
CD PROJEKT Group’s 2021 Sustainability Report
30
CAPITAL
GROUP
SOCIAL
RESPONSIBILITY
SUSTAINABLE
DEVELOPMENT
RESPONSIBLE GOVERNANCE
AND ORGANIZATION
ENVIRONMENTAL
RESPONSIBILITY
Risk of
noncompliance
with
employment
regulations
Given the number and diversity of individuals
employed at the Group there is a risk of
violating employment regulations in the course
of daily activities at Group member companies.
In this context the Group may be subject to
periodic inspections carried out by institutions
and authorities authorized to perform such
inspections, as well as to lawsuits filed by former
employees alleging breaches of labor law and
employment regulations. Such noncompliance
may also cause undesirable dynamics in
employer-employee relations and undermine
the substance of civil law agreements related to
the videogame development cycle.
With regards to proper management of
employment risks, the Company undertakes
a range of activities to safeguard its team
members. Each team at the Company is
assigned a HR Partner; furthermore, procedures
which regulate the rights and responsibilities
of employees are implemented and enforced –
this includes a procedure for counteracting
undesirable conduct in employee relations, as
well as a formal Diversity Policy. Employees are
able to anonymously or personally report any
irregularities, including breaches of employment
regulations, and there are systems in place
which protect the confidentiality of such
reports and their authors, and which protect
whistleblowers from potential retribution. The
Company also works to ensure transparent
internal communication related to employment,
including changes in regulations, types of
agreements, absences, leaves (including
parental leave) and feedback options.
Governance and organization risks
Cybersecurity
risks related
to leakage, loss
or unauthorized
modification
of data
*
Data storage and data processing in IT systems
carries the risk of leakage, loss or unauthorized
modification. Cybersecurity risks go beyond
corruption or destruction of data and the
associated financial loss, and may include theft
of intellectual property, loss of productivity or
loss of reputation. Cybersecurity risks may
involve internal or external circumstances,
whether intentional or inadvertent, which result
e.g. from cyberattacks, deployment of malicious
software or other breaches of security.
To minimize cybersecurity risks the Group
has developed a plan based on the “defense
in depth” principle, with multiple overlapping
security systems. The Group continues to roll
out and improve technical measures which
contribute to the security of its IT infrastructure.
Security requirements are uniformized and
iterated to ensure that access to information
and data processing are performed in a
controlled manner. An important aspect of
the Group’s approach to cybersecurity is a
series of internal training courses related to IT
security, raising awareness of threats related
to social manipulation as well as phishing. The
Group continues to monitor its data processing
systems to ensure appropriate technical
safeguards against potential evasion of security
measures.
Risk associated
with processing
personal data
*
The risk associated with processing personal
data aects a range of data processing activities
carried out by Group member companies which
fall within the scope of Polish and foreign legal
regulations on territories where the Group
conducts its business. Such risk may materialize
e.g. through infringement of the confidentiality,
integrity or availability of personal data,
resulting in significant financial penalties. It
may also involve noncompliance with legal
regulations which govern privacy, causing
Group member companies to incur excessive
administrative costs (whether operational or
financial) in order to ensure proper observance
of such regulations.
Should data protection measures – whether
existing at present or expected to be rolled
out in the future – prove insucient, exposure,
corruption or loss of personal data may
ensue. This may be caused by IT system
failures, human error or malicious third-party
interference.
With regards to processing of personal data,
CD PROJEKT Group member companies are
assisted by internal mechanisms in place at
the Group, as well as by external entities. The
Group takes action to mitigate and control risks
associated with processing personal data. This
includes internal audits, confidentiality audits
carried out in the framework of specific projects,
data protection and privacy impact analysis,
and ad-hoc consultations held for the benefit
of employees who supervise processing of
personal data. Additionally, a dedicated Privacy
& Compliance department has been established
at the Company, tasked, among others, with
organizing regular training courses related to
protection of personal data and information
security in general, as well as with assisting
Group member companies in minimizing the
presented risk.