Keeping Ahead of Regulations

Security, Compliance & Resilience

Built into every release. Backed by recognised standards. Trusted by leisure operators every day.

Governance

Technology regulation doesn't stand still. Neither do we.

The regulatory environment for digital services is evolving, from the UK Cyber Security and Resilience Bill to AI governance and payment security standards. For leisure operators managing sensitive member data across multiple sites, knowing your technology partner is ahead of these changes matters.

Our platform is built with security, resilience and compliance at its core. We monitor legislative developments, assess their impact on our products and services, and adapt our controls so you can remain confident in your technology partner.

 

500+
Leisure Operators

ISO 27001
Information Security

UK Hosted
Microsoft Azure

G-Cloud 15 
Procurement Framework

 

Visit Trust Centre

Regulatory landscape

Regulations we're tracking

Regulation Gladstone Status
UK Cyber Security and Resilience Bill Monitoring and assessing readiness
NIS Regulations 2018 Compliant 
UK GDPR and Data Protection Act 2018  Compliant
PCI DSS 4.0.1 Certified
EU AI Act AI governance programme underway
WCAG 2.1 Accessibility AA compliance targeted across consumer platform

 

Where we help you stay compliant

Regulation Applies to Gladstone Status
DMCCA Subscription Contracts
(January 2027)
Our Customers Platform updates in development for January 2027 requirements 

 

We continually monitor regulatory developments and adapt our roadmap where legislation changes. Following the Government's decision to bring the new DMCCA subscription rules forward to January 2027, we have reprioritised development to deliver the required platform changes during 2026. What is DMCCA?

What this means for our customers

We operate a structured approach to regulatory change:

Monitor

We track regulatory developments relevant to leisure technology and data services.

Assess

We evaluate any impact on our platform, infrastructure and customer data.

Act

We update our platform, controls and processes where required.

Communicate

We inform customers of material changes through appropriate channels.

Evidence

We provide documentation through our Trust Centre and assurance process.

Support

We respond directly to supplier security and procurement questionnaires.

3M+ active members
1.9B monthly platform requests
1.7k+ operator sites
24/7 monitored cloud platform

Standards and certifications

 

Standard / Control Detail
ISO 27001:2022 Information security management (externally audited annually)
ISO 9001:2015 Quality management
Cyber Essentials Plus UK Government-backed cyber security certification
PCI DSS 4.0.1 Payment card data security
Penetration Testing Continuous testing programme (beyond annual fixed schedule)
Business Continuity Tested every six months with a 6 hour RTO and 6 minute RPO.

 

Platform and Infrastructure:
Hosted on Microsoft Azure UK South. Data encrypted at rest and in transit. 99.9% uptime SLA. Three availability zones for resilience. We provide a publicly accessible Service Status page so customers can view the current status of our cloud services, planned maintenance and incident updates.

Procurement made simpler.

Approved on G-Cloud 15

Gladstone is an approved supplier on the UK Government's G-Cloud 15 framework, giving eligible public sector organisations a straightforward, compliant route to procure our cloud software and services.

G-Cloud 15 | RM1557.15 | Live from 6 August 2026

Explore Gladstone on G-Cloud

That is externally defensible. G-Cloud 15 replaced G-Cloud 14 on 6 August 2026 and is available to local authorities, education, health, central government and other eligible public bodies.

Logo for Gcloud15

Frequently Asked Questions

How does the DMCCA affect leisure memberships?

The Digital Markets, Competition and Consumers Act introduces new requirements for subscription contracts from January 2027, including clearer pre-contract information, reminder notices, cooling-off rights and easier cancellation.

Gladstone is actively developing the platform changes required to support these obligations, including self-service cancellations, cooling-off periods, fixed end-date memberships, pre-contract information and reminder notices. Our current roadmap is targeting delivery during 2026, ahead of the new rules taking effect.

Does Gladstone help us meet our own regulatory obligations?

Yes. Where legislation affects how you manage memberships, payments, or communications, we assess the impact on our platform and plan updates so you can meet your obligations through the tools you already use.

Can Gladstone complete supplier assurance questionnaires?

Yes. Our team regularly supports procurement and assurance exercises. If you have received a request related to the Cyber Security and Resilience Bill or NIS Regulations, we can help.

Where can I find your certifications and security documentation?

Visit our Trust Centre. For access to detailed policies, architecture summaries and audit reports, you can request elevated access directly through the Trust Centre.

How quickly will Gladstone notify us of a security incident?

Within 24 hours of a confirmed incident affecting customer data, in line with our ISO 27001 incident management process. We are already aligned with the anticipated 24 hour initial notification and 72 hour follow up reporting framework outlined in the Cyber Security and Resilience Bill.

Where is our data stored?

All customer data is hosted in Azure UK South (London), within UK data centres. Data is logically separated per customer, encrypted at rest and in transit, and backed up every 6 minutes.

How does Gladstone manage its own supply chain?

We assess, monitor and contractually bind our critical third-party providers. Supply chain assurance is embedded within our ISO 27001 framework and reviewed as part of our ongoing risk management programme.

Will Gladstone tell us if regulations affect our service?

Yes. We monitor legislative developments and communicate material changes proactively. 

What is your uptime commitment?

99.9% over a rolling 90-day period, publicly monitored via our status page.

Can I procure Gladstone through the government framework? (GCloud)

Yes. From 6 August 2026 Gladstone is an approved supplier on the G-Cloud 15 framework, making it easier for eligible UK public sector organisations to procure our cloud software and services. Contact our team if you'd like help identifying the appropriate service or navigating the procurement process.

Why use G-Cloud?
G-Cloud provides eligible UK public sector organisations with a faster, compliant route to procure cloud software and services. As a pre-approved Government framework, it removes much of the complexity of traditional procurement, with transparent pricing, clearly defined service offerings and simplified purchasing, helping organisations get started more quickly.  G-Cloud 15 is available to eligible UK public sector organisations, including local authorities, leisure trusts, universities, educational institutions, NHS organisations and other public bodies covered by the framework.

Get in touch with us about purchasing via G-Cloud

Back to top

Looking for technical detail?

Our Trust Centre contains security documentation, certifications, operational policies, penetration test summaries and service architecture information for customers and procurement teams.

Visit our Trust Centre →

Rest Assured

Need to run a supplier assurance exercise?

We know procurement and IT security teams are increasingly asking suppliers about regulatory readiness. If you need a formal response, our team can support you directly.

Contact our compliance team