INTRODUCTION PEOPLE COMMUNITY PLANET GOVERNANCE APPENDIX SASB: Sustainability Accounting Standards Board disclosure The Sustainability Accounting Standards Board (SASB)’s objective is to enable companies to communicate industry-specific sustainability accounting standards to their shareholders. As part of our commitment to ensure ESG transparency we are reporting ESG metrics in accordance with the SASB standards for the Multiline and Specialty Retailers & Distributors industry. Topic Code Accounting Metric Response Energy CG-MR- (1) Total energy Total energy consumed 1,508,029 GJ (excludes non-operated building electricity) Management in 130a.1 consumed (GJ), Retail & Distribution (2) percentage % grid electricity 91.4% grid electricity, (3) percentage renewable % renewable 8.6% Data Security CG-MR- Description of Bed Bath & Beyond is committed to protecting its customers’ and Associates’ data throughout the 230a.1 approach to identifying organization. Data protection measures are in place for data at rest and in transit within our data centers, and addressing data with our business partners, and in the cloud. Information security policies are reviewed, approved annually, security risks and made available to all Associates. The Bed Bath & Beyond information security program is aligned with recognized information security management system standards (ISO/IEC 27001/2) and cybersecurity frameworks (NIST SP-800). We are compliant with the Payment Card Industry (PCI) Data Security Standards, the Sarbanes Oxley Act (SOx), and California Consumer Privacy Act (CCPA). CG-MR- (1) Number of Not reported for 2021. 230a.2 data breaches, (2) percentage involving personally identifiable information (PII), (3) number of customers 29 affected 29Disclosure shall include a description of corrective actions implemented in response to data breaches. Bed Bath & Beyond 2021 ESG Report 38
Bed, Bath and Beyond ESG Report Page 38 Page 40