Each entry states the instrument and the specific obligation it places on us. Where a control is in progress rather than certified, it is marked as such.
Data protection
Regulation (EU) 2016/679 (GDPR)
Personal data appearing in the register — names of officers, registered addresses — is processed under Article 6(1)(f), our legitimate interest in corporate transparency, balanced against the rights of the individuals concerned.
Supplemented in Cyprus by Law 125(I)/2018; supervised by the Office of the Commissioner for Personal Data Protection.
Company law
Companies Law, Cap. 113
The statute establishing the Cyprus register and the filing obligations of every company, partnership, business name and overseas branch. It is the reason the underlying facts are public, and it defines the fields we display.
Open data
Directive (EU) 2019/1024 on open data and re-use of PSI
As transposed in Cyprus, this is the basis on which register extracts published on data.gov.cy may be re-used commercially. We re-use dataset 1026 on its published licence terms and attribute the Registrar as source on every page.
Information security
ISO/IEC 27001 — implementation in progress
We are aligning our information security management system to ISO/IEC 27001. Certification has not yet been issued and we make no claim to hold it.
In operation today: encryption in transit, least-privilege access to the import pipeline, and no storage of user accounts, passwords or payment data.
AML context
Directive (EU) 2015/849 and successors
Register data supports customer and counterparty due diligence but does not by itself discharge any obligated entity’s KYB duties. Beneficial ownership is held in a separate Cypriot register to which we have no access and which we do not republish.
Service commitment
Refresh SLA
A complete re-import of the published register is performed once every seven days. Where the Registrar’s publication is delayed, the affected profiles continue to state the import date they reflect rather than presenting stale data as current.