Security, Compliance & Resilience
Built into every release. Backed by recognised standards. Trusted by leisure operators every day.
Technology regulation doesn't stand still. Neither do we.
The regulatory environment for digital services is evolving, from the UK Cyber Security and Resilience Bill to AI governance and payment security standards. For leisure operators managing sensitive member data across multiple sites, knowing your technology partner is ahead of these changes matters.
Our platform is built with security, resilience and compliance at its core. We monitor legislative developments, assess their impact on our products and services, and adapt our controls so you can remain confident in your technology partner.
500+
Leisure Operators
ISO 27001
Information Security
UK Hosted
Microsoft Azure
G-Cloud 15
Procurement Framework
Regulatory landscape
Regulations we're tracking
| Regulation | Gladstone Status |
|---|---|
| UK Cyber Security and Resilience Bill | Monitoring and assessing readiness |
| NIS Regulations 2018 | Compliant |
| UK GDPR and Data Protection Act 2018 | Compliant |
| PCI DSS 4.0.1 | Certified |
| EU AI Act | AI governance programme underway |
| WCAG 2.1 Accessibility | AA compliance targeted across consumer platform |
Where we help you stay compliant
| Regulation | Applies to | Gladstone Status |
|---|---|---|
| DMCCA Subscription Contracts (January 2027) |
Our Customers | Platform updates in development for January 2027 requirements |
We continually monitor regulatory developments and adapt our roadmap where legislation changes. Following the Government's decision to bring the new DMCCA subscription rules forward to January 2027, we have reprioritised development to deliver the required platform changes during 2026. What is DMCCA?
What this means for our customers
We operate a structured approach to regulatory change:
Monitor
We track regulatory developments relevant to leisure technology and data services.
Assess
We evaluate any impact on our platform, infrastructure and customer data.
Act
We update our platform, controls and processes where required.
Communicate
We inform customers of material changes through appropriate channels.
Evidence
We provide documentation through our Trust Centre and assurance process.
Support
We respond directly to supplier security and procurement questionnaires.
Standards and certifications
| Standard / Control | Detail |
|---|---|
| ISO 27001:2022 | Information security management (externally audited annually) |
| ISO 9001:2015 | Quality management |
| Cyber Essentials Plus | UK Government-backed cyber security certification |
| PCI DSS 4.0.1 | Payment card data security |
| Penetration Testing | Continuous testing programme (beyond annual fixed schedule) |
| Business Continuity | Tested every six months with a 6 hour RTO and 6 minute RPO. |
|
Platform and Infrastructure: |
Procurement made simpler.
Approved on G-Cloud 15
Gladstone is an approved supplier on the UK Government's G-Cloud 15 framework, giving eligible public sector organisations a straightforward, compliant route to procure our cloud software and services.
G-Cloud 15 | RM1557.15 | Live from 6 August 2026
Explore Gladstone on G-Cloud
That is externally defensible. G-Cloud 15 replaced G-Cloud 14 on 6 August 2026 and is available to local authorities, education, health, central government and other eligible public bodies.
Frequently Asked Questions
The Digital Markets, Competition and Consumers Act introduces new requirements for subscription contracts from January 2027, including clearer pre-contract information, reminder notices, cooling-off rights and easier cancellation.
Gladstone is actively developing the platform changes required to support these obligations, including self-service cancellations, cooling-off periods, fixed end-date memberships, pre-contract information and reminder notices. Our current roadmap is targeting delivery during 2026, ahead of the new rules taking effect.
Yes. Where legislation affects how you manage memberships, payments, or communications, we assess the impact on our platform and plan updates so you can meet your obligations through the tools you already use.
Yes. Our team regularly supports procurement and assurance exercises. If you have received a request related to the Cyber Security and Resilience Bill or NIS Regulations, we can help.
Visit our Trust Centre. For access to detailed policies, architecture summaries and audit reports, you can request elevated access directly through the Trust Centre.
Within 24 hours of a confirmed incident affecting customer data, in line with our ISO 27001 incident management process. We are already aligned with the anticipated 24 hour initial notification and 72 hour follow up reporting framework outlined in the Cyber Security and Resilience Bill.
All customer data is hosted in Azure UK South (London), within UK data centres. Data is logically separated per customer, encrypted at rest and in transit, and backed up every 6 minutes.
We assess, monitor and contractually bind our critical third-party providers. Supply chain assurance is embedded within our ISO 27001 framework and reviewed as part of our ongoing risk management programme.
Yes. We monitor legislative developments and communicate material changes proactively.
99.9% over a rolling 90-day period, publicly monitored via our status page.
Yes. From 6 August 2026 Gladstone is an approved supplier on the G-Cloud 15 framework, making it easier for eligible UK public sector organisations to procure our cloud software and services. Contact our team if you'd like help identifying the appropriate service or navigating the procurement process.
Why use G-Cloud?
G-Cloud provides eligible UK public sector organisations with a faster, compliant route to procure cloud software and services. As a pre-approved Government framework, it removes much of the complexity of traditional procurement, with transparent pricing, clearly defined service offerings and simplified purchasing, helping organisations get started more quickly. G-Cloud 15 is available to eligible UK public sector organisations, including local authorities, leisure trusts, universities, educational institutions, NHS organisations and other public bodies covered by the framework.
Get in touch with us about purchasing via G-Cloud
Looking for technical detail?
Our Trust Centre contains security documentation, certifications, operational policies, penetration test summaries and service architecture information for customers and procurement teams.
Need to run a supplier assurance exercise?
We know procurement and IT security teams are increasingly asking suppliers about regulatory readiness. If you need a formal response, our team can support you directly.
