← Corporate information

Security, data processing and continuity

Sensitive publishing work needs clear controls.

Journal operations can involve unpublished manuscripts, reviewer information, contributor records, editorial correspondence and platform access. The correct controls depend on the data, the systems, the parties and the work being performed.

The Harrowell approach

Clear terms around the work that matters.

Harrowell does not treat a public website description as a substitute for project controls. Before restricted records are shared, the engagement should define authorised access, permitted purpose, transfer route, roles, relevant supplier arrangements and any client-specific requirements.

In practice

What this means in a real engagement.

Access and least necessary information

The project should identify which people need access, what information is necessary and how access is approved, reviewed and withdrawn. Credentials and system exports should not be sent through an initial enquiry form or ordinary unprotected email.

Data processing and client requirements

Where Harrowell handles personal information or client systems as part of an engagement, the parties should establish the relevant responsibilities, instructions, authorised sub-processors and project-specific data-handling terms before the work begins.

Backup, recovery and change

For a platform, migration or operational change, the scope should identify source records, backup responsibilities, validation, rollback or recovery decisions where appropriate, acceptance checks and the point at which the receiving environment becomes operational.

Incident and continuity communications

The engagement should identify how a suspected disclosure, access concern, publishing interruption or significant data issue is raised, assessed and communicated to the correct client and project contacts.

Working framework

Controls should match the engagement.

  1. 01

    Classify the work

    Identify the systems, records, sensitivity, users and risks relevant to the assignment.

  2. 02

    Agree the controls

    Define access, transfer, storage, supplier, approval and incident arrangements needed for that work.

  3. 03

    Verify before change

    Use inventories, test activity, validation and agreed acceptance criteria for material migrations or system changes.

  4. 04

    Review after delivery

    Confirm handover, access changes, outstanding risks, documentation and the next continuity actions.

Common questions

The details clients ask about.

Does this page promise a specific certification?+

No. Security controls and certifications should only be claimed where they are demonstrably in place. Project requirements are agreed against the actual service and client expectations.

Can a client use its own data-processing agreement?+

This can be considered as part of the engagement and procurement process.

What should we include in a security questionnaire?+

Send the relevant requirements after an initial confidential discussion. Harrowell can then respond against the actual proposed scope and systems involved.

Speak with Harrowell

Discuss security requirements.

Share the journal, programme or requirement. We’ll establish whether there is a suitable next step and the information needed for a considered discussion.

Start a conversation →