मुख्य सामग्री पर जाएँ
Parousia Group

कानूनी

अनुपालन

Compliance framework

The regimes that bind the group, the obligations they impose, and the function that answers for each of them.

कानूनी समीक्षा मेंयह दस्तावेज़ लिखा जा चुका है और खुले तौर पर प्रकाशित है, किंतु इसे अभी न तो बोर्ड ने अनुमोदित किया है और न समूह के विधिक परामर्शदाता ने। यह अंतिम नहीं है।
प्रामाणिक भाषाएँयह दस्तावेज़ अंग्रेज़ी और फ़्रेंच में प्रामाणिक है। यहाँ इसे अंग्रेज़ी में दिखाया जा रहा है, क्योंकि इस भाषा में अभी इसका कोई समीक्षित संस्करण मौजूद नहीं है — विधिक प्रभाव रखने वाले पाठ का मशीनी अनुवाद इस सूचना से भी बुरा होता।

Scope and application

This framework binds Parousia Group, the regional companies it holds — Parousia West Africa, Parousia East Africa, Parousia Europe, Parousia America and Parousia Middle East — and Echad Technologies, the group’s technical arm in Singapore. It applies to every person who acts for the group: directors, officers, employees, temporary staff, and anyone engaged to act on the group’s behalf. Each regional company applies it in its own jurisdiction and remains subject to the obligations that its own law imposes on it.

It covers the six solutions the group operates — NetVox Intelligence, Global Technology Africa, Afrika Plaza, PAGEXPRESS, PAGPay and INTIC — and every market in which they are offered. Where local law is stricter than this framework, local law applies. Where this framework is stricter than local law, this framework applies: being lawful in one country is not a defence in the others where the group is present.

Three activities carry most of the group’s regulatory exposure: telecommunications infrastructure and connectivity, which are licensed and which bring export control into play; payments, which bring financial supervision, anti-money-laundering duties and operational resilience rules into play; and the hosting of data for public institutions, which brings data protection and network security law into play. The sections below follow that exposure.

This framework is read together with the code of conduct and with the policies listed on the group’s governance page: the anti-bribery policy, the data protection policy, the information security policy, the supplier code of conduct and the reporting and whistleblowing procedure. Where one of those documents deals with a subject in detail, it governs the detail and this framework states the obligation and the function that answers for it.

Compliance governance

Compliance is a board matter. This framework is submitted to the board of directors for approval, and it is accounted for before the board’s standing committees: the ethics and compliance committee for this framework, the code of conduct, the anti-bribery controls and the reporting channel; the risk and security committee for operational, cyber and infrastructure risk across the group and the regional companies; the audit committee for financial reporting, internal control and the relationship with the external auditors. The Group Secretariat convenes those committees, records their proceedings and carries their conclusions to the board.

The Compliance Department owns this framework. It maintains it, screens counterparties, records the decisions taken under it, keeps the registers it requires, and answers requests from regulators, clients and auditors. It reports to the ethics and compliance committee, and it reaches that committee directly, without passing through the line of management on which it may have to report.

The code of conduct is the first-level instrument of this framework. It binds every person who acts for the group, states the standards of conduct required of them, and applies to conduct towards clients, public authorities, competitors, suppliers and colleagues. The Compliance Department owns the code, submits each amendment of it to the ethics and compliance committee, and answers questions on its application. Where the code and a local rule of an employer entity differ, the stricter of the two applies.

A conflict of interest is declared as soon as it arises, and before the decision it could affect is taken. It is declared to the Compliance Department, which enters it in the register of declared interests; the person concerned takes no part in the decision, and the approval of that decision is given by a person other than the one who declared the interest. An outside directorship or employment, an interest held in a client, a supplier or a competitor, a personal relationship with a counterparty’s decision-maker, and the recruitment or engagement of a relative are declared on the same terms. Gifts and hospitality are governed by the anti-bribery policy.

Control over this framework is exercised at three levels. Group Operations and the business lines apply it in the course of their work and answer for the operations they run. The Compliance Department, the Legal Department, Group Security and the Data Protection Office monitor its application within their respective subjects and may require an operation to be suspended. Internal Audit tests the design and the operation of those controls independently of the functions that run them, has access to the premises, systems, records and staff it needs for that purpose, and reports its findings to the audit committee. Each finding is answered with a remediation plan bearing a named owner and a date, and the closing of that plan is verified by Internal Audit.

