ClearBGV

Trust

Compliance centre

How ClearBGV handles candidate data, which frameworks we operate against, and what we can hand your security team during due diligence.

Frameworks we operate against

  • ISO/IEC 27001 aligned

    Our information security management system is built to the ISO 27001 control set — documented policies, access control, risk assessment and continuous monitoring across everything that touches candidate data.

  • SOC 2 Type II

    Controls over security and confidentiality, independently tested across an audit window. The report is available to clients and prospective clients under NDA.

  • DPDP Act 2023

    We process candidate personal data as a Data Processor on documented instructions from you, the Data Fiduciary, under a written agreement.

  • GDPR ready

    For candidates in the EEA and UK we support lawful basis documentation, data subject rights handling and standard contractual clauses for transfers.

How candidate data is protected

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access control — analysts see only cases assigned to them
  • Every read and write against a case is written to an immutable audit log
  • Background-verified staff, with data-protection training before system access
  • Segregated client environments; no cross-client data reuse of any kind
  • Documented retention schedule with automated deletion at end of term

Consent and candidate rights

No check begins without explicit, informed, revocable consent from the candidate. The consent notice states what will be verified, which categories of data will be collected, and how long it will be held.

Candidates may request access to their report, ask for correction of inaccurate data, or raise a dispute over a finding. Requests are acknowledged within 72 hours and resolved within 30 days.

Sub-processors

We use a limited set of sub-processors for hosting, communications and international verification partners. A current list is available on request and clients are notified before any addition.

Incident response

We maintain a documented incident response plan with defined severity levels and escalation paths. In the event of a personal data breach affecting your candidates, we notify you without undue delay and support your reporting obligations to the Data Protection Board of India.

Request documentation

Security questionnaires, audit reports and our standard data processing terms are available to prospective and current clients. Write to bgv_request@clearbgv.com or Pegasus Tower, Block-A, Sector 68, Noida, Uttar Pradesh - 201309.