Primary jurisdiction
Malaysia, through Upstream BPO Sdn. Bhd.
Trust Centre
This page names the specific regulations Upstream BPO operates under across data protection, anti-corruption and employment, by jurisdiction. Our ISO/IEC 27001:2022 certification provides certified evidence of the information security management system supporting data protection compliance.
These points summarise the public scope of this page and the main contact or review context around it.
Primary jurisdiction
Malaysia, through Upstream BPO Sdn. Bhd.
Data protection
Malaysia PDPA 2010, Singapore PDPA 2012, Uzbekistan Personal Data Law, EU and UK GDPR
Anti-corruption
Malaysia MACC Act 2009, UK Bribery Act 2010, US FCPA
Compliance contact
dpo@upstreambpo.com
Section 1
Upstream BPO operates under the following data protection regimes. Where we act as a processor, our obligations follow the customer's instructions and the executed Data Processing Agreement.
Section 2
Upstream BPO maintains compliance with the anti-corruption regimes below. Detailed prohibitions, gift controls, third-party conduct expectations and enforcement are set out in our standalone Anti-Bribery and Anti-Corruption Policy.
Section 3
Upstream BPO complies with employment law in all operating jurisdictions. The regimes below cover our principal workforce locations.
Section 4
Our information security management system is certified to ISO/IEC 27001:2022 under Certificate II-23080301. That certification provides independent evidence of the management system supporting our data protection compliance, and the certificate and Statement of Applicability are available to reviewers.
Certificate details, certified scope and the certification body are stated on our security posture page.
Answers are stated in full here so they are quotable directly into a security questionnaire.
Malaysia PDPA 2010, Singapore PDPA 2012 and the Uzbekistan Personal Data Law directly, and the EU GDPR 2016/679 as a processor when engaged by EU-based customers. UK GDPR handling mirrors the EU position.
The Malaysia Anti-Corruption Commission Act 2009 in our primary operating jurisdiction, the UK Bribery Act 2010 for interactions with UK-connected parties, and the US Foreign Corrupt Practices Act for interactions with US-connected parties.
Malaysia employment law including the Employment Act 1955 for our primary workforce jurisdiction, Uzbekistan labour law through Upstream BPO MCHJ, and Philippines labour law across our Philippine operations. We comply with employment law in all operating jurisdictions.
The EU Standard Contractual Clauses, 2021 module set, are incorporated into our standard Data Processing Agreement. For customers subject to UK GDPR, the UK International Data Transfer Agreement is available.
ISO/IEC 27001:2022 under Certificate II-23080301. The certificate and Statement of Applicability SOA-UBSB-01 are available to reviewers.
Use the connected pages below for deeper privacy, governance, service or contact context.
Data Processing Agreement
Transfer mechanisms, DPA variants and the regulations it addresses.
Open page
Security Posture
Certificate details, certified scope and penetration testing.
Open page
Anti-Bribery & Corruption Policy
Detailed prohibitions, gift controls and enforcement.
Open page
Audit Rights
Customer audit scope, notice period and third-party evidence.
Open page
Contact & Escalation
Regulatory enquiries and compliance documentation requests route to dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.
Send certificate requests, subprocessor list requests, incident reports and vulnerability disclosures to dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.
Your choice about cookies
We use essential cookies to run this site. With your permission we would also use functional, performance, analytics and marketing cookies. Nothing optional loads until you choose.