Bench active · EN ↔ TH · TEL +66 02-859-2145 · NDA from first email · 1-hour quote SLA
EN TH
Request a Proposal
COMPLIANCE · TWO-REGIME DATA PROTECTION · NDA FROM FIRST EMAIL · FAR-GRADE AUDIT-TRAIL
GDPR · PDPA · ISO 17100 · FAR-grade founding
Othello / Compliance
★ COMPLIANCE PRACTICE · GDPR + PDPA · NDA-FIRST · FAR-GRADE · NO OUTSOURCING · BANGKOK-MANAGED

Compliance, calibrated to the stricter regime.

Othello operates two data-protection regimes in parallelEU GDPR for European-facing work and Thai PDPA as the home regime — running a single handling discipline calibrated to whichever standard is stricter for the engagement. Confidentiality runs from first email under the firm’s standing NDA, the bench is named on every engagement record (no undisclosed freelancer marketplaces), and the audit-trail discipline traces to the firm’s 2020 founding on US Government bilingual contracts under Federal Acquisition Regulation contractor-verification. Sector-specific compliance — capital markets, healthcare, legal privilege, government — layers on top. One engagement letter · one NDA · one audit-trail retained Bangkok-side.

Data-Protection Regimes
2
GDPR + PDPA · stricter wins
Outsourcing
0
No freelancer marketplaces
NDA Window
1st
From first email · standing
Audit-Trail Standard
2020
FAR-grade · US Gov founding
★ OPERATING POSTURE · TRANSPARENT
One handling discipline. Stricter of two regimes. Audit-trail Bangkok-side.
  • Data · EUGDPR · SCCs + DPA + TIA
  • Data · ThaiPDPA · Sec 40 processor
  • ConfidentialityNDA · from first email
  • BenchNamed · no marketplaces
  • Audit-trailFAR-grade · since 2020
  • SectorSEC · HIPAA · Privilege
  • StorageBangkok-side · retained
★ §01 · Three Pillars Of Operating Compliance

Three pillars. One operating discipline.

Compliance at Othello sits on three pillars — data protection, confidentiality, and audit-trail. Each pillar has a documented operating standard the firm runs the same way for every engagement, and each is independently verifiable. The certifications page documents what Othello holds; this page documents how Othello operates.

OPERATIONAL, NOT ASPIRATIONAL · Each pillar is operated the same way on every engagement — not adjusted upward for high-stakes clients and downward for small ones. The discipline is set at the floor; the floor is the engagement standard for everyone. Independently verifiable on request, under mutual NDA. See all 20 credentials.

★ §02 · Data Protection · The Two-Regime Discipline

EU GDPR and Thai PDPA. Run in parallel. Stricter wins per engagement.

A Thai firm with European-facing work cannot pick one regime and ignore the other. Othello calibrates each engagement to whichever standard is stricter for that client and that data. Both detail pages on the credentials hub document the substantive posture; this section explains how the two regimes operate in parallel inside one handling discipline.

★ TWO-REGIME OPERATING POSTURE · STRICTER-WINS CALIBRATION

Six instruments that document the lawful mechanism — not the assumed posture.

Thailand holds no EU adequacy decision; EU→Thailand data transfers therefore cannot rely on adequacy. The six instruments below are how Othello documents the lawful basis for processing across the two regimes. None of them is asserted — each is an executed document on file. See /certifications/gdpr/ and /certifications/pdpa/ for the substantive detail.

