← Governance framework
Governance
Legal and Regulatory Compliance Matrix
High-level mapping of ImpactMiles policies to applicable Hong Kong laws, key EU, UK and APAC regulations and relevant international standards.
- Version
- v1.0
- Effective
- 2026-07-19
- Last reviewed
- 2026-07-20
- Next review
- 2027-07-19
- Owner
- General Counsel
- Approver
- Board of Directors
Anchored by content hashissued 2026-07-29
Payload hash
441a0169a16b8a2f16541914ff1864fdc98b064788f806c7e8888de3779a459eSHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhEParty that issued this receipt
ImpactMiles handle
audit:governance:441a0169a16b8a2fThis receipt is anchored by content hash. A resolvable credential SAID is not available for this record.
Applies to
- All jurisdictions in which ImpactMiles operates or has users
Jurisdictions
- Hong Kong (PDPO, IRD s.88)
- United Kingdom (UK GDPR, DPA 2018)
- European Union (GDPR)
- Singapore (PDPA)
- Australia (Privacy Act 1988)
- Japan (APPI)
- Wider APAC per country taxonomy
How this is applied in-product
- Policy owners maintain mapping evidence in the Governance CMS
- Legal review of policy amendments for regulatory impact
- External counsel engaged for material regulatory change
1. Hong Kong
- Personal Data (Privacy) Ordinance (Cap. 486) - Data Protection and Privacy Policy, Retention Schedule, DPIA Methodology, Cookies Policy.
- Companies Ordinance (Cap. 622) - Governance Charter, Audit and Reporting.
- Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) - AML/CTF Policy.
- Prevention of Bribery Ordinance (Cap. 201) - Code of Conduct, Vendor Management.
- Inland Revenue Ordinance s.88 - Charity verification within Trust and Verification Policy.
2. European Union
- GDPR - Data Protection and Privacy Policy, Retention Schedule, DPIA, Incident Response, Vendor Management.
- Digital Services Act (DSA) - Fraud, Abuse and Misuse Policy; transparency reporting under Audit, Reporting and Transparency Policy.
- eIDAS - referenced for interoperability of trust services within the Trust and Verification Policy.
3. United Kingdom
- UK GDPR and Data Protection Act 2018 - Data Protection and Privacy Policy, Retention Schedule.
- Charities Act 2011 (as amended) - Charity onboarding, Trust and Verification, Third-Party and Ecosystem Governance.
- Bribery Act 2010 - Code of Conduct, Vendor Management.
4. Singapore and wider APAC
- Singapore Personal Data Protection Act (PDPA) - Data Protection and Privacy Policy, Incident Response (72-hour breach notification adapted to 3-day PDPC notifiable-breach rule).
- Australia Privacy Act 1988 (APPs) - Data Protection and Privacy Policy.
- Japan APPI - Data Protection and Privacy Policy, cross-border transfer safeguards.
- Wider APAC obligations tracked per country taxonomy and reviewed annually.
5. International Standards Referenced
- ISO/IEC 27001 - Information Security Policy control set.
- NIST CSF - Incident Response and Change Management alignment.
- OECD Guidelines for Multinational Enterprises - Sustainability, DEI, Third-Party governance.
- KERI and ACDC specifications - Trust and Verification, KERI Operations.
6. Maintenance
This matrix is a signposting document and does not replace legal advice. Policy owners must record mapping evidence and update this matrix when regulations change or a policy is materially amended.
Questions or concerns about this policy? Contact the DPO.