Data privacy Governance high impact, and / or if the law of the land Raising DP awareness through Driving DP thought leadership mandates, such breaches are notified to the impacted data subjects and /or supervisory campaigns and events In this constantly changing privacy threat ESG REPORT 2022-23 authority. We also incorporate key learnings landscape, the Infosys DPO recognizes the from incidents in privacy awareness stories Every year, we celebrate the Data Privacy Day need for regular engagement with industry ESG is an opportunity and tips sent to employees. Incidents of high by hosting engaging interventions and diverse and government bodies to shape the future and critical nature are reported to the incident online interactive events like crosswords, of data privacy. Towards this, it actively disclosure committee, consisting of senior quizzes, chat with DPO and messages from participates in various initiatives with ENVIRONMENT leaders including the CEO & MD. Infosys has senior leaders to spread awareness. The events industry forums and standard bodies globally, zero tolerance for any breaches, which in span over several months and rewards are contributing to developing DP frameworks, SOCIAL addition to appropriate preventive measures, offered to promote employee participation. policies and standards. The Infosys DPO is the are controlled through effective deterrent Additionally, monthly awareness mailers in the co-editor for ISO and IEEE standards related GOVERNANCE mechanisms including stringent consequence form of privacy tips and scenarios reflecting to privacy engineering, management and management. changing threats are also sent to everyone in privacy in emerging technologies, some of Performance on governance goals In fiscal 2023, there were no substantiated the organization to strengthen awareness. We which have been published while others are complaints received concerning breaches of conducted International Privacy Symposium being developed. Such emerging technologies Corporate governance customer privacy from outside parties and 2022, a virtual conference organized by the include AI, digital twins, Metaverse and ZKP Data privacy regulatory authorities. Infosys Data Privacy Office in association with (Zero Knowledge Proof). IAPP and ACC, where participants included Recently, AI-based tools and technologies Information management Data subject rights global privacy leaders, CPOs, experts from have proliferated across the digital industry, academia and global frontline practitioners bringing in rich dividends both for consumers management to reflect on key trends, challenges and best and businesses. However, this has also practices. Some of the sessions organized introduced hitherto unknown privacy threats, Data subject rights, which have become an as part of this included privacy engineering, particularly on decisional autonomy, basic intrinsic part of data privacy laws in many anonymization, privacy-preserving synthetic to individual data empowerment. At Infosys, countries, are legal rights enjoyed by the data data, AI, data ethics and human behavior, data privacy and data ethics are an integral subject. These rights are legally enforceable, privacy standards, data subject rights and parts of the responsible AI framework and all but never absolute, which makes the fulfilment other emerging areas. A similar symposium AI-based solutions and platforms are subjected complex in the current enterprise setting with is proposed to be organized in 2023 in to privacy assessments before deployment, data spread across systems and servers in collaboration with international bodies. to balance business value derived with data multiple geographies with diverse regulatory All employees and sub-contractors have to privacy. regimes. Infosys has established necessary also mandatorily complete privacy awareness tools and processes to cater to such data quizzes annually, the questions and scenarios subject rights requests within the legally for which are tailored based on the their stipulated timelines across Infosys locations, respective roles. including subsidiaries. Infosys | ESG REPORT 2022-23 External Document © 2023 Infosys Limited 62
Infosys ESG report 2022-23 Page 61 Page 63