Security & Compliance
General Data Protection Regulation (GDPR)
GDPR came into place in Europe on May 25, 2018 and is a regulation that protects an individual’s rights with regard to personal data and privacy of data linked to them.
As a organization with a large European footprint, GTT takes GDPR very seriously and has stringent security controls that comply with GDPR. We follow the regulation’s guidance itself, and are also aligned with internationally recognized security methodologies, frameworks, and standards.
You can find our full security and compliance section below.
Most standards and frameworks for information security focus on people, processes and technology. Additionally, the same standards have specific controls relating to the physical security of assets used to store or access information. Find out more about GDPR and how we comply by reading our FAQs below.
SECURITY CERTIFICATIONS
ISO 27001
GTT uses a continuous security improvement approach to all information security objectives. This includes the continuous identification, grading, control and maintenance of risks. The GTT lifecycle is based upon the Edward Deming Plan, Do, Check and Act (PDCA) lifecycle which is internationally recognized and used by numerous standards and frameworks.
GTT is assessed and regularly audited by independent third parties against the ISO 27001 standard to ensure that high standards are maintained continuously.
SOC 1 AND SOC 2 REPORTS
A SOC1 report examines the Controls of a Service Organization which are relevant to a user entity’s internal control over financial reporting. It is specifically intended to meet the needs of customers who require assurance on the effectiveness of the controls at the service organization on the customers’ financial statements. GTT’s SOC 1 scope includes Managed Hosting and VDC services.
PCI DSS
UK PUBLIC SECTOR CERTIFICATIONS
PSN
The Public Services Network (PSN) is the UK government’s high-performance network, which helps public sector organizations work together, reduce duplication and share resources. To achieve PSN compliance a service provider needs to also be certified to ISO 27001.
PSN enables us to provide services to Public Sector organizations at OFFICIAL status. GTT connects to the Government Conveyance Network (GCN) which is at the core of the PSN. GTT is committed to PSN as a valued service for our UK government customers.
GENERAL COMPLIANCE
ISO 20000
GTT COMMUNICATIONS INC. TAX STRATEGY
The tax team, which is led by the VP of Tax, is accountable for the day-to-day management of tax affairs, unless accountability is clearly devolved and accepted elsewhere. Any decisions to be made in respect of uncertain tax issues are subject to diligent professional care and judgement by the tax team but also after consulting with and justifying the decision with local and international management teams. In those situations where the level of uncertainty is high the tax department will utilize outside advisors to help evaluate the risks.
The Company manages tax costs through maximizing the tax efficiency of business transactions. This includes taking advantage of available tax incentives and exemptions. This is done in a way that is aligned with the Company’s commercial objectives and meets its legal obligations and ethical standards. This is also be done in a way that the Company reasonably believes is not contrary to the clear intentions of the legislation concerned.
GTT recognizes that it is responsible for paying an appropriate amount of tax in the UK. Against this GTT must balance its responsibilities to maximize its sustainable returns to shareholders. GTT will not undertake any tax planning that cannot be sustained by the commercial requirements of the group and does not have economic substance. GTT will not undertake any tax planning unless GTT believes that the strategy is compliant with tax legislation and more likely than not to succeed.
The Company is committed to building constructive working relationships with HMRC based on a policy of full disclosure to remove uncertainty in its business transactions and to allow the authorities to review possible risks.
Tax advice will be sought from external advisors in relation to material uncertain transactions or where the tax department does not have the level of expertise required in a particular area. Any tax opinions received are an aid to, not a replacement for, professional judgement to be exercised by the team. Where appropriate, best practice solutions will be sought or such issue may be discussed with HMRC, as the best way to avoid costly disputes is to reach a consensus on issues in advance.
OPERATION CENTER CERTIFICATES
GDPR FAQs
Q. Who does the GDPR affect?
A. The General Data Protection Regulation (GDPR) not only applies to organizations located within the EU but it will also apply to organizations located outside of the EU if they offer goods or services to, or monitor the behavior of, EU data subjects.
Q. What are the penalties for non-compliance?
Q. What constitutes personal data?
Q. Is GTT GDPR certified?
Q. How does GTT comply with GDPR?
Q. How does GTT carry out key technical aspects of GDPR, such as ‘privacy by design’ or data privacy impact assessments (DPIA)?
Q. Can my solution or service from GTT be tailored for my organization’s GDPR compliance needs?
Q. Where can I learn more about GDPR compliance in GTT. How can I request personal data protection support from GTT?
A. GTT has established a Privacy Policy that we encourage our customers, employees, agents, contractors, and suppliers to read. The purpose of this Policy is to outline how GTT will collect and manage personal information in accordance with all relevant privacy legislations. GTT has a Data Protection team responsible for ensuring GDPR compliance. The Data Protection team can be contacted via e-mail to: [email protected]
OUR GARTNER RATING
62 Reviews
Talk to an Expert
Thank you for your information. One of our sales consultants will be in touch with you.