Information Security Management System
Information Security Organization
To proactively respond to increasingly sophisticated cyber threats and the risk of information leakage, HL D&I Halla has established and operates an information security management system based on a dual-accountability structure reporting directly to the CEO. The Chief Privacy Officer (CPO) oversees the secure management of personal information throughout its collection, processing, and retention, as well as the prevention of and response to personal information breaches. The Chief Information Security Officer (CISO), who concurrently serves as the Chief Location Information Officer, is responsible for information security across the Company, ranging from the establishment of company-wide security policies and the enhancement of employees’ security capabilities to the management of technical vulnerabilities. In particular, the CISO maintains close coordination with the HL Group Security Council and the security councils of its subsidiaries, enabling the Company to manage information security in an integrated manner and maintain a consistent group-wide security response framework. Based on this systematic organizational structure, HL D&I Halla will continue to strengthen the protection of employees’ personal information and the secure management of corporate information assets.
Information Security Organizational Chart
Information Security Policy
Under the leadership of the Chief Privacy Officer (CPO) and Chief Information Security Officer (CISO), HL D&I Halla has established and operates an information security management system based on its Security Management Regulations. The Company focuses on the systematic and effective protection of key information assets, including corporate information and personal information, while continuously advancing its security framework by regularly reviewing and revising its security management regulations to proactively respond to increasingly sophisticated cyber threats and changes in laws and regulations. In 2025, the Company promptly responded to the changing external environment by revising its Guidelines for the Operation and Management of Fixed Video Information Processing Devices on its website to reflect the latest operational practices HL D&I Halla also strictly complies with domestic and international laws and regulations related to personal information protection. To ensure that all stakeholders can clearly understand its personal information protection policies, the Company transparently discloses the key elements of its personal information processing policy in an easily accessible format through both the corporate website and the EFETE brand website. HL D&I Halla will continue to create a secure and trusted information protection environment through systematic information security management and ongoing security enhancement activities.
Key Personal Information Processing Labels
-
Purpose of Personal Information Processing
View Details
Purpose of Personal Information Processing
HL D&I Halla does not use personal information for purposes other than those for which it was collected.
-
Collection of General Personal Information
View Details
Collection of General Personal Information
HL D&I Halla collects only the minimum amount of personal information necessary for the purposes for which consent has been obtained.
-
Retention Period of Personal Information
View Details
Retention Period of Personal Information
HL D&I Halla retains personal information only for the period consented to by the data subject or as prescribed by applicable laws and regulations.
-
Provision of Personal Information
View Details
Provision of Personal Information
HL D&I Halla does not provide personal information to third parties without the consent of the data subject.
-
Entrustment of Personal Information Processing
View Details
Entrustment of Personal Information Processing
HL D&I Halla entrusts certain personal information processing activities to specialized service providers to ensure the efficient processing of personal information and publicly discloses and supervises such entrusted activities.
-
Department Responsible for Grievance Handling
View Details
Department Responsible for Grievance Handling
HL D&I Halla operates a customer consultation and reporting center for personal information protection-related inquiries and complaints.
Information Security Incident Response System
Security Incident Response and Handling System
HL D&I Halla works closely with the HL Group Data Center (GDC) to strengthen information security by conducting preventive activities and regular security inspections. Through these efforts, the Company continuously maintains system stability and has established a framework for preventing security incidents. In the event of an information security incident, HL D&I Halla responds promptly in accordance with the “Security Incident Management” standards stipulated in its Security Management Regulations. Following the completion of remedial measures, the Company conducts a thorough analysis of the cause of the incident in close cooperation with GDC and systematically develops measures to prevent the recurrence of similar incidents.
Types of Security Incidents
Security Incident Handling Process
Information Security Activities
HL D&I Halla has strengthened the trust of customers and stakeholders through compliance with information security-related laws and regulations and systematic management activities. From an institutional perspective, the Company has enhanced the effectiveness of its information security policies and improved transparency for stakeholders by responding flexibly to changes in laws and regulations and continuously advancing its compliance system. To strengthen employees’ security capabilities, HL D&I Halla has focused on embedding security as a personal responsibility and an integral part of its organizational culture by organically linking education, training, and signed pledges. Through these efforts, the Company seeks to proactively minimize internal information security risks. In terms of threat detection and response, HL D&I Halla conducts continuous monitoring and regular risk assessments to identify potential threats at an early stage. The Company also focuses on building practical response capabilities to ensure prompt action against external emergency threats.
2025 Information Security Activities
| Category | Detailed Activities |
|---|---|
| Strengthening the Institutional Foundation | Revised the guidelines for the operation and management of fixed video information processing devices on the website |
| Responded to information security disclosure requirements and obtained personal data protection liability insurance | |
| Strengthening Employees’ Security Capabilities | Conducted an information security awareness campaign |
| Conducted phishing email simulation training twice a year to raise employees’ security awareness | |
| Provided customized security training by position | |
| Required the submission of security and compliance pledges | |
| Strengthening Threat Detection and Response | Conducted monthly inspections of access logs for personal information processing systems |
| Inspected the account status of security equipment and solutions | |
| Implemented follow-up measures based on information security risk assessments | |
| Responded to emergency security inspection requests from the Ministry of Science and ICT | |
| Performed emergency security updates for zero-day vulnerabilities |