<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>data security Archives - SustainCase - Sustainability Magazine</title>
	<atom:link href="https://sustaincase.com/tag/data-security/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Insights on how you can protect the environment, maintain and increase the value of your company, through a structured CSR/Sustainability process with the use of the GRI Standards. Learn how Today&#039;s Best-Run Companies are achieving Economic, Social, and Environmental Success - and How You Can Too...</description>
	<lastBuildDate>Fri, 03 Mar 2023 11:47:18 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>
	<item>
		<title>Case study: How Mediclinic promotes information security</title>
		<link>https://sustaincase.com/case-study-how-mediclinic-promotes-information-security/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Wed, 15 Sep 2021 06:06:46 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Healthcare Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Mediclinic]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12898</guid>

					<description><![CDATA[<p>Mediclinic is an international private healthcare services group established in South Africa in 1983, with divisions in Switzerland, Southern Africa (South Africa and Namibia) and the UAE. , to conduct its business in a safe and secure manner. This case study is based on the 2020 Sustainable Development Report by Mediclinic published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-mediclinic-promotes-information-security/">Case study: How Mediclinic promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Mediclinic is an international private healthcare services group established in South Africa in 1983, with divisions in Switzerland, Southern Africa (South Africa and Namibia) and the UAE. <strong>Effective information and cyber security is paramount for Mediclinic</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Effective%20information%20and%20cyber%20security%20is%20paramount%20for%20Mediclinic&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-mediclinic-promotes-information-security%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a>, to conduct its business in a safe and secure manner.</p>
<p><strong>This case study is based on the</strong> <strong>2020</strong> <strong>Sustainable Development Report </strong><strong>by</strong><strong> Mediclinic </strong><strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/79636/" target="_blank" rel="noopener"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>With operations spanning multiple geographical areas and a global data network required in support of such scale, the protection of information assets is a top priority for Mediclinic. In order to promote information security Mediclinic took action to:</p>
<ul>
<li>implement a Group InfoSec programme</li>
<li>promote data privacy</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img fetchpriority="high" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="(max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Mediclinic has identified;</li>
<li>How Mediclinic proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Mediclinic to promote information security</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?             </strong></p>
<p>In its 2020 Sustainable Development Report Mediclinic identified a range of material issues, such as climate change, human rights, supply chain management, employee wellness and safety, waste and hazardous waste management. Among these, promoting information security stands out as a key material issue for Mediclinic.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups Mediclinic engages with:</strong></p>
<p>To identify and prioritise material topics Mediclinic engaged with its stakeholders through the following channels:<strong> </strong></p>
<table width="479">
<tbody>
<tr>
<td width="135"><strong>Stakeholder Group</strong></td>
<td width="344"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="135">Clients</p>
<p>&nbsp;</td>
<td width="344">·      Press Ganey® patient experience index surveys</p>
<p>·      Disclosure of clinical performance results</p>
<p>·      Systematic patient rounds during hospital stay</p>
<p>·      24-hour helplines</p>
<p>·      Health awareness days</p>
<p>·      Brochures and magazines</p>
<p>·      Websites and blogs offering health-related information</p>
<p>·       Social media</p>
<p>·      Client alliance programmes</td>
</tr>
<tr>
<td width="135">Communities</p>
<p>&nbsp;</td>
<td width="344">·      Corporate social responsibility (‘CSR’) initiatives</p>
<p>·      Supporting employee volunteer initiatives</p>
<p>·      Participation at national level in health training and education</p>
<p>·      Public-private initiatives and joint ventures at Hirslanden, Mediclinic Southern Africa and Mediclinic Middle East</p>
<p>·      Participation in the Public Health Enhancement Fund (‘PHEF’) in South Africa</td>
</tr>
<tr>
<td width="135">Employees and potential applicants</p>
<p>&nbsp;</td>
<td width="344">·      Annual Gallup® employee engagement surveys</p>
<p>·      Training and development</p>
<p>·      Growth opportunities</p>
<p>·      Intranet and social media</p>
<p>·      Newsflashes and regular electronic updates</p>
<p>·      Performance reviews and formal recognition</p>
<p>·      Leadership video conferences and roadshows</p>
<p>·      Employee wellness programmes</p>
<p>·      Magazines and newsletters</p>
<p>·      Non-executive director for workforce engagement</td>
</tr>
<tr>
<td width="135">Governments and authorities</p>
<p>&nbsp;</td>
<td width="344">·      Regular meetings</p>
<p>·      Participation in conferences and seminars</p>
<p>·      Representation on industry bodies and government boards</p>
<p>·      Participation in PPPs to enable healthcare, training and research</td>
</tr>
<tr>
<td width="135">Healthcare insurers</td>
<td width="344">·      Regular meetings regarding possible cost savings, clinical quality and healthcare delivery improvements</p>
<p>·      Annual tariff negotiations in a fair and transparent manner</td>
</tr>
<tr>
<td width="135">Industry associations</p>
<p>&nbsp;</td>
<td width="344">·      Membership of industry associations and representation on governing bodies</p>
<p>·      Participation in research commissioned by associations</p>
<p>·      Participation in conferences</td>
</tr>
<tr>
<td width="135">Industry partners</p>
<p>&nbsp;</td>
<td width="344">·      Direct engagement based on industry knowledge and market reputations</p>
<p>·      Cooperation and PPPs</p>
<p>·      Introductions through advisors</p>
<p>·      Industry conferences and events</td>
</tr>
<tr>
<td width="135">Investors</p>
<p>&nbsp;</td>
<td width="344">·      Investor Relations department</p>
<p>·      Shareholder annual general meetings</p>
<p>·      Financial results reporting and presentations</p>
<p>·      Investor meetings, roadshows and conferences</p>
<p>·      Operational site visits</p>
<p>·      Stock exchange announcements</p>
<p>·      Sell-side analyst and salesforce meetings</p>
<p>·      Corporate website</td>
</tr>
<tr>
<td width="135">Media</td>
<td width="344">·      Media releases</p>
<p>·      Press conferences</p>
<p>·      Financial results reporting and presentations</p>
<p>·      Interviews and responses to media enquiries</p>
<p>·      Paid advertisements</p>
<p>·      Monitoring industry-related news and proactive response</p>
<p>·      Social media</p>
<p>·      The Future of Healthcare blog</td>
</tr>
<tr>
<td width="135">Medical practitioners</td>
<td width="344">·      Regular meetings</p>
<p>·      Participation in hospital clinical committees</p>
<p>·      Continuous professional education events</p>
<p>·      Electronic newsletters</p>
<p>·      Networking and know-how exchange events at Hirslanden</p>
<p>·      Dedicated medical practitioner portals at Hirslanden and Mediclinic Southern Africa</p>
<p>·      Medical practitioner participation in hospital boards</p>
<p>·      Biannual engagement events at Mediclinic Middle East</p>
<p>·      Annual Research Day at Mediclinic Middle East</td>
</tr>
<tr>
<td width="135">Suppliers</td>
<td width="344">·      Regular meetings and business reviews</p>
<p>·      Contract negotiations and management post-signature</p>
<p>·      Electronic product approval processes</p>
<p>·      Product demonstrations and evaluations</p>
<p>·      Training on product specifications</p>
<p>·      Attendance at trade fairs</p>
<p>·      Factory visits</p>
<p>·      Annual Modern Slavery Act due diligence questionnaire</td>
</tr>
</tbody>
</table>
<p><strong>What actions were taken by</strong><strong> Mediclinic </strong><strong>to</strong> <strong>promote information security</strong><strong>?</strong></p>
<p>In its 2020 Sustainable Development Report Mediclinic reports that it took the following actions for promoting information security:</p>
<ul>
<li><strong>Implementing a Group InfoSec programme</strong></li>
<li>Mediclinic implements an elaborate Group InfoSec programme to optimally manage, monitor, detect and respond to InfoSec. The Group InfoSec Committee is represented by all divisions through dedicated Divisional Information Security Officers, while the proceedings of this committee are governed and informed through information security best practices sourced from several internationally acclaimed information and cyber security institutions. The Group InfoSec programme is based on the following guiding principles:
<ul>
<li>Adopting a risk-based approach towards cyber threats, which considers the likelihood of any risk materialising as well as its potential impact and measures for prevention and detection.</li>
<li>Expanding responsibility for cyber security beyond ICT to the whole organisation.</li>
<li>Ensuring end-to-end security across business processes, for mobile workers and teams as well as for data flows across geographic borders.</li>
<li>Implementing cyber-security-by-design, i.e. provision for effective protection against cyber threats from the outset when ICT capabilities are acquired or developed.</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Promoting data privacy</strong></li>
<li>Mediclinic reaffirmed its commitment to protecting the personal data of its stakeholders by embarking on an extensive Group-wide data privacy project to align and ensure compliance with all relevant data protection legislation, as may be applicable in the various countries of operation, including the EU’s General Data Protection Regulation (‘GDPR’), widely regarded as the gold standard for data protection. The Group Privacy and Data Protection Policy has been reviewed to ensure alignment to the GDPR standards and various initiatives are underway to ensure that core components are compliant with the GDPR framework. The project has been rolled out to the entire Group to ensure that other applicable data protection legislation is also complied with, or where no such specific legislations exist (i.e. Namibia), GDPR standards are complied with as a minimum.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Mediclinic, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Mediclinic: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-mediclinic-promotes-information-security/">Case study: How Mediclinic promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Vodafone Egypt promotes data security and privacy</title>
		<link>https://sustaincase.com/case-study-how-vodafone-egypt-promotes-data-security-and-privacy/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Fri, 18 Dec 2020 06:46:25 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Telecommunications]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<category><![CDATA[Vodafone Egypt]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12031</guid>

					<description><![CDATA[<p>&#160; Vodafone Egypt is a subsidiary of the Vodafone Group and the largest mobile network operator in Egypt, offering a range of communication services to both consumers and businesses all over Egypt. Vodafone Egypt is committed to processing personal data honestly, ethically, with integrity, and always in accordance with applicable laws and its values. This case study is based on the 2018-2020 Sustainability Report by Vodafone Egypt published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-vodafone-egypt-promotes-data-security-and-privacy/">Case study: How Vodafone Egypt promotes data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>Vodafone Egypt is a subsidiary of the Vodafone Group and the largest mobile network operator in Egypt, offering a range of communication services to both consumers and businesses all over Egypt. Vodafone Egypt is committed to processing personal data honestly, ethically, with integrity, and always in accordance with applicable laws and its values.</p>
