Integrity and trust Data privacy and security We collect only what we need. Data minimization and basic account information; and a View as Driver We safeguard personal data. Our users trust us is a goal for all teams, and not just our privacy and feature, which provides riders with visibility into the to protect their personal information whenever security experts. For Uber products, campaigns, personal information drivers can see about them they use our apps. Uber’s information security and services, we keep a specific objective in mind before, during, and after a trip. program, which is based on the industry-recognized when collecting, using, or handling personal data We give users choices about their data. At Uber, ISO 27001/2 framework, includes written policies, that is consistent with our values. One example is we don’t believe privacy has to come at the expense processes, and standards designed to protect the Mask Verification, a feature that detects whether of innovation. In fact, we think protecting consumer security, confidentiality, and integrity of Uber’s a user is wearing a mask without relying on privacy is essential to being a truly innovative data environment. Uber has maintained ISO 27001 biometric information. company. Our privacy product team is responsible certification for its enterprise business line (Uber for We are transparent about our data practices. We for building tools and features in our mobile apps Business, Uber Central, and Uber Health) since 2019 keep our users informed about our data collection that can help protect privacy while using Uber’s and in 2021 obtained the certification for its core and use practices in our layered Privacy Notice, services. Some of these features can be found in rides business. Additionally, in 2020, Uber obtained our Help pages, and our app and website, where the Privacy Settings menu, including controls for SOC 2 certification and was assessed by an users have the ability to edit their data, modify their sharing location data with Uber or with trusted independent assessor against NIST 800-171 for its privacy settings, request a copy of their personal contacts, for notifications received from us, and Uber for Business commercial offerings to become information, and more. Additionally, in 2020, we for deleting an account. Users also have control approved as a US government contract service. launched 2 new features: an Explore Your Data over how their personal data is used for marketing feature where, once authenticated, users can find a purposes, and may opt out of having their data convenient summary of personal data including a used for these purposes. summary of trips, Uber Eats deliveries, rider rating, 2021 ESG Report 61
Uber ESG Report Page 60 Page 62