Security & Confidentiality

When you outsource transcription or typing, you are entrusting someone else with your data.
We understand that for many of our clients — particularly in legal, medical, research and professional environments — confidentiality is not optional. We’ve spent over 15 years refining how we handle sensitive transcription work securely across legal, medical and research sectors.


Your Responsibility (and Ours)

Under UK GDPR and the Data Protection Act 2018, the organisation outsourcing the work remains the data controller.

Outsource Typing acts as a data processor.

This means:

  • You retain responsibility for the data
  • We are responsible for processing it securely, lawfully, and only on your instructions

We take that responsibility seriously.


Article 28: Data Processing Agreements

We operate in line with Article 28 of UK GDPR, which governs relationships between data controllers and processors.

In practice, this means:

  • We only process data on documented instructions
  • All team members are bound by strict confidentiality agreements
  • We implement appropriate technical and organisational security measures
  • We do not engage sub-processors without appropriate safeguards
  • We assist clients, where appropriate, with their own compliance obligations

A Data Processing Agreement (DPA) can be provided on request.


Secure File Handling

We use a secure, structured workflow designed specifically for confidential transcription work.

  • Files are uploaded via a secure file transfer system
  • The system is AES-256-bit encrypted and password protected
  • Files are never requested or accepted via unsecured channels where avoidable
  • Access is strictly limited to authorised team members only

Security & Confidentiality in Transcription


Controlled Access & Confidentiality

All work is carried out by a carefully selected UK-based team.

  • Every typist signs a formal Acceptance Agreement of Transcription/Proofreading Work
  • This includes confidentiality obligations before any work is assigned
  • Work is allocated on a need-to-know basis
  • Final outputs are subject to oversight and quality control

Your work is never treated as anonymous or disposable — it is handled with accountability.

Our processes are designed to support secure transcription services in the UK, in line with UK GDPR requirements.


Secure Storage

We maintain strict controls over how files are stored and accessed:

  • Files are only stored on encrypted, password-protected devices
  • No long-term storage on unsecured local machines
  • No use of open or shared environments

Data Retention & Deletion

We operate a clearly defined data lifecycle:

  • Audio files are deleted within 48 hours of secure download
  • Files remain on the secure transfer system for approximately 72 days, after which they are automatically removed
  • No unnecessary retention of client data

If you require alternative deletion timelines, we are happy to discuss this.


No Unauthorised Outsourcing

We do not pass work to unknown third parties.

  • No offshore outsourcing without clear agreement
  • No use of unvetted subcontractors

All work is handled by trained human professionals within a controlled workflow.


ICO Registration

Outsource Typing is registered with the Information Commissioner’s Office.

This reflects our commitment to handling personal data in line with UK data protection requirements.


A Practical Approach to Security

Security is not about complicated language or box-ticking.

It is about:

  • Clear processes
  • Controlled access
  • Defined responsibilities
  • And doing what you say you will do

We have refined our approach over more than 15 years of working with sensitive material.


Questions

If you have specific requirements — NDAs, DPAs, or internal compliance processes — we are always happy to discuss these before any work begins. Find our full list of services here.

📩 enquiries@outsource-typing.com