<p><strong>This case study is based on the</strong><strong> 20</strong><strong>18-2020 </strong><strong>Sustainability Report by</strong> <strong>Vodafone Egypt</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/80533/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p><strong>Respect for privacy is a key component in the design, development, and delivery of Vodafone Egypt’s products and services.</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Respect%20for%20privacy%20is%20a%20key%20component%20in%20the%20design%2C%20development%2C%20and%20delivery%20of%20Vodafone%20Egypt%E2%80%99s%20products%20and%20services.&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-vodafone-egypt-promotes-data-security-and-privacy%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a> In order to promote data security and privacy Vodafone Egypt took action to:</p>
<ul>
<li>implement the Vodafone Group GDPR Programme</li>
<li>apply a Privacy Programme</li>
<li>implement a Privacy Policy</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="(max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Vodafone Egypt has identified;</li>
<li>How Vodafone Egypt proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Vodafone Egypt to promote data security and privacy</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2018-2020 Sustainability Report Vodafone Egypt identified a range of material issues, such as Covid-19 pandemic and crisis management, market leadership, business continuity, customer service excellence, community development. Among these, promoting data security and privacy stands out as a key material issue for Vodafone Egypt.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards              </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong> <strong>Vodafone Egypt</strong> <strong>engages with:                </strong></p>
<p>To identify and prioritise material topics Vodafone Egypt engaged with its stakeholders through the following channels:</p>
<table width="638">
<tbody>
<tr>
<td width="180"><strong>Stakeholder Group</strong></td>
<td width="459"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="180">Employees</td>
<td width="459">·       Daily direct communication</p>
<p>·       Digital Communication</p>
<p>·       Workplace and Workchat</p>
<p>·       Annual surveys</p>
<p>·       Events and newsletters</p>
<p>·       Emails</p>
<p>·       Meetings</p>
<p>·       Social media</td>
</tr>
<tr>
<td width="180">Consumer and enterprise customers</td>
<td width="459">·       Call centres</p>
<p>·       Satisfaction surveys</p>
<p>·       Website</p>
<p>·       Social media</p>
<p>·       Sales channels and retail stores</p>
<p>·       My Vodafone application</p>
<p>·       Advertisements</p>
<p>·       Digital marketing</td>
</tr>
<tr>
<td width="180">Shareholders, investors and Vodafone Group</td>
<td width="459">·       Financial information disclosure</p>
<p>·       Annual reports</p>
<p>·       Quarterly updates</p>
<p>·       General assembly meetings</p>
<p>·       Website</td>
</tr>
<tr>
<td width="180">Suppliers and partners</td>
<td width="459">·       Direct communication channels</p>
<p>·       Suppliers events</p>
<p>·       Trainings and awareness campaigns</p>
<p>·       Evaluation and qualification</td>
</tr>
<tr>
<td width="180">Regulator</p>
<p>&nbsp;</td>
<td width="459">·       Public forums</p>
<p>·       Meetings</p>
<p>·       Industry consultations</p>
<p>·       Financial information disclosure</p>
<p>·       Audits</p>
<p>·       Participation in public policies</td>
</tr>
<tr>
<td width="180">Local communities</td>
<td width="459">·       Vodafone Foundation’s activities</p>
<p>·       Employees volunteering activities</p>
<p>·       Community partnerships</p>
<p>·       Public participation</p>
<p>·       Social media</p>
<p>·       Events</p>
<p>·       Word of mouth</td>
</tr>
<tr>
<td width="180">Civil society and NGOs</td>
<td width="459">·       Vodafone Foundation’s activities</p>
<p>·       Events in universities</p>
<p>·       Partnerships and collaborations</p>
<p>·       Social media</td>
</tr>
</tbody>
</table>
<p><strong>What actions were taken by</strong> <strong>Vodafone Egypt</strong> <strong>to</strong> <strong>promote</strong> <strong>data security and privacy</strong><strong>?</strong></p>
<p>In its 2018-2020 Sustainability Report Vodafone Egypt reports that it took the following actions for promoting data security and privacy:</p>
<ul>
<li><strong>Implementing the </strong><strong>Vodafone Group GDPR Program</strong><strong>me</strong></li>
<li>Vodafone Egypt follows and implements the Vodafone Group GDPR (General Data Protection Regulation) Programme to ensure compliance with the new European GDPR, since it is mandated by Vodafone Group even for non-European Markets that do not primarily deal with European personal data and are not directly impacted by the new regulation. This direction ensures consistency, maturity and standards for the Vodafone Privacy Programme across Vodafone’s global footprint, to meet the requirements of the changing global regulatory and reputational privacy landscape. In addition, it puts Vodafone Egypt in the leading position in the Egyptian Market, being pioneers in this field and allows Vodafone Egypt to be the first compliant telecom operator with the intended Data Protection Law that is adopting GDPR, to be released soon in Egypt. Vodafone sets the required controls for protection against transactions with a sanctioned entity in breach of the sanctions legislation, potentially resulting in reputational damage, large fines, criminal penalties for individuals, and termination of the Vodafone Group’s financing arrangements. The objective is to make sure that Vodafone Egypt has a clear and robust set of controls in place, to minimise the risk of Vodafone breaching sanctions legislation.</li>
</ul>
<ul>
<li><strong>Applying a </strong><strong>Privacy Program</strong><strong>me</strong></li>
<li>Vodafone Egypt has initiated a customised Privacy Programme to ensure compliance with GDPR and with the planned Egyptian Data Protection Law through its various domains that correspond to GDPR’s requirements. The Privacy Programme assumes 10 basic commandments, reflecting Vodafone Egypt’s obligations according to the legal and global standards:
<ul>
<li>Design for Privacy</li>
<li>Protect Confidentiality</li>
<li>Collect relevant data</li>
<li>Provide a Privacy Notice</li>
<li>Provide Choices</li>
<li>Manage Data Carefully</li>
<li>No unauthorised disclosure</li>
<li>Secure Data</li>
<li>Protect Children’s Privacy</li>
<li>Respect Individual Rights</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Implementing a </strong><strong>Privacy Policy</strong></li>
<li>Vodafone Egypt’s Customer Privacy Policy concerns the handling of Data Subject’s personal information, including the collection, storage, access, use, updating, disclosure, disposal, destruction, or any other processing of such information. Gathering information from customers serves the purpose of operating Vodafone Egypt’s business and enhancing its customer experience. Vodafone Egypt’s Privacy Notice was updated in April 2020.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Vodafone Egypt, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Vodafone Egypt: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-vodafone-egypt-promotes-data-security-and-privacy/">Case study: How Vodafone Egypt promotes data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How BMO promotes customer data security and privacy</title>
		<link>https://sustaincase.com/case-study-how-bmo-promotes-customer-data-security-and-privacy/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Wed, 09 Dec 2020 06:46:09 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[BMO]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12008</guid>

					<description><![CDATA[<p>Established in 1817, BMO Financial Group is a highly diversified financial services provider based in North America, providing a broad range of personal and commercial banking, wealth management and investment banking products and services. , and to letting them know how BMO collects and uses that information. This case study is based on the 2018 Environmental, Social and Governance Report by BMO published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-bmo-promotes-customer-data-security-and-privacy/">Case study: How BMO promotes customer data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span style="font-weight: 400;"><a href="https://fbrh.co.uk/en/fbrh-four-assurance-standards" target="_blank" rel="noopener noreferrer"><img decoding="async" class="alignright size-full wp-image-12421" src="https://sustaincase.com/wp-content/uploads/2020/12/200x477-FBRH-Assurance-SustainCase-GRI-standards-sustainability-report.jpg" alt="" width="200" height="477" /><br />
</a></span></p>
<p>Established in 1817, BMO Financial Group is a highly diversified financial services provider based in North America, providing a broad range of personal and commercial banking, wealth management and investment banking products and services. <strong>BMO is committed to respecting and protecting the privacy and confidentiality of its customers’ personal information</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=BMO%20is%20committed%20to%20respecting%20and%20protecting%20the%20privacy%20and%20confidentiality%20of%20its%20customers%E2%80%99%20personal%20information&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-bmo-promotes-customer-data-security-and-privacy%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a>, and to letting them know how BMO collects and uses that information.</p>
<p><strong>This case study is based on the</strong><strong> 2018 Environment</strong><strong>al</strong><strong>, Social and Governance Report by</strong> <strong>BMO</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/62821/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>BMO actively invests in its people, technology and processes to improve its ability to prevent, detect, manage and respond to information security threats. In order to promote customer data security and privacy BMO took action to:</p>
<ul>
<li>evaluate the effectiveness of key controls</li>
<li>implement a Privacy Code</li>
<li>assess and monitor privacy risks</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) BMO has identified;</li>
<li>How <span style="font-weight: 400;">BMO</span><span style="font-weight: 400;"> </span>proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by <span style="font-weight: 400;">BMO</span><span style="font-weight: 400;"> </span>to promote customer data security and privacy</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2018 Environmental, Social and Governance Report BMO identified a range of material issues, such as business conduct, corporate governance, diversity and inclusion, employee engagement, talent attraction and retention. Among these, promoting customer data security and privacy stands out as a key material issue for BMO.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards              </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong> <strong>BMO engages with:</strong></p>
<table width="638">
<tbody>
<tr>
<td width="180"><strong>Stakeholder Group</strong></td>
<td width="459"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="180">Customers</td>
<td width="459">·       Advisory panels</p>
<p>·       Complaints management process (e.g., BMO’s Ombudsman Office)</p>
<p>·       Customer experience surveys</p>
<p>·       Dedicated mailboxes</p>
<p>·       Focus groups</p>
<p>·       Meetings, phone calls and email correspondence</p>
<p>·       Social media</p>
<p>·       Stakeholder ESG surveys</td>
</tr>
<tr>
<td width="180">Employees</td>
<td width="459">·       Dedicated mailboxes</p>
<p>·       Enterprise Resource Groups</p>
<p>·       Internal grievance mechanisms</p>
<p>·       Senior leader internal blogs</p>
<p>·       Stakeholder ESG surveys</p>
<p>·       Surveys (ad hoc surveys, annual employee survey)</p>
<p>·       Team meetings</p>
<p>·       Town halls</td>
</tr>
<tr>
<td width="180">Shareholder and</p>
<p>Investor Community</td>
<td width="459">·       Annual meeting</p>
<p>·       Disclosure of interim and annual financial results</p>
<p>·       Investor conferences</p>
<p>·       Investor Relations website</p>
<p>·       Management proxy circular</p>
<p>·       Meetings, phone calls and email correspondence</p>
<p>·       Quarterly conference calls</p>
<p>·       Stakeholder ESG surveys</p>
<p>·       Shareholder and Investor dialogue</td>
</tr>
<tr>
<td width="180">Government and Regulators</td>
<td width="459">·       Meetings, phone calls and email correspondence</p>
<p>·       Regulatory submissions</td>
</tr>
<tr>
<td width="180">Civil Society</p>
<p>&nbsp;</td>
<td width="459">·       Interviews</p>
<p>·       Meetings, phone calls and email correspondence</p>
<p>·       Questionnaires</p>
<p>·       Research papers (on key issues for BMO’s industry)</p>
<p>·       Stakeholder ESG surveys</p>
<p>·       Surveys (on key issues for BMO’s organisation)</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics BMO surveyed over 3,300 individuals – a representative sampling of employees, customers, investors, communities/civil society organisations (CSO) and BMO leaders in North America, Europe and Asia – to find out how they rated potential material topics on a four-point scale.</p>
