privacy

OLIVE YOUNG operates a company-wide information security management system centered on the Information Security Center, which reports directly to the CEO, so that customers can use its services with confidence.
We raise internal management standards through privacy impact assessments and regular training, and we extend our oversight to partner companies that handle personal data, managing data protection standards together.

OLIVE YOUNG operates a company-wide information security management system so customers can use its services with confidence, managing data protection standards with its partner companies.
[ 01 ]

Data Security System

Data Security and Privacy Policy

OLIVE YOUNG complies with both domestic and international data privacy regulations and has established Data Security and Privacy Policy that aligns with its business practices and corporate culture.
It contains data security rules and 13 specific guidelines for practical use and is reviewed and revised regularly, at least once a year.
Furthermore, the company makes the privacy policy readily accessible on each service website, enabling customers to review it any time. OLIVE YOUNG protects customers' personal data with the highest priority in accordance with its privacy protection principles.

Information Security Committee

The head of the Information Security Center serves as Chief Information Security Officer (CISO) and Chief Privacy Officer (CPO) and oversees company-wide security,
sharing key security issues through regular meetings attended by management and responding jointly with the relevant departments.

Information
Security Committee

  • Presided by CISO
  • Held periodically
    (once a year)

Information
Security Center
Chief Information
Security Officer (CISO)
Chief Privacy
Officer (CPO)

  • Overseeing Data Privacy and
    Information Security Issues and
    Collaborating on
    Data Security Policies
  • Reporting Security Matters
    to CEO When Necessary
[ 02 ]

Data Security Management

Simulated Training for Data Leak Incidents

To reinforce its cybersecurity response capabilities across the company, we conduct simulated training based on various security threat scenarios, at least once a year.
Simulations raise awareness of security incidents among all employees and help them experience how to respond promptly in real-life situations.

Regular Simulation-Based Training

  • Simulated leak incident

    Various threat scenarios are applied

  • Response training

    Relevant departments participate to experience the necessary response procedures

  • Training result analysis

    Areas for improvement are identified and integrated into future trainings

Incident Response Manual

We take thorough preventive and corrective security measures, develop and distribute internal incident response manuals for various types of incidents, such as intrusions, data leaks, and ransomware infections.
The Response Manual for Personal Data Leak provides detailed procedures based on laws, and also remediation procedures to minimize the impact of data breaches, helping employees respond promptly and effectively.

Personal Data Breach Response Procedures

  • Security incident identification

    Identifying and reporting a security incident

  • Security incident response

    Reporting to regulatory bodies, analyzing the risks and taking corrective actions promptly

  • Follow-up measures

    Analyzing the cause and establishing measures to prevent recurrence

Data Security Trainings for Employees

We require all employees, including executives, to sign an information security pledge and conduct information protection training at least once a year.
Additionally, personal information handlers receive specialized training that covers legal updates and personal information protection measures.

[ 03 ]

Partner Data Security

We provide training on personal data handling principles and safeguards for employees of partner companies that handle personal data.
We review partners' personal data management practices together with the Korea Online Privacy Association (OPA), securing objectivity and reliability in these reviews.

Preventive Data Security
Measures
Frequency
At least once a year
Target
Employees of partners handling personal information
Content
Understanding personal data and protection principles at each stage, signing a security pledge
Partner Security Audits
Frequency
At least once a year
Target
Registered partners, etc.
Content
Inspecting personal data management status through the Personal Information Protection Association (OPA), providing support to implement corrective measures to overcome deficiencies found
Evaluation and Guidance on
Personal Data Protection
Frequency
As needed
Target
Registered partners, etc.
Content
Evaluating data security and privacy measures of partners during contract negotiations and helping implement corrective measures for any identified deficiencies