top of page
Team Working in the System Room

UK GDPR Compliance 
and
ISO 27001
Alignment

At OutSec Legal, the security and confidentiality of client information are fundamental to the way we provide legal transcription, digital dictation and document production services.

​

OutSec Legal is part of The OutSec Group and is required to process personal information and is a data controller for the purposes of data protection legislation including the UK Data Protection Act 2018, the UK GDPR and the General Data Protection Regulation (EU2016/679). The OutSec Group is registered as a data controller (number ZA298519).

​

OutSec Legal complies with applicable UK data protection requirements. We are also Cyber Essentials certified.

 

OutSec Legal does not currently hold ISO 27001 certification.

​

However, a number of the technical and organisational security measures already in place at OutSec address information-security requirements and control areas also covered by ISO 27001.

​

We believe it is important to explain this distinction clearly, particularly when organisations are comparing transcription and document-production providers.

​

GDPR Compliance Does Not Require ISO 27001 Certification

​

UK GDPR and ISO 27001 are not the same thing.

​

UK GDPR is part of the legal framework governing the processing and protection of personal information. It requires organisations to implement appropriate technical and organisational measures according to the nature of the personal data being processed and the risks associated with that processing.

​

ISO 27001 is an international standard that specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System, or ISMS.

​

An organisation does not need to hold ISO 27001 certification in order to comply with UK GDPR.

​​

Equally, ISO 27001 certification is not, by itself, a substitute for meeting an organisation's obligations under data-protection law.

​

At OutSec, our focus is therefore on the practical measures used to protect the personal, confidential and potentially sensitive information entrusted to us.

​

How OutSec Supports UK GDPR Compliance

 

Legal dictation and documents can contain personal data, confidential information, legally privileged material and, in some cases, special category personal data.

​

OutSec uses a combination of technical and organisational safeguards designed to protect that information throughout its lifecycle.

​

These safeguards include authenticated system access, encrypted data transmission, restrictions on access to client information, secure infrastructure, confidentiality obligations, defined retention and deletion procedures, and security controls built into both our FileManager platform and our new mobile application.

​

These measures support the UK GDPR principles of integrity and confidentiality and the requirement to maintain security appropriate to the risks involved in processing personal data.

​

Secure File Transfer Through OutSec FileManager

​

OutSec FileManager provides a controlled environment through which clients can securely submit digital dictation and supporting documents and retrieve completed work.

​

Access to FileManager is authenticated, with individual users accessing protected client areas using their own credentials.

​

Communication with FileManager is protected using encrypted connections, helping to protect information against interception or unauthorised access while it is being transferred.

​

OutSec uses secure cloud infrastructure, including encryption of information both in transit and at rest, together with resilience and availability measures designed to protect the systems on which our services depend.

Using FileManager also reduces the need for confidential client information to be transferred through ordinary email attachments or uncontrolled consumer file-sharing services.

​

Security in the OutSec | Crystal Clara Dictation App

​

The new OutSec application has been designed around a modern API-based architecture.

​

Rather than relying on the legacy file-transfer approach used by earlier applications, communication between the app and OutSec takes place through authenticated API connections protected by encrypted HTTPS/TLS transport.

​

The application uses secure token-based authentication, including access and refresh tokens, so that user credentials do not need to be repeatedly transmitted during normal use.

​

Authentication information stored by the application is held using secure storage mechanisms provided by the mobile operating system rather than ordinary application storage.

​

Files are transferred directly from the application into OutSec's controlled processing environment.

​

This architecture also allows authentication and access controls to be managed centrally by OutSec and enables security improvements to be introduced without requiring clients to configure or maintain separate file-transfer software.

​

Security is therefore incorporated into the architecture of the application rather than being treated simply as an additional feature.

​

Access to Client Information

​

Access to personal and confidential information is resAcctricted according to operational need.

​

OutSec transcriptionists and other personnel handling client information are subject to confidentiality requirements and confidentiality agreements.

​

Restricting access helps reduce unnecessary exposure of personal information and supports the principle that access should be available only to those who require it to perform their role.

​

Data Retention and Secure Deletion

​

OutSec does not retain client files indefinitely.

