Compliance, calibrated to the stricter regime.
Othello operates two data-protection regimes in parallel — EU GDPR for European-facing work and Thai PDPA as the home regime — running a single handling discipline calibrated to whichever standard is stricter for the engagement. Confidentiality runs from first email under the firm’s standing NDA, the bench is named on every engagement record (no undisclosed freelancer marketplaces), and the audit-trail discipline traces to the firm’s 2020 founding on US Government bilingual contracts under Federal Acquisition Regulation contractor-verification. Sector-specific compliance — capital markets, healthcare, legal privilege, government — layers on top. One engagement letter · one NDA · one audit-trail retained Bangkok-side.
- Data · EUGDPR · SCCs + DPA + TIA
- Data · ThaiPDPA · Sec 40 processor
- ConfidentialityNDA · from first email
- BenchNamed · no marketplaces
- Audit-trailFAR-grade · since 2020
- SectorSEC · HIPAA · Privilege
- StorageBangkok-side · retained
Three pillars. One operating discipline.
Compliance at Othello sits on three pillars — data protection, confidentiality, and audit-trail. Each pillar has a documented operating standard the firm runs the same way for every engagement, and each is independently verifiable. The certifications page documents what Othello holds; this page documents how Othello operates.
Two regimes. Stricter wins.
Othello operates under EU GDPR and Thai PDPA in parallel — modernised SCCs (Decision 2021/914) into an Article 28 Data Processing Agreement, Transfer Impact Assessment on file, 72-hour breach notification, in-house processing without consumer LLM endpoints. Thailand holds no EU adequacy decision — the lawful transfer mechanism is documented, not assumed.
NDA from first email.
The standing NDA runs from the first email, before scoping, before any document is shared. The bench is named on every engagement record — no undisclosed freelancer marketplaces, no anonymous sub-contractors. Confidentiality propagates across the chain via back-to-back NDAs; legal privilege preserved in litigation matters.
FAR-grade. Since 2020.
The audit-trail discipline traces to the firm’s 2020 founding on US Government bilingual contracts — US CDC, US State Dept, UN Women, UK PACT — under Federal Acquisition Regulation contractor verification. Every engagement leaves a documented trail: scoping note, signed NDA, named bench, terminology decisions, revision cycles, editor sign-off, delivery acknowledgment.
★ OPERATIONAL, NOT ASPIRATIONAL · Each pillar is operated the same way on every engagement — not adjusted upward for high-stakes clients and downward for small ones. The discipline is set at the floor; the floor is the engagement standard for everyone. Independently verifiable on request, under mutual NDA. See all 20 credentials.
EU GDPR and Thai PDPA. Run in parallel. Stricter wins per engagement.
A Thai firm with European-facing work cannot pick one regime and ignore the other. Othello calibrates each engagement to whichever standard is stricter for that client and that data. Both detail pages on the credentials hub document the substantive posture; this section explains how the two regimes operate in parallel inside one handling discipline.
Six instruments that document the lawful mechanism — not the assumed posture.
Thailand holds no EU adequacy decision; EU→Thailand data transfers therefore cannot rely on adequacy. The six instruments below are how Othello documents the lawful basis for processing across the two regimes. None of them is asserted — each is an executed document on file. See /certifications/gdpr/ and /certifications/pdpa/ for the substantive detail.
★ CALIBRATION RULE · Where GDPR and PDPA disagree, Othello applies the stricter standard for that engagement — not the easier one. Example: PDPA’s 72-hour breach notification window aligns with GDPR; PDPA criminal liability for unauthorised disclosure can exceed GDPR remedies; the supplementary measures under a TIA can require encryption at rest that neither regime mandates by itself. The floor is the operating standard.
The NDA runs before scoping. Privilege preserved end to end.
Confidentiality is not a contract clause added at procurement — it is the standing posture from first email, before a quote is issued, before a document is shared, before the bench is named. Legal privilege is preserved across litigation matters; the named bench replaces undisclosed freelancer marketplaces.
Six confidentiality instruments standard across every engagement.
The instruments below are the operating defaults, not negotiated upgrades. A client engaging Othello for a single certified translation gets the same NDA discipline as a SET-listed corporate engaging us for an annual report. The floor is the standard; the standard does not lower.
★ VERIFICATION · The NDA, the named bench, the retention policy, and the destruction certificate are all available under mutual NDA at procurement stage. Email [email protected] for the confidentiality pack.
Every engagement leaves a trail. Six stages, each with a documented gate.
Othello was founded in 2020 on US Government bilingual contracts — US CDC, US State Department, UN Women, UK PACT — under Federal Acquisition Regulation contractor-verification discipline. The audit-trail standard set against those contracts in 2020 is the operating standard for every engagement today — SET-listed annual report, immigration filing, or sustainability disclosure.
