M ManySignal

United Kingdom

UK data residency with FCA, NCSC CAF, and UK GDPR compliance

UK customer data stays in AWS EU-WEST-2 (London). ManySignal supports FCA PS21/3 operational resilience, NCSC Cyber Assessment Framework monitoring, and UK GDPR Article 28 DPA — in a deployment configured for UK financial services and critical infrastructure operators.

UK data residency guarantees

Storage region

AWS EU-WEST-2 (London) — all log data, entity graph, case records, and analytics data stored within the UK. No transfer to EU or US regions without explicit consent.

Processing boundary

All detection, analytics, and AI inference runs within AWS London infrastructure. UK customer data does not transit US-based inference endpoints under any circumstances.

Regulatory boundary

UK GDPR governs processing. The ICO is ManySignal's UK supervisory authority. Standard Contractual Clauses (UK Addendum) apply to any incidental cross-border access by ManySignal support staff outside the UK.

UK regulatory frameworks supported

UK GDPR / DPA 2018

72-hour breach notification to ICO, UK GDPR Article 28 DPA, Data Subject Rights support

FCA PS21/3

Operational resilience — ICT monitoring evidence, impact tolerance testing documentation

NCSC Cyber Assessment Framework

CAF Objective C (Security Monitoring) and Objective D (Minimising Impact) monitoring evidence for Ofcom, Ofgem, FCA, and other CA assessments

UK NIS Regulations

Operators of essential services and DSPs — incident detection, CA notification support (NCSC, Ofcom, Ofgem, BEIS)

PRA Supervisory Statement SS2/21

Operational resilience requirements for PRA-regulated firms — critical business service monitoring

FCA SYSC 8

Outsourcing and third-party risk monitoring — vendor access controls and incident evidence

Breach notification timelines — UK

72 hours

UK GDPR Art. 33 — Personal data breach notification to ICO

As soon as possible

UK NIS Regulations — Incident notification to Competent Authority (NCSC/Ofcom/Ofgem)

72 hours (NIS2-aligned)

Upcoming UK Cyber Security and Resilience Bill — anticipated alignment with EU NIS2 timelines

UK sales and support contact

UK enterprise sales: [email protected]

Data Protection Officer: [email protected]

Office: London, UK (registered UK entity)

UK data residency — common questions

Where is UK customer data stored?

UK customer data is stored and processed in AWS EU-WEST-2 (London). No UK customer data is transferred to non-UK regions under normal operations. Disaster recovery replication to AWS EU-WEST-1 (Dublin) is available with explicit customer consent, subject to UK GDPR's adequacy decision for EU transfers.

Does ManySignal comply with UK GDPR?

Yes. UK GDPR (as retained by the Data Protection Act 2018) applies to ManySignal's processing of UK customer data. ManySignal executes a UK-specific DPA covering the UK GDPR Article 28 requirements. The Information Commissioner's Office (ICO) is the UK supervisory authority. The 72-hour breach notification requirement applies to UK personal data processing.

How does ManySignal support FCA operational resilience requirements?

ManySignal supports the FCA's PS21/3 operational resilience requirements — specifically the ICT monitoring controls required to evidence operational within impact tolerances. The platform monitors critical business services, provides incident detection and response evidence, and generates operational resilience scenario testing documentation for FCA supervisory reviews.

Does ManySignal support the NCSC Cyber Assessment Framework (CAF)?

Yes. ManySignal maps to the NCSC CAF's four objectives: Managing Security Risk (A), Protecting Against Cyber Attack (B), Detecting Cyber Security Events (C), and Minimising Impact (D). The platform provides continuous monitoring evidence for Objective C (Security Monitoring) and supports the evidence requirements for regulated entities subject to CAF assessment by Ofcom, Ofgem, the FCA, and other UK regulators.

What is ManySignal's approach to the UK NIS Regulations and the upcoming UK Cyber Security and Resilience Bill?

ManySignal currently supports UK NIS Regulations requirements for operators of essential services and digital service providers — incident detection, reporting to Competent Authorities (Ofcom, Ofgem, FCA, etc.), and security measures. The upcoming UK Cyber Security and Resilience Bill (anticipated 2025) is expected to expand the NIS scope; ManySignal is monitoring the legislation and will update its compliance mapping upon enactment.

Deploy ManySignal in the UK

Speak with our UK team about FCA operational resilience, NCSC CAF monitoring, and UK GDPR DPA execution — all in one session.