Document control
- Document
- BSHQ-LGL-014
- Version
- 1.0
- Status
- Published
- Effective
- 24 July 2026
- Last reviewed
- 24 July 2026
- Owner
- Office of Legal & Governance
- Approval
- Board of Directors
- Jurisdiction
- Republic of India
- Classification
- Public
I
Data Governance Principles
BioStackHQ recognises data as an institutional asset and seeks to manage information responsibly through appropriate governance, controls and accountability.
This Framework applies to information assets created, collected, received, stored, used, shared or disposed of by BioStack HQ and relevant service providers, regardless of format or location.
Implementation is risk-based and may differ according to the sensitivity of the activity, the systems involved, the scale of potential harm and the operational context. Control effectiveness is reviewed periodically and following material change, identified weakness or incident.
Data owners, custodians and users must apply classification, quality, access, retention, disposal and incident-handling requirements appropriate to the asset and its use. Access is limited to a legitimate business need and may be monitored, reviewed, changed or withdrawn where necessary.
II
Data Management
Information assets are managed through structured processes covering collection, storage, access, usage, retention and disposal.
This Framework applies to information assets created, collected, received, stored, used, shared or disposed of by BioStack HQ and relevant service providers, regardless of format or location.
Implementation is risk-based and may differ according to the sensitivity of the activity, the systems involved, the scale of potential harm and the operational context. Control effectiveness is reviewed periodically and following material change, identified weakness or incident.
Data owners, custodians and users must apply classification, quality, access, retention, disposal and incident-handling requirements appropriate to the asset and its use. Access is limited to a legitimate business need and may be monitored, reviewed, changed or withdrawn where necessary.
III
Data Responsibility
Individuals and teams handling institutional information are expected to maintain appropriate standards of accuracy, confidentiality and responsible usage.
This Framework applies to information assets created, collected, received, stored, used, shared or disposed of by BioStack HQ and relevant service providers, regardless of format or location.
Where third parties act for, provide services to or receive protected information from BioStack HQ, the Group may apply proportionate diligence, contractual safeguards, audit rights, approval requirements and remediation measures. Responsibility cannot be avoided by delegating an activity to another person or organisation.
Data owners, custodians and users must apply classification, quality, access, retention, disposal and incident-handling requirements appropriate to the asset and its use. Access is limited to a legitimate business need and may be monitored, reviewed, changed or withdrawn where necessary.