Dataweavers and ISO 27001: Our commitment to security

Piers matthews
Piers matthews
  • Updated

We are ISO 27001 certified

ISO 27001 is an internationally recognized certification for information security management. It's a standard worth checking for when you're evaluating any platform supplier.

Being ISO 27001 certified means our security practices have been independently assessed against a recognized framework.  

What is ISO 27001?  

ISO 27001 is a widely used standard for information security management systems (ISMS). It sets out a structured framework for managing sensitive information-— identifying, assessing, and mitigating risks in a consistent way. Certification confirms we meet established requirements for safeguarding data, covering areas like risk management, access controls, and ongoing improvement.  

Why this matters  

Security is built into how we operate, not treated as an add-on. Whether you're running critical workloads or handling sensitive customer data, our processes are designed with that in mind. ISO 27001 certification means:  

  • Independently assessed controls – our systems are evaluated against recognized international security standards. 
  • Ongoing review – certification isn't a one-time check; it requires continuous monitoring and periodic reassessment. 
  • External verification – an accredited body has assessed how we manage security, rather than us self-reporting. 
  • Consistent processes – standardized procedures support reliability across the platform.  

GDPR compliance 

GDPR compliance refers to adherence to the General Data Protection Regulation, which sets requirements for the collection and processing of personal data belonging to individuals in the EU.

There is no certification for GDPR compliance, because GDPR is a regulation rather than a standard. Organisations demonstrate compliance through their policies, procedures, and practices rather than through certification.

GDPR sets out specific requirements for protecting personal data but leaves it to each organisation to determine the measures it takes to meet them. This reflects the principle of accountability - a key part of GDPR - which requires organisations to be transparent about how they process personal data and to be able to demonstrate compliance to supervisory authorities and individuals on request.

 

Related articles: 

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request