{"id":38486,"date":"2026-04-05T22:25:51","date_gmt":"2026-04-05T22:25:51","guid":{"rendered":"https:\/\/metachannelcorp.com\/politica-de-seguridad\/"},"modified":"2026-05-27T14:24:51","modified_gmt":"2026-05-27T14:24:51","slug":"security-policy","status":"publish","type":"page","link":"https:\/\/metachannelcorp.com\/en\/security-policy\/","title":{"rendered":"Security Policy"},"content":{"rendered":"<div class=\"meta\">Ref: MCC-PSI-01  \u00b7 Last updated: April 1, 2026<br \/>\nmetachannelcorp.com \u00b7 <a href=\"mailto:privacidad@metachannelcorp.com\">privacidad@metachannelcorp.com<\/a><\/div>\n<p>META Channel Corporation Limited is a Praxis House firm specializing in regulatory, legal, and technological compliance. Our business requires that the information systems supporting our operations and the data of our clients, partners, and affiliated institutions be managed with the utmost rigor. This policy establishes the principles, frameworks, and commitments governing information security at META Channel Corporation Limited.<\/p>\n<p>As an organization that advises on and executes regulatory compliance projects within the European regulatory ecosystem, we apply internally the same standards that we require and provide to our clients. Consistency between what we do for others and what we apply in our own house is not an option: it is the foundation of our credibility.<\/p>\n<h2>1. Regulatory Reference Frameworks<\/h2>\n<p>Information security management at META Channel Corporation Limited aligns with the following regulatory frameworks and international standards:<\/p>\n<table>\n<tbody>\n<tr>\n<td>GDPR (EU) 2016\/679<\/td>\n<td>The fundamental framework for the protection of personal data. It establishes technical and organizational security obligations in accordance with Articles 25 (privacy by design) and 32 (security of processing).<\/td>\n<\/tr>\n<tr>\n<td>NIS2 (EU) 2022\/2555<\/td>\n<td>Directive on cybersecurity in the European Union. META Channel Corporation Limited adopts its risk management principles as an operational reference framework and as a basis for assisting clients in their compliance efforts.<\/td>\n<\/tr>\n<tr>\n<td>DORA (EU) 2022\/2554<\/td>\n<td>Digital Operational Resilience Regulation for the financial sector. Directly applicable to numerous META Channel Corporation Limited clients in the fintech, tokenization, and litigation finance sectors. We adopt its principles as an internal reference and implementation model.<\/td>\n<\/tr>\n<tr>\n<td>ISO\/IEC 27001:2022<\/td>\n<td>International standard for Information Security Management Systems (ISMS). Reference framework for asset identification, risk assessment, implementation of controls, and continuous improvement.<\/td>\n<\/tr>\n<tr>\n<td>AI Act (EU) 2024\/1689<\/td>\n<td>European regulatory framework for artificial intelligence systems. META Channel Corporation Limited manages its AI systems and tools in accordance with the principles of transparency, auditability, and risk minimization, anticipating the requirements applicable to its clients.<\/td>\n<\/tr>\n<tr>\n<td>LOPDGDD (LO 3\/2018)<\/td>\n<td>Spanish supplement to the GDPR. Applicable to data processing carried out from Spanish territory, including META Channel Corporation Limited\u2019s operations in Tenerife and Madrid.<\/td>\n<\/tr>\n<tr>\n<td>Data Protection Act 2018 (IE)<\/td>\n<td>Data protection framework of the Republic of Ireland. Applicable to META Channel Corporation Limited as an entity incorporated in Ireland under the Companies Act 2014.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>2. Fundamental Security Principles<\/h2>\n<table>\n<tbody>\n<tr>\n<td>Confidentiality<\/td>\n<td>Only authorized personnel have access to the data and information of META Channel Corporation Limited, its clients, and partners. Access is managed through role-based controls and the principle of least privilege. All personnel and partners with access to systems are subject to an indefinite duty of confidentiality.<\/td>\n<\/tr>\n<tr>\n<td>Integrity<\/td>\n<td>The data and information managed by META Channel Corporation Limited are kept accurate, complete, and consistent. Controls are in place to detect and correct unauthorized alterations to documents, records, and management systems.<\/td>\n<\/tr>\n<tr>\n<td>Availability<\/td>\n<td>Systems and information critical to the operation of META Channel Corporation Limited are accessible to authorized personnel when needed. Contingency plans and incident recovery procedures are maintained.<\/td>\n<\/tr>\n<tr>\n<td>Privacy by Design and by Default<\/td>\n<td>In accordance with Article 25 of the GDPR, the protection of personal data is integrated into the design of any new process, system, or product. The default settings of all systems ensure the highest level of privacy without requiring action by the data subject.<\/td>\n<\/tr>\n<tr>\n<td>Operational resilience<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<td>META Channel Corporation Limited manages its technology infrastructure with a focus on resilience: identifying critical assets, evaluating technology vendors, and developing continuity and recovery plans in the event of disruptions or cyber incidents.<\/td>\n<tr>\n<td>Proactive Accountability<\/td>\n<td>In accordance with Article 5.2 of the GDPR, META Channel Corporation Limited not only complies with security obligations but can demonstrate such compliance at all times. Documentation, records, and internal procedures serve as evidence of this commitment.<\/td>\n<\/tr>\n<tr>\n<td>Continuous improvement<\/td>\n<td>META Channel Corporation Limited periodically reviews the effectiveness of its controls, updates its procedures in response to regulatory or technological changes, and applies lessons learned from incidents and review exercises.<\/td>\n<\/tr>\n<tr>\n<td>Proportionality<\/td>\n<td>Security controls are implemented in proportion to the actual risk of each processing operation and asset. Neither excessive nor insufficient measures are acceptable: security must be appropriate, effective, and operationally sustainable.