Trust
Compliance centre
How ClearBGV handles candidate data, which frameworks we operate against, and what we can hand your security team during due diligence.
Frameworks we operate against
ISO/IEC 27001 aligned
Our information security management system is built to the ISO 27001 control set — documented policies, access control, risk assessment and continuous monitoring across everything that touches candidate data.
SOC 2 Type II
Controls over security and confidentiality, independently tested across an audit window. The report is available to clients and prospective clients under NDA.
DPDP Act 2023
We process candidate personal data as a Data Processor on documented instructions from you, the Data Fiduciary, under a written agreement.
GDPR ready
For candidates in the EEA and UK we support lawful basis documentation, data subject rights handling and standard contractual clauses for transfers.
How candidate data is protected
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access control — analysts see only cases assigned to them
- Every read and write against a case is written to an immutable audit log
- Background-verified staff, with data-protection training before system access
- Segregated client environments; no cross-client data reuse of any kind
- Documented retention schedule with automated deletion at end of term
Consent and candidate rights
No check begins without explicit, informed, revocable consent from the candidate. The consent notice states what will be verified, which categories of data will be collected, and how long it will be held.
Candidates may request access to their report, ask for correction of inaccurate data, or raise a dispute over a finding. Requests are acknowledged within 72 hours and resolved within 30 days.
Sub-processors
We use a limited set of sub-processors for hosting, communications and international verification partners. A current list is available on request and clients are notified before any addition.
Incident response
We maintain a documented incident response plan with defined severity levels and escalation paths. In the event of a personal data breach affecting your candidates, we notify you without undue delay and support your reporting obligations to the Data Protection Board of India.
Request documentation
Security questionnaires, audit reports and our standard data processing terms are available to prospective and current clients. Write to bgv_request@clearbgv.com or Pegasus Tower, Block-A, Sector 68, Noida, Uttar Pradesh - 201309.