76
APPENDICES
INTRODUCTION
SUSTAINABILITY OBJECTIVES AND STRATEGY
ENVIRONMENTAL
SOCIAL
POLICIES AND TRANSPARENT REPORTING
CUSTOMER PRIVACY INFORMATION
Privacy Protection
ESRT’s privacy protection policy applies to our entire operations, including suppliers. Our cybersecurity department and Chief Technology Officer are responsible for privacy issues. The privacy policy system is embedded in group- wide risk or compliance management. Breach of the company’s privacy protection policy and security system will result in disciplinary action, up to and including termination. We conduct internal audits of privacy policy compliance. ESRT informs our customers regarding privacy protection issues including the nature of information captured, the use of the collected information, and the possibility for customer to decide how private data is collected, used, retained and processed. We allow our customers on opt-out option and opt-in consent is required. We do not request access to hold their data nor request for their data to be transferred to other service providers. We request their data to be corrected and deleted. Information is kept on corporate files for seven years and the time length is shared. Information encrypted and account access only given related to role. We have a third-party disclosure policy. We monitor the percentage of users whose customer data is used for internal secondary purposes.
Customer Privacy Information
EMPIRE STATE REALTY TRUST: 2023 SUSTAINABILITY REPORT
Made with FlippingBook - Online magazine maker