Data Security
EFFECTIVE DATE: JULY 27, 2026 · VERSION 1.0
We implement industry-standard technical and organisational measures to protect your personal information against unauthorised access, disclosure, alteration, loss, and destruction.
8.1 Technical Measures
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Multi-factor authentication for user accounts and internal systems
- End-to-end encryption for sensitive communications
- Tokenisation of sensitive financial data
- Web application firewall and DDoS protection
- Intrusion detection and prevention systems
- Regular independent penetration testing
- Vulnerability scanning and patch management
- Secure software development lifecycle practices
8.2 Organisational Measures
- Role-based access controls so employees access only what is necessary for their role
- Background checks for employees handling sensitive data
- Mandatory data protection and security training
- Data classification based on sensitivity
- Third-party vendor security assessments
- Regular security audits and compliance reviews
- Incident response and breach notification procedures
- Business continuity and disaster recovery planning
8.3 Data Breach Response
If a personal data breach is likely to put your rights and freedoms at risk, we will:
- Notify the relevant data protection authority within 72 hours where required by applicable law
- Notify affected individuals without undue delay where the breach is likely to create a high risk
- Document breaches in our internal breach register
- Take immediate steps to contain the breach and prevent recurrence
To report a suspected security vulnerability or breach, contact security@sykabank.com.