Request a Demo
MI 2.0: The biggest reveal for Global Mobility in 2026

Disclaimer:

This page is intended to provide updates about Benivo’s compliance to EU data privacy laws such as the GDPR, you should not treat this as legal advice for your company. The page contains background information to GDPR to illustrate how Benivo is addressing some key legal points, however, it is not the same as legal advice nor should it be treated as such. Please consult a lawyer or a legal professional if you’d like advice on  compliance to GDPR.

Introduction

Protecting employee and client data is fundamental to how Benivo operates.

Benivo maintains a comprehensive data protection and information security framework designed to support compliance with applicable privacy laws, including the UK GDPR, the EU GDPR and the UK Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.

Our approach combines privacy controls, technical and organisational security measures, independent certification, employee training and ongoing review of the third parties that support our services.

How Benivo protects personal data

Benivo processes personal data to provide global mobility technology and relocation services to our clients and their employees.

Depending on the circumstances and the services being provided, Benivo may act as a data processor on behalf of a client or as a data controller for specific processing activities.

Our data protection framework is built around the core principles of:

  • lawful, fair and transparent processing;
  • collecting personal data for specified and legitimate purposes;
  • limiting data collection to what is necessary;
  • maintaining accurate information;
  • retaining personal data only for as long as required;
  • protecting data through appropriate technical and organisational safeguards; and
  • supporting individuals in exercising their data protection rights.

Information security

Benivo's Information Security Management System is independently certified to ISO/IEC 27001:2022.

Our security programme includes measures such as:

  • encryption of data in transit and at rest;
  • role-based access controls;
  • multi-factor authentication;
  • vulnerability management and independent penetration testing;
  • security monitoring and incident management;
  • business continuity and disaster recovery procedures;
  • employee information security and privacy training; and
  • security and privacy assessment of relevant third-party service providers.

Information security is continuously reviewed as our technology, services and regulatory requirements evolve.

Data subject rights

Benivo supports the rights available to individuals under applicable data protection laws.

Depending on the circumstances and jurisdiction, these may include rights to:

  • access personal data;
  • correct inaccurate information;
  • request deletion or restriction of processing;
  • object to certain processing;
  • obtain certain personal data in a portable format;
  • withdraw consent where processing relies on consent; and
  • raise a complaint about the way personal data has been handled.

Where Benivo acts as a processor for a client, we support our client in responding to relevant data subject requests.

Our full Benivo Users Privacy Policy explains how personal data relating to users of the Benivo platform is processed and how individuals can exercise their rights.

International data transfers

Benivo operates internationally and supports global mobility programmes around the world.

Where personal data is transferred internationally, Benivo uses appropriate safeguards as required by applicable law. Depending on the jurisdiction and transfer, these may include adequacy decisions, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, and other legally recognised transfer mechanisms.

We also assess relevant third-party processors and apply appropriate contractual, technical and organisational controls.

Privacy by design

Privacy and security considerations form part of how Benivo develops and operates its technology.

We seek to minimise the personal data required to provide our services and apply appropriate access controls and safeguards throughout the data lifecycle.

New products, features, integrations and third-party services are assessed for privacy and security considerations as appropriate.

Third-party providers

Benivo uses carefully selected third-party providers to support areas such as hosting, communications, payments and delivery of mobility and relocation services.

Relevant providers undergo due diligence and are subject to contractual data protection, security and confidentiality requirements appropriate to the services they perform and the information they process.

Data protection governance

Benivo maintains internal privacy and information security policies supported by employee training, defined responsibilities and ongoing review.

We maintain processes for managing data subject requests, data protection complaints, security incidents, retention requirements and third-party risk.

Benivo also maintains contractual data protection arrangements with clients and relevant processors, including appropriate provisions governing the processing and international transfer of personal data.

Data protection complaints

Individuals can raise questions, exercise their data protection rights or make a complaint about the way Benivo handles their personal data through the contact details provided in our Privacy Policies.

We investigate data protection complaints appropriately and without undue delay and maintain a complaints process in accordance with applicable UK data protection requirements.

Further information

For further information, please refer to:

Benivo Users Privacy Policy
www.benivo.com/platform-service/privacy-policy

Benivo Website Privacy Policy
www.benivo.com/privacy-policy

Cookies Policy
www.benivo.com/cookies-policy

Data Security / ISO 27001 Certification
www.benivo.com/benivo-earns-iso-27001-certification

For questions about Benivo's data protection and security practices, please contact our team.

  • Is Benivo GDPR compliant?

    Benivo maintains a data protection programme designed to comply with the UK GDPR, EU GDPR and other applicable privacy requirements relevant to our services.

    Compliance is an ongoing programme rather than a one-time exercise. We continually review our policies, technology, security controls, suppliers and operating practices as our business and regulatory requirements evolve.

  • Is Benivo a data controller or a data processor?

    It depends on the processing activity.

    For much of the personal data processed through our services on behalf of employers, Benivo acts as a data processor or service provider operating on the client's instructions.

    For certain activities where Benivo determines the purposes and means of processing, Benivo may act as a data controller.

    The applicable contractual arrangements and Privacy Policies provide further detail.

  • Does GDPR require personal data to remain in Europe?

    No. GDPR does not generally require all personal data to be physically stored within the European Union or European Economic Area.

    Personal data may be transferred internationally where the requirements of applicable data protection law are met and appropriate transfer safeguards are used.

  • Does Benivo protect employees outside Europe?

     Yes. Benivo applies its information security and data protection framework to personal data processed through its services globally, while also considering additional or different requirements imposed by applicable local privacy laws. 

  • Does Benivo sell employee personal data?

    No. Benivo does not sell platform users' personal data to third parties for their own marketing purposes.

    Personal data is shared only where appropriate for providing and administering the services, fulfilling client requirements, meeting legal obligations or for other purposes described in the applicable Privacy Policy.