Compliance

We build to GDPR — the strictest standard — for every client.

Nepal is a third country for EU data protection purposes, with no adequacy decision under Article 45 GDPR. We treat that as a design requirement, not an afterthought — and we apply the same rigour to clients outside the EU too.

Our default approach

Data stays in your own systems.

Encryption alone is not a legally sufficient basis for moving personal data across borders. So our standard operating model avoids the question almost entirely.

How this works in practice

Your personal data remains in your own EU-hosted or regionally-hosted environment at all times. Our Nepal-based team accesses it exclusively through your controlled cloud workspace — for example, Microsoft 365 or SharePoint with confirmed regional data residency.

Access is granted through named individual accounts only, with multi-factor authentication, role-based permissions, and full audit logging. No local download to Nepal-based infrastructure happens unless explicitly approved by you in writing.

Under this model, no personal data is transferred to Nepal at all — which means the EU's Chapter V third-country transfer provisions simply don't apply to the data itself. This eliminates the primary data-protection risk before it exists.

When a transfer is unavoidable

A complete legal framework, not a checkbox.

Where the specific nature of an engagement makes it unavoidable for personal data to be processed on Nepal-based infrastructure, the following apply as mandatory pre-conditions — every time, without exception.

STEP 1

Article 28 GDPR Data Processing Agreement

A written DPA meeting all Article 28 requirements is signed before processing begins. It governs purposes, duration, data categories, our obligations, and your data subjects' rights. This is a legal requirement, not a preference.

STEP 2

EU Standard Contractual Clauses

All transfers are governed by EU Commission Implementing Decision (EU) 2021/914, specifically Module 2 — Controller to Processor. You are the Data Controller; Prime Quest is the Data Processor. These clauses apply in their standard, unmodified form.

STEP 3

Transfer Impact Assessment

Completed before go-live for any engagement involving personal data transfer to Nepal. It assesses Nepal's legal framework for government data access, the practical risk level for your specific data, and the effectiveness of our safeguards.

Who is responsible for what

Controller, processor, and representative — clearly defined.

PartyGDPR roleResponsibility
You (the client) Data Controller (Art. 4(7)) Determines the purposes and means of processing; issues written instructions to Prime Quest; retains ultimate responsibility for the lawfulness of processing.
Prime Quest Private Limited Data Processor (Art. 4(8)) Processes personal data only under your documented instructions; implements and maintains technical and organisational safeguards; maintains records of processing activities (Art. 30).
Regional governance partner EU Representative (Art. 27), for EU clients Formally designated as Prime Quest's EU Representative in writing where applicable; serves as the contact point for EU supervisory authorities; coordinates compliance documentation and communication.
What we actually do

Technical and organisational safeguards.

Technical safeguards

  • TLS 1.2/1.3 encryption in transit and at rest for all client data
  • Multi-factor authentication mandatory for all team members with data access
  • Named individual accounts only — shared credentials are strictly prohibited
  • Role-based access control on a minimum-privilege basis
  • Audit logs for all data access events, available to you within 24 hours on request
  • No local download to personal or unmanaged devices without written approval

Organisational safeguards

  • Every team member signs an individual NDA enforceable under Nepali law before any engagement
  • Documented data protection training completed before any pilot go-live
  • Clean-desk and clear-screen policy in effect at our Kalikasthan office at all times
  • Documented data retention and deletion procedures, applied at engagement end per your instructions
  • Documented incident response: detection, escalation, containment, root-cause investigation, correction
  • Client notification within 72 hours of any confirmed breach, in line with GDPR Article 33
Where we are, and where we're going

Certification roadmap.

We're transparent about what's in place today and what's in progress — and happy to share our implementation timeline in more detail on request.

MilestoneTargetStatusNotes
GDPR compliance framework Ongoing Active DPA/SCC templates, TIA process, staff training and access controls are live and applied to every engagement involving personal data.
EU Representative designation Per engagement Active Formally designated in writing under Article 27 GDPR where a regional governance partner is engaged for an EU client.
ISO 27001 (Information Security) Within 12–18 months of first engagement In progress Certification body engaged; information security controls implementation underway.
ISO 9001 (Quality Management) Within 18 months Planning stage Quality management system design in progress; internal quality procedures are already applied in daily delivery.
Why a regional partner matters

Local accountability, not just a promise from Kathmandu.

Most offshore engagements fail on trust, not delivery. A regional governance partner closes that gap — they're who you actually call.

Kathmandu · Prime Quest Private Limited

Nepal-based delivery

  • Implements all technical safeguards and processing records
  • Maintains audit logs, access controls, and staff training records
  • Executes day-to-day work under your documented instructions
Your Region · Local Governance Partner

Compliance accountability in your market

  • Acts as your EU Representative under Article 27 GDPR, where applicable
  • Coordinates DPA, SCC, and Transfer Impact Assessment documentation
  • Single point of contact for any compliance question or concern

For European clients, there are potential governance partners in Germany and other markets across the region. For clients elsewhere, we structure an equivalent local governance arrangement, or work with you directly where a regional partner is not yet in place.

Have a compliance question?

Ask your compliance team to talk to ours.

We're happy to walk your legal or procurement team through our DPA template, SCCs, and TIA process directly.