Data Protection
Governance principles for personal, professional, operational and client data handled through BESONG engagements.

Purpose and Minimisation
Collect and process only the information required for a defined business, professional, legal or operational purpose.
Access and Segregation
Use role-based access, least privilege, segregation between clients and workstreams, approved devices and controlled sharing.
Security and Evidence
Apply appropriate encryption, logging, backup, recovery, incident management, retention and secure disposal controls based on data sensitivity and risk.
Sovereignty and Cross-Border Data
Hosting, residency, transfer and access requirements should be defined in the engagement architecture and aligned with applicable law, client authority and professional obligations.
Human Authority over AI
AI tools may assist authorised users, but data sources, permissions, review, approval and accountability remain governed by people and the engagement terms.
