CERBA HEALTHCARE // CSR REPORT 2022-23

52 PROMOTE EXEMPLARY BUSINESS ETHICS PROTECT THE PERSONAL DATA OF PATIENTS AND COLLABORATORS Aware of the sensitivity of the health data we process on a daily basis, we have put in place strict procedures for monitoring and protecting this information. THE PROCESSING OF PERSONAL DATA, A CHALLENGE INHERENT TO CERBA HEALTHCARE'S BUSINESS As a healthcare player, Cerba HealthCare is subject to particularly strict regulatory obligations when it comes to processing data – especially health data. The majority of the countries in which Cerba HealthCare operates has adopted personal data regulations. Thus, the General Data Protection Regulation (GDPR) applies in all European Union countries. In France, it is supplemented by Law No. 78-17 of 6 January 1978, known as the Loi Informatique et Libertés [French Data Protection Act], which reinforces the rules applicable to the processing of health data. In South Africa, where the head office of the Cerba Lancet Africa laboratories network is located, the 'Protection of Personal Information Act' (POPIA) applies, which in turn is also in line with European regulations. STRONG GOVERNANCE AT ALL LEVELS OF THE GROUP The protection of personal data is the responsibility of a Data Protection Officer (DPO) network throughout the Group. A DPO has been appointed for each country in the European Union in which the Group is present and declared to the competent local authority. In France, a Data Protection Point of Contact (DPP) has been appointed in each operational entity. This DPP network supports the French DPO in their compliance work. Close collaboration is also established between the Group's Legal Department, the DPOs and DPPs. Finally, an audit committee meets quarterly to review the implementation of the defined actions, and communicates progress to the Board of Directors. ‘The protection of the personal data of our patients and employees represents one of our priorities, to which our teams are committed on a daily basis.’ Merryl Durrenbach, Director of Internal Audit and Group DPO

RkJQdWJsaXNoZXIy NzMxNTcx