AI Content Chat (Beta) logo

2021 Owens Corning Sustainability Report | Our Approach | Compliance and Beyond | 75 Data Privacy Because we view data privacy as an element of personal safety, we comply with global privacy laws, and we collect, process, and transfer personal data in a trustworthy manner worldwide. Our commitment to data privacy extends to all Owens Corning employees and our stakeholders. To address data privacy, Owens Corning works to: ■ Minimize data collection. ■ Protect collected data. ■ Limit access to personal data to the personnel who need it (our systems owners and data holders). ■ Provide system owners and data handlers with extensive training on privacy laws such as the EU General Data Protection Regulation (GDPR). ■ Ensure that processes are in place to respond to personal data requests and to mitigate or address any privacy breach or other issues. We also continuously strive to strengthen our data privacy program. In recent years, we have taken on the following initiatives: ■ We have expanded the reach of our GDPR standards. ■ We have developed our own global data protection standards. ■ We have a cross-functional team to help maintain our protection standards and adapt to an evolving global landscape. ■ We have raised awareness of data privacy within our organization. ■ We have adapted our IT systems and platforms to reflect a “privacy by design” perspective. ■ We assess the IT environment and technical security systems of companies we acquire, ensuring that data collection and processing comply with our existing policy. We comply with all data privacy laws applicable in the countries and locations where we do business. We have also implemented enhanced security measures designed to protect against misappropriation or corruption of our systems, intentional or unintentional disclosure of confidential information, or disruption of our operations. Owens Corning has established information security controls to prevent unauthorized access to our systems. External assessments of Owens Corning’s security controls are conducted at least twice a year to validate the effectiveness of the controls and identify areas to continuously improve controls. Owens Corning received no substantiated complaints of customer data breaches in 2021. Data Privacy, Data Security, and COVID-19 During the COVID-19 pandemic, Owens Corning has remained cognizant of issues surrounding data privacy and data security. As we continue to monitor the health of our people, we have continued to comply with different regulations around the world with regard to the collection of information such as employee temperatures and other potential COVID-19 indicators. Our COVID Management Team has carefully monitored the flow of information to preserve employee privacy. As many employees have continued to work remotely throughout 2021, we have also maintained security standards to protect company data as people access information off-site. Photo submitted by: Jan-Christian Stenroos | Parainen, Finland Reviewing plant data and operations.

Owens Corning Sustainability Report - Page 75 Owens Corning Sustainability Report Page 74 Page 76