Compliance & Data ProtectionCompliance & Audit
Compliance Framework
The platform's compliance framework and compliance register
The SSM.ro compliance framework brings together the applicable legal and security requirements and maps them to the implemented controls.
Compliance Domains
| Domain | Requirement | Controls / Reference |
|---|---|---|
| Data Protection | GDPR, Law 190/2018 | GDPR Section; DPO; ROPA |
| Electronic Signature | eIDAS Regulation (910/2014) | Qualified Trust Service Provider (QTSP) for electronic signatures |
| Information Security | ISO/IEC 27001 (certified); SOC 2 alignment | Certifications and Standards; Trust Center |
| SSM / PSI (Occupational Health & Safety / Fire Prevention and Firefighting) | Labor and fire safety legislation | Core platform functionality |
| Security in the Absence of a WAF | Approved compensating controls | Network Security |
Compliance Register
Compliance is supported by a set of versioned documents v1.0 (2026-04-29), reviewed annually:
| Document | Role |
|---|---|
| Data Flow Diagram (DFD) | Mapping of data flows |
| Architecture Diagram | Components and network flows |
| Risk Register | 12 risks, controls, residual risk |
| Roles Catalog | Roles and authorized operations |
| WAF Compensating Controls Memo | Approved substitution for the WAF |
| Operational SOP | Backup, DR, and patching |
These documents are provided to clients upon request — see Reports Available to Clients.
Governance
- Owner: SSM.ro security / compliance team, with DPO support
- Review: annually or upon significant architectural changes
- Applicable Legislation: see Applicable Legislation