A decision that would breach this framework is escalated before it is taken, and is not taken at a lower level and reported afterwards. An instruction to disregard this framework is not a valid instruction. No person is penalised for refusing such an instruction, for asking for it in writing, or for referring it upward.

The Finance Department keeps the books and records of each group entity so that every transaction is recorded accurately and in reasonable detail, and no fund, asset or account is held outside them. Tax returns are filed and tax is paid in each jurisdiction where the group is established and where it carries on business, under the law of that jurisdiction; transactions between group entities are priced on arm’s length terms and documented, in accordance with the OECD Transfer Pricing Guidelines. The group does not enter into an arrangement whose main purpose is to obtain a tax advantage, and no person acting for the group facilitates the evasion of tax by another — conduct for which sections 45 and 46 of the UK Criminal Finances Act 2017 make a body corporate liable.

Correspondence on this frameworkQuestions on this framework and requests for evidence of its application are addressed to the Compliance Department at contact@parousiagroup.com, with COMPLIANCE as the first word of the subject line, or by post to Parousia Group, 157, avenue du Livre, Kinshasa – Gombe, Democratic Republic of the Congo; telephone +243 892 844 000. A report of a suspected breach follows the route set out in the section on reporting a concern.

International sanctions

The group does not do business with a person, entity, vessel or government subject to financial sanctions that bind it, and does not facilitate a transaction for a third party that would breach such a regime. Several regimes apply at once, and for different reasons: the nationality of the company involved, its place of business, the currency the transaction settles in, and the networks and servers the transaction crosses.

Sanctions regimes screened before a counterparty is accepted
ListAuthorityWhy it binds the group
United Nations Consolidated ListUN Security Council, under Chapter VII resolutionsImplemented by every state in which the group operates, including the Democratic Republic of the Congo
EU consolidated list of financial sanctionsCouncil of the European Union, by CFSP decisions and implementing regulationsApplies to dealings with EU persons, to funds within the Union, and to items and technology exported from it
UK consolidated list of financial sanctions targetsHM Treasury, Office of Financial Sanctions Implementation, under the Sanctions and Anti-Money Laundering Act 2018Parousia Europe is established in the United Kingdom, and UK sanctions bind UK companies and UK persons worldwide
US Specially Designated Nationals list and sectoral sanctions listsUS Department of the Treasury, Office of Foreign Assets Control (31 CFR Chapter V)Parousia America is a US person, and US measures also reach transactions settled in US dollars and US-origin technology

Counterparties — clients, suppliers, agents, distributors, and the persons who ultimately own them — are screened by the Compliance Department against these lists before the relationship starts, and again when a list changes in a way that could affect them. A possible match suspends the relationship until it is resolved. A confirmed match is reported by the Compliance Department, with the Legal Department, to the competent authority where the law requires it, and any funds or economic resources concerned are dealt with as that law directs.

Where a transaction requires a licence, an authorisation or a derogation from a competent authority, it is not carried out before that licence, authorisation or derogation is held; the application is made by the Legal Department with the Compliance Department. The group does not restructure a transaction, a route or a payment chain so that a sanctions regime ceases to apply to it. A request to do so is itself a fact to be reported under this framework.

Export control and dual-use items

A telecommunications operator exports controlled technology whether or not it describes itself as an exporter. Network equipment, cryptographic software, monitoring and network-management tools, functions capable of interception, and the technical documentation and source code that go with them, appear on dual-use control lists. The regime therefore bears directly on the group’s principal activity.

Regulation (EU) 2021/821 sets the Union’s dual-use regime. Its Annex I lists the controlled items, Category 5 covering telecommunications and information security; the regulation brought cyber-surveillance items expressly into scope and obliges an exporter who is aware that an item may be intended for use in connection with internal repression or serious violations of human rights or international humanitarian law to act on that awareness. Where an item, its software or its technology leaves the Union, the licence position is established before the transfer, not after it.

Two further regimes reach the group. The US Export Administration Regulations (15 CFR Parts 730–774) apply to US-origin items and to foreign items with US content wherever they are located, and to re-exports. The UK regime, under the Export Control Act 2002 and the Export Control Order 2008, applies to transfers from the United Kingdom and to UK persons. All three implement the control lists agreed in the Wassenaar Arrangement, which is why the descriptions of the items largely coincide while the licences do not.

