← Governance framework
Governance

Legal and Regulatory Compliance Matrix

High-level mapping of ImpactMiles policies to applicable Hong Kong laws, key EU, UK and APAC regulations and relevant international standards.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-20
Next review
2027-07-19
Owner
General Counsel
Approver
Board of Directors
Anchored by content hashissued 2026-07-29
Payload hash
441a0169a16b8a2f16541914ff1864fdc98b064788f806c7e8888de3779a459e
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:441a0169a16b8a2f

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • All jurisdictions in which ImpactMiles operates or has users

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • Policy owners maintain mapping evidence in the Governance CMS
  • Legal review of policy amendments for regulatory impact
  • External counsel engaged for material regulatory change

1. Hong Kong

  • Personal Data (Privacy) Ordinance (Cap. 486) - Data Protection and Privacy Policy, Retention Schedule, DPIA Methodology, Cookies Policy.
  • Companies Ordinance (Cap. 622) - Governance Charter, Audit and Reporting.
  • Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) - AML/CTF Policy.
  • Prevention of Bribery Ordinance (Cap. 201) - Code of Conduct, Vendor Management.
  • Inland Revenue Ordinance s.88 - Charity verification within Trust and Verification Policy.

2. European Union

  • GDPR - Data Protection and Privacy Policy, Retention Schedule, DPIA, Incident Response, Vendor Management.
  • Digital Services Act (DSA) - Fraud, Abuse and Misuse Policy; transparency reporting under Audit, Reporting and Transparency Policy.
  • eIDAS - referenced for interoperability of trust services within the Trust and Verification Policy.

3. United Kingdom

  • UK GDPR and Data Protection Act 2018 - Data Protection and Privacy Policy, Retention Schedule.
  • Charities Act 2011 (as amended) - Charity onboarding, Trust and Verification, Third-Party and Ecosystem Governance.
  • Bribery Act 2010 - Code of Conduct, Vendor Management.

4. Singapore and wider APAC

  • Singapore Personal Data Protection Act (PDPA) - Data Protection and Privacy Policy, Incident Response (72-hour breach notification adapted to 3-day PDPC notifiable-breach rule).
  • Australia Privacy Act 1988 (APPs) - Data Protection and Privacy Policy.
  • Japan APPI - Data Protection and Privacy Policy, cross-border transfer safeguards.
  • Wider APAC obligations tracked per country taxonomy and reviewed annually.

5. International Standards Referenced

  • ISO/IEC 27001 - Information Security Policy control set.
  • NIST CSF - Incident Response and Change Management alignment.
  • OECD Guidelines for Multinational Enterprises - Sustainability, DEI, Third-Party governance.
  • KERI and ACDC specifications - Trust and Verification, KERI Operations.

6. Maintenance

This matrix is a signposting document and does not replace legal advice. Policy owners must record mapping evidence and update this matrix when regulations change or a policy is materially amended.

Questions or concerns about this policy? Contact the DPO.

Related policies