Information security posture varies by entity type and jurisdiction.
Singapore: statutory boards and GLCs follow IM8 (the Instruction Manual for ICT and SS Management), issued by GovTech. IM8 governs how data collected through digital campaigns is classified, stored, and processed.
Australia: entities under the Australian Government Information Security Manual (ISM), published by the Australian Cyber Security Centre (ACSC). We document every third-party platform (Google, Meta, programmatic demand-side platforms) against the ISM guidelines before engagement.
United States: federal contractors working with GSA Schedule 541 must maintain SOC 2 Type II documentation for any system that processes federal data. FedRAMP authorisation required for cloud-based marketing technology used by federal agencies.
Canada: Treasury Board of Canada Secretariat Directive on Security Management applies to all federal contractors.
Our standard position: all campaign data is processed in-region where technically possible, all consent signals are captured per the applicable privacy law, and all third-party platform data processing agreements are reviewed before launch.