GN Store Nord
ESRS disclosure: ESRS S4 \ DR S4-1 \ Paragraph 17
Tags Tree
- Provide a detailed account of whether and how your company's policies concerning consumers and end-users are aligned with internationally recognized instruments pertinent to these groups, such as the United Nations Guiding Principles on Business and Human Rights. Additionally, disclose any instances of non-compliance with the UN Guiding Principles on Business and Human Rights, the ILO Declaration on Fundamental Principles and Rights at Work, or the OECD Guidelines for Multinational Enterprises that have been identified within your downstream value chain, specifying the nature of such cases, if applicable.
-
Question Id: S4-1_06
GN has implemented several policies, actions, and targets for managing product safety and data privacy related risks. As data privacy and product safety are strictly regulated by international and local laws, targets are mainly determined based on these regulations.
Report Date: 4Q2024Relevance: 35%
- Provide a detailed account of whether and how your company's policies concerning consumers and/or end-users align with internationally recognized instruments, specifically the United Nations (UN) Guiding Principles on Business and Human Rights. Additionally, disclose the extent to which instances of non-compliance with the UN Guiding Principles on Business and Human Rights, the ILO Declaration on Fundamental Principles and Rights at Work, or the OECD Guidelines for Multinational Enterprises, involving consumers and/or end-users, have been identified within your downstream value chain. If applicable, include an indication of the nature of these cases.
-
Question Id: S4-1_07
GN has implemented several policies, actions, and targets for managing product safety and data privacy related risks. As data privacy and product safety are strictly regulated by international and local laws, targets are mainly determined based on these regulations.
Report Date: 4Q2024Relevance: 50%
- Has the undertaking taken action to provide or enable remedy concerning an actual material impact on consumers and end-users? Describe whether and how such actions have been implemented, including the effectiveness of these measures.
-
Question Id: S4-4_02
To address the material risk related to data privacy, our Data Privacy Code of Conduct and Data Privacy Policy are created to ensure that all GN employees have the knowledge to mitigate risks and to ensure that GN complies with relevant data protection regulations as the General Data Protection Regulation (GDPR). Our Data Privacy Code of Conduct guides how all employees process and protect the consumer and end-user data that GN handles. The Data Privacy Policy also describes processes for collecting, processing, and protecting consumer and end-user data and applies to all employees in GN.
A key ongoing initiative to ensure compliance with our Data Privacy Policy and GDPR regulation is a GDPR risk assessment. As part of this, questionnaires are sent to business process owners via our compliance application. The aim with the initiative is to assess data privacy risks across all business processes including alignment with the EU AI Act, where AI systems and models are used in connection with personal data.
Another ongoing initiative to contribute to compliance with our Data Privacy Policy and work procedures is 'zero trust technologies'. It assumes that individuals, devices, and services that are attempting to access company resources, even if inside the network, cannot automatically be trusted. The initiative has resulted in significantly reducing any intruders’ ability to breach GN systems and data.
Report Date: 4Q2024Relevance: 60%