HOW WE ENSURE THE CONFIDENTIALITY OF OUR LANGUAGE AND COMMUNICATION SERVICES

SMG collects, processes and stores information using an Internal Security System, which is certified to ISO 9001:2015 and ISO 27001:2022 and designed to mitigate the risk of information being compromised, disclosed or lost in various scenarios. The system includes, for example, backup measures, controlled access to operational facilities and disaster recovery procedures.

The Project Manager responsible for the client’s project ensures that the processing of information complies with applicable laws and regulations:

  • Regulation (EU) No 2016/679 (General Data Protection Regulation – GDPR) on the protection of individuals with regard to the processing of personal data and on the free movement of such data.
  • National legislation on information security in force in the countries where SMG and the client operate.
  • Company protocol: ‘Confidentiality, Business Continuity and Operational Contingency Plan’.
  • Supplementary clauses, as set out in the client’s specifications.
  • Provisions for the management of information classified as confidential, strictly confidential, secret and top secret, such as, for example, specific Security Clearances and Industrial Security Clearances.
  • Confidentiality clauses in staff contracts.

SMG Languages, which bears full responsibility for the protection of the information it receives, guarantees the utmost confidentiality in the management of its language, translation and communication services through a special Internal Security System.

This system offers three levels of information and process management, set out below, to be agreed with the client according to their specific requirements.

Standard Security Procedure – PSO

This standard procedure applies when the client does not require language services covered by a security clearance or the Extraordinary Security Procedure, and provides for the following.

  • Access to information and documentation provided by clients (including, for example, translations and supporting documents for interpreters) is restricted to authorised staff who have received adequate training on data processing and the associated risks.
  • Paper-based material is stored in a fireproof safe, located in an armoured security room.
  • Digital material is managed via IT systems accessible only to holders of specific personal access credentials.
  • Protection against internet threats, perimeter defence and endpoint protection are ensured by firewalls and antivirus software.
  • Multi-level backup strategies (local, external, remote): three backup systems for documentation and data are in place on special internal servers, on external physical media and on remote servers, with virtualisation of work environments. This includes the capability for rapid data recovery and Disaster Recover procedures.

Handling classified information

SMG Languages provides linguistic, translation and interpreting services guaranteed by systems and procedures that ensure the correct handling of information classified as ‘Confidential’, ‘Strictly Confidential’, ‘Secret’ and ‘Top Secret’ or protected by NATO classifications (‘NATO Restricted’, ‘NATO Confidential’, ‘NATO Secret’ and ‘Cosmic Top Secret’ – NR, NC, NS, CTS) or by corresponding classifications in other countries.

The security system is described in detail in the ‘Confidentiality, Business Continuity and Operational Contingency Plan’, which can be provided to the client upon request.

For the handling of information classified as ‘Strictly Confidential’, the client may request the services of translators, interpreters and staff holding a Security Clearance, as well as the deployment of a language management facility holding an Industrial Security Clearance.

Extraordinary Security Procedure

This procedure applies to linguistic, translation, interpreting and communication services for which the client requires operational measures involving a high level of security. The client must be aware that such measures entail longer lead times and higher costs.

We recommend applying this procedure where the service requires, for example, the handling of information classified as Confidential, Strictly Confidential, Secret and Top Secret or other special confidentiality measures.

The main features of this operating procedure are as follows:

  • The management of work subject to the extraordinary security procedure falls within the remit of the Extraordinary Security Officers (FSS), who are specifically selected from amongst our staff.
  • The description of the extraordinary security procedure, access to the systems used, and access to the data and information processed are restricted to the FSS. The FSS keep confidential the procedures and systems used, the information processed and the identity of clients receiving services subject to the extraordinary security procedure.
  • Information relating to the extraordinary security procedure is shared exclusively with clients upon formal written request.