Skip to content
About

LAB / CONFIDENTIALITY

Confidentiality policy

Client results and records remain the client’s property. How the laboratory controls access, protects client information and handles the exceptions the law defines.

CONTROLLED DOCUMENT

Confidentiality Policy

The purpose of this Confidentiality Policy is to outline the measures and procedures implemented by QSI Nexus Testing and Calibration Labs to ensure the confidentiality of information in accordance with ISO/IEC 17025:2017 requirements.

This policy applies to all employees, contractors and third parties who have access to confidential information within QSI Nexus Testing and Calibration Labs.

  1. Confidential information

    Confidential information includes, but is not limited to:

    • Test results
    • Customer information
    • Calibration procedures
    • Internal documents and procedures
    • Intellectual property
  2. Responsibilities

    It is the responsibility of all employees, contractors and third parties to:

    • Maintain the confidentiality of all information obtained during the course of their duties.
    • Protect confidential information from unauthorised access, disclosure, alteration or destruction.
    • Use confidential information solely for authorised purposes and in accordance with established procedures.
    • Report any breach of confidentiality, or any suspected security incident, to management immediately.
    • Be responsible, through legally enforceable commitments, for the management of all information obtained or created during the performance of laboratory activities.
  3. Information released under legal obligation

    Where the laboratory is required by law, or authorised by contractual arrangement, to release confidential information, the customer or individual concerned shall be notified of the information provided, unless prohibited by law.

  4. Information obtained from other sources

    Information about a customer obtained from a source other than the customer — a complainant or a regulator, for example — shall be confidential between that source and the laboratory. The identity of the source is not disclosed to the customer, and the information is not shared with the customer.

  5. Access control

    Access to confidential information shall be restricted to authorised personnel only. Measures shall be implemented to ensure that access is granted on a need-to-know basis and is appropriately controlled and monitored.

  6. Data protection

    Confidential information shall be protected against unauthorised access, disclosure, alteration or destruction through the implementation of appropriate physical, technical and organisational security measures.

  7. Confidentiality undertakings

    Employees, contractors and third parties shall sign a legally enforceable confidentiality undertaking before being granted access to confidential information. The undertaking survives the end of employment or contract, and signed undertakings are retained by the laboratory.

  8. Records retention and disposal

    Client records, results and associated technical records are retained for the period defined in the laboratory’s records-control procedure, and for no longer than is necessary. On expiry of the retention period, records are disposed of by a method appropriate to their form and sensitivity, and the disposal is recorded.

  9. Training and awareness

    Employees, contractors and third parties shall receive training on the importance of confidentiality, their responsibilities regarding confidential information, and the procedures for safeguarding it.

  10. Compliance

    All employees, contractors and third parties are required to comply with this policy and related procedures. Non-compliance may result in disciplinary action, termination of contracts, or legal action as appropriate.

  11. Review and revision

    This policy shall be reviewed regularly to ensure its effectiveness and compliance with ISO/IEC 17025:2017 requirements. Any necessary revisions shall be made in a timely manner.

  12. Communication

    This policy shall be communicated to all employees, contractors and third parties who have access to confidential information within QSI Nexus Testing and Calibration Labs.

Reference

ISO/IEC 17025:2017, clause 4.2

Issue

Issue 2

Date

Publishes on reissue

Approved by

Dr. Rana Amjad — President / CEO, QSI Nexus Testing and Calibration Labs

Questions or concerns about this policy may be raised with coo@qsinexus.com or lab-mgr@qsinexus.com.

LAB / CONFIDENTIALITY

What this means in practice

Your results are your property. What the laboratory does with them, who can see them, and the narrow set of circumstances in which anyone else ever does.

Your results belong to you

01 / 02

Everything the laboratory produces for you — results, reports, certificates and the technical records underneath them — is your property and is treated as confidential by default. Nexus does not publish client names, does not use results as marketing, and does not disclose that an organisation is a client without written permission.

The laboratory retains its own copy because it has to: traceability of a result back to the sample and the method is an accreditation requirement, and it is what allows a report to be defended months later. That copy is held under the access controls in clause 05 above.

The two exceptions, stated plainly

02 / 02

There are exactly two circumstances in which information leaves the laboratory without your instruction. The first is a legal obligation or an obligation under a contract you have signed — and where that happens, you are told what was provided, unless the law forbids telling you. The second is the accreditation body: SAAC assessors review records as part of assessing the laboratory, under their own confidentiality obligations.

Nothing else qualifies. A request from anyone other than you, without one of those two grounds, is refused.

Information we hold about you that came from someone else — a complainant, a regulator — is confidential to that source, and we will not share it with you either. The rule cuts both ways, which is what makes it a rule rather than a preference.

Requests are read at the bench.

Send the sample question or the instrument list. It is read by a bench professional, not routed through a ticket queue. Call +966 59 637 8052 or write to lab-mgr@qsinexus.com.