
Privacy
We handle data for organizations serving hundreds of thousands of individuals worldwide. We take this responsibility seriously and are committed to the highest standards of privacy and data security.
Privacy you can rely on
All customer data is securely stored and processed in accordance with the GDPR and applicable local data privacy regulation(s). Our infrastructure ensures data sovereignty, transparency, and control — helping you stay compliant with confidence.
Protecting your data is more than a requirement — it’s our ongoing commitment.
Data Privacy
To EG, data protection is a human right, and we want to be a 100% trusted data partner. Therefore, we handle your data responsibly when it is in our care. In our privacy policy you can read about how the companies in EG process personal data about you, in our role as data controller.
EG may process your personal data in connection with e.g. participating in EG events, as visitor to EG offices, or other circumstances where EG is the data controller of the information you provide. For more information on how EG process your personal data and your rights under GDPR, please read our Privacy Policy.
Data Privacy Program
EG has an extensive Data Privacy Program. The program includes policies and guidelines, risk-based assessments, close monitoring, incident handling, and continued awareness and training. The program is governed by our GDPR Committee and implemented by our central legal department in close collaboration with our business units.
Privacy Commitments and Data Ethics
Without greater digitization and better use of data, it will be difficult to maintain and develop our welfare system.
We need to know more if we are to act in the right way when managing local and global challenges such as shortage of resources and the green shift.
Data Processing Agreements
As a data processor, EG must ensure that our customers have provided us with instructions on how they want their personal data to be processed in our systems.
We therefore enter into data processing agreements with our customers where relevant.
Transfers of personal data outside of the EU/EEA
Written procedures are in place which include a requirement that EG may only transfer personal data to third countries or international organizations in accordance with the data processing agreement with the data controller by using a valid basis of such transfer. EG ensures that data transfers outside of the EU/EEA are compliant with the relevant provisions of the GDPR.
Privacy Incident Handling
EG has detailed procedures for effectively handling privacy related incidents and data breaches.
In the event of a privacy related incident or data breach, EGs Group Legal and Compliance department will assess and handle the incident in accordance with any Data Processing Agreement and the provisions of the GDPR.