À propos
Governance and compliance
Toronto governance, Dominican Ley 172-13, and full alignment and compliance with ISO 27001, ISO 9001, SOC 2 Type II, PCI-DSS, HIPAA and GDPR.

Corpshore Dominicana operates under the information-security governance of its Toronto-headquartered parent, in compliance with Dominican Republic Law 172-13 on Personal Data Protection, and fully aligned and compliant with ISO 27001, ISO 9001, SOC 2 Type II, PCI-DSS, HIPAA and GDPR. This framework stack is what lets Corpshore Dominicana serve regulated banking, healthcare, payments and enterprise clients from the Dominican Republic with confidence.
Corpshore Dominicana is fully aligned and compliant with the information-security, quality and data-protection frameworks that regulated clients require: ISO 27001 for information security management, ISO 9001 for quality management, SOC 2 Type II for security, availability and confidentiality controls, PCI-DSS for cardholder-data environments, HIPAA for protected health information, and the EU GDPR for personal data of individuals in Europe. These sit alongside Dominican Ley 172-13 on Personal Data Protection.
Ley 172-13 is the Dominican Personal Data Protection Law. Corpshore Dominicana operates in compliance with it, and the documentation available to clients covers how personal data is collected, handled, stored and transferred, the lawful bases for processing, and the rights of data subjects and how to exercise them.
Information-security governance is inherited from the Toronto-headquartered parent and applied consistently across all four Dominican delivery sites: role-based access control, encryption in transit and at rest, continuous monitoring, logging and audit trails, secure software delivery, and vendor and sub-processor management. Controls are reviewed on a defined cadence and evidenced to clients during due diligence.
Compliance is operational, not a badge on a page: background-vetted staff, confidentiality and acceptable-use agreements, security awareness training, incident response and breach-notification procedures aligned to Ley 172-13 and GDPR timelines, business continuity and disaster recovery across sites, and defined client audit rights. Clients in banking, insurance, healthcare, payments and technology rely on this posture, and it is documented so procurement and risk teams can verify it.
For due diligence, we work through the specifics with your risk team directly: the control scope that applies to your engagement, where and how your data is handled, our sub-processor arrangements, and the exact clauses in the data-processing agreement. Our published data protection notice sets out the Ley 172-13 basis and the data-subject rights and how to exercise them, and a formal request to verify certification scope or run an audit is answered as part of onboarding rather than left to a marketing claim.
ISO 27001
Information security management system: aligned and compliant.
ISO 9001
Quality management system for consistent, measurable delivery.
SOC 2 Type II
Security, availability and confidentiality controls, evidenced over time.
PCI-DSS
Cardholder-data environment controls for payment-adjacent work.
HIPAA
Safeguards for protected health information in healthcare engagements.
GDPR and Ley 172-13
EU GDPR and Dominican Law 172-13 for personal-data protection.
Ready to evaluate a nearshore partner?
Book a discovery call or request a proposal. We respond to qualified enquiries within one business day.
All engagements comply with Dominican Republic Law 172-13 on Personal Data Protection.
Looking for work?
Browse open roles across four Dominican cities, or join the talent community and we will reach out when a match opens.