Data Control & Information Management Policy

Data Control & Information Management Policy

Spectrumlabs S.A. is fully committed to the reliable, secure and controlled management of data and information generated, received, processed, stored and transmitted in the course of its activities, whether in physical or electronic form. This Policy applies to primary testing data, test reports, controlled Management System documents, customer and project information, and other business information. This commitment supports the requirements of EN ISO 9001:2015 and EN ISO/IEC 17025:2017 and is implemented through the following principles and actions:

  • Ensuring the accuracy, integrity, confidentiality, availability and traceability of data and information throughout their lifecycle.
  • Recording, controlling, processing, storing, retrieving, retaining and disposing of data in a controlled manner, in accordance with applicable internal procedures and relevant regulatory and contractual requirements.
  • Restricting access to data, information systems and records to appropriately authorized personnel, in accordance with responsibilities and access rights established by the Company.
  • Protecting primary testing data and related records against loss, unauthorized access, alteration, destruction or uncontrolled modification, in a manner that preserves the reliability and technical traceability of results.
  • Controlled preparation, review, approval, storage and distribution of test reports through approved corporate systems and media, so as to maintain the integrity of final issued files.
  • Use of approved information systems, corporate accounts and designated means for storing and transmitting information, in accordance with the applicable data control and cybersecurity procedures.
  • Implementation of appropriate backup, recovery and protection mechanisms for electronic data, according to the type, criticality and storage medium of the information.
  • Maintenance of controlled versions, change history and appropriate traceability where required, in order to prevent the unintended use of obsolete or unauthorized information.
  • Protection of confidential and personal data in accordance with applicable Company policies, contractual obligations and applicable personal data protection legislation.
  • Prompt reporting and appropriate management of incidents involving loss, unauthorized access, alteration or other compromise of data and information, in accordance with the Company’s relevant procedures.
  • Regular review of data and information management practices and allocation of the necessary resources to maintain and continually improve their effectiveness