privacy
OLIVE YOUNG operates a company-wide information security management system centered on the Information Security Center, which reports directly to the CEO, so that customers can use its services with confidence.
We raise internal management standards through privacy impact assessments and regular training, and we extend our oversight to partner companies that handle personal data, managing data protection standards together.
Data Security System
Data Security and Privacy Policy
OLIVE YOUNG complies with both domestic and international data privacy regulations and has established Data Security and Privacy Policy that aligns with its business practices and corporate culture.
It contains data security rules and 13 specific guidelines for practical use and is reviewed and revised regularly, at least once a year.
Furthermore, the company makes the privacy policy readily accessible on each service website, enabling customers to review it any time. OLIVE YOUNG protects customers' personal data with the highest priority in accordance with its privacy protection principles.
Information Security Committee
The head of the Information Security Center serves as Chief Information Security Officer (CISO) and Chief Privacy Officer (CPO) and oversees company-wide security,
sharing key security issues through regular meetings attended by management and responding jointly with the relevant departments.
Information
Security Committee
- Presided by CISO
- Held periodically
(once a year)
Information
Security Center
Chief Information
Security Officer (CISO)
Chief Privacy
Officer (CPO)
- Overseeing Data Privacy and
Information Security Issues and
Collaborating on
Data Security Policies - Reporting Security Matters
to CEO When Necessary
Data Security Management
Simulated Training for Data Leak Incidents
To reinforce its cybersecurity response capabilities across the company, we conduct simulated training based on various security threat scenarios, at least once a year.
Simulations raise awareness of security incidents among all employees and help them experience how to respond promptly in real-life situations.
Regular Simulation-Based Training
-
Simulated leak incident
Various threat scenarios are applied
-
Response training
Relevant departments participate to experience the necessary response procedures
-
Training result analysis
Areas for improvement are identified and integrated into future trainings
Incident Response Manual
We take thorough preventive and corrective security measures, develop and distribute internal incident response manuals for various types of incidents, such as intrusions, data leaks, and ransomware infections.
The Response Manual for Personal Data Leak provides detailed procedures based on laws, and also remediation procedures to minimize the impact of data breaches, helping employees respond promptly and effectively.
Personal Data Breach Response Procedures
-
Security incident identification
Identifying and reporting a security incident
-
Security incident response
Reporting to regulatory bodies, analyzing the risks and taking corrective actions promptly
-
Follow-up measures
Analyzing the cause and establishing measures to prevent recurrence
Data Security Trainings for Employees
We require all employees, including executives, to sign an information security pledge and conduct information protection training at least once a year.
Additionally, personal information handlers receive specialized training that covers legal updates and personal information protection measures.
Partner Data Security
We provide training on personal data handling principles and safeguards for employees of partner companies that handle personal data.
We review partners' personal data management practices together with the Korea Online Privacy Association (OPA), securing objectivity and reliability in these reviews.
Measures
- Frequency
- At least once a year
- Target
- Employees of partners handling personal information
- Content
- Understanding personal data and protection principles at each stage, signing a security pledge
- Frequency
- At least once a year
- Target
- Registered partners, etc.
- Content
- Inspecting personal data management status through the Personal Information Protection Association (OPA), providing support to implement corrective measures to overcome deficiencies found
Personal Data Protection
- Frequency
- As needed
- Target
- Registered partners, etc.
- Content
- Evaluating data security and privacy measures of partners during contract negotiations and helping implement corrective measures for any identified deficiencies