Six stages, six gates. No stage advances unsigned.
An engagement progresses through the six stages below; each stage has an explicit gate, and the gate-passage is recorded in the engagement file. The trail survives the engagement — retrieved on subpoena, on procurement-audit, on PDPA / GDPR data-subject request, on FOIA-equivalent inquiry. See Our Process for the underlying bench workflow.
★ WHY FAR-GRADE · Federal Acquisition Regulation contractor-verification is the most demanding procurement discipline a translation firm can be set against — it was Othello’s founding standard, not a later upgrade. The discipline travels: a SET-listed corporate engaging Othello for an annual report gets the same audit-trail rigour a federal contracting officer demanded in 2020. The standard does not lower for non-government clients.
Four sectors with sector-specific compliance overlays on top of the three pillars.
Capital markets, healthcare, legal, and government each layer a sector-specific compliance regime on top of GDPR / PDPA / FAR-grade. Othello operates the sector overlay where the engagement touches it — documented at scoping, not improvised at delivery.
Capital Markets · SEC Thailand & SET
For SET-listed corporates, SEC Thailand 56-1 One Report and listing rules govern disclosure timing, material-event language, and bilingual lockstep. Insider-information handling: documents marked confidential at scoping, access logged, retention per matter. From 2026, IFRS S2 climate disclosure becomes mandatory.
Healthcare · HIPAA & Thai MoPH
US-bound healthcare documents — clinical records, IRB protocols, FDA submissions, US-bound consent forms — layer HIPAA Privacy & Security Rules on top of PDPA/GDPR. Thai MoPH and PDPA Special-Category provisions apply to local healthcare data. Pseudonymisation and minimum-necessary principles documented.
Legal · Privilege & Court Rules
Attorney-client privilege and work-product doctrine preserved through the workflow — segregated access, matter-specific retention, no co-mingling with adverse-party files. For US courts, Federal Rule of Evidence 604 governs interpreter qualification; for Thai courts, the Office of the Judiciary interpreter framework applies. Privilege is process discipline, not luck.
Government · FAR & UN Procurement
The founding sector. Federal Acquisition Regulation contractor-verification for US Government bilingual contracts; UN procurement vendor standards for UN system engagements; FCPA and Thai Anti-Corruption Act for cross-border transactions. Audit-trail standard set against this requirement in 2020 — remains the operating standard for all engagements today.
★ SECTOR DOCUMENTATION · Each sector overlay is documented at scoping — named in the engagement letter, mapped to specific clauses in the underlying regime. If the sector overlay is not in the engagement letter, it is not in the engagement.
Compliance is the floor for every Othello engagement.
The three pillars and four sector overlays are not a separate “compliance product” — they are the operating standard for ESG advisory, technical translation, certified translation, and interpretation. One engagement letter, one NDA, one audit-trail, one credential register.
20 credentials · what we hold
The certifications hub documents the credentials — 5 firm-level (ISO 17100, ATA, ATC, GDPR, PDPA) plus 15 bench practitioner. The credentials are the proof; this compliance page is how the credentials operate in practice.
Open All 20 CredentialsESG Advisory · bench-led
The 2026 flagship practice runs under the same compliance floor — AA1000AS-grade assurance preparation, IFRS S2 disclosure, FTSE Russell readiness. Sector overlay: capital markets · SEC Thailand · SET.
Open ESG AdvisoryOur Process · the workflow itself
The underlying bench workflow — intake, scoping, named-bench assignment, ISO 17100 stage-two editorial, certified delivery, audit-trail consolidation. The six-stage discipline that operationalises the three compliance pillars.
Open Our ProcessProcurement questions answered up front.
Substantive answers to what counsel, in-house procurement, and audit teams routinely ask when reviewing Othello’s compliance posture.
Q.01What’s the difference between Othello’s Compliance and Certifications pages?
Certifications documents what Othello holds; Compliance documents how Othello operates. The certifications page lists 5 firm-level credentials (ISO 17100, ATA, ATC, GDPR, PDPA) and 15 bench practitioner credentials (AA1000AS, ISO 14064, GRI, IFRS S1/S2, FTSE Russell, and more), each verifiable on the issuing body’s registry. This page documents the operating discipline that the credentials underwrite — data protection in two regimes, NDA from first email, FAR-grade audit-trail, and sector-specific overlays. Both pages are independently verifiable under mutual NDA at procurement stage.
Q.02How does Othello calibrate GDPR vs PDPA when both apply?
Othello applies the stricter standard for that engagement — not the easier one. For an EU→Thailand transfer with personal data, that means the modernised SCCs (Decision (EU) 2021/914) plus a Transfer Impact Assessment, plus Article 28 DPA, plus the PDPA Section 40 processor undertaking, plus the supplementary measures the TIA requires (encryption, minimisation, no consumer LLM endpoints). The breach-notification window aligns at 72 hours under both regimes; where the regimes diverge, the stricter applies.