<p><strong>What actions were taken by</strong> <strong>BMO</strong> <strong>to</strong> <strong>promote</strong> <strong>customer data security and privacy?</strong></p>
<p>In its 2018 Environmental, Social and Governance Report BMO reports that it took the following actions for promoting customer data security and privacy:</p>
<ul>
<li><strong>Evaluat</strong><strong>ing</strong><strong> the effectiveness of key controls </strong></li>
<li>To maintain its resilience in the face of cyber-attacks, BMO routinely evaluates the effectiveness of key controls through testing, reviewing best practices and benchmarking. In these evaluations, BMO refers to the ISO 27001 information security management standard and the U.S. National Institute of Standards and Technology cyber security framework. BMO also works with cyber security experts and suppliers to improve controls, strengthen internal resources and enhance its technological capabilities. BMO’s enterprise-wide information security programme sets out requirements for carrying out mandatory annual information security and privacy training for employees, complying with relevant regulations and reporting information security issues to management and the Board.</li>
</ul>
<ul>
<li><strong>Implementing a </strong><strong>Privacy Code</strong></li>
<li>In Canada, BMO’s Privacy Code outlines its commitment to its customers and the 10 key privacy principles BMO embraces. The Code also outlines the channels through which BMO’s customers can make and escalate privacy complaints. In other jurisdictions, BMO complies with all local requirements for providing mechanisms to raise privacy concerns. Additionally, BMO’s Privacy Office oversees a privacy risk governance programme, which sets out BMO’s policies and procedures for identifying, measuring, managing, mitigating and reporting privacy risk. All incidents involving suspected or actual breaches of privacy must be reported to the Privacy Office, which then manages BMO’s response to these incidents.</li>
</ul>
<ul>
<li><strong>Assessing and monitoring privacy risks</strong></li>
<li>Privacy risk is assessed and monitored in BMO’s supplier management and enterprise compliance programme The Privacy Office has a data-driven reporting system that tracks key metrics. The Office reports quarterly to the Audit and Conduct Review Committee of the Board of the Bank, and to the Audit Committee of BFC. It also provides reports on privacy issues to all BMO’s operating groups and corporate support areas, to help them understand their state of readiness for protecting privacy and to identify opportunities for improvement. In addition, to provide another layer of security for online banking customers, BMO invited them to download third–party software from its website that helps protect information against malware and fraudulent activity. When prompted through an online marketing campaign, 61,755 customers downloaded the software and in March 2018, during Fraud Awareness Month, BMO also posted a video about phishing on the Security Centre page of its website that attracted nearly 163,500 views, with 6,891 visitors viewing the complete video.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by BMO, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to BMO: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-bmo-promotes-customer-data-security-and-privacy/">Case study: How BMO promotes customer data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How United Internet promotes data privacy</title>
		<link>https://sustaincase.com/case-study-how-united-internet-promotes-data-privacy/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Mon, 01 Jun 2020 08:54:29 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Telecommunications]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<category><![CDATA[United Internet]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=10875</guid>

					<description><![CDATA[<p>With 23.85 million fee-based customer contracts and 37.00 million ad-financed free accounts, United Internet is a leading European internet specialist, owning one of Germany’s largest fiber-optic networks. As a responsible internet service provider, United Internet is committed to guaranteeing maximum security for its customers and effectively protecting their data against all unauthorised access. This case study is based on the 2018 Sustainability Report by United Internet published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-united-internet-promotes-data-privacy/">Case study: How United Internet promotes data privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>With 23.85 million fee-based customer contracts and 37.00 million ad-financed free accounts, United Internet is a leading European internet specialist, owning one of Germany’s largest fiber-optic networks. As a responsible internet service provider, United Internet is committed to guaranteeing maximum security for its customers and effectively protecting their data against all unauthorised access.</p>
<p><strong>This case study is based on the</strong><strong> 2018 Sustainability Report </strong><strong>by </strong><strong>United Internet</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/63115/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p><strong>United Internet is committed to making digitisation safe and secure and protecting personal data</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=United%20Internet%20is%20committed%20to%20making%20digitisation%20safe%20and%20secure%20and%20protecting%20personal%20data&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-united-internet-promotes-data-privacy%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a>, anchoring data privacy in its systems and processes. In order to promote data privacy United Internet took action to:</p>
<ul>
<li>apply extensive and clearly understandable rules</li>
<li>provide regular data privacy training</li>
<li>conduct systematic dialogue with the regulatory authorities</li>
<li>deploy complaint mechanisms</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) United Internet has identified;</li>
<li>How United Internet proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by United Internet to promote data privacy</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2018 Sustainability Report United Internet identified a range of material issues, such as customer satisfaction, environmental impact of products and services, non-discrimination, compliance and anti-corruption, diversity and equal opportunities. Among these, promoting data privacy stands out as a key material issue for United Internet.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong> <strong>United Internet </strong><strong>engages with:</strong></p>
<table width="261">
<tbody>
<tr>
<td width="261"><strong>Stakeholder Group</strong></td>
</tr>
<tr>
<td width="261">Customers</td>
</tr>
<tr>
<td width="261">Investors</td>
</tr>
<tr>
<td width="261">Employees</td>
</tr>
<tr>
<td width="261">Business partners</td>
</tr>
<tr>
<td width="261">Non-governmental organisations</td>
</tr>
<tr>
<td width="261">Politicians and associations</td>
</tr>
<tr>
<td width="261">Communities</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics United Internet carried out an online survey among its external stakeholders, to obtain their perspectives on material sustainability topics. Survey participants included representatives of investors /analysts, business partners /customers (including wholesale telecommunications partners and outsourcing service providers), other suppliers, and industry associations.</p>
<p><strong><a href="https://fbrh.co.uk/en/gri-certified-training/2-day-fbrh-gri-standards-certified-training-course-about" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright size-full wp-image-11761" src="https://sustaincase.com/wp-content/uploads/2020/08/sustainability-GRI-report-key-doc-for-success-ad-sustaincase-GRI-SDG-ESG-Sustainability-report-200x320px.jpg" alt="" width="200" height="320" /></a>What actions were taken by</strong><strong> United Internet </strong><strong>to</strong> <strong>promote data privacy</strong><strong>?</strong></p>
<p>In its 2018 Sustainability Report United Internet reports that it took the following actions for promoting data privacy:</p>
<ul>
<li><strong>Applying e</strong><strong>xtensive and clearly understandable rules</strong><strong> </strong></li>
<li>United Internet promotes compliance by designing its guidelines and processes in a way that makes data privacy requirements more transparent and easier to understand. United Internet’s information brochure Information Security and Data Privacy provides clear explanations on how to handle data and information in a responsible way. Among other things, this includes questions on compliance with the basic rules of data privacy, how e-mail and the internet can be used securely, and which aspects have to be observed when welcoming visitors to the company.</li>
</ul>
<ul>
<li><strong>Providing regular data privacy training</strong><strong> </strong></li>
<li>United Internet seeks to make sure that every employee plays an active role in protecting data against loss or unauthorised access and trains employees personally on data privacy regulations. In 2018, United Internet held a variety of training sessions on data privacy and information security, especially in connection with the EU’s new General Data Protection Regulation (GDPR). In addition to basic staff training, there were classroom sessions which specifically addressed the responsibilities of United Internet’s managers with regard to data privacy. United Internet’s Privacy department and Data Privacy Coordinators also give advice on issues concerning data privacy legislation, for example, in the field of product design and product development, or with regard to contractual agreements.</li>
</ul>
<ul>
<li><strong>Conducting</strong> <strong>systematic dialogue with the regulatory authorities</strong><strong> </strong></li>
<li>United Internet’s Privacy department is in regular contact with the relevant data privacy authorities, above all to process concerns from clients that have been forwarded by the regulatory authorities. United Internet also passes on reports of data privacy violations in accordance with GDPR (49 in the reporting year) to the Federal Network Agency (Bundesnetzagentur) and to the Federal Commissioner for Data Protection and Freedom of Information (Bundesbeauftragter für den Datenschutz und die Informationsfreiheit &#8211; BfDI). Additionally, members of the Privacy department regularly engage in discussions with the BfDI about the latest data privacy issues.</li>
</ul>
<ul>
<li><strong>Deploying complaint mechanisms</strong><strong> </strong></li>
<li>United Internet processes customer inquiries and customer complaints about data privacy through the trained staff of a special Customer Care department, in close coordination with the Privacy department, and responds to any incidents internally by adapting guidelines and sensitising employees where necessary. Employees also have the possibility to confer in confidence with the Compliance and Privacy departments in order to review any questions relating to data privacy which may arise during their activities. The Privacy department also carries out event-driven internal data privacy checks and is additionally involved in conducting audits to make sure United Internet’s service providers comply with data privacy regulations.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed?</strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Promote peaceful and inclusive societies for sustainable development, provide access to justice for all and build effective, accountable and inclusive institutions at all levels</li>
<li><strong>Business theme: </strong>Compliance with laws and regulations, Protection of privacy</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by United Internet, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to United Internet: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-united-internet-promotes-data-privacy/">Case study: How United Internet promotes data privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Idea Cellular promotes customer data security and privacy</title>
		<link>https://sustaincase.com/case-study-how-idea-cellular-promotes-customer-data-security-and-privacy/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Sun, 02 Feb 2020 16:36:03 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Telecommunications]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Idea Cellular]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=10410</guid>

