Data Protection and Cybersecurity
Our cybersecurity and data protection programs are shaped by regulatory requirements, past incidents, and evolving industry standards. We periodically update these programs based on our enterprise risk management (ERM) assessments, third-party audits and independent reviews, tabletop exercises, and other processes.
We are committed to strong data privacy standards and processes that protect individuals and their personal data. We collect and process personal data only to the extent necessary and with explicit consent when required. As generative artificial intelligence (GenAI) tools become more prevalent, we have published a GenAI policy providing clear guidance on acceptable use.
A key part of our strategy for managing cybersecurity risks is the ongoing assessment and testing of our policies, processes, and strategies through audits, assessments, tabletop exercises, threat modeling, vulnerability testing, and other exercises that evaluate the effectiveness of our controls and oversight and identify where they can improve. We engage third-parties to audit and independently review our cybersecurity measures, information security control environment, and operating effectiveness at least annually.