2021 Stakeholder Sustainability Report
A MESSAGE FROM OUR
PRESIDENT & CEO
2021 SUSTAINABILITY
HIGHLIGHTS
ABOUT MOODY'S
BETTER BUSINESS
BETTER LIVES
BETTER SOLUTIONS
APPENDIX
Moody's 2021 Stakeholder Sustainability Report
38
DATA PRIVACY AND
PROTECTION
We are improving our organizational and technical policies
to ensure that we comply with changing data privacy
laws and protect personal information. For example, we
implemented Single Sign-On across multiple platforms to
give us more control and visibility into potential threats.
We updated our Privacy Policy to highlight existing
protections, including how we would handle requests
for personal data from domestic or foreign government
or public authorities. The policy explains how we collect
personal information; how we use, disclose and protect
such information; and the choices our customers have
concerning use of such data. We have a dedicated data
subject rights process, and all data is safeguarded based on
requirements and controls determined by our Information
Risk & Security team. We require key vendors to complete
security assessments and execute appropriate terms to their
vendor agreements if they process personal data controlled
by Moody's. Security controls, including access and right-
of-use controls, are periodically evaluated by Internal Audit
and external auditors on a product-specific basis.
All employees must protect confidential information they
receive in the course of performing their job responsibilities.
Protecting confidential information helps us to fulfill
our legal obligations and helps to encourage customers'
good faith disclosures. Data privacy training is mandatory
for all of our employees at onboarding and periodically
thereafter, and we also offer additional role-based
training and guidance for teams that regularly handle
personal data. Employees who inappropriately disclose or
otherwise misuse confidential information may be subject
to disciplinary action up to and including termination. For
more information, see our Code of Business Conduct.
For more information on our policies regarding
cybersecurity and data privacy, see Additional Resources.View entire presentation