					<description><![CDATA[<p>Idea Cellular is the third largest mobile phone operator in India, with a pan-India network that spans over 400,000 towns and villages, helping connect its nearly 200 million subscribers. and underlines its stand on the protection of the personal information of its employees, customers and relevant stakeholders. This case study is based on the 2018 Sustainable Business Report by Idea Cellular published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-idea-cellular-promotes-customer-data-security-and-privacy/">Case study: How Idea Cellular promotes customer data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Idea Cellular is the third largest mobile phone operator in India, with a pan-India network that spans over 400,000 towns and villages, helping connect its nearly 200 million subscribers. <strong>Protecting customer information is a key section of Idea Cellular’s privacy framework</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Protecting%20customer%20information%20is%20a%20key%20section%20of%20Idea%20Cellular%E2%80%99s%20privacy%20framework&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-idea-cellular-promotes-customer-data-security-and-privacy%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a> and underlines its stand on the protection of the personal information of its employees, customers and relevant stakeholders.</p>
<p><strong>This case study is based on the</strong><strong> 2018 Sustainable Business Report </strong><strong>by Idea Cellular published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/62231/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>Idea Cellular has established a company-wide privacy governance model that includes having policies, processes and checklists in place to ensure the continuing confidence of customers and stakeholders who entrust Idea Cellular with their personal information. In order to promote customer data security and privacy Idea Cellular took action to:</p>
<ul>
<li>carry out privacy risk assessments</li>
<li>implement the Data Privacy Framework</li>
<li>apply the decoy deception tool</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Idea Cellular has identified;</li>
<li>How Idea Cellular proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Idea Cellular to promote sustainable water use</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2018 Sustainable Business Report Idea Cellular identified a range of material issues, such as network reliability and availability, customer experience and satisfaction, product stewardship, digital inclusion. Among these, promoting customer data security and privacy stands out as a key material issue for Idea Cellular.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong><strong> Idea Cellular </strong><strong>engages with:</strong></p>
<table width="479">
<tbody>
<tr>
<td width="135"><strong>Stakeholder Group</strong></td>
<td width="344"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="135">Customers</p>
<p>&nbsp;</td>
<td width="344">·      Customer Satisfaction (CSAT) Survey</p>
<p>·      Net Promoter Survey</p>
<p>·      Spot surveys</td>
</tr>
<tr>
<td width="135">Employees</td>
<td width="344">·      Group &amp; Team level Employee Satisfaction survey</td>
</tr>
<tr>
<td width="135">Franchisees</td>
<td width="344">·      FSAT &amp; Mystery Shopping</td>
</tr>
<tr>
<td width="135">Rating Agencies</p>
<p>&nbsp;</td>
<td width="344">·      Annual financial statement along-with other details as may be required for Annual Review</td>
</tr>
<tr>
<td width="135">Shareholders &amp; Investors</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Annual General Meeting (AGM)</p>
<p>·      Investor meeting</p>
<p>·      Analyst meeting</p>
<p>·      Major Event update call</p>
<p>·      Earning call</td>
</tr>
<tr>
<td width="135">Regulators and Government authorities</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Various Compliances</p>
<p>·      Regular Meetings</p>
<p>·      Correspondence</p>
<p>·      Report Filings</td>
</tr>
<tr>
<td width="135">Suppliers</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Supplier Assessments</p>
<p>·      RFP</p>
<p>·      Vendor Surveys</p>
<p>·      Vendor performance evaluation feedback</p>
<p>·      Contract</p>
<p>·      Supplier training</p>
<p>·      Supplier rejection</td>
</tr>
<tr>
<td width="135">Lenders</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Annual financial statement along with Auditor’s Report</p>
<p>·      Quarterly Financial Statements</p>
<p>·      Network Rollout</p>
<p>·      Compliance Certificate</td>
</tr>
<tr>
<td width="135">Media</p>
<p>&nbsp;</td>
<td width="344">·      Media Events</p>
<p>·      Media Interactions</p>
<p>·      Press Releases</p>
<p>·      Letters to Editors</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics Idea Cellular engaged with its stakeholders through a questionnaire (suppliers and vendors) and surveys (customers and employees).</p>
<p><strong><a href="https://fbrh.co.uk/en/gri-certified-training/2-day-fbrh-gri-standards-certified-training-course-about" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright size-full wp-image-11761" src="https://sustaincase.com/wp-content/uploads/2020/08/sustainability-GRI-report-key-doc-for-success-ad-sustaincase-GRI-SDG-ESG-Sustainability-report-200x320px.jpg" alt="" width="200" height="320" /></a>What actions were taken by Idea Cellular to</strong> <strong>promote</strong> <strong>customer data security and privacy?</strong></p>
<p>In its 2018 Sustainable Business Report Idea Cellular reports that it took the following actions for promoting customer data security and privacy:</p>
<ul>
<li><strong>Carrying out </strong><strong>privacy risk assessments</strong></li>
<li>Idea Cellular conducts periodic privacy risk assessments to identify potential areas of risks and mitigation. ISMS (information security management system) practices are implemented to address such risks and compliance verifications are performed, through regular internal and external audits. Additionally, changes to applicable privacy laws, regulations, and policies from across various geographies are monitored and assessed and data privacy specific training programmes are designed and imparted to employees of customer accounts on all applicable privacy regulations.</li>
</ul>
<ul>
<li><strong>Implementing the </strong><strong>Data Privacy Framework </strong></li>
<li>Idea Cellular’s Data Privacy Framework consists of three major enterprise components: the people (customers, employees, third party vendors and suppliers), the business processes and the technology (enterprise platforms).
<ul>
<li>The enablers of data protection and privacy under the enterprise component of ‘people’ comprise of privacy policy and procedure, the privacy of organisation and the efforts of training and awareness about it.</li>
<li>The enablers under the enterprise component of ‘business processes’ include the Personally Identifiable Information (PII) elements inventory, the PII usage framework, the privacy impact assessment framework and the Process PII containers and privacy controls.</li>
<li>The enablers under the enterprise component of ‘technology’ are application privacy controls, Aadhaar data vault privacy controls and end user privacy controls.</li>
</ul>
</li>
<li>This Framework ensures a consistent approach to privacy across Idea Cellular and enables the company to have a robust privacy policy, improving privacy adherence levels. It also improves effectiveness in privacy incident management and helps Idea Cellular with improved contractual guidelines with vendors for privacy.<strong> </strong></li>
</ul>
<ul>
<li><strong>Applying the decoy deception tool</strong></li>
<li>Another privacy, cyber security tool deployed by Idea Cellular is the decoy deception tool, which creates virtual honeypots across the network mimicking real world systems. A honeypot is a closely monitored network decoy serving several purposes: it can distract adversaries from more valuable machines on a network, can provide early warning about new attack and exploitation trends, or allow in-depth examination of adversaries during and after exploitation of a honeypot. This helps to detect any infected systems which are scanning the entire network for further infections and entice even the stealthiest hacker into revealing themselves and drawing them away from real assets. This new generation of distributed decoy technologies that employ deception as a way to misdirect intruders and disrupt their activities at multiple points along the attack chain help delay attackers and force them to spend more time and effort figuring out what is real and whether to proceed with an attack or not.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed?</strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong> </strong></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Promote peaceful and inclusive societies for sustainable development, provide access to justice for all and build effective, accountable and inclusive institutions at all levels</li>
<li><strong>Business theme: </strong>Compliance with laws and regulations, Protection of privacy</li>
</ul>
<p><strong> </strong></p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a></p>
<p>&nbsp;</p>
<p>References:</p>
<p>1) This case study is based on published information by Idea Cellular, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Idea Cellular: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-idea-cellular-promotes-customer-data-security-and-privacy/">Case study: How Idea Cellular promotes customer data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How SGS promotes data security and privacy</title>
		<link>https://sustaincase.com/case-study-how-sgs-promotes-data-security-and-privacy/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Tue, 14 Jan 2020 15:53:15 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Other]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[SGS]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=10344</guid>

					<description><![CDATA[<p>With over 97,000 employees and a global network of more than 2,600 offices and laboratories, SGS is the world’s leading inspection, verification, testing and certification company, recognised as the global benchmark for quality and integrity. As a company that holds itself to the highest standards of professional behaviour, . This case study is based on the 2018 Corporate Sustainability Report by SGS published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-sgs-promotes-data-security-and-privacy/">Case study: How SGS promotes data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>With over 97,000 employees and a global network of more than 2,600 offices and laboratories, SGS is the world’s leading inspection, verification, testing and certification company, recognised as the global benchmark for quality and integrity. As a company that holds itself to the highest standards of professional behaviour, <strong>protecting personal data and compliance with associated privacy laws, are essential commitments for SGS</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=protecting%20personal%20data%20and%20compliance%20with%20associated%20privacy%20laws%2C%20are%20essential%20commitments%20for%20SGS&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-sgs-promotes-data-security-and-privacy%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a>.</p>
<p><strong>This case study is based on the</strong><strong> 2018 Corporate Sustainability Report</strong> <strong>by SGS published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/64798/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>On an ongoing basis, SGS works on managing, preventing, detecting and responding to security issues or risks identified, also taking a lead in shaping the future of the digital world as a Charter of Trust co-signatory, with the aim of strengthening cybersecurity to protect people, companies and infrastructure. In order to promote data security and privacy SGS took action to:</p>
<ul>
<li>promote cybersecurity</li>
<li>comply with the GDPR</li>
<li>provide training</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) SGS has identified;</li>
<li>How SGS proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by SGS to promote data security and privacy</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2018 Corporate Sustainability Report SGS identified a range of material issues, such as professional and operational integrity, talent acquisition and retention, market presence, diversity and equal opportunities, respect for human rights. Among these, promoting data security and privacy stands out as a key material issue for SGS.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong><strong> SGS </strong><strong>engages with:</strong><strong> </strong></p>
<table width="479">
<tbody>
<tr>
<td width="128"><strong>Stakeholder Group</strong></td>
<td width="351"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="128">Employees and suppliers</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Global employee engagement programme, CATALYST</p>
<p>·      SGS Sharepoint intranet portal</p>
<p>·      SGS Inside newsletter</p>
<p>·      Training programmes, videos and e-learning modules</p>
<p>·      SHINE Onboarding</p>
<p>·      Annual integrity training</p>
<p>·      Annual Safety Month</p>
<p>·      Spot the Orange Dot environmental behaviour campaign</p>
<p>·      Sustainability learning</p>
