Compliance Policy
Last updated: July 10, 2026
Many of the businesses we work with operate under regulatory or contractual compliance requirements — data privacy laws, industry standards, or customer security questionnaires. This page outlines our general approach; specific compliance commitments for a given project are defined in that engagement's agreement.
Our approach with clients
As part of our Cybersecurity Services and IT Consulting work, we help clients assess their current posture against relevant frameworks, identify gaps, and develop practical policies and controls to close them.
Frameworks we commonly work with
- Data privacy: GDPR (EU/UK), CCPA/CPRA (California)
- Payments: PCI-DSS
- Healthcare: HIPAA
- Information security management: ISO 27001, SOC 2
These are frameworks we help clients assess and build toward — not certifications JSK Corporation itself holds, unless stated in writing for a particular engagement.
Internal practices
We handle client data confidentially, limit access to what a given engagement requires, and apply the practices described in our Information Security Policy. We do not claim certification against any specific compliance framework unless stated in writing for a particular engagement.
Data processing agreements
For engagements involving processing of personal data on a client's behalf, we can enter into a data processing agreement (DPA) or similar contractual terms on request, as part of that engagement's written agreement.
Working within your regulatory context
Every client's regulatory obligations are different. Rather than apply a one-size-fits-all checklist, we scope compliance work around your industry, jurisdiction, and existing obligations at the start of an engagement.
Questions
For compliance-related questions about a current or prospective engagement, contact info@jskcorporation.com.