Releasing controlled technology to a national of a third country is a transfer, even where nothing crosses a border. Granting access to a repository, a design document or a test environment that holds controlled technology is therefore treated as an export decision, taken before the access is granted. The Compliance Department establishes the classification of an item, of its software and of its technology and holds the record of that classification; Group Security applies the resulting access restrictions in the systems; and no controlled technology is released before the classification and the licence position are established.

What the group does not supplyThe group does not supply mass-surveillance, bulk traffic-analysis or population-monitoring capability. Lawful interception assistance is provided only where it is required by the law of the country concerned, on an individualised and judicially or independently supervised basis, and within the terms of the operating licence. Where a licence would be required for a transfer, the absence of that licence ends the matter; where a licence could be obtained but the intended use is the surveillance of a population, the group declines the business. The Legal Department records each request for lawful interception assistance and the ground on which it was answered.

Money laundering, terrorist financing and knowing the counterparty

The group operates a payment solution, PAGPay, and a logistics solution, PAGEXPRESS. Both move value, and both are used by counterparties the group does not choose one by one. Controls against money laundering and terrorist financing therefore apply across the group, and not only to the payment business. The Compliance Department owns those controls, and where the applicable law requires an entity to designate an officer responsible for them, the designation is made and notified to the competent authority.

Directive (EU) 2015/849, as amended by Directive (EU) 2018/843, is the reference framework in the European Union; it is replaced for the most part by Regulation (EU) 2024/1624 and Directive (EU) 2024/1640 as from 10 July 2027, with an Anti-Money Laundering Authority established by Regulation (EU) 2024/1620. In the Democratic Republic of the Congo, Loi n° 22/068 of 27 December 2022 governs money laundering, terrorist financing and proliferation financing, and replaced Loi n° 04/016 of 19 July 2004; the financial intelligence unit is CENAREF. Those texts implement the FATF Recommendations, which state the standard applied across the group.

Where a payment or money transmission service requires an authorisation or a licence, the service is not offered in that market until the authorisation is held. The group does not operate under another party’s licence without a written arrangement that names it and that the regulator concerned would recognise.

Due diligence carried out before a counterparty is accepted, and when it is repeated
CounterpartyWhat is verifiedWhen it is repeated
Corporate or institutional clientLegal existence, ownership and beneficial ownership, directors and signatories, sanctions screening, and the source of funds where the relationship or a transaction departs from what the business explainsOn onboarding, on a material change of ownership or control, and on a periodic review whose interval is set by the risk rating
Individual customer of a payment serviceIdentity from a probative document, address, and the additional checks imposed by the licence conditions of that marketOn onboarding, and whenever activity departs from the expected pattern
Supplier and subcontractorLegal existence, beneficial ownership, sanctions screening, and the anti-bribery diligence set out in the anti-bribery policyOn engagement and on renewal or material amendment of the contract
Agent, intermediary, distributor or resellerEverything required of a supplier, plus the written business rationale for the appointment and the basis on which remuneration is calculatedOn appointment, and annually for as long as the appointment lasts
Politically exposed person, their family and close associatesEnhanced due diligence including source of wealth, and approval at a level above the person who owns the relationshipThroughout the relationship, and for as long after the person leaves office as the risk requires
Any counterparty connected with a jurisdiction the FATF identifies as high-risk or under increased monitoringEnhanced due diligence, closer transaction monitoring, and any counter-measure the applicable law imposesContinuously, and on each change to the FATF public statements

A relationship is not entered into, and is brought to an end, where the due diligence set out above cannot be completed. Transactions are monitored against the profile established at onboarding, and a departure from that profile is examined before the transaction is executed where the law or the licence conditions so require.

The Compliance Department reports suspicious activity to the financial intelligence unit competent for the entity concerned, within the time the applicable law sets, and keeps the record of the report. Where that law forbids telling the customer that a report has been made, the customer is not told, and nothing in this framework overrides that prohibition. Records of due diligence and of transactions are kept for the period the applicable law prescribes and are produced to a competent authority on request.

Competition

The group competes on what it builds and on what it charges for it. It does not agree with a competitor on prices, on the division of markets, territories or customers, or on who will win a tender; it does not exchange current or forward-looking commercially sensitive information with a competitor, including within a trade association, a consortium or a standards body; and where it holds a strong position in a market, it does not use that position to shut a rival out.

