Compliance Framework
Last updated: June 1, 2026
Landers operates under a robust, multi-domain compliance programme covering aviation, maritime, data protection, financial services, and export controls across 190+ countries.
1. Aviation Regulatory Compliance
Our aviation intelligence adheres to standards set by ICAO (Annex 4, 11, 15), EASA (EU 2017/373), FAA (14 CFR Part 139), and national CAAs in our operating jurisdictions. NOTAM, AIP, and ATIS data are validated against official authority feeds with a maximum 30-second refresh cycle.
2. Maritime Regulatory Compliance
Our maritime intelligence complies with IMO SOLAS Chapter V (Safety of Navigation), IMO Resolution A.917(22), and regional port authority standards. AIS data integration follows ITU-R M.1371-5 standards. We hold EMSA-compliant data processing agreements in EU waters.
3. Road & Multimodal Compliance
Vehicle routing data for cars, motorcycles, and bicycles complies with regional traffic authority standards. We adhere to national road authority specifications for road classification, speed limits, and restriction data in all markets.
4. Data Protection Compliance
We maintain compliance with: GDPR (EU), UK GDPR, CCPA/CPRA (California), PDPA (Thailand), PIPL (China — limited data, no residency), and DIFC Data Protection Law (Dubai). Our compliance programme is reviewed annually by external auditors (BDO Ireland).
5. Financial & Payment Compliance
Payment card processing complies with PCI DSS Level 1 (validated annually by a QSA). We do not store raw card data — all card data is tokenised by Stripe. AML/CTF screening is applied at account creation and on an ongoing basis for Enterprise accounts.
6. Export Controls & Sanctions
Landers intelligence data and software are subject to EU, UK, and US export control laws (EAR, ITAR where applicable). We screen users against EU, UN, OFAC, and HMRC sanctions lists at registration and on an ongoing basis. Users in sanctioned jurisdictions may have restricted or no access to certain features.
7. Security Certifications & Audits
Landers holds ISO/IEC 27001:2022 certification (Certificate No. IS-728834, valid until 2027). We undergo bi-annual penetration testing by an CREST-accredited third party. We participate in a responsible disclosure programme — report vulnerabilities to security@landers.io.
8. Incident Response & Reporting
We maintain a documented Incident Response Plan (IRP) aligned with NIST SP 800-61. In the event of a personal data breach, we notify affected users and the relevant supervisory authority within 72 hours as required by GDPR Article 33. All incidents are logged in our compliance register.
9. Compliance Contact
For compliance inquiries, regulatory partnership requests, or to report a compliance concern: compliance@landers.io. Chief Compliance Officer, Landers International Ltd., 1 Aviation Way, Dublin D01 XY00, Ireland.