Q.03Why doesn’t Othello use ChatGPT or other AI tools on client data?
Consumer AI endpoints are not compatible with Article 28 GDPR processor undertakings or PDPA Section 40. Their data-handling terms typically permit ingestion of submitted text into provider training and analytics pipelines — which means the firm cannot guarantee the limits Article 28 requires (purpose, retention, no sub-processing without controller consent, deletion at end of contract). Othello uses in-house translation memory, terminology databases, and CAT tools under processor control. This is operating discipline, not anti-AI ideology — the bench evaluates new tooling continuously; only data-handling-compatible tools enter the workflow.
Q.04What is “FAR-grade” and why does Othello cite it?
FAR is the US Federal Acquisition Regulation — the procurement standard US Government contractors are vetted against. Othello was founded in 2020 on US Government bilingual contracts (US CDC, US State Department, UN Women, UK PACT) under that contractor-verification discipline. FAR-grade is the audit-trail and confidentiality standard Othello was set against from day one, and it remains the operating standard today — a Thai SET-listed corporate engaging Othello for an annual report gets the same audit-trail rigour a federal contracting officer demanded in 2020. It is a heritage standard, not a separately-certified credential.
Q.05What does “NDA from first email” actually mean operationally?
It means the firm’s standing mutual NDA covers every inbound enquiry from the first email — before a quote is issued, before scoping, before any document is shared. Clients may execute their own NDA on top, which is then back-to-back to the bench. No document is reviewed under a “we’ll sign later” arrangement. If you send a confidential draft in the first email asking for a quote, it sits inside the standing NDA the moment it lands in the firm’s inbox.
Q.06Does Othello use freelancer marketplaces or anonymous sub-contractors?
No. The bench is named on every engagement record — translator, editor, reviewer identified by name before work begins. Where work involves any external linguist (rare; bench-first), back-to-back NDAs are executed and the chain is logged in the engagement file. No undisclosed marketplace sub-contracting, no anonymous freelancer routing. Counsel can verify each named individual’s NDA, ISO 17100 qualification, and language-pair coverage at procurement stage.
Q.07What is Othello’s data retention policy?
Retention is set per engagement letter against the matter type. Defaults: 7 years for standard translations, 10 years for sworn or ATA-certified work, matter-specific for litigation (often through the appeal window plus margin), as-required for capital-markets disclosure (per SEC Thailand and SET retention rules). Storage is Bangkok-side on processor-controlled infrastructure under PDPA, with the GDPR transfer mechanism on file for EU-origin data. Secure destruction on request and at end of retention; destruction certificate issued.
Q.08How does Othello handle a personal-data breach?
Othello operates a documented incident-response runbook with the 72-hour notification clock built in. On detection: incident logged, scope assessed, controller notified, regulator notification prepared (PDPC for PDPA matters, the relevant DPA for GDPR), affected data subjects identified, mitigation measures documented, post-incident report issued. Article 33 GDPR and PDPA equivalents mandate 72-hour notification to controller and regulator — that window is not negotiable. The runbook is available under NDA at procurement.
Q.09Can procurement audit Othello’s compliance posture before engaging?
Yes, that is what the compliance pack is for. Under mutual NDA at procurement, Othello provides: standing NDA template, sample Article 28 DPA + SCCs, sample TIA, PDPA Section 40 processor undertaking, incident-response runbook, retention & destruction policy, named-bench register with credential cross-reference. Each line on this page is procurement-grade language — nothing is asserted that cannot be confirmed in a vendor-due-diligence file. Email [email protected] for the compliance pack.
Q.10How does compliance fit Othello’s broader engagement framework?
The three pillars (data protection, confidentiality, audit-trail) and the four sector overlays (capital markets, healthcare, legal, government) are the operating floor for every engagement Othello delivers — ESG advisory, technical translation, certified translation, interpretation. Founded 2020 on US Government bilingual contracts under FAR-grade contractor verification, the floor is set higher than most translation firms’ ceilings. A client engaging Othello gets one engagement letter, one NDA, one audit-trail, and twenty credentials standing behind it. Email [email protected] or call +66 02-859-2145.
Compliance, independently auditable.
Two data-protection regimes, NDA from first email, FAR-grade audit-trail, and sector-specific overlays where the engagement touches them. The operating floor for every Othello engagement — documented, executed, retained Bangkok-side. ≤1 BH acknowledgement · compliance pack within 1 BD · NDA from first email.
Unit 12-03, Chartered Square · 152 N Sathon Rd · Si Lom · Bangkok 10500