



Information security is built into every system, service and process.
We apply the highest standards of data protection in compliance with the UK Data Protection Act 2018, the EU & UK General Data Protection Regulation (GDPR) and relevant international privacy laws. Our Information Security Management System (ISMS), certified to ISO 27001:2022, defines clear controls for data storage, access and transfer.
All client and their global talent's information is stored securely on encrypted servers with controlled access permissions, regular penetration testing and data-loss prevention tools. Each system is reviewed and maintained by dedicated IT and compliance teams to ensure ongoing alignment with both regulatory and contractual requirements.

We treat privacy as a universal right, not a regional requirement.
K2 Relocate operates globally, handling data across multiple jurisdictions. Our privacy framework aligns with GDPR principles of lawfulness, fairness, transparency, purpose limitation and minimisation. Data transfers between regions are governed by Standard Contractual Clauses (SCCs) and strict internal protocols to ensure compliance with local laws.
We ensure that:

Data protection is everyone’s responsibility.
Our teams receive continuous training on data privacy, information handling and incident response. This ensures every employee understands the importance of confidentiality and the impact of their role in maintaining trust.
Should a breach occur, our global incident response protocol ensures rapid containment, investigation and transparent reporting in line with legal and ethical requirements.