WorkPermitCloud Limited ("WPC") aims to maintain appropriate information security arrangements for the website and mobile applications used to support right to work checks (including the WpcRtwEmployer and WpcRtwCandidate applications), together referred to as the "Services".
This Information Security Policy sets out WPC's approach to protecting the confidentiality, integrity and availability of information processed by the Services, and the expectations placed on WPC personnel and relevant suppliers. It supports WPC's wider governance and does not replace contractual terms agreed with customers.
This policy applies to information processed by WPC in connection with the Services, including information relating to employer organisations, authorised users and candidates.
The Services may process, depending on the check route used and features enabled:
Employer information, such as organisation name, job position details, authorised user contact details, and check management information.
Candidate information and evidence submitted for checks, such as passport or other right to work evidence, and information extracted from documents.
Technical and operational information, such as authentication events, audit logs and system monitoring records.
WPC seeks to comply with applicable UK data protection and cyber security obligations relevant to the Services, including the UK GDPR and the Data Protection Act 2018, where applicable. WPC recognises that the security measures required may vary according to the nature of the information, the processing context, and the risks to individuals and customers.
Where WPC processes personal data on behalf of customers, WPC's security obligations are also governed by the relevant customer contract and processing instructions. This policy is intended to support those obligations by describing WPC's general approach.
WPC's security approach is based on the following core principles:
Confidentiality: information is protected from unauthorised access or disclosure.
Integrity: information is protected from unauthorised alteration and is maintained in a correct and reliable state.
Availability: information and supporting systems are designed to be available to authorised users when required, subject to reasonable operational constraints and planned maintenance.
WPC implements technical and organisational measures designed to reduce the likelihood and impact of security incidents. Measures applied will be proportionate to the risk and may include:
Access control: access is restricted to authorised personnel with a business need, using role-based access controls (RBAC) and authentication controls such as multi-factor authentication (MFA) for administrative access where appropriate.
Encryption and secure communications: the Services use cryptographic protections for data in transit and, where appropriate, for data stored within WPC-managed systems.
Logging and monitoring: security-relevant logs are maintained to support monitoring, investigation and auditability.
Change and vulnerability management: WPC applies processes intended to identify and address security vulnerabilities and to control changes to systems supporting the Services.
Supplier management: WPC uses third-party providers to support delivery of the Services (for example hosting, messaging, payment processing and document/biometric verification). Where third parties process information on WPC's behalf, WPC seeks to apply contractual safeguards and proportionate assurance activities.
WPC uses Amazon Web Services (AWS) as a hosting environment for components of the Services. AWS provides infrastructure and security capabilities (for example network segmentation options and access control tooling). WPC remains responsible for configuring and using these services securely within WPC's environment and in accordance with the Service design.
WPC maintains procedures for managing security incidents affecting the Services, including incidents involving suspected fraud, service disruption or unauthorised access.
Where an incident involves personal data:
WPC will assess the incident and take steps to contain, mitigate and investigate.
Where WPC is processing personal data on behalf of a customer (as a processor), WPC will notify the customer without undue delay once WPC becomes aware of a personal data breach, to support the customer's assessment and any notification obligations.
Where WPC acts as a controller for the affected information, WPC will consider whether notification to the Information Commissioner's Office (ICO) and/or affected individuals is required under applicable law and will take appropriate steps where required.
WPC will maintain records of material security incidents and corrective actions taken, in line with its governance and legal obligations.
Access to systems and information supporting the Services is restricted to authorised users and is subject to monitoring. WPC uses access controls, authentication mechanisms and audit logging to support detection and investigation of unauthorised activity.
WPC expects personnel with access to WPC information systems to follow security requirements and to complete appropriate training and awareness activities relevant to their role. This includes training on secure data handling and reporting suspected security issues through WPC's internal channels.
The Services may offer or require two-factor authentication (2FA) for certain user accounts. Where enabled, 2FA provides an additional verification step (for example a code sent to a registered email address or mobile number) alongside a password.
For certain check routes, candidates may use one-time passwords (OTPs) issued by government services to obtain or access information relevant to a right to work check (for example a share code). Where the Services support these routes, OTP-related information and any resulting codes are protected through access controls and secure transmission mechanisms within WPC-managed systems.
WPC does not control the availability or performance of government systems that generate or deliver OTPs.
This policy describes WPC's intended security approach and does not create additional contractual rights or warranties. Liability and indemnities relating to the Services are governed by the relevant customer contract and applicable law.
This policy is reviewed at least annually and may be updated where there are significant changes to WPC's Services, risks, technology, or applicable legal requirements. The latest version will be made available to relevant stakeholders through WPC's usual policy distribution channels.
To report a security concern relating to the Services, contact:
Email: rtwcheck@workpermitcloud.co.uk
Registered Office: The Gherkin, Level 28, 30 St. Mary Axe, London, England, EC3A 8BF
This app is not affiliated with, endorsed by, or authorised by any government entity. Services provided within the apps, including document verification and right-to-work checks, are based on information and processes made available through the Services and relevant published guidance. Employers remain responsible for meeting their statutory right to work obligations.
Legal
Subscribe to our newsletter!
Keeping you informed. Want to keep updated with the UK immigration news? Subscribe to our newsletter!