BUSINESS INTEGRITY CYBERSECURITY & DATA PRIVACY O INTR We do business with the highest We’re dedicated to prioritizing level of integrity, every day and in cybersecurity and safeguarding our everything we do. customers’ personal information. ANET BUSINESS ETHICS As a design-driven company, our in-house quality CYBERSECURITY & DATA PRIVACY We safeguard our customers’ PL We’re committed to conducting our global business professionals are engaged from the very beginning We take a proactive, highly conservative ethically and with integrity. Our Code of Business of our design process, informing material selection approach to cybersecurity, with the intention of personal information, Conduct & Ethics stands against corruption in all and product development with safety in mind. preventing harm. This commitment is reflected conducting internal testing its forms and establishes expectations to guide in our governance structure, our data security ethical decision-making by our associates. We have a global team of product quality and policies and procedures and our systems to and assessments monthly, assurance professionals who test all our products measure, monitor and respond to data breaches third-party assessments Our Vendor Code of Conduct outlines our for safety and restricted substances. To guarantee and cyberattacks. OPLE expectations of ethical behavior by our business that we communicate the correct information to quarterly and external PE partners. We require all associates to complete customers, we have an internal review process and Our Chief Technology Officer and Chief Information independent audits at least a Code of Conduct Questionnaire annually to work with third-party certification organizations Security Officer have a dedicated team of reinforce our expectations. Every associate and where needed to provide accurate product claims. professionals focused on cybersecurity and data once a year. business partner has a responsibility to act with protection, and we invest in continuous monitoring the highest ethical standards. Our products are tested and improvement of our systems. Our policies and standards are reinforced by training and engagement to ensure our customers’ To foster an environment of open, honest at either one of our WSI We review and update our dedicated Standard privacy and security is central. We disclose communication, associates across our offices, in-country labs or by Operating Procedures, policies and standards this information in accordance with the SEC’s stores and factories have access to a third-party annually. In 2021, we updated our Cybersecurity Commission Statement and Guidance on Public ethics hotline to report any potential violations, independent, third-party labs & Data Privacy Commitment to respond to Company Cybersecurity Disclosures. PURPOSE while ensuring confidentiality and transparency. stockholder concerns and more clearly articulate Whistleblower protections are included in our Code certified by the U.S. Consumer our approach to cybersecurity and data privacy. of Business Conduct & Ethics. Product Safety Commission. Our associates, as well as third parties who PRODUCT SAFETY & TESTING provide services on our behalf, are required by T 2021 At WSI, we are committed to high-quality, safe and policy, practice, and contract (if applicable) to treat long-lasting products for our customers. In addition customer information with care. We also closely to complying with rules and regulations related monitor emerging data privacy laws to ensure T REPOR to marketing and product safety and testing, we legal compliance. C invest in up-front technical expertise to inform A APPENDIX product design and development. IMP 77 78
Williams-Sonoma, Inc - Impact Report Page 38 Page 40