<p>·      Employee Representation Councils (e.g. European Works Council – Euroforum)</p>
<p>·      Supplier Self-Assessment</p>
<p>·      Supplier Code of Conduct</p>
<p>·      Supplier Audits</p>
<p>·      Supplier Innovation Programme</td>
</tr>
<tr>
<td width="128">Customers</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      One-to-one meetings</p>
<p>·      SGS-hosted conferences, seminars and webinars</p>
<p>·      Customer surveys, e.g. Voice of the Customer</p>
<p>·      White papers</p>
<p>·      Customer portal</td>
</tr>
<tr>
<td width="128">Governments and industries</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      SGS-hosted conferences, seminars and webinars</p>
<p>·      Membership meetings and events</p>
<p>·      White papers</p>
<p>·      Governments and Institutions business line</td>
</tr>
<tr>
<td width="128">Investors</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Annual General Meeting</p>
<p>·      SGS Investor Days</p>
<p>·      Meetings with investors and analysts</p>
<p>·      Responses to analyst questionnaires</td>
</tr>
<tr>
<td width="128">Communities and the planet</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Annual community survey to measure the impact of community investment</p>
<p>·      White papers</p>
<p>·      One-to-one meetings with NGOs and responses to questionnaires</td>
</tr>
<tr>
<td width="128">Consumers</td>
<td width="351">·      Certification and product labelling</p>
<p>·      Direct marketing and communication with certain B2C products</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics SGS carried out a survey among approximately 850 stakeholders in 52 countries, who included customers, senior managers, employees, suppliers, non-governmental organisations, ratings agencies, sustainability professionals and academics.</p>
<p><strong><a href="https://fbrh.co.uk/en/gri-certified-training/2-day-fbrh-gri-standards-certified-training-course-about" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright size-full wp-image-11761" src="https://sustaincase.com/wp-content/uploads/2020/08/sustainability-GRI-report-key-doc-for-success-ad-sustaincase-GRI-SDG-ESG-Sustainability-report-200x320px.jpg" alt="" width="200" height="320" /></a>What actions were taken by</strong><strong> SGS </strong><strong>to</strong> <strong>promote data security and privacy?</strong></p>
<p>In its 2018 Corporate Sustainability Report SGS reports that it took the following actions for promoting data security and privacy:</p>
<ul>
<li><strong>Promoting cybersecurity</strong></li>
<li>SGS has a framework and team in place to protect intellectual property, business services and customer data by governing and managing cybersecurity. It is the team’s responsibility to manage SGS IT Security and Anomaly Detection Systems, deploying new tools where needed while identifying vulnerabilities, threats and potential incidents. SGS utilises several detection systems that monitor its network, system infrastructure and applications. The most critical of these detection systems are monitored on a continuous basis, while the rest keep audit information for analysis in case of enquiries or suspicion of fraudulent activity. Response times to potential incidents are monitored according to specific timeframe requirements, depending on the severity of the threat and its criticality. Any major security issues are investigated by the IT Security Department and, once the root cause has been identified, the impact of any proposed mitigation is evaluated and communicated. To promote high levels of cybersecurity, technical standards ensuring a sound security baseline have been developed and SGS also runs a continuous security awareness programme. As part of this programme, SGS carries out IT security training several times a year, for all employees. Cybersecurity is also an area that is taken seriously when integrating the IT systems of acquisitions and partners into those of the SGS Group.</li>
</ul>
<ul>
<li><strong>Complying with the GDPR</strong></li>
<li>In 2018, SGS put in place measures and mechanisms to make sure it complies with the General Data Protection Regulation (GDPR). These are detailed in the SGS GDPR Compliance Statement, which describes the steps SGS is taking to update and expand data security and protection across the Group. It also outlines the dedicated internal team in place to develop and implement the GDPR roadmap &#8211; assessing gaps and implementing enhanced and new policies and procedures. At the same time, SGS launched the GDPRONLINE service, to support customers in complying with the EU regulation.</li>
</ul>
<ul>
<li><strong>Providing training</strong></li>
<li>In 2018, SGS rolled out global awareness training on data protection and privacy principles as an e-learning module. This training is relevant to all employees, whether they collect and process personal data or not. Accordingly, the aim is to reach all SGS employees and, currently, SGS’s awareness training has been rolled out to more than 93,000 employees, with a completion rate of 95%.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed?</strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong> </strong></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Promote peaceful and inclusive societies for sustainable development, provide access to justice for all and build effective, accountable and inclusive institutions at all levels</li>
<li><strong>Business theme: </strong>Compliance with laws and regulations, Protection of privacy</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a></p>
<p>&nbsp;</p>
<p>References:</p>
<p>1) This case study is based on published information by SGS, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to SGS: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-sgs-promotes-data-security-and-privacy/">Case study: How SGS promotes data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Sun Life promotes data security and privacy</title>
		<link>https://sustaincase.com/case-study-how-sun-life-promotes-data-security-and-privacy/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Thu, 22 Aug 2019 14:08:03 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Sun Life]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=9969</guid>

					<description><![CDATA[<p>Sun Life is a leading international financial services organisation providing insurance, wealth and asset management solutions to both individual and corporate clients in several markets worldwide. Being in the insurance and wealth management business, Sun Life handles sensitive personal information, from medical records to financial statements. Accordingly, This case study is based on the 2018 Sustainability Report by Sun Life published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-sun-life-promotes-data-security-and-privacy/">Case study: How Sun Life promotes data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Sun Life is a leading international financial services organisation providing insurance, wealth and asset management solutions to both individual and corporate clients in several markets worldwide. Being in the insurance and wealth management business, Sun Life handles sensitive personal information, from medical records to financial statements. Accordingly, <strong>Sun Life maintains and constantly invests in practices, processes and tools to safeguard its networks and clients’ personal information.</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Sun%20Life%20maintains%20and%20constantly%20invests%20in%20practices%2C%20processes%20and%20tools%20to%20safeguard%20its%20networks%20and%20clients%E2%80%99%20personal%20information.&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-sun-life-promotes-data-security-and-privacy%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a></p>
<p><strong>This case study is based on the </strong><strong>2018 Sustainability Report b</strong><strong>y</strong><strong> Sun Life</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/64570/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing. </strong></p>
<p>Sun Life’s business is dependent on maintaining a secure, confidential environment for its clients’, employees’ and other partners’ information, making sure it protects and manages it with great care. In order to promote data security and privacy Sun Life took action to:</p>
<ul>
<li>implement a security awareness programme</li>
<li>promote privacy protection</li>
<li>strengthen defences</li>
<li>promote cyber safety</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Sun Life has identified;</li>
<li>How Sun Life proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Sun Life to promote data security and privacy</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2018 Sustainability Report Sun Life identified a range of material issues, such as digital innovation, talent management, workforce wellness, diversity and inclusion, environmental impacts. Among these, promoting data security and privacy stands out as a key material issue for Sun Life.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards</strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The organization should identify its stakeholders, and explain how it has responded to their reasonable expectations.”</a></p>
<p>Stakeholders must be consulted in the process s of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups </strong><strong>Sun Life </strong><strong>engages with:   </strong></p>
<p>To identify and prioritise material topics Sun Life listened to and consulted with internal and external stakeholders throughout the year via diverse channels that included the following:</p>
<table width="479">
<tbody>
<tr>
<td width="119"><strong>Stakeholder Group</strong></td>
<td width="360"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="119">Clients</p>
<p>&nbsp;</td>
<td width="360">·      Client experience surveys</p>
<p>·      Focus groups</p>
<p>·      Other feedback channels (in-person, mobile apps, email, social media, call centres, online communities)</p>
<p>·      User testing website</td>
</tr>
<tr>
<td width="119">Employees/Advisors</p>
<p>&nbsp;</td>
<td width="360">·      Global Engagement Survey</p>
<p>·      Training and development activities</p>
<p>·      Internal social media and online forums</p>
<p>·      Manager/staff meetings, including formal performance appraisals</p>
<p>·      Town hall meetings with senior executives</p>
<p>·      Employee Ethics Hotline</p>
<p>·      Internal inclusion networks</p>
<p>·      Millennial think tank</td>
</tr>
<tr>
<td width="119">Shareholders, Investors, ESG Analysts</p>
<p>&nbsp;</td>
<td width="360">·      Investor Days</p>
<p>·      Annual meetings</p>
<p>·      Quarterly earnings conference calls</p>
<p>·      Webcast presentations</p>
<p>·      Participation in conferences</p>
<p>·      Meetings with investor groups</p>
<p>·      Participation in surveys</td>
</tr>
<tr>
<td width="119">Community Organisations and Members</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="360">·      Community outreach</p>
<p>·      Sponsorships</p>
<p>·      Employee and advisor giving and volunteerism</p>
<p>·      Media relations</p>
<p>·      Community consultations/meetings</td>
</tr>
<tr>
<td width="119">Suppliers</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="360">·      Request for proposal processes</p>
<p>·      Regular meetings and briefings</p>
<p>·      Ongoing relationship management</p>
<p>·      Supplier risk assessment</p>
<p>·      Supplier Diversity Programme</td>
</tr>
<tr>
<td width="119">Governments and Regulators, Industry Associations</p>
<p>&nbsp;</td>
<td width="360">·      Participation in consultation processes, conferences and events</p>
<p>·      Memberships and participation in industry/trade associations and working groups</p>
<p>·      Sun Life Political Action Committee (U.S.)</p>
<p>·      Ongoing dialogue</td>
</tr>
</tbody>
</table>
<p><strong><a href="https://fbrh.co.uk/en/gri-certified-training/2-day-fbrh-gri-standards-certified-training-course-about" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright size-full wp-image-11761" src="https://sustaincase.com/wp-content/uploads/2020/08/sustainability-GRI-report-key-doc-for-success-ad-sustaincase-GRI-SDG-ESG-Sustainability-report-200x320px.jpg" alt="" width="200" height="320" /></a>What actions were taken by</strong> <strong>Sun Life</strong> <strong>to promote data security and privacy</strong><strong>?</strong></p>
<p>In its 2018 Sustainability Report Sun Life reports that it took the following actions for promoting data security and privacy:</p>
<ul>
<li><strong>Implementing a </strong><strong>security awareness programme</strong></li>
<li>Sun Life’s global security awareness programme educates all employees on their security responsibilities and on Sun Life’s Security Policy. The programme includes compulsory security training, security alerts and bulletins, and additional training for specific groups, such as managers and system administrators. Sun Life’s security architecture includes firewalls, intrusion detection systems, network monitoring, encryption and other tools to prevent and detect cyber security attacks.</li>
