Back to Home
MSL

Data Privacy Framework

Last Updated: July 2026

1. GDPR & Cross-Border Data Residency

MSL architected its infrastructure to ensure strict adherence to the General Data Protection Regulation (GDPR) and equivalent global privacy statutes. We maintain a regional data residency commitment:

European worker and supplier data is processed and stored exclusively on EU-hosted instances (Frankfurt/Dublin). Data does not cross borders without explicit Standard Contractual Clauses (SCCs) governing the transfer.

2. Supplier Data Confidentiality

We recognize that supply chain mapping requires suppliers to submit highly sensitive commercial data (e.g., sub-tier vendor lists, wage structures, recruitment agency contracts).

MSL utilizes granular access controls. Clients are granted access to risk outputs and compliance status indicators only. The underlying proprietary commercial documents submitted by suppliers remain encrypted and are never shared directly with the buying enterprise unless the supplier grants explicit, separate consent during a formal audit process.

3. Worker Identity & Whistleblower Protection

The Worker Grievance Portal is designed as a secure, end-to-end encrypted channel.

  • Absolute Anonymity: If a worker selects the anonymous reporting option, MSL drops all PII, strips IP addresses, and scrubs metadata from uploaded evidence files before routing the grievance to the compliance team.
  • Anti-Retaliation Strictures: MSL explicitly forbids the use of the platform to identify whistleblowers. Any client found attempting to de-anonymize worker reports will face immediate platform suspension and reporting to relevant regulatory bodies.

4. Data Categories Collected

We process the following categories of data solely for the provision of the MSL Platform:

  • Corporate Identifiers: Entity names, addresses, registration numbers, sector codes.
  • Administrative PII: Names, business emails, and roles of Client and Supplier compliance officers.
  • Grievance Records: Case descriptions, locations, and (if opted-in) reporter contact details.
  • Telemetry: System access logs, session data, and audit trails required for security monitoring.

5. Retention Periods

Compliance records (SAQs, framework reports, audit logs) are retained for a minimum of seven (7) years to satisfy statutory record-keeping obligations under modern slavery legislation.

Upon termination of a client contract, enterprise data is archived in a cold-storage state for the remainder of the statutory period, after which it is cryptographically destroyed.

6. Data Subject Rights

Individuals have the right to access, correct, restrict processing, or request deletion of their personal data (Right to be Forgotten). Because MSL acts as a Data Processor for the majority of platform data, subject access requests (DSARs) should be directed to the relevant employing entity (the Data Controller).

If you require assistance or wish to contact MSL's Data Protection Officer, please email privacy@modernslaverylaws.com.

© 2026 Modern Slavery Laws. All rights reserved.