INSTR 01
Article 28 Data Processing Agreement.Every EU-facing engagement is governed by a written DPA per Article 28 GDPR — specifying subject-matter, duration, nature and purpose of processing, categories of data subjects, and the controller-processor split. Executed before any personal data is shared.
INSTR 02
Standard Contractual Clauses (2021/914).The modernised SCCs from European Commission Decision (EU) 2021/914 are incorporated into the DPA — Module 2 (controller-to-processor) typical, Module 3 (processor-to-processor) where the engagement involves Othello’s own sub-processors. The post-Schrems II instrument.
INSTR 03
Transfer Impact Assessment.A TIA documents Thai surveillance law, data-access rights, and supplementary measures. Where required, encryption, pseudonymisation, contractual access controls, and rapid-notification commitments are documented as the supplementary measures. SCCs without a TIA fail Schrems II.
INSTR 04
PDPA Section 40 processor undertaking.The Thai PDPA B.E. 2562 fines processors as well as controllers (max ฿5M per violation + criminal + civil). Othello carries its Section 40 duties as a processor under written undertaking. Modelled on GDPR; calibrated to whichever is stricter for the engagement.
INSTR 05
72-hour breach notification.Article 33 GDPR + PDPA equivalents mandate breach notification to the controller and to the regulator within 72 hours. Othello operates a documented incident-response runbook with the 72-hour clock built in — including the post-incident report. Notification windows are not negotiable.
INSTR 06
In-house processing · no consumer LLM endpoints.Translation memory, terminology databases, and CAT tools run on in-house infrastructure under processor control. Consumer LLM endpoints (ChatGPT, public Claude, Gemini) are not used on client data — their data-handling terms are not compatible with Article 28 or PDPA Section 40 processor undertakings.

CALIBRATION RULE · Where GDPR and PDPA disagree, Othello applies the stricter standard for that engagement — not the easier one. Example: PDPA’s 72-hour breach notification window aligns with GDPR; PDPA criminal liability for unauthorised disclosure can exceed GDPR remedies; the supplementary measures under a TIA can require encryption at rest that neither regime mandates by itself. The floor is the operating standard.

★ §03 · Confidentiality · NDA From First Email

The NDA runs before scoping. Privilege preserved end to end.

Confidentiality is not a contract clause added at procurement — it is the standing posture from first email, before a quote is issued, before a document is shared, before the bench is named. Legal privilege is preserved across litigation matters; the named bench replaces undisclosed freelancer marketplaces.

★ CONFIDENTIALITY DISCIPLINE · STANDING NDA · NAMED BENCH

Six confidentiality instruments standard across every engagement.

The instruments below are the operating defaults, not negotiated upgrades. A client engaging Othello for a single certified translation gets the same NDA discipline as a SET-listed corporate engaging us for an annual report. The floor is the standard; the standard does not lower.

INSTR 01
Standing NDA from first email.The firm’s standing mutual NDA covers every inbound enquiry from the first email — before scoping. Clients may execute their own NDA on top, which is then back-to-back to the bench. No document is reviewed under a “we’ll sign later” arrangement.
INSTR 02
Named bench on the engagement record.The translator, editor, and reviewer are identified by name on the engagement record before work begins — no undisclosed freelancer marketplaces, no anonymous sub-contractors. Counsel can verify each individual’s NDA, ISO 17100 qualification, and language-pair coverage at procurement.
INSTR 03
Back-to-back NDAs across the chain.Where work involves any external linguist (rare; bench-first), NDAs are executed back-to-back so the client’s confidentiality protection follows the document end to end. The chain is logged in the engagement file; no gaps.
INSTR 04
Legal privilege preservation.For litigation, arbitration, and regulatory matters, attorney work-product and attorney-client privilege are preserved through the workflow — documents segregated, access logged, retention period set per matter. Othello does not break privilege through process inattention.
INSTR 05
No consumer LLM endpoints on client data.Translation memory and terminology work on in-house, processor-controlled infrastructure. Consumer AI endpoints (ChatGPT, public Claude, Gemini) ingest client text into provider training and analytics pipelines incompatible with Article 28 and PDPA Section 40. They are not used.
INSTR 06
Defined retention & secure destruction.Source documents and deliverables are retained Bangkok-side per the engagement letter — default 7 years for translations, 10 years for sworn / ATA-certified work, matter-specific for litigation. Secure destruction on request and at end of retention; destruction certificate issued.

VERIFICATION · The NDA, the named bench, the retention policy, and the destruction certificate are all available under mutual NDA at procurement stage. Email [email protected] for the confidentiality pack.