Which law applies follows where the conduct has effect, not where the meeting was held: Articles 101 and 102 of the Treaty on the Functioning of the European Union, Chapters I and II of the UK Competition Act 1998, sections 1 and 2 of the Sherman Act (15 U.S.C. §§ 1–2), Loi organique n° 18/020 of 9 July 2018 in the Democratic Republic of the Congo, the Competition Act 2010 in Kenya, the Federal Competition and Consumer Protection Act 2018 in Nigeria, and the COMESA Competition Regulations in the common market. A concentration that requires clearance is not completed before the clearances are held.

Two situations recur in this industry and are treated as high risk. The first is the consortium bid, where the group and a competitor bid together and necessarily see each other’s cost base: what may be exchanged is settled in writing by the Legal Department before the first meeting, and the Compliance Department records that decision. The second is access to infrastructure the group operates, where refusing access, delaying it, or pricing it so that a downstream competitor cannot survive can itself be an abuse: the terms of access are settled in advance and applied consistently between the group’s own business lines and third parties.

Where a competition authority opens an investigation or carries out an inspection, the Legal Department is informed at once and conducts the relationship with the authority. No document is destroyed, altered or removed, no answer is given outside the presence of the Legal Department where the authority allows it to attend, and staff cooperate within the terms of the authority’s warrant or decision.

Data protection

How the group collects, uses, shares and retains personal data — the categories of recipient, the retention periods, and the rights of a data subject and how to exercise them — is set out in the group’s privacy policy. The Data Protection Office receives and handles requests relating to personal data, keeps the record of processing activities required by Article 30 of Regulation (EU) 2016/679, and approves a new processing operation before it begins. This section states the obligations that bear on this framework and the functions that answer for them.

The applicable texts include Regulation (EU) 2016/679 in the European Union and, in the United Kingdom, the UK GDPR with the Data Protection Act 2018; in the Democratic Republic of the Congo, Ordonnance-loi n° 23/010 of 13 March 2023 bearing the Code du numérique, whose Book III, Title III governs personal data; the Data Protection Act 2019 in Kenya and the Nigeria Data Protection Act 2023; and the African Union Convention on Cyber Security and Personal Data Protection, in force since 8 June 2023.

Data is hosted in the jurisdiction whose law governs it, and where the client is a public institution, that institution holds the encryption keys. This is a compliance control: it determines which authority may compel disclosure, and it limits what the group is in a position to produce when it is compelled.

A transfer of personal data out of a jurisdiction that restricts it rests on a legal basis named in the contract — an adequacy decision, the standard contractual clauses adopted by the European Commission, rules approved by a competent authority, or the mechanism the local law provides — and never on the fact that two group companies are related. The Legal Department settles the transfer mechanism and the contractual clauses that carry it; the Data Protection Office holds the list of transfers and of the safeguards applicable to each, and assesses, before a transfer is made, whether the law of the destination country allows those safeguards to be effective. A processor is engaged only under a contract meeting Article 28 of Regulation (EU) 2016/679.

A request from a public authority for access to personal data or to client data is referred to the Legal Department before anything is disclosed. The Legal Department verifies the legal basis of the request, the competence of the authority that makes it and the form it takes, discloses no more than the request requires, and informs the client and the persons concerned where the law does not prohibit it. Where the data is held for a client under an arrangement by which the client holds the encryption keys, the request is directed to that client.

Information security, continuity and the standards the group works to

Security obligations arrive from three directions at once: the client contract, sector regulation, and the law that applies to the product itself. They are not interchangeable, and satisfying one does not answer another. Group Security owns the information security measures of the group and the handling of incidents, and reports on them to the risk and security committee.

Directive (EU) 2022/2555, known as NIS 2, sets risk-management measures and incident reporting for entities in sectors that include electronic communications, cloud computing services, data centres and managed service providers. Where a group company is established in a member state, or offers such services in the Union and is caught by the directive’s jurisdiction rules, the consequences follow: accountability at management level, supply-chain security, an early warning within 24 hours of becoming aware of a significant incident, and a notification within 72 hours.

Regulation (EU) 2022/2554, known as DORA, applies to financial entities in the Union and reaches their ICT third-party service providers through the contractual content required by Article 30 — including audit and access rights, exit strategies, service levels and cooperation on incidents — while a provider designated as critical under Article 31 comes under direct oversight. The group supplies payment and connectivity services to financial institutions, and those contractual requirements are the baseline of such contracts.