​

Original and completed files within FileManager are automatically deleted in accordance with OutSec's defined retention policy, currently 40 days after work completion. Clients are able to lower this limit as required.

​

Defined retention and deletion procedures reduce the volume of historical client information held within operational systems and support the UK GDPR principle of storage limitation.

​

Cyber Essentials

​

OutSec is Cyber Essentials certified.

​

Cyber Essentials is a UK government-backed scheme focused on technical measures designed to protect organisations against common forms of cyber attack.

​

Cyber Essentials certification is separate from ISO 27001 certification, but it provides additional independent assurance that important technical cyber-security controls are in place.

​

Where Our Existing Controls Align with ISO/IEC 27001

​

OutSec Legal does not claim to be ISO 27001 certified and has not presented the following as evidence of certification.

​

However, several existing OutSec security measures address areas that also form part of the information-security framework established by ISO 27001.​​

​

Access control

​

Authenticated access to FileManager and other systems; access to client information restricted according to operational need

​

Identity and authentication

​

Individual authentication and secure token-based authentication within the new OutSec app.

​

Protection of Information in transit

​

HTTPS/TLS encrypted communications between clients, the app and OutSec systems.

​

Protection of stored information

​

Security controls and encryption for information stored within OutSec's cloud infrastructure.

​

Confidentiality

​

Restricted access and confidentiality agreements for personnel handling client information.

​

Information lifecycle management

​

Defined retention periods and automatic deletion of FileManager files after the applicable retention period.

​

Secure system development

​

Security incorporated into the new app architecture, including authenticated APIs, encrypted communications and secure handling of authentication information.

​

Availability and resilience

​

Cloud infrastructure, resilience measures and system availability controls.

 

These examples demonstrate areas where OutSec's existing controls are consistent with information-security objectives and control areas addressed by ISO 27001.

​

They should not be interpreted as a claim that OutSec has been certified to ISO 27001 or that an accredited certification body has assessed OutSec's complete Information Security Management System against every requirement of the standard.

​

Confidentiality, Integrity and Availability​

​

ISO 27001 is built around three fundamental information-security objectives: confidentiality, integrity and availability.

​

These same objectives are highly relevant to the protection of personal information under UK GDPR.

​

Confidentiality

​

Information should only be accessible to authorised people.

​

OutSec supports confidentiality through authenticated systems, encrypted communications, restricted access to client information and confidentiality obligations for personnel handling client work.

​

Integrity

​

Information should be protected against unauthorised or accidental alteration, corruption or destruction.

​

OutSec uses controlled systems and secure transfer mechanisms designed to protect client information throughout the transcription workflow.

​

Availability

​

Information and systems should be available when legitimately required.

​

OutSec uses resilient cloud-based infrastructure and operational safeguards intended to maintain the availability of the systems required to provide our services.

​

What Does the Absence of ISO 27001 Certification Mean?

​

ISO 27001 certification provides independent confirmation that an organisation's Information Security Management System has been assessed against the requirements of the standard.

​

OutSec does not currently hold that certification but is currently in the process of working towards it.

​

This does not mean that the security controls associated with ISO 27001 are absent, nor does it mean that an organisation cannot comply with UK GDPR.

​

ISO itself distinguishes between implementing ISO 27001 and choosing to undergo a certification process.

 

Organisations may implement the standard and benefit from its practices without obtaining certification.

 

At OutSec, a number of security measures are already in place that address areas covered by ISO 27001, while our wider information security arrangements continue to be reviewed and developed.

 

How OutSec Compares on Data Protection and Information Security

 

When comparing transcription providers, ISO 27001 certification can be one useful indicator of an organisation's approach to information security, but it should not be considered in isolation.

​

It is also important to understand the actual controls used to protect client information.

​

OutSec Legal combines UK GDPR compliance with Cyber Essentials certification and practical security measures including encrypted communications, authenticated and restricted access, secure cloud infrastructure, defined data-retention procedures, confidentiality obligations and security built into our FileManager and new mobile application.

​

While we do not currently hold ISO 27001 certification, many of these measures address information-security areas also covered by the ISO 27001 framework..

​

If you have any questions concerning any privacy, confidentiality, data security or data protection issue, please email our Data Protection Officer at dpo@outsec.co.uk who will be delighted to help you further.

bottom of page