ensure PII principals are provided with appropriate information about the processing of their PII, and that any other applicable obligations to PII principals are met. | |||
| B.8.3.1 | Obligations to PII principals | The Organisation shall provide the customer with the means to comply with its obligations related to PII principals. | QS provides the customer with the means to comply with its obligations related to PII principals. |
| B.8.4 — Privacy by design and privacy by default. Objective: to ensure processes and systems are designed such that the collection and processing of PII (including use, disclosure, retention, transmission, and disposal) is limited to what is necessary for the identified purpose. | |||
| B.8.4.1 | Temporary files | The Organisation shall ensure that temporary files created as a result of processing PII are disposed of (e.g. erased or destroyed) following documented procedures within a specified, documented period. | Along with Technical and Organisational Measures, the Acceptable Use of IT Systems policy, and Employee Declaration, QS ensures temporary files created from processing PII are disposed of following documented procedures within a specified period. |
| B.8.4.2 | Return, transfer or disposal of PII | The Organisation shall provide the ability to return, transfer and/or dispose of PII in a secure manner, and shall make its policy available to the customer. | Along with Technical and Organisational Measures and its Privacy Policy, QS provides the ability to return, transfer and/or dispose of PII securely, and makes its policy available to the customer. |
| B.8.4.3 | PII transmission controls | The Organisation shall subject PII transmitted over a data-transmission network to appropriate controls designed to ensure that the data reaches its intended destination. | Along with Technical and Organisational Measures, QS subjects PII transmitted over a data-transmission network to appropriate controls to ensure it reaches its intended destination. |
| B.8.5 — PII sharing, transfer and disclosure. Objective: to determine whether and document when PII is shared, transferred to other jurisdictions or third parties, and/or disclosed in accordance with applicable obligations. | |||
| B.8.5.1 | Basis for PII transfer between jurisdictions | The Organisation shall inform the customer in a timely manner of the basis for PII transfer between jurisdictions and of any intended changes, so the customer can object or terminate the contract. | QS informs the customer in a timely manner of the basis for PII transfer between jurisdictions and of intended changes. An inventory of data processing and Data Flow Diagrams are maintained where applicable, and a Transfer Impact Analysis (TIA) is undertaken where cross-border transfers of EU data subjects’ personal data outside Europe fall under GDPR. |
| B.8.5.2 | Countries and international organisations to which PII can be transferred | The Organisation shall specify and document the countries and international organisations to which PII can possibly be transferred. | QS lists, specifies, and documents the countries and international organisations to which PII can possibly be transferred. |
| B.8.5.3 | Records of PII disclosure to third parties | The Organisation shall record disclosures of PII to third parties, including what PII has been disclosed, to whom, and when. | QS records disclosures of PII to third parties, including what PII has been disclosed, to whom, and when. |
| B.8.5.4 | Notification of PII disclosure requests | The Organisation shall notify the customer of any legally binding requests for disclosure of PII. | QS notifies the customer of any legally binding requests for disclosure of PII. |
| B.8.5.5 | Legally binding PII disclosures | The Organisation shall reject any requests for PII disclosure that are not legally binding, and consult the corresponding customer before making any authorised disclosures. | QS rejects any requests for PII disclosure that are not legally binding, and consults the corresponding customer before making any disclosures authorised by that customer. |
| B.8.5.6 | Disclosure of sub-contractors used to process PII | The Organisation shall disclose any use of subcontractors to process PII to the customer before use. | QS discloses any use of subcontractors to process PII to the customer before use. |
| B.8.5.7 | Engagement of a subcontractor to process PII | The Organisation shall only engage a subcontractor to process PII according to the customer contract. | QS only engages a subcontractor to process PII according to the customer contract. |
| B.8.5.8 | Change of subcontractor to process PII | Where general written authorisation has been given, the Organisation shall inform the customer of any intended changes concerning the addition or replacement of subcontractors, giving the customer the opportunity to object. | Where QS has general written authorisation, it informs the customer of any intended changes concerning the addition or replacement of subcontractors to process PII, giving the customer the opportunity to object. |



