Trust Centre

Regulatory & Legal Compliance

This page names the specific regulations Upstream BPO operates under across data protection, anti-corruption and employment, by jurisdiction. Our ISO/IEC 27001:2022 certification provides certified evidence of the information security management system supporting data protection compliance.

Key information

At-a-glance governance context

These points summarise the public scope of this page and the main contact or review context around it.

Primary jurisdiction

Malaysia, through Upstream BPO Sdn. Bhd.

Data protection

Malaysia PDPA 2010, Singapore PDPA 2012, Uzbekistan Personal Data Law, EU and UK GDPR

Anti-corruption

Malaysia MACC Act 2009, UK Bribery Act 2010, US FCPA

Compliance contact

dpo@upstreambpo.com

Section 1

Data protection and privacy

Upstream BPO operates under the following data protection regimes. Where we act as a processor, our obligations follow the customer's instructions and the executed Data Processing Agreement.

  • Malaysia Personal Data Protection Act 2010: fully compliant. Malaysia is our primary operating jurisdiction.
  • Singapore Personal Data Protection Act 2012: fully compliant, covering our regional operations.
  • Uzbekistan Personal Data Law: fully compliant, through the Upstream BPO MCHJ operating entity.
  • EU General Data Protection Regulation 2016/679: compliant as a processor when engaged by EU-based customers. The EU Standard Contractual Clauses, 2021 module set, are incorporated via our Data Processing Agreement.
  • UK GDPR: our compliance handling mirrors the EU position, and the UK International Data Transfer Agreement is available.

Section 2

Anti-corruption

Upstream BPO maintains compliance with the anti-corruption regimes below. Detailed prohibitions, gift controls, third-party conduct expectations and enforcement are set out in our standalone Anti-Bribery and Anti-Corruption Policy.

  • Malaysia Anti-Corruption Commission Act 2009: our primary operating jurisdiction, and the regime referenced in our standalone Anti-Bribery and Anti-Corruption Policy.
  • UK Bribery Act 2010: compliance maintained, applying to interactions with UK-connected parties.
  • US Foreign Corrupt Practices Act (FCPA): compliance maintained, applying to interactions with US-connected parties.

Section 3

Employment and workplace

Upstream BPO complies with employment law in all operating jurisdictions. The regimes below cover our principal workforce locations.

  • Malaysia employment law, including the Employment Act 1955 and related legislation, covering our primary workforce jurisdiction.
  • Uzbekistan labour law, through the Upstream BPO MCHJ operating entity.
  • Philippines labour law, across our Philippine operations.

Section 4

Certified evidence

Our information security management system is certified to ISO/IEC 27001:2022 under Certificate II-23080301. That certification provides independent evidence of the management system supporting our data protection compliance, and the certificate and Statement of Applicability are available to reviewers.

Certificate details, certified scope and the certification body are stated on our security posture page.

Reviewer questions

Questions we are asked in security review

Answers are stated in full here so they are quotable directly into a security questionnaire.

Which data protection laws does Upstream BPO comply with?

Malaysia PDPA 2010, Singapore PDPA 2012 and the Uzbekistan Personal Data Law directly, and the EU GDPR 2016/679 as a processor when engaged by EU-based customers. UK GDPR handling mirrors the EU position.

What anti-corruption laws apply to Upstream BPO?

The Malaysia Anti-Corruption Commission Act 2009 in our primary operating jurisdiction, the UK Bribery Act 2010 for interactions with UK-connected parties, and the US Foreign Corrupt Practices Act for interactions with US-connected parties.

Which employment law applies to your workforce?

Malaysia employment law including the Employment Act 1955 for our primary workforce jurisdiction, Uzbekistan labour law through Upstream BPO MCHJ, and Philippines labour law across our Philippine operations. We comply with employment law in all operating jurisdictions.

How do EU transfers work?

The EU Standard Contractual Clauses, 2021 module set, are incorporated into our standard Data Processing Agreement. For customers subject to UK GDPR, the UK International Data Transfer Agreement is available.

What certification evidences your compliance posture?

ISO/IEC 27001:2022 under Certificate II-23080301. The certificate and Statement of Applicability SOA-UBSB-01 are available to reviewers.

Contact & Escalation

Regulatory enquiries and compliance documentation requests route to dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.

Next Step

Need a deeper governance review?

Send certificate requests, subprocessor list requests, incident reports and vulnerability disclosures to dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.