<\/td>\n<\/tr>\n<h2>3. Technical and organizational measures applied<\/h2>\n<p>META Channel Corporation Limited applies the following measures in accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of the processing:<\/p>\n<h3>Encryption and secure communications<\/h3>\n<ul>\n<li>Encryption in transit using TLS 1.2\/1.3 in all web communications (HTTPS).<\/li>\n<li>Encryption at rest on storage systems where personal data is processed.<\/li>\n<li>Internal communications via encrypted channels. Prohibition on transmitting sensitive data via unencrypted channels.<\/li>\n<\/ul>\n<h3>Access control and authentication<\/h3>\n<ul>\n<li>Two-factor authentication (2FA) is mandatory for access to systems containing personal data.<\/li>\n<li>Principle of least privilege: each user has access only to the data necessary for their role.<\/li>\n<li>Periodic review of permissions and immediate revocation of access upon change or termination of employment.<\/li>\n<\/ul>\n<h3>Vendor and processor management<\/h3>\n<ul>\n<li>Data processing agreements (Art. 28 GDPR) formalized with all vendors who access personal data.<\/li>\n<li>Prior assessment of technology providers regarding security and regulatory compliance.<\/li>\n<li>International transfers covered by appropriate safeguards in accordance with Chapter V of the GDPR.<\/li>\n<\/ul>\n<h3>Incident and breach management<\/h3>\n<ul>\n<li>Internal security breach response protocol activated within the first 4 hours.<\/li>\n<li>Notification to the DPC (Ireland) and\/or AEPD (Spain) within a maximum of 72 hours when required.<\/li>\n<li>Internal record of all incidents, whether notifiable or not, in accordance with Article 33(5) of the GDPR.<\/li>\n<li>Documented procedure for communicating with affected data subjects when the risk is high.<\/li>\n<\/ul>\n<h3>Continuity and Resilience<\/h3>\n<ul>\n<li>Regular backups of critical systems and data with integrity verification.<\/li>\n<li>Procedures for recovery from technological failures or cyber incidents.<\/li>\n<li>Assessment of critical technological dependencies and contingency plans in the event of supplier unavailability.<\/li>\n<\/ul>\n<h3>Training and Awareness<\/h3>\n<ul>\n<li>All staff and contractors with access to systems receive information regarding their security obligations.<\/li>\n<li>Regular updates on relevant threats and cybersecurity best practices.<\/li>\n<li>A duty of confidentiality of indefinite duration formalized in a contract.<\/li>\n<\/ul>\n<h2>4. Impact assessments and risk analysis<\/h2>\n<p>META Channel Corporation Limited conducts Data Protection Impact Assessments (DPIAs) in accordance with Article 35 of the GDPR for processing operations that may pose a high risk to the rights and freedoms of data subjects. The risk analysis is conducted prior to the commencement of any new processing operation or any substantial modification to an existing one.<\/p>\n<p>The risk analysis methodology applied is based on the criteria of the European Data Protection Board (EDPB) and the principles of the ISO\/IEC 27005 standard for information security risk management. The results of each assessment are documented and retained as part of META Channel Corporation Limited\u2019s proactive accountability system.<\/p>\n<h2>5. Regulatory Consistency: What We Apply Is What We Implement<\/h2>\n<p>META Channel Corporation Limited advises on and executes compliance projects under the most demanding European regulatory frameworks: GDPR, NIS2, DORA, AI Act, MiCA, and the ENS cybersecurity frameworks. Our credibility as a regulatory implementation firm is grounded in a non-negotiable principle: we rigorously apply the same standards internally that we provide to our clients.<\/p>\n<p>This means that when a client entrusts us with a NIS2 compliance project or the implementation of a DORA framework, they do so knowing that the team executing it already operates under those principles. We do not sell compliance that we do not practice. This consistency is, in itself, a guarantee for our clients and institutional partners.<\/p>\n<h2>6. Review, Update, and Contact<\/h2>\n<p>This policy is reviewed at least annually and in the event of any relevant regulatory change, significant incident, or substantial modification to the systems or processing operations of META Channel Corporation Limited. The current version is always the one published at <a href=\"https:\/\/metachannelcorp.com\/en\/security-policy\/\">metachannelcorp.com\/security-policy\/<\/a>.<\/p>\n<p>For any inquiries regarding this policy or to report a security vulnerability or incident: <a href=\"mailto:privacidad@metachannelcorp.com\">privacidad@metachannelcorp.com<\/a><\/p>\n<p>Competent supervisory authorities: <a href=\"https:\/\/www.dataprotection.ie\/\" target=\"_blank\" rel=\"noopener\">Data Protection Commission (DPC) \u2014 Ireland<\/a> \u00b7 <a href=\"https:\/\/www.aepd.es\/\" target=\"_blank\" rel=\"noopener\">Spanish Data Protection Agency (AEPD)<\/a> \u00b7 <a href=\"https:\/\/www.enisa.europa.eu\/\" target=\"_blank\" rel=\"noopener\">European Union Agency for Cybersecurity (ENISA)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ref: MCC-PSI-01 \u00b7 Last updated: April 1, 2026 metachannelcorp.com \u00b7 privacidad@metachannelcorp.com META Channel Corporation Limited is a Praxis House firm&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-38486","page","type-page","status-publish"],"_links":{"self":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/pages\/38486","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/comments?post=38486"}],"version-history":[{"count":0,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/pages\/38486\/revisions"}],"wp:attachment":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/media?parent=38486"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}