Standards the group engineers to, and their certification status
StandardWhat it coversStatus
ISO/IEC 27001Information security management systemApplied in engineering
ISO/IEC 27701Privacy information management, extending 27001Applied in engineering
ISO 22301Business continuity managementApplied in engineering
ISO 9001Quality managementApplied in engineering
PCI DSS v4Payment card data security, for the payment solutionTargeted
SOC 2Service organisation controls reported on by an independent auditorTargeted
WCAG 2.2 level AADigital accessibilityApplied and self-assessed; the accessibility statement gives the method and the known limitations
Certification statusNo certificate has been issued to a group entity under the standards above, and no certification is claimed. Where a certificate is issued, its number, its scope and the issuing body are published on the group’s governance page.

Group Security handles incidents under a single process across the group, with the Data Protection Office where personal data is concerned and with the Legal Department where a notification to an authority or to a client is required. Notification follows the law and the contract: the 72-hour notification of a personal data breach under Article 33 of Regulation (EU) 2016/679, the NIS 2 deadlines above, the terms of the client contract, and the rules of the sector regulator where one applies. Where an incident must be notified, it is notified, and a commercial consideration is not a ground for withholding a notification. The group’s coordinated vulnerability disclosure policy states the terms on which a vulnerability affecting the group’s web estate is received, handled and disclosed.

Continuity of service is a contractual and regulatory obligation as much as an engineering one. Group Security and Group Operations maintain, for the services the group operates, the continuity and recovery arrangements those obligations require: the identification of the critical services and of what they depend on, the recovery objectives agreed in the client contract, backup and restoration procedures, alternative sites and routes, and the crisis organisation that takes over during an interruption. Those arrangements are exercised, and each exercise and each incident is followed by a review of them. Where an entity of the group serves a financial entity of the Union, the testing, exit and continuity requirements of Regulation (EU) 2022/2554 apply to the contract, and the client’s right to audit is honoured on the terms that contract sets.

Third parties and subcontractors

Part of what the group delivers is delivered through third parties: carriers, data centres, installers, resellers, payment partners, and the labour those parties subcontract in turn. The obligations stated in this framework extend to them, and the group answers for what is done on its behalf.

Third parties are assessed before engagement, at a depth set by what they will do and where they will do it: sanctions and ownership screening for all of them; anti-bribery diligence where they will face a public body, a customs authority or a regulator on the group’s behalf; a security and data protection assessment where they will hold group or client data; and labour and human rights diligence where they supply site works, security services or logistics. The Procurement Department conducts that assessment with the Compliance Department, and Group Security carries out the security assessment.

Contracts carry the obligations down the chain. The clauses the Legal Department settles and the group does not trade away are: compliance with sanctions and export control; the anti-bribery undertakings and the right to terminate for a breach of them; data protection terms meeting Article 28 of Regulation (EU) 2016/679 where the third party processes personal data on the group’s behalf; security requirements and incident notification with fixed timings; the right to audit or to accept an equivalent independent report; and prior written consent before a subcontractor is appointed.

A third party who does not accept the clauses relating to sanctions, anti-bribery and data protection is not engaged. A third party is re-assessed on renewal of the contract, on a material amendment to it, on a change in its ownership or control, and where an incident or a finding concerning it so requires; where it breaches an obligation the contract carries, the Procurement Department and the Legal Department decide on the measure to be taken, up to termination. The supplier code of conduct states the same obligations in the form a supplier subscribes to, and it is listed with the group’s other policies on the governance page.

Training and attestation

Everyone who acts for the group is trained on this framework on joining and at least once a year afterwards, in a language they work in. Roles with more exposure receive more: procurement, public sector sales and tendering, licensing and regulatory affairs, customs and logistics, payments and customer onboarding, and anyone who instructs or supervises an agent. The Compliance Department sets the content of the training and delivers it with Human Resources, and it repeats it when this framework, the code of conduct or the applicable law changes materially.

Training ends in an attestation: the person confirms that they have read this framework, that they are not aware of a breach they have not reported, and that they have declared any conflict of interest. An attestation that cannot honestly be given is itself a report, and is handled as one.

Attendance and attestations are recorded by the Compliance Department. Where a client, a regulator or an auditor asks for evidence that named personnel have been trained and have attested, the Compliance Department produces the records for those personnel. Internal Audit uses the same records when it tests the operation of the controls in this framework.