</ul>
<ul>
<li><strong>Promoting privacy protection</strong></li>
<li>Sun Life’s Global Privacy Programme is embedded in its enterprise-wide risk management framework and includes various standards and processes. Additionally, Sun Life’s Global Privacy Commitment outlines principles to ensure personal information remains private and confidential. Sun Life employs privacy by design in its product development, and includes privacy clauses in contracts with third parties that handle client data. All employees receive privacy training and guidance through Sun Life’s privacy policies, to understand and fulfill Sun Life’s corporate privacy commitments and all relevant regulations.</li>
</ul>
<ul>
<li><strong>Strengthening defences </strong></li>
<li>To strengthen its defences, in 2018 Sun Life:
<ul>
<li>Initiated over 20 projects to increase its cyber security capabilities. Examples include enhancements to security alerting and incident response processes.</li>
<li>Continued to embed its privacy risk appetite statement and compass in internal processes, to better manage privacy risks and guide employees during the development and deployment of new products and initiatives.</li>
<li>Enhanced its privacy risk self-assessment processes to better identify risks and strengthen privacy controls in ongoing business processes, products and initiatives.<strong> </strong></li>
</ul>
</li>
</ul>
<ul>
<li><strong>Promoting cyber safety</strong></li>
<li>To promote cyber safety, in 2018 Sun Life:
<ul>
<li>Carried out monthly phishing simulation tests with every employee.</li>
<li>Broadened its cyber security training and education to include new ways of reaching and engaging employees. For example, Sun Life:
<ul>
<li>used Workplace by Facebook to deliver a live streaming event that featured Q&amp;As with executives, offering a forum for employees to ask questions about how to protect data and privacy both at work and at home; and</li>
<li>created topical blogs, posts and animated videos to bring cyber security issues to life. Topics addressed common questions and concerns raised by employees, such as online security, anti-virus protection, social media security and the Internet of Things.</li>
</ul>
</li>
</ul>
</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Promote peaceful and inclusive societies for sustainable development, provide access to justice for all and build effective, accountable and inclusive institutions at all levels</li>
<li><strong>Business theme: </strong>Compliance with laws and regulations, Protection of privacy</li>
</ul>
<p><strong> </strong></p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a></p>
<p>&nbsp;</p>
<p>References:</p>
<p>1) This case study is based on published information by Sun Life, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning.  If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Sun Life: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-sun-life-promotes-data-security-and-privacy/">Case study: How Sun Life promotes data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How State Street promotes client data protection and privacy</title>
		<link>https://sustaincase.com/case-study-how-state-street-ensures-client-data-protection-and-privacy/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Mon, 16 Apr 2018 06:00:05 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[State Street]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=6234</guid>

					<description><![CDATA[<p>As a global leader in asset management, and as the second oldest financial institution in the United States, with over 30,000 employees and offices in 30 countries around the globe, , through a range of information security and customer privacy programs and tools. This case study is based on the 2016 Corporate Responsibility Report by State Street published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-state-street-ensures-client-data-protection-and-privacy/">Case study: How State Street promotes client data protection and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><a href="https://fbrh.co.uk/en/gri-certified-training/2-day-fbrh-gri-standards-certified-training-course-about" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright size-full wp-image-11761" src="https://sustaincase.com/wp-content/uploads/2020/08/sustainability-GRI-report-key-doc-for-success-ad-sustaincase-GRI-SDG-ESG-Sustainability-report-200x320px.jpg" alt="" width="200" height="320" /></a></p>
<p>As a global leader in asset management, and as the second oldest financial institution in the United States, with over 30,000 employees and offices in 30 countries around the globe, <strong>State Street is committed to protecting and properly handling sensitive client information</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=State%20Street%20is%20committed%20to%20protecting%20and%20properly%20handling%20sensitive%20client%20information&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-state-street-ensures-client-data-protection-and-privacy%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a>, through a range of information security and customer privacy programs and tools.</p>
<p><strong>This case study is based on the </strong><strong>2016 Corporate Responsibility Report</strong> <strong>by</strong> <strong>State Street</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/search" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="http://database.globalreporting.org/reports/47592/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. </strong><strong>Through all case studies we aim to demonstrate what CSR/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="alignright wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" sizes="auto, (max-width: 618px) 100vw, 618px" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w" alt="Layout 1" width="618" height="84" /></a></p>
<p><strong>Abstract</strong></p>
<p>Building trust and confidence with clients, not leasτ by making sure client data is handled responsibly over its entire life cycle, is a top priority for State Street. In order to promote client data protection and privacy State Street took action to:</p>
<ul>
<li>use a software data classification tool</li>
<li>implement a Data Loss Protection Program</li>
<li>employ endpoint protection software</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>100 case studies. These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders</strong> (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) State Street has identified;</li>
<li>How State Street proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by State Street to promote client data protection and privacy</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2016 Corporate Responsibility Report State Street identified a range of material issues, such as compliance and business ethics, talent recruitment, development and retention, client satisfaction, wealth and income creation in society, ESG products and services, fair competition, local job creation, responsible sourcing. Among these, promoting client data protection and privacy stands out as a key material issue for State Street.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards</strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://g4.globalreporting.org/how-you-should-report/reporting-principles/principles-for-defining-report-content/stakeholder-inclusiveness/Pages/default.aspx" target="_blank" rel="noopener noreferrer">“The organization should identify its stakeholders, and explain how it has responded to their reasonable expectations.”</a></p>
<p>Stakeholders must be consulted in the process s of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups </strong><strong>State Street</strong><strong> engages with:   </strong></p>
<table width="347">
<tbody>
<tr>
<td width="347"><strong>Stakeholder Group</strong></td>
</tr>
<tr>
<td width="347">Shareholders</td>
</tr>
<tr>
<td width="347">Clients</td>
</tr>
<tr>
<td width="347">Employees</td>
</tr>
<tr>
<td width="347">Academics</td>
</tr>
<tr>
<td width="347">NGOs</td>
</tr>
<tr>
<td width="347">Investment analysts</td>
</tr>
<tr>
<td width="347">Business partners</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues </strong></p>
<p>To identify and prioritize material topics State Street conducted an online survey among employees, clients, investors, suppliers, NGOs and academics. The survey was supplemented with in-person and online workshops for employees and follow-up interviews with external stakeholders.</p>
<p><strong><a href="https://fbrh.co.uk/en/gri-certified-training/2-day-fbrh-gri-standards-certified-training-course-about" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright size-full wp-image-11761" src="https://sustaincase.com/wp-content/uploads/2020/08/sustainability-GRI-report-key-doc-for-success-ad-sustaincase-GRI-SDG-ESG-Sustainability-report-200x320px.jpg" alt="" width="200" height="320" /></a>What actions were taken by</strong> <strong>State Street</strong> <strong>to promote </strong><strong>client data protection and privacy?</strong></p>
<p>In its 2016 Corporate Responsibility Report State Street reports that it took the following actions for promoting client data protection and privacy:</p>
<ul>
<li><strong>Using a software data classification tool</strong></li>
<li>As accurate data classification is highly important for State Street, a software tool that helps classify information assets is deployed. The tool requires that emails and most common user-created documents fall into one of the following classifications: <em>Highly Confidential, Personal Sensitive Data, Confidential, Limited Access, Company Internal</em> or <em>General</em>. All information has to be properly labeled, distributed, stored and disposed of on the basis of this classification.</li>
</ul>
<ul>
<li><strong>Implementing a Data Loss Protection Program</strong></li>
<li>To monitor and prevent data leakage, State Street implements a Data Loss Protection Program. The Data Loss Protection Program includes tools that prevent endpoint data loss, web proxy controls, file transfer protocol (FTP) monitoring and internet usage monitoring. In addition, State Street has developed a corporate Data Loss Protection strategy. This strategy will help standardize and streamline such programs across the company.<a href="https://sustaincase.com/sustaincase-how-state-street-ensures-client-data-protection-and-privacy/" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright wp-image-7121 size-medium" src="https://sustaincase.com/wp-content/uploads/2018/04/F218010008-SC-State-Street-client-data-protection-and-privacy_E-pubs_BANNERS_a1-300x180.jpg" alt="" width="300" height="180" srcset="https://sustaincase.com/wp-content/uploads/2018/04/F218010008-SC-State-Street-client-data-protection-and-privacy_E-pubs_BANNERS_a1-300x180.jpg 300w, https://sustaincase.com/wp-content/uploads/2018/04/F218010008-SC-State-Street-client-data-protection-and-privacy_E-pubs_BANNERS_a1.jpg 333w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a></li>
</ul>
<ul>
<li><strong>Employing endpoint protection software</strong></li>
<li>To promote threat detection, as well as analysis of activities on endpoint devices (e.g. laptops, desktops, virtual desktops), State Street applies endpoint protection software. Additionally, through a Shadow IT identification program, State Street is able to detect and analyze data communicated to external sites, so as to further control unauthorized activity and data exfiltration.</li>
</ul>
<p><strong>Which GRI indicators/Standards have been addressed?</strong></p>
<p>The GRI indicator addressed in this case is: <strong>G4-PR8: </strong><a href="https://g4.globalreporting.org/specific-standard-disclosures/social/product-responsibility/customer-privacy/Pages/G4-PR8.aspx" target="_blank" rel="noopener noreferrer">Total number of substantiated complaints regarding breaches of customer privacy and losses of customer data </a>and the updated GRI Standard is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a></p>
<p>&nbsp;</p>
<p>References:</p>
<p>1) This case study is based on published information by State Street, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="http://www.fbrh.co.uk/en/global-reporting-initiative-gri-g4-guidelines-download-page" target="_blank" rel="noopener noreferrer">http://www.fbrh.co.uk/en/global-reporting-initiative-gri-g4-guidelines-download-page</a></p>
<p>3) <a href="https://g4.globalreporting.org/Pages/default.aspx" target="_blank" rel="noopener noreferrer">https://g4.globalreporting.org/Pages/default.aspx</a></p>
<p>4) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalre</a><a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">porting.org/standards/gri-standards-download-center/</a></p>
<p>Note to  State Street: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-state-street-ensures-client-data-protection-and-privacy/">Case study: How State Street promotes client data protection and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Deutsche Telekom promotes data privacy and security</title>
