ISS AS
ESRS disclosure: ESRS S4 \ DR S4-1 \ Paragraph 15
Tags Tree
- Provide detailed information on your organization's policies designed to manage material impacts, risks, and opportunities concerning consumers and end-users. Specify whether these policies are applicable to specific groups or encompass all consumers and end-users, in alignment with ESRS 2 MDR-P on managing material sustainability matters.
-
Question Id: S4-1_01
We have not adopted policies specifically related to our end-users, but capture the interests of end-users as part of our data ethics, data protection and information security policies.
Our Data Ethics Policy provides the overarching framework for how we work with and manage data. It is aligned with the Charter of Fundamental Rights of the European Union and includes principles on the areas of self-determination, human dignity, responsibility, equality and fairness, progressiveness, diversity and inclusion and accountability. Further, it sets parameters around our use of AI systems. The policy applies to all ISS employees as well as suppliers and business partners that have access to data on behalf of or in collaboration with ISS. Implementation of the policy is the joint responsibility of our Group Data Privacy & Legal Compliance function and our Global IT, Digitalisation & Services function.
We collect and process personal data in accordance with our Group Data Protection Policy. It adheres globally to the principles of the EU General Data Protection Regulation, and additional higher standards, if required by local law and sets requirements around data protection principles, transfer of personal data, data breach, training & awareness and control & assurance. The Group Data Protection Policy is owned by our Group Legal function and our Group Data Protection Manager.
Where our Data Protection Policy establishes procedures for how we work with and manage personal data, our Group Information Security Policy aims at upholding the integrity of our IT ecosystem and among others prevent unauthorised access to personal data. It does so through an information security management system aligned with the ISO27001:2022 standard and is supported by documented procedures around organisational controls, employee controls, physical controls and technological controls.
Report Date: 4Q2024Relevance: 60%
- Provide a detailed account of the methods and channels utilized to communicate your policies to the relevant individuals, groups, or entities. This includes those expected to implement the policies, such as employees, contractors, and suppliers, as well as those with a vested interest in their execution, like workers and investors. Describe the tools and mediums employed, such as flyers, newsletters, dedicated websites, social media, face-to-face interactions, and workers' representatives, to ensure policy accessibility and comprehension among diverse audiences. Additionally, elucidate the strategies employed to identify and eliminate potential dissemination barriers, including translation into pertinent languages or the use of visual aids.
-
Question Id: S4-1_09
Our Group Data Protection Policy described above establishes a firm process for handling incidents of data breaches, which is the key enabler for us to provide remediation for negative impacts to end-users.
Just as for value chain workers our whistleblower channel is available to end-users for raising concerns though we would consider it a more natural and straight forward approach for end-users to raise concerns via their employer (our customer). During 2024 we have not received data privacy concerns from end-users via our whistleblower channel. For details on our whistleblower channel and Speak Up Policy, see S1-3 and G1-1. Our Speak Up Policy is publicly available to end-users at www.issworld.com.
Report Date: 4Q2024Relevance: 20%