2023 Sustainability Report: Empire State Realty Trust

76

APPENDICES

INTRODUCTION

SUSTAINABILITY OBJECTIVES AND STRATEGY

ENVIRONMENTAL

SOCIAL

POLICIES AND TRANSPARENT REPORTING

CUSTOMER PRIVACY INFORMATION

Privacy Protection

ESRT’s privacy protection policy applies to our entire operations, including suppliers. Our cybersecurity department and Chief Technology Officer are responsible for privacy issues. The privacy policy system is embedded in group- wide risk or compliance management. Breach of the company’s privacy protection policy and security system will result in disciplinary action, up to and including termination. We conduct internal audits of privacy policy compliance. ESRT informs our customers regarding privacy protection issues including the nature of information captured, the use of the collected information, and the possibility for customer to decide how private data is collected, used, retained and processed. We allow our customers on opt-out option and opt-in consent is required. We do not request access to hold their data nor request for their data to be transferred to other service providers. We request their data to be corrected and deleted. Information is kept on corporate files for seven years and the time length is shared. Information encrypted and account access only given related to role. We have a third-party disclosure policy. We monitor the percentage of users whose customer data is used for internal secondary purposes.

Customer Privacy Information

EMPIRE STATE REALTY TRUST: 2023 SUSTAINABILITY REPORT

Made with FlippingBook - Online magazine maker