Home
Compliance

Compliance Framework

Last updated: June 1, 2026

Landers operates under a robust, multi-domain compliance programme covering aviation, maritime, data protection, financial services, and export controls across 190+ countries.

1. Aviation Regulatory Compliance

Our aviation intelligence adheres to standards set by ICAO (Annex 4, 11, 15), EASA (EU 2017/373), FAA (14 CFR Part 139), and national CAAs in our operating jurisdictions. NOTAM, AIP, and ATIS data are validated against official authority feeds with a maximum 30-second refresh cycle.

2. Maritime Regulatory Compliance

Our maritime intelligence complies with IMO SOLAS Chapter V (Safety of Navigation), IMO Resolution A.917(22), and regional port authority standards. AIS data integration follows ITU-R M.1371-5 standards. We hold EMSA-compliant data processing agreements in EU waters.

3. Road & Multimodal Compliance

Vehicle routing data for cars, motorcycles, and bicycles complies with regional traffic authority standards. We adhere to national road authority specifications for road classification, speed limits, and restriction data in all markets.

4. Data Protection Compliance

We maintain compliance with: GDPR (EU), UK GDPR, CCPA/CPRA (California), PDPA (Thailand), PIPL (China — limited data, no residency), and DIFC Data Protection Law (Dubai). Our compliance programme is reviewed annually by external auditors (BDO Ireland).

5. Financial & Payment Compliance

Payment card processing complies with PCI DSS Level 1 (validated annually by a QSA). We do not store raw card data — all card data is tokenised by Stripe. AML/CTF screening is applied at account creation and on an ongoing basis for Enterprise accounts.

6. Export Controls & Sanctions

Landers intelligence data and software are subject to EU, UK, and US export control laws (EAR, ITAR where applicable). We screen users against EU, UN, OFAC, and HMRC sanctions lists at registration and on an ongoing basis. Users in sanctioned jurisdictions may have restricted or no access to certain features.

7. Security Certifications & Audits

Landers holds ISO/IEC 27001:2022 certification (Certificate No. IS-728834, valid until 2027). We undergo bi-annual penetration testing by an CREST-accredited third party. We participate in a responsible disclosure programme — report vulnerabilities to security@landers.io.

8. Incident Response & Reporting

We maintain a documented Incident Response Plan (IRP) aligned with NIST SP 800-61. In the event of a personal data breach, we notify affected users and the relevant supervisory authority within 72 hours as required by GDPR Article 33. All incidents are logged in our compliance register.

9. Compliance Contact

For compliance inquiries, regulatory partnership requests, or to report a compliance concern: compliance@landers.io. Chief Compliance Officer, Landers International Ltd., 1 Aviation Way, Dublin D01 XY00, Ireland.

Questions about this policy?

Our legal team responds within 2 business days.

Contact Legal Team