		<link>https://sustaincase.com/case-study-how-deutsche-telekom-ensures-data-privacy-and-security/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Mon, 18 Dec 2017 09:12:42 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Telecommunications]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[csr]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Deutsche Telekom]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=5832</guid>

					<description><![CDATA[<p>As a leading global information and telecommunications technology company, present in over 50 countries worldwide and with 165 million mobile customers, 28,5 million fixed-network lines and 18,5 million broadband lines, , in trying to gain customers’ trust. This case study is based on the 2015 Corporate Responsibility Report by Deutsche Telekom published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate that CSR/ sustainability reporting done responsibly is achieved by identifying a company’s most important impacts on the environment and stakeholders and by measuring, managing and changing.  Abstract [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-deutsche-telekom-ensures-data-privacy-and-security/">Case study: How Deutsche Telekom promotes data privacy and security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>As a leading global information and telecommunications technology company, present in over 50 countries worldwide and with 165 million mobile customers, 28,5 million fixed-network lines and 18,5 million broadband lines, <strong>promoting data privacy and security is a top priority for Deutsche Telekom</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=promoting%C2%A0data%20privacy%20and%20security%20is%20a%20top%20priority%20for%20Deutsche%20Telekom&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-deutsche-telekom-ensures-data-privacy-and-security%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a>, in trying to gain customers’ trust.</p>
<p><strong>This case study is based on the </strong><strong>2015 Corporate Responsibility Report</strong> <strong>by Deutsche Telekom published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/search" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="http://database.globalreporting.org/reports/37169/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate that CSR/ sustainability reporting done responsibly is achieved by identifying a company’s most important impacts on the environment and stakeholders and by measuring, managing and changing. </strong></p>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="alignright wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" sizes="auto, (max-width: 618px) 100vw, 618px" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w" alt="Layout 1" width="618" height="84" /></a></p>
<p><strong>Abstract</strong></p>
<p>According to a survey conducted by TNS Emnid for Deutsche Telekom in February 2016, nearly half of the German population (48%) has fallen victim to Internet crime. Guaranteeing data privacy and security is, thus, highly important for Deutsche Telekom. In order to promote data privacy and security Deutsche Telekom took action to:</p>
<ul>
<li>publish an annual data privacy and Transparency Report</li>
<li>provide employees with data privacy training</li>
<li>annually audit data privacy standards</li>
<li>raise employee awareness about data privacy</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>100 case studies. These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders</strong> (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Deutsche Telekom has identified;</li>
<li>How Deutsche Telekom proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Deutsche Telekom to promote data privacy and security</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2015 Corporate Responsibility Report Deutsche Telekom identified a range of material issues, such as ICT solutions for a low-carbon economy, service quality, ICT and child safety, cyber safety, talent acquisition, retention, development and staff reduction, climate change mitigation. Among these, promoting data privacy and security stands out as a key material issue for Deutsche Telekom.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards</strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://g4.globalreporting.org/how-you-should-report/reporting-principles/principles-for-defining-report-content/stakeholder-inclusiveness/Pages/default.aspx" target="_blank" rel="noopener noreferrer">“The organization should identify its stakeholders, and explain how it has responded to their reasonable expectations.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups Deutsche Telekom engages with:   </strong></p>
<table width="638">
<tbody>
<tr>
<td width="158"><strong>Stakeholder Group</strong></td>
<td width="480"><strong>               Method of engagement</strong></td>
</tr>
<tr>
<td width="158">General public / all stakeholders</td>
<td width="480">·         Annual CR report</p>
<p>·         Telekom.com/responsibility</p>
<p>·         We Care app magazine</td>
</tr>
<tr>
<td width="158">Employees</td>
<td width="480">·         engagement@telekom corporate citizenship program</p>
<p>·         Telekom Social Network</p>
<p>·         Internal events such as Guiding Principles Day</td>
</tr>
<tr>
<td width="158">Customers</td>
<td width="480">·         Free 24-hour service</p>
<p>·         Used cell-phone collection campaigns</p>
<p>·         Involvement in product development</td>
</tr>
<tr>
<td width="158">Suppliers</p>
<p>&nbsp;</td>
<td width="480">·         Development programs for suppliers</p>
<p>·         CR Stakeholder Forum</td>
</tr>
<tr>
<td width="158">Analysts and investors</td>
<td width="480">·         SRI roadshows</p>
<p>·         Webinars</td>
</tr>
<tr>
<td width="158">Non-governmental organizations (NGOs)</td>
<td width="480">·         Collaborations</p>
<p>·         Stakeholder dialog</td>
</tr>
<tr>
<td width="158">Politics</td>
<td width="480">·         Political advocacy at EU, Germany-wide and state level</p>
<p>·         Memberships, e.g., in the ZIRP Rhineland-Palatinate initiative for the future (www.zirp.de)</td>
</tr>
<tr>
<td width="158">Journalists</td>
<td width="480">·         Workshops, e.g., with Deutsche Journalistenschule students</td>
</tr>
<tr>
<td width="158">Compliance experts</td>
<td width="480">·         Exchange and membership in international and national organizations</td>
</tr>
<tr>
<td width="158">Corporate partners</td>
<td width="480">·         Collaborations and partnerships for the development of sustainable solutions</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritize material aspects Deutsche Telekom evaluated the results of an online stakeholder survey among 312 stakeholders (including customers, employees, analysts and investors, NGO representatives, suppliers and others).</p>
<p><strong>What actions were taken by Deutsche Telekom</strong><strong> to</strong> <strong>promote data privacy and security?</strong></p>
<p>In its 2015 Corporate Responsibility Report Deutsche Telekom reports that it took the following actions for promoting data privacy and security:</p>
<ul>
<li><strong>Publishing an annual data privacy and Transparency Report</strong></li>
<li>Deutsche Telekom was the first DAX-30 company to publish an annual data privacy report in 2008, regarding all relevant processes, and since 2011 has been also publishing an integrated data privacy and data security report. Additionally, since 2014 Deutsche Telekom has been publishing an annual Transparency Report, relating to the amount and types of information shared by the company with German and international security agencies.</li>
</ul>
<ul>
<li><strong>Providing employees with data privacy training</strong></li>
<li>Every two years Deutsche Telekom’s employees receive data privacy training, with specific trainings carried out in the company’s customer and human resources departments to minimize the risk of data abuse, which include online courses, presentations, and face-to-face courses on topics such as &#8220;Data privacy at call centers&#8221;.</li>
</ul>
<ul>
<li><strong>Annually auditing data privacy standards</strong></li>
<li>Deutsche Telekom carries out an annual data privacy audit, intended to measure and improve the company’s general data privacy standards. In 2015, 30 per cent of Deutsche Telekom’s employees were randomly chosen and interviewed online, with the data privacy audit accompanied by data privacy officers’ self-assessments at Deutsche Telekom’s national companies, relating to the implementation of the Binding Corporate Rules on Privacy.<a href="https://sustaincase.com/sustaincase-how-deutsche-telekom-ensures-data-privacy-and-security/" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright wp-image-6822 size-medium" src="https://sustaincase.com/wp-content/uploads/2017/12/F217110175-SC-Deutsche-Telekom-_E-pubs_BANNERS_a1-300x180.jpg" alt="" width="300" height="180" srcset="https://sustaincase.com/wp-content/uploads/2017/12/F217110175-SC-Deutsche-Telekom-_E-pubs_BANNERS_a1-300x180.jpg 300w, https://sustaincase.com/wp-content/uploads/2017/12/F217110175-SC-Deutsche-Telekom-_E-pubs_BANNERS_a1.jpg 333w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a></li>
</ul>
<ul>
<li><strong>Raising employee awareness about data privacy</strong></li>
<li>Deutsche Telekom launched, in January 2015, an international campaign aimed at increasing employee awareness of data privacy’s importance. Approximately 150 employees participated in the &#8220;Don&#8217;t give the data slob a chance&#8221; ideas competition, addressing the issue of dealing with data privacy lightly in a number of ways, including cartoons and videos.</li>
</ul>
<p><strong>Which GRI indicators/Standards have been addressed?</strong></p>
<p>The GRI indicator addressed in this case is: <strong>G4-PR8: </strong><a href="https://g4.globalreporting.org/specific-standard-disclosures/social/product-responsibility/customer-privacy/Pages/G4-PR8.aspx" target="_blank" rel="noopener noreferrer">Total number of substantiated complaints regarding breaches of customer privacy and losses of customer data </a>and the updated GRI Standard is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a></p>
<p>&nbsp;</p>
<p>References:</p>
<p>1) This case study is based on published information by Deutsche Telekom, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="http://www.fbrh.co.uk/en/global-reporting-initiative-gri-g4-guidelines-download-page" target="_blank" rel="noopener noreferrer">http://www.fbrh.co.uk/en/global-reporting-initiative-gri-g4-guidelines-download-page</a></p>
<p>3) <a href="https://g4.globalreporting.org/Pages/default.aspx" target="_blank" rel="noopener noreferrer">https://g4.globalreporting.org/Pages/default.aspx</a></p>
<p>4) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalre</a><a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">porting.org/standards/gri-standards-download-center/</a></p>
<p>&nbsp;</p>
<p>Note to Deutsche Telekom: With each case study we send out an email to your listed address in request for a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-deutsche-telekom-ensures-data-privacy-and-security/">Case study: How Deutsche Telekom promotes data privacy and security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: BT’s policies and measures to make its customers feel secure while using its technology and confident that BT will respect and protect their personal information</title>
		<link>https://sustaincase.com/case-study-bts-policies-and-measures-to-ensure-its-customers-feel-secure-while-using-its-technology-and-confident-that-bt-will-respect-and-protect-their-personal-information/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Sat, 28 Jan 2017 10:03:25 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Telecommunications]]></category>
		<category><![CDATA[BT]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[child safety online]]></category>
		<category><![CDATA[corporate citizenship]]></category>
		<category><![CDATA[csr]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">http://sustaincase.com/?p=625</guid>

					<description><![CDATA[<p>Telecommunications companies are a major target for cyber-attacks because they build, control and operate critical infrastructure that is widely used to communicate and store large amounts of sensitive data. As the UK’s number one broadband provider, keeping its own and its customers’ data secure, as well as protecting its customers’ devices, is a truly vital issue for BT. This case study is based on the 2014 Better Future Report by BT published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate that CSR/ sustainability reporting done responsibly is [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-bts-policies-and-measures-to-ensure-its-customers-feel-secure-while-using-its-technology-and-confident-that-bt-will-respect-and-protect-their-personal-information/">Case study: BT’s policies and measures to make its customers feel secure while using its technology and confident that BT will respect and protect their personal information</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Telecommunications companies are a major target for cyber-attacks because they build, control and operate critical infrastructure that is widely used to communicate and store large amounts of sensitive data. As the UK’s number one broadband provider, keeping its own and its customers’ data secure, as well as protecting its customers’ devices, is a truly vital issue for BT.</p>
