AS Sustainability Report

Governance

Introduction

CEO letter

Air SERBIA’s Story

Air Serbia in 2025 - year in review

Materiality analysis and stakeholder engagement

Environment

Economic value and connectivity

Social

Appendix

6.5 Data protection and cyber security Why this topic matters

Technical and organizational measures

The Company protects personal data and information systems through a combination of technical and organizational measures, including access controls, network protection, data encryption, regular data backup procedures, endpoint security, timely software updates, continuous system monitoring, vulnerability management, incident response processes, and information security policies and procedures. To assess the effectiveness of these measures and identify opportunities for improvement, the Company conducts annual security assessments, including penetration testing. The findings are used to strengthen security controls and continuously enhance the protection of information systems.

As an airline, Air Serbia processes significant volumes of personal data belonging to passengers, employees, partners and suppliers. Protecting this data, and ensuring the resilience of the company's information systems against cyber threats, is essential to maintaining the trust of passengers and partners, ensuring regulatory compliance and safeguarding operational continuity. Reflecting its importance, data protection and cyber security was identified as one of the company's highest-priority material topics in the 2025 materiality assessment.

Our approach

Data protection at Air Serbia is governed by compliance with the EU General Data Protection Regulation (GDPR), the Serbian Law on Personal Data Protection, and the Law on Information Security of the Republic of Serbia. Personal data of passengers, partners and employees is processed only for legitimate, clearly defined purposes, with access limited to those who require it for their work. The company applies technical and organizational information-security measures, maintains internal data-protection policies and procedures, and provides employees who handle personal data with relevant awareness. The company has appointed a Data Protection Officer responsible for overseeing compliance with data-protection requirements, advising on processing activities and serving as the contact point for data subjects and the supervisory authority. While Air Serbia is not certified under ISO/IEC 27001, its information-security practices are aligned with the principles of that internationally recognized standard.

Awareness and training

Air Serbia promotes awareness of data protection and cybersecurity responsibilities through cybersecurity awareness training and periodic internal guidance. These initiatives help employees recognize and respond to cybersecurity risks, reducing the likelihood of incidents resulting from human error. Performance in 2025 In 2025, Air Serbia recorded zero substantiated complaints concerning breaches of customer privacy, comprising zero complaints received from outside parties and substantiated by the organization and zero complaints from regulatory bodies. The company identified zero incidents of leaks, thefts or losses of customer data during the reporting period.

Sustainability Report 36

Made with FlippingBook interactive PDF creator