Reporting a concern

Anyone — an employee, a supplier, a client, a candidate or a member of the public — may report a suspected breach of this framework. Reports are received by the Legal Department under the group’s reporting and whistleblowing procedure, which sets the route a report takes, the acknowledgement and feedback deadlines, the confidentiality of the reporting person’s identity, and the protection against retaliation. Where a report concerns a member of the Legal Department or a member of a governing body, the file is transferred to the ethics and compliance committee.

Two rules of that procedure govern this framework: a report may be made without passing through line management, and retaliation against a person who reports in good faith is itself a breach of this framework. Directive (EU) 2019/1937 sets the minimum protection in the European Union; the group applies the same protection in every country it operates in, including where local law does not require it. The Legal Department reports on the operation of the channel to the ethics and compliance committee, on the basis of a register kept without identifying data.

Where to writeA report of a suspected breach: contact@parousiagroup.com, with REPORT as the first word of the subject line, for the attention of the Legal Department, or by post to Parousia Group, 157, avenue du Livre, Kinshasa – Gombe, Democratic Republic of the Congo, in a sealed envelope marked CONFIDENTIAL — REPORT. A question on this framework: the same address, with COMPLIANCE as the first word of the subject line, for the attention of the Compliance Department; telephone +243 892 844 000. A report may be made in any of the languages this site is published in.

Consequences of a breach

A breach of this framework is a disciplinary matter, up to and including dismissal, and it is handled the same way at every level of the group. Human Resources conducts the disciplinary procedure, with the Compliance Department, under the law applicable to the employment relationship. For a third party, a breach is a ground for suspension of the relationship and for termination of the contract, decided by the Legal Department with the Procurement Department. Where the conduct is also an offence, the group reports it where the law requires and cooperates with the authority that investigates it.

Two arguments are not a defence: that the breach was profitable for the group, and that it was instructed by a more senior person. A person who declines an instruction that would breach this framework is protected by it; a person who carries such an instruction out is not.

The group can lose a contract, a licence or a whole market for a compliance failure, and an individual can be prosecuted for the same conduct; the two consequences are independent of each other. Where a breach is established, the Compliance Department records it, reports it to the ethics and compliance committee, and reviews the control that failed; Internal Audit verifies that the corrective measure has been carried out.

नियामकीय आधार

  • Regulation (EU) 2021/821 — control of exports of dual-use items
  • US Export Administration Regulations (15 CFR Parts 730–774)
  • UK Export Control Act 2002 and Export Control Order 2008
  • United Nations Security Council Consolidated List
  • EU consolidated list of persons, groups and entities subject to financial sanctions
  • UK Sanctions and Anti-Money Laundering Act 2018 (HM Treasury consolidated list)
  • US sanctions administered by OFAC (31 CFR Chapter V)
  • Directive (EU) 2015/849 as amended by Directive (EU) 2018/843
  • Regulation (EU) 2024/1624, Directive (EU) 2024/1640 and Regulation (EU) 2024/1620
  • FATF Recommendations (2012, as updated)
  • Loi n° 22/068 du 27 décembre 2022 (DRC) — anti-money laundering, counter-terrorist financing and counter-proliferation financing
  • Articles 101 and 102 of the Treaty on the Functioning of the European Union
  • UK Competition Act 1998, Chapters I and II
  • Sherman Antitrust Act (15 U.S.C. §§ 1–2)
  • Loi organique n° 18/020 du 9 juillet 2018 (DRC) — price freedom and competition
  • COMESA Competition Regulations
  • UK Criminal Finances Act 2017, sections 45 and 46
  • OECD Transfer Pricing Guidelines for Multinational Enterprises and Tax Administrations
  • Regulation (EU) 2016/679 (GDPR) and UK GDPR with the Data Protection Act 2018
  • Ordonnance-loi n° 23/010 du 13 mars 2023 (DRC) — Code du numérique, Book III, Title III
  • African Union Convention on Cyber Security and Personal Data Protection (Malabo, 2014)
  • Directive (EU) 2022/2555 (NIS 2)
  • Regulation (EU) 2022/2554 (DORA)
  • Loi n° 20/017 du 25 novembre 2020 (DRC) — telecommunications and ICT
  • Directive (EU) 2019/1937 — protection of persons who report breaches of Union law

सभी कानूनी दस्तावेज़

समूह से संपर्क करें contact@parousiagroup.com