★ §04 · Audit-Trail · FAR-Grade Founding Standard

Every engagement leaves a trail. Six stages, each with a documented gate.

Othello was founded in 2020 on US Government bilingual contracts — US CDC, US State Department, UN Women, UK PACT — under Federal Acquisition Regulation contractor-verification discipline. The audit-trail standard set against those contracts in 2020 is the operating standard for every engagement today — SET-listed annual report, immigration filing, or sustainability disclosure.

★ AUDIT-TRAIL DISCIPLINE · FAR-GRADE · BANGKOK-SIDE RETENTION

Six stages, six gates. No stage advances unsigned.

An engagement progresses through the six stages below; each stage has an explicit gate, and the gate-passage is recorded in the engagement file. The trail survives the engagement — retrieved on subpoena, on procurement-audit, on PDPA / GDPR data-subject request, on FOIA-equivalent inquiry. See Our Process for the underlying bench workflow.

STAGE 01
Inbound & standing NDA.First email logged. Standing NDA in force. No document reviewed before NDA is at least in force; client NDA executed if requested. Free scoping call within 1 business hour.
STAGE 02
Scoping & engagement letter.Receiving institution / matter identified, pair confirmed, credential path set (ATA / ISO 17100 alternative / AA1000AS / etc.), data-protection regime calibrated (GDPR / PDPA / both). Engagement letter signed: scope, price, SLA, retention.
STAGE 03
Named bench assigned.Translator, editor, and reviewer named on the engagement record before any document is touched. Back-to-back NDA executed where any external linguist is involved. No marketplace sub-contracting.
STAGE 04
Work + ISO 17100 stage-two editorial.Translation, terminology decisions, and revision cycles all logged. Independent editor revises against source per ISO 17100 stage two. Editor sign-off recorded. Drafts are not delivered.
STAGE 05
Delivery + signed certification.Certified delivery with signed translator certification where required (ATA seal for covered pairs, USCIS §103.2(b)(3) statement for Thai). Apostille / MFA / Embassy chain managed on request. Delivery acknowledgment captured.
STAGE 06
Retention & audit-trail consolidation.Source, deliverable, terminology decisions, revision cycles, NDA chain, sign-offs — consolidated and retained Bangkok-side per the engagement letter. Available on procurement audit, regulator request, or data-subject access request. Secure destruction at end of retention with certificate.

WHY FAR-GRADE · Federal Acquisition Regulation contractor-verification is the most demanding procurement discipline a translation firm can be set against — it was Othello’s founding standard, not a later upgrade. The discipline travels: a SET-listed corporate engaging Othello for an annual report gets the same audit-trail rigour a federal contracting officer demanded in 2020. The standard does not lower for non-government clients.

★ §05 · Sector-Specific Compliance · Four Regulated Verticals

Four sectors with sector-specific compliance overlays on top of the three pillars.

Capital markets, healthcare, legal, and government each layer a sector-specific compliance regime on top of GDPR / PDPA / FAR-grade. Othello operates the sector overlay where the engagement touches it — documented at scoping, not improvised at delivery.

SECTOR 01 · FLAGSHIP

Capital Markets · SEC Thailand & SET

For SET-listed corporates, SEC Thailand 56-1 One Report and listing rules govern disclosure timing, material-event language, and bilingual lockstep. Insider-information handling: documents marked confidential at scoping, access logged, retention per matter. From 2026, IFRS S2 climate disclosure becomes mandatory.

SEC ThailandSET56-1IFRS S2
SECTOR 02 · HEALTHCARE

Healthcare · HIPAA & Thai MoPH

US-bound healthcare documents — clinical records, IRB protocols, FDA submissions, US-bound consent forms — layer HIPAA Privacy & Security Rules on top of PDPA/GDPR. Thai MoPH and PDPA Special-Category provisions apply to local healthcare data. Pseudonymisation and minimum-necessary principles documented.