<p><strong>This case study is based on the 2014 Better Future Report by BT </strong><strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/search" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="http://www.btplc.com/betterfuture/betterfuturereport/pdf/2014/Better_Future_report2014-complete_report.pdf" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate that CSR/ sustainability reporting done responsibly is achieved by identifying a company’s most important impacts on the environment and stakeholders and by measuring, managing and changing.</strong></p>
<p>Among a number of key material issues, keeping data secure and helping keep the internet safe, as well as respecting its customers’ privacy, is a matter of crucial significance for BT, as the UK’s number one broadband provider and for its stakeholders. After measuring and setting targets, BT took action to keep its network and customers’ devices secure, strengthen its ability to manage cyber-threats and raise data security standards. Also, in order to promote child safety online BT invested in filtering tools and developed new filtering services and programmes aimed at offering practical advice to both parents and children on online child safety. Last but not least, BT makes sure its employees understand the importance of its customers’ privacy through mandatory training, workshops and a consequence management system for violations of its privacy policies.</p>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>100 case studies. These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders</strong> (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) BT has identified;</li>
<li>How BT proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by BT to make its customers feel secure while using its technology and confident that BT will respect and protect their personal information</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2014 Better Future Report BT has identified a range of material issues, such as climate change &amp; energy, customer experience, pay &amp; benefits, health and safety, fibre &amp; Wi-Fi investment. Among these, online safety and privacy stands out as an issue of critical importance: in the digital age, staying one step ahead of potential cyber-attacks and using state-of-the-art technology to protect its own and its customers’ data, keeping customers’ devices secure, is key for any telecommunications company.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards<br />
</strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://g4.globalreporting.org/how-you-should-report/reporting-principles/principles-for-defining-report-content/stakeholder-inclusiveness/Pages/default.aspx" target="_blank" rel="noopener noreferrer">“The organization should identify its stakeholders, and explain how it has responded to their reasonable expectations.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups </strong><strong>BT</strong><strong> engages with:</strong></p>
<table width="347">
<tbody>
<tr>
<td width="347"><strong>Stakeholder Group</strong></td>
</tr>
<tr>
<td width="347">Customers</td>
</tr>
<tr>
<td width="347">Suppliers</td>
</tr>
<tr>
<td width="347">Investors</td>
</tr>
<tr>
<td width="347">Employees</td>
</tr>
<tr>
<td width="347">Government bodies</td>
</tr>
<tr>
<td width="347">Non-governmental organisations</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>BT regularly talks to people with a stake in its business to explain its approach and to understand what they expect of BT and how well they think it is doing. This takes place during its daily dealings with different groups, through online discussion forums, phone conversations, meetings, focus groups, social media and regular dialogue with expert membership groups, such as Business in the Community (BITC) and Chatham House. In 2013 BT introduced innovative techniques to crowdsource opinion to help the company incorporate more stakeholder views and greater analysis into its Better Future programme.</p>
<p>In 2013/14, BT sought additional stakeholder views by identifying and analysing public content from blogs, social media and online news sites, as well as on TV and radio. This technique gives the company a better understanding of issues that are important across all stakeholder groups and of who is influential in relation to those issues. BT monitors how these issues affect its business and Better Future programme, feeding the insights into its business decisions and materiality process. This analysis supplements more traditional stakeholder engagement such as meetings and focus groups to give BT access to a much broader stakeholder perspective.</p>
<p>In July 2013, BT ran its first online Better Future Forum, bringing together almost 200 sustainability experts from 22 countries to discuss the potential for business to make a positive overall contribution to the environment. A panel of 15 experts moderated by GlobeScan shared their thoughts and participants globally responded with almost 800 comments. Driven by these insights BT worked with WWF-UK, Forum for the Future, The Climate Group and leading UK and multinational companies to launch the Net Positive Movement, a diverse group working together to promote the Net Positive approach and encourage other businesses to focus on having a positive impact on the environment.</p>
<p><strong>What actions were taken to make BT’s customers feel secure using its technology and confident that BT will respect and protect their personal information? </strong></p>
<p>In its <em>Better Future Report 2014 </em>the following targets were set by BT regarding the protection of its own and its customers’ data, based on the Group’s approach to materiality – on taking action on what matters, where it matters:</p>
<ul>
<li><strong>Keeping BT’s network and customers’ devices secure</strong></li>
</ul>
<p>As well as protecting its own customers’ data, BT uses more than 70 years of experience to offer managed security services that help its enterprise customers protect their clients’ data. Its free advice and security software helps consumers to keep their devices secure from viruses – and their families safe while online. The company developed BT Protect, which helps prevent infection from all sorts of nasty viruses and spyware by warning a customer if he/she is about to visit a potentially harmful website whenever he/she is browsing online using his/her BT broadband connection. Behind the scenes, BT’s Security Operations Centres monitor its customers’ devices 24 hours a day, 365 days a year, to spot breaches and potential weaknesses and to keep its network secure.</p>
<ul>
<li><strong>Combating cyber-threats </strong></li>
</ul>
<p>In 2013 BT launched a cyber-security operations centre to monitor all internal networks and cyber related incidents round the clock. The centre helped launch BT Sport safely and securely in August 2013 and provided enhanced network and systems monitoring during high-profile UK Premiership matches.</p>
<ul>
<li><strong>Raising data security standards</strong></li>
</ul>
<p>BT collaborated with other internet service providers and UK Government to develop a set of Guiding Principles on Cyber Security, which were published in December 2013. As voluntary signatories, BT committed to help its customers understand online threats and to provide tools and advice on security software to help keep them safe while online.</p>
<ul>
<li><strong>Promoting child safety online</strong></li>
</ul>
<p>Since 2010, BT has invested more than £5m in filtering tools and education to help children and young adults use the internet safely. In 2013 it launched a new filter, BT Parental Controls, which gives new customers the option to install network-based parental controls as standard. To help its Wi-Fi site partners stop pornographic and child abuse material being viewed on their premises, BT launched BT Wi-Fi Protect. This free filtering service is used by 50 of its Wi-Fi partners (representing 90% of its hotspot traffic) and all new partners receive this service as standard, unless they opt out. In 2013/14, BT launched The Right Click: Internet Safety Matters in partnership with UNICEF – a three-year programme providing practical advice about online child safety to up to 35,000 teachers, parents and children in the UK. Working in partnership with Sky, TalkTalk and Virgin Media, BT also created Internet Matters – an organisation that promotes child online safety to parents. The supporting campaign emphasises the message ‘Learn about it. Talk about it. Deal with it.’ In 2013 BT increased its annual funding to the Internet Watch Foundation (IWF), a hotline for reporting criminal child abuse content, from £40,000 to £75,000. To deter users from accessing child abuse material identified by IWF, BT also launched a new ‘splash page’ that makes clear why access has been denied, warns users that viewing indecent images of children is a criminal offence and provides the number of Stop it Now!, a confidential helpline for those with concerning or illegal internet use.<a href="https://sustaincase.com/sustaincase-bts-policies-and-measures-to-ensure-its-customers-feel-secure-while-using-its-technology-and-confident-that-bt-will-respect-and-protect-their-personal-information/" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright wp-image-3657 size-medium" src="https://sustaincase.com/wp-content/uploads/2017/01/FF21611027-SC-BT_E-pubs_BANNERS_vk2-300x180.jpg" alt="" width="300" height="180" srcset="https://sustaincase.com/wp-content/uploads/2017/01/FF21611027-SC-BT_E-pubs_BANNERS_vk2-300x180.jpg 300w, https://sustaincase.com/wp-content/uploads/2017/01/FF21611027-SC-BT_E-pubs_BANNERS_vk2.jpg 333w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a></p>
<ul>
<li><strong>Respecting BT customers privacy</strong></li>
</ul>
<p>BT ensures its employees understand the importance of privacy and their role in protecting its customers’ personal information. [tweetthis]<strong>All of BT’s 87,800 employees participate in mandatory privacy training</strong>[/tweetthis], and BT conducts awareness-raising workshops for employees across its operations who are directly involved in managing customers’ data. BT recognises that there is always room for improvement and has implemented a consequence management system for violations of its privacy policies to help employees learn from their mistakes.</p>
<p><strong>Which GRI indicators/Standards have been addressed?</strong></p>
<p>The GRI indicator addressed in this case is:<strong> G4-PR8: </strong><a href="https://g4.globalreporting.org/specific-standard-disclosures/social/product-responsibility/customer-privacy/Pages/G4-PR8.aspx" target="_blank" rel="noopener noreferrer">Total number of substantiated complaints regarding breaches of customer privacy and losses of customer data </a>and the updated GRI Standard is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p>&nbsp;</p>
<p>References:</p>
<p>1) This case study was compiled using published information by BT which is located at the links below. For the sake of readability, we did not use brackets or ellipses but made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original please revert to the following links:</p>
<p><a href="http://www.btplc.com/betterfuture/betterfuturereport/pdf/2014/Better_Future_report2014-complete_report.pdf" target="_blank" rel="noopener noreferrer">http://www.btplc.com/betterfuture/betterfuturereport/pdf/2014/Better_Future_report2014-complete_report.pdf </a>(May 2014)</p>
<p><a href="http://www.btplc.com/Purposefulbusiness/Safetyandsecurity/Privacyandsecurity/" target="_blank" rel="noopener noreferrer">http://www.btplc.com/Purposefulbusiness/Safetyandsecurity/Privacyandsecurity/ </a>(April 2016)</p>
<p>2) <a href="http://www.fbrh.co.uk/en/global-reporting-initiative-gri-g4-guidelines-download-page" target="_blank" rel="noopener noreferrer">http://www.fbrh.co.uk/en/global-reporting-initiative-gri-g4-guidelines-download-page</a></p>
<p>3) <a href="https://g4.globalreporting.org/Pages/default.aspx" target="_blank" rel="noopener noreferrer">https://g4.globalreporting.org/Pages/default.aspx</a></p>
<p>4) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/ </a></p>
<p>Note to BT: With each case study we send out an email to your listed address in request for a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-bts-policies-and-measures-to-ensure-its-customers-feel-secure-while-using-its-technology-and-confident-that-bt-will-respect-and-protect-their-personal-information/">Case study: BT’s policies and measures to make its customers feel secure while using its technology and confident that BT will respect and protect their personal information</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
