Skip to main content
BuruOps Statutory Governance & Regulatory Compliance
UK REGULATORY & STATUTORY GOVERNANCE

Compliance, Ethics & Legal Framework

BuruOps Intelligence Lab operates under rigorous United Kingdom statutory frameworks, absolute transparency, and verifiable engineering integrity. As the technical engineering arm of Mtengwa Strategic Advisory, our defensive operations, data governance, and commercial engagements conform to the highest UK standards of institutional accountability.

Browse Compliance Registers Contact Compliance Officer
JURISDICTION
England & Wales
UK Statutory Enactments
DATA PROTECTION
UK GDPR / DPA 2018
PECR Compliant Consent
CORPORATE ETHICS
Bribery Act 2010
Zero-Tolerance Mandate
CYBER FRAMEWORK
ISO 27001 / CE+
Continuous Audit Cycle
DIRECTORY OF POLICIES

Official Statutory Registers

Each policy document constitutes a legally binding commitment to ethical engineering, data confidentiality, workplace welfare, and statutory compliance under UK law.

UK GDPR // DPA 2018 REG-01

Privacy & Data Protection Notice

Full transparency on Data Controller details, legal bases under UK GDPR Article 6, zero third-party profiling, strict retention timelines, and data subject rights (DSAR).

Status: Active View Privacy Notice →
PECR 2003 REG 6 REG-02

Cookie & Technical Storage Policy

Explanations of strictly necessary security tokens (anti-CSRF, rate limiters) vs optional telemetry. Interactive preference controls to customize or revoke consent anytime.

View Cookie Policy →
COMMERCIAL CONTRACT REG-03

Master Terms of Engagement

Commercial framework governing technical audits, Statements of Work (SOW), intellectual property rights, non-destructive warranties, liability caps, and English jurisdiction.

Governing Law: England View Terms →
COMPUTER MISUSE ACT REG-04

Acceptable Use Policy (AUP)

Prohibits unauthorized penetration testing of non-client hosts, automated denial-of-service, API scrapers, credential theft, and reverse engineering of proprietary telemetry.

Strict Enforcement View Acceptable Use →
BRIBERY ACT 2010 REG-05

Anti-Bribery & Corruption Policy

Zero tolerance for commercial bribery, public official inducements, and facilitation payments. Strict gifts and hospitality register, procurement integrity, and severe disciplinary sanctions.

MODERN SLAVERY ACT REG-06

Modern Slavery & Human Trafficking

Compliance statement pursuant to Section 54 of the Modern Slavery Act 2015. Supplier due diligence across cloud platforms, hardware sourcing, fair wages, and ethical recruitment.

Annual Board Review View Slavery Statement →
CRIMINAL FINANCES ACT REG-07

Corporate Anti-Facilitation of Tax Evasion

Measures under Part 3 of the Criminal Finances Act 2017 to prevent the criminal facilitation of tax evasion in the United Kingdom and internationally. Rigorous billing and invoicing controls.

Strict Financial Controls View Tax Evasion Policy →
PIDA 1998 REG-08

Whistleblowing & Protected Disclosures

Protected channels under the Public Interest Disclosure Act 1998 for reporting security concealment, financial irregularities, or unlawful activity with full anti-retaliation immunity.

Protected Safe Harbor View Whistleblowing →
ISO 27001 // CE+ REG-09

Information Security & Cyber Policy

Technical & Organisational Measures (TOMs) under UK GDPR Article 32: TLS 1.3 encryption, AES-256 envelope vaults, Zero-Trust network segmentation, and 72h ICO breach notification SLA.

Zero-Trust Architecture View Security Policy →
HASAWA 1974 REG-10

Health, Safety & Environment (HSE)

Adherence to the Health and Safety at Work etc. Act 1974. Hardware laboratory safety, display screen ergonomics, engineer mental wellbeing, and sustainable low-carbon cloud computing.

Workplace & Ecology View Health & Safety →
ISO 29147 // RFC 9116 REG-11

Vulnerability Disclosure & Safe Harbor

Rules of engagement for defensive researchers, legal Safe Harbor against Computer Misuse Act claims for good-faith disclosures, PGP encryption key, and security.txt standards.

RFC 9116 Compliant View Disclosure Policy →
VERIFICATION MATRIX

UK Statutory Enactments & Compliance Audit Table

STATUTORY ENACTMENT PRIMARY MANDATE BURUOPS STATUS REVIEW FREQUENCY
Data Protection Act 2018 / UK GDPR Data minimization, lawful basis, subject rights, breach notification VERIFIED COMPLIANT Biannual
PECR 2003 (Reg 6) Prior consent for non-essential cookies, no pre-ticked boxes VERIFIED COMPLIANT Continuous
Bribery Act 2010 (Sec 7) Adequate procedures preventing commercial & public official bribery VERIFIED COMPLIANT Annual
Modern Slavery Act 2015 (Sec 54) Supply chain transparency, zero forced labor, fair living wage VERIFIED COMPLIANT Annual Board Sign-off
Criminal Finances Act 2017 (Part 3) Prevention of facilitation of UK and foreign tax evasion VERIFIED COMPLIANT Annual
Computer Misuse Act 1990 Prohibition of unauthorized access; authorized scope boundaries STRICT CONTRACT ENFORCEMENT Per Engagement SOW
Public Interest Disclosure Act 1998 Confidential reporting protection for whistleblowers VERIFIED COMPLIANT Continuous
Health and Safety at Work etc. Act 1974 Duty of care for staff, electrical testing, display screen equipment VERIFIED COMPLIANT Annual Assessment
OFFICIAL CORRESPONDENCE

Compliance Officer & Data Protection

For Data Subject Access Requests (DSAR), legal inquiries, or verification of our regulatory documentation, address correspondence to the compliance office.

Attn: Principal Compliance Officer • Burhani Mtengwa • 61 Bridge Street, Kington, HR5 3DJ, UK
Email: principal@buruops.com • Phone: +44 1483 928037