HIPAAFDAMoPHPDPA SC
SECTOR 03 · LEGAL

Legal · Privilege & Court Rules

Attorney-client privilege and work-product doctrine preserved through the workflow — segregated access, matter-specific retention, no co-mingling with adverse-party files. For US courts, Federal Rule of Evidence 604 governs interpreter qualification; for Thai courts, the Office of the Judiciary interpreter framework applies. Privilege is process discipline, not luck.

FRE 604PrivilegeWork-product
SECTOR 04 · GOVERNMENT

Government · FAR & UN Procurement

The founding sector. Federal Acquisition Regulation contractor-verification for US Government bilingual contracts; UN procurement vendor standards for UN system engagements; FCPA and Thai Anti-Corruption Act for cross-border transactions. Audit-trail standard set against this requirement in 2020 — remains the operating standard for all engagements today.

FARUNFCPAThai ACT

SECTOR DOCUMENTATION · Each sector overlay is documented at scoping — named in the engagement letter, mapped to specific clauses in the underlying regime. If the sector overlay is not in the engagement letter, it is not in the engagement.

★ Compliance FAQ · Procurement Questions

Procurement questions answered up front.

Substantive answers to what counsel, in-house procurement, and audit teams routinely ask when reviewing Othello’s compliance posture.

Q.01What’s the difference between Othello’s Compliance and Certifications pages?

Certifications documents what Othello holds; Compliance documents how Othello operates. The certifications page lists 5 firm-level credentials (ISO 17100, ATA, ATC, GDPR, PDPA) and 15 bench practitioner credentials (AA1000AS, ISO 14064, GRI, IFRS S1/S2, FTSE Russell, and more), each verifiable on the issuing body’s registry. This page documents the operating discipline that the credentials underwrite — data protection in two regimes, NDA from first email, FAR-grade audit-trail, and sector-specific overlays. Both pages are independently verifiable under mutual NDA at procurement stage.

Q.02How does Othello calibrate GDPR vs PDPA when both apply?

Othello applies the stricter standard for that engagement — not the easier one. For an EU→Thailand transfer with personal data, that means the modernised SCCs (Decision (EU) 2021/914) plus a Transfer Impact Assessment, plus Article 28 DPA, plus the PDPA Section 40 processor undertaking, plus the supplementary measures the TIA requires (encryption, minimisation, no consumer LLM endpoints). The breach-notification window aligns at 72 hours under both regimes; where the regimes diverge, the stricter applies.

Q.03Why doesn’t Othello use ChatGPT or other AI tools on client data?

Consumer AI endpoints are not compatible with Article 28 GDPR processor undertakings or PDPA Section 40. Their data-handling terms typically permit ingestion of submitted text into provider training and analytics pipelines — which means the firm cannot guarantee the limits Article 28 requires (purpose, retention, no sub-processing without controller consent, deletion at end of contract). Othello uses in-house translation memory, terminology databases, and CAT tools under processor control. This is operating discipline, not anti-AI ideology — the bench evaluates new tooling continuously; only data-handling-compatible tools enter the workflow.

Q.04What is “FAR-grade” and why does Othello cite it?

FAR is the US Federal Acquisition Regulation — the procurement standard US Government contractors are vetted against. Othello was founded in 2020 on US Government bilingual contracts (US CDC, US State Department, UN Women, UK PACT) under that contractor-verification discipline. FAR-grade is the audit-trail and confidentiality standard Othello was set against from day one, and it remains the operating standard today — a Thai SET-listed corporate engaging Othello for an annual report gets the same audit-trail rigour a federal contracting officer demanded in 2020. It is a heritage standard, not a separately-certified credential.

Q.05What does “NDA from first email” actually mean operationally?

It means the firm’s standing mutual NDA covers every inbound enquiry from the first email — before a quote is issued, before scoping, before any document is shared. Clients may execute their own NDA on top, which is then back-to-back to the bench. No document is reviewed under a “we’ll sign later” arrangement. If you send a confidential draft in the first email asking for a quote, it sits inside the standing NDA the moment it lands in the firm’s inbox.

