The case for CSR/ Sustainability Reporting Done Responsibly


IDENTIFY - MEASURE - MANAGE - CHANGE

Insights on how you can protect the environment, maintain and increase the value of your company, through a structured process.

Insights on how you can protect the environment, maintain and increase the value of your company, through a structured process.

Home / case studies / Case study: How Vodafone Egypt promotes data security and privacy

Case study: How Vodafone Egypt promotes data security and privacy

Vodafone Egypt is a subsidiary of the Vodafone Group and the largest mobile network operator in Egypt, offering a range of communication services to both consumers and businesses all over Egypt. Vodafone Egypt is committed to processing personal data honestly, ethically, with integrity, and always in accordance with applicable laws and its values.

This case study is based on the 2018-2020 Sustainability Report by Vodafone Egypt published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.

Layout 1Abstract

Respect for privacy is a key component in the design, development, and delivery of Vodafone Egypt’s products and services.  Tweet This! In order to promote data security and privacy Vodafone Egypt took action to:

  • implement the Vodafone Group GDPR Programme
  • apply a Privacy Programme
  • implement a Privacy Policy

What are the material issues the company has identified?

In its 2018-2020 Sustainability Report Vodafone Egypt identified a range of material issues, such as Covid-19 pandemic and crisis management, market leadership, business continuity, customer service excellence, community development. Among these, promoting data security and privacy stands out as a key material issue for Vodafone Egypt.

Stakeholder engagement in accordance with the GRI Standards             

The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:

“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”

Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.

Key stakeholder groups Vodafone Egypt engages with:               

To identify and prioritise material topics Vodafone Egypt engaged with its stakeholders through the following channels:

Stakeholder Group                Method of engagement
Employees ·       Daily direct communication

·       Digital Communication

·       Workplace and Workchat

·       Annual surveys

·       Events and newsletters

·       Emails

·       Meetings

·       Social media

Consumer and enterprise customers ·       Call centres

·       Satisfaction surveys

·       Website

·       Social media

·       Sales channels and retail stores

·       My Vodafone application

·       Advertisements

·       Digital marketing

Shareholders, investors and Vodafone Group ·       Financial information disclosure

·       Annual reports

·       Quarterly updates

·       General assembly meetings

·       Website

Suppliers and partners ·       Direct communication channels

·       Suppliers events

·       Trainings and awareness campaigns

·       Evaluation and qualification

Regulator

 

·       Public forums

·       Meetings

·       Industry consultations

·       Financial information disclosure

·       Audits

·       Participation in public policies

Local communities ·       Vodafone Foundation’s activities

·       Employees volunteering activities

·       Community partnerships

·       Public participation

·       Social media

·       Events

·       Word of mouth

Civil society and NGOs ·       Vodafone Foundation’s activities

·       Events in universities

·       Partnerships and collaborations

·       Social media

What actions were taken by Vodafone Egypt to promote data security and privacy?

In its 2018-2020 Sustainability Report Vodafone Egypt reports that it took the following actions for promoting data security and privacy:

  • Implementing the Vodafone Group GDPR Programme
  • Vodafone Egypt follows and implements the Vodafone Group GDPR (General Data Protection Regulation) Programme to ensure compliance with the new European GDPR, since it is mandated by Vodafone Group even for non-European Markets that do not primarily deal with European personal data and are not directly impacted by the new regulation. This direction ensures consistency, maturity and standards for the Vodafone Privacy Programme across Vodafone’s global footprint, to meet the requirements of the changing global regulatory and reputational privacy landscape. In addition, it puts Vodafone Egypt in the leading position in the Egyptian Market, being pioneers in this field and allows Vodafone Egypt to be the first compliant telecom operator with the intended Data Protection Law that is adopting GDPR, to be released soon in Egypt. Vodafone sets the required controls for protection against transactions with a sanctioned entity in breach of the sanctions legislation, potentially resulting in reputational damage, large fines, criminal penalties for individuals, and termination of the Vodafone Group’s financing arrangements. The objective is to make sure that Vodafone Egypt has a clear and robust set of controls in place, to minimise the risk of Vodafone breaching sanctions legislation.
  • Applying a Privacy Programme
  • Vodafone Egypt has initiated a customised Privacy Programme to ensure compliance with GDPR and with the planned Egyptian Data Protection Law through its various domains that correspond to GDPR’s requirements. The Privacy Programme assumes 10 basic commandments, reflecting Vodafone Egypt’s obligations according to the legal and global standards:
    • Design for Privacy
    • Protect Confidentiality
    • Collect relevant data
    • Provide a Privacy Notice
    • Provide Choices
    • Manage Data Carefully
    • No unauthorised disclosure
    • Secure Data
    • Protect Children’s Privacy
    • Respect Individual Rights
  • Implementing a Privacy Policy
  • Vodafone Egypt’s Customer Privacy Policy concerns the handling of Data Subject’s personal information, including the collection, storage, access, use, updating, disclosure, disposal, destruction, or any other processing of such information. Gathering information from customers serves the purpose of operating Vodafone Egypt’s business and enhancing its customer experience. Vodafone Egypt’s Privacy Notice was updated in April 2020.

Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed?

The GRI Standard addressed in this case is: Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data

Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:

 

80% of the world’s 250 largest companies report in accordance with the GRI Standards

SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.

Research by well-recognised institutions is clearly proving that responsible companies can look to the future with optimism.



FBRH GRI Standards Certified, IEMA & CIM recognised Sustainability Course | Venue: London LSE

By registering for the next 2-day FBRH GRI Standards Certified, IEMA & CIM recognised course you will be taking the first step in gaining the many benefits of sustainability reporting.

Most importantly, you will gain the knowledge to use the GRI Standards, project manage your own first-class sustainability report and:

  • Identify your most important impacts on the Environment, Economy and Society
  • Begin taking solid, focused, all-round sustainability action ASAP

 

References:

1) This case study is based on published information by Vodafone Egypt, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:

http://database.globalreporting.org/

2) https://www.globalreporting.org/standards/gri-standards-download-center/

Note to Vodafone Egypt: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please contact us.