Authorised by the Financial Conduct Authority (FCA)

Security and data protection

Your payments and your customers’ data deserve more than a checkbox exercise. At London & Zurich, security isn’t a feature — it’s the foundation everything else is built on.

Why data security matters for your Direct Debit collections

When you collect recurring payments, you’re handling something that sits at the heart of your customers’ financial lives. A data breach, a failed mandate or a compliance oversight doesn’t just cost money — it costs trust. And trust, once lost, is difficult to rebuild.

That’s why we’ve built our platform around robust, independently verified security standards. We use multi-factor authentication (MFA), AWS infrastructure and 24/7 enhanced security monitoring — not because regulations require it, but because our clients and their customers deserve nothing less.

We operate as a Bacs Approved Bureau. Every measure is regularly reviewed against industry best practice, so you can collect with confidence and get on with running your business.

  • Every 5 minutes

    Continuous monitoring to identify and resolve potential system threats

  • 100%

    Your Direct Debit mandates protected by AWS security standards

     

Rigorous data protection

Our robust systems ensure sensitive information is securely stored and protected.

FCA regulation and Bacs approved bureau status

London & Zurich is authorised and regulated by the Financial Conduct Authority (FCA). As a Bacs Approved Bureau, we’re also subject to regular inspections — independently verifying that our security, confidentiality and service availability consistently meet required standards. That’s not just a badge. It’s a commitment we’re held to.

Independently verified cyber security

Our AWS infrastructure is monitored continuously and tested rigorously against the CIS AWS Foundations Benchmark — a globally recognised security standard. We carry Cyber Essentials Plus certification, verified by external cyber security experts. You get anti-malware scanning, endpoint protection and enhanced 24/7 security monitoring as standard.

Protecting your customers’ personal data

All personal data is stored and managed in line with GDPR requirements, on UK-based servers only. Access to our systems is controlled through multi-factor authentication (MFA), and we apply strict protocols around who can access what — and when. Your customers’ information is never stored carelessly or shared without cause.

A secure gateway for your Direct Debit collections

Our payment portal provides a secure environment for managing your Direct Debit mandates — from set-up through to collection. With bank-level security at every stage, full access controls and real-time visibility of your collections, you’re always in control. And so are we, on your behalf.

We never compromise on security and nor should you

Find out more about our secure Direct Debit collection services and let’s find the right solution for your business.