Q.06Does Othello use freelancer marketplaces or anonymous sub-contractors?

No. The bench is named on every engagement record — translator, editor, reviewer identified by name before work begins. Where work involves any external linguist (rare; bench-first), back-to-back NDAs are executed and the chain is logged in the engagement file. No undisclosed marketplace sub-contracting, no anonymous freelancer routing. Counsel can verify each named individual’s NDA, ISO 17100 qualification, and language-pair coverage at procurement stage.

Q.07What is Othello’s data retention policy?

Retention is set per engagement letter against the matter type. Defaults: 7 years for standard translations, 10 years for sworn or ATA-certified work, matter-specific for litigation (often through the appeal window plus margin), as-required for capital-markets disclosure (per SEC Thailand and SET retention rules). Storage is Bangkok-side on processor-controlled infrastructure under PDPA, with the GDPR transfer mechanism on file for EU-origin data. Secure destruction on request and at end of retention; destruction certificate issued.

Q.08How does Othello handle a personal-data breach?

Othello operates a documented incident-response runbook with the 72-hour notification clock built in. On detection: incident logged, scope assessed, controller notified, regulator notification prepared (PDPC for PDPA matters, the relevant DPA for GDPR), affected data subjects identified, mitigation measures documented, post-incident report issued. Article 33 GDPR and PDPA equivalents mandate 72-hour notification to controller and regulator — that window is not negotiable. The runbook is available under NDA at procurement.

Q.09Can procurement audit Othello’s compliance posture before engaging?

Yes, that is what the compliance pack is for. Under mutual NDA at procurement, Othello provides: standing NDA template, sample Article 28 DPA + SCCs, sample TIA, PDPA Section 40 processor undertaking, incident-response runbook, retention & destruction policy, named-bench register with credential cross-reference. Each line on this page is procurement-grade language — nothing is asserted that cannot be confirmed in a vendor-due-diligence file. Email [email protected] for the compliance pack.

Q.10How does compliance fit Othello’s broader engagement framework?

The three pillars (data protection, confidentiality, audit-trail) and the four sector overlays (capital markets, healthcare, legal, government) are the operating floor for every engagement Othello delivers — ESG advisory, technical translation, certified translation, interpretation. Founded 2020 on US Government bilingual contracts under FAR-grade contractor verification, the floor is set higher than most translation firms’ ceilings. A client engaging Othello gets one engagement letter, one NDA, one audit-trail, and twenty credentials standing behind it. Email [email protected] or call +66 02-859-2145.

Compliance, independently auditable.

Two data-protection regimes, NDA from first email, FAR-grade audit-trail, and sector-specific overlays where the engagement touches them. The operating floor for every Othello engagement — documented, executed, retained Bangkok-side. ≤1 BH acknowledgement · compliance pack within 1 BD · NDA from first email.

+66 02-859-2145 · [email protected]
Unit 12-03, Chartered Square · 152 N Sathon Rd · Si Lom · Bangkok 10500
Compliance Practice · Three Pillars · GDPR + PDPA Two-Regime · NDA From First Email · FAR-Grade Audit-Trail · Named Bench · ISO 17100 + 9001 · Sector Overlays: SEC Thailand · HIPAA · Privilege · FAR Othello International
FTSE 2026 PlaybooksFree ESG disclosure guides
Chat on LINEแอดไลน์ · ตอบใน 1 ชม.
Add Othello ESG on LINE (QR code)
แอดไลน์ · Add us on LINE
Scan to chat with Othello ESG on LINE — a reply within one business hour, under NDA from the first message.
Open LINE →
Recognised & delivered Credited in DLA Piper × UK PACT × DCCE’s carbon-pricing report · SET JUMP+ Advisory Pool listed advisor · FTSE Russell 4.0/5.0 delivered · ISO 17100 certified
Get a 1-hour quote →

Research & Reports

Free Tools

Free tools & research State of ESG Disclosure· ESG Rating Check· FTSE 2026 Playbooks· Regulation Radar· Greenwashing Checker