Skip to content

Trust & compliance

The enterprise review pack: GDPR, DPA, sub-processors and security documents.

  1. Trust CentreOne place for the security, privacy and compliance information your legal and security teams need to approve Laya.
  2. Security programmeThe technical and organisational measures protecting Laya: encryption, access control, authentication, monitoring and secure development.
  3. GDPR complianceHow Laya meets the UK GDPR and EU GDPR: controller and processor roles, lawful bases, data subject rights and processor obligations.
  4. Data Processing AgreementThe Article 28 processor terms governing Laya’s handling of customer personal data, including sub-processing, security, transfers and deletion.
  5. Sub-processorsThe third parties that may process Laya customer data, what each is used for, where it processes, and how changes are notified.
  6. International data transfersWhere Laya hosts data, the transfer mechanisms relied on for moving personal data out of the UK and EEA, and the safeguards applied.
  7. Data retention and deletionWhat Laya keeps, for how long, what deletion actually removes, and how to export your data before you go.
  8. Incident responseHow Laya detects, contains and communicates security incidents, including personal data breach notification commitments.
  9. Privacy rights requestsHow to exercise access, correction, erasure, portability and objection rights with Laya, and how requests are handled.
  10. Security questionnaire answersPre-answered responses to the questions vendor security assessments ask most often, so a review can be completed without a call.