DNFP_2018_English

2018 DECLARATION OF NON-FINANCIAL PERFORMANCE OF THE DESCOURS & CABAUD GROUP 29 THE GENERAL DATA PROTECTION REGULATION (GDPR) The GDPR, which was passed by the European Parliament and the Council on 27 April 2016 and came into force on 25 May 2018, aims to harmonise the protection rules for individuals in all European countries with regard to the processing of their personal data. The risk factors, consequences and means of control: The risks in the event of non-compliance are primarily financial, as non-observance can be punishable by administrative and financial penalties of up to 20 million euros or 4% of the Group's turnover. Beyond this, the impact on the Group's image is liable to lead to a loss of confidence detrimental to the company's business. > The means of control: The company's policy The commitment of the Executive Board with regard to the European Regulation follows on from its commitment to compliance with the French data protection law (“loi informatique et libertés”). The company has opted to officially declare a Data Protection Officer (DPO) with the CNIL (the French data protection authority). The DPO is tasked with overseeing a compliance programme at European level and is accountable for compliance with the GDPR for all new projects. A European compliance programme This programme has been rolled out to our European subsidiaries. It seeks to help them to: • identify data processing activities • bring the e-commerce sites into compliance (legal notice, cookies policy, terms of use) • provide templates (contract clause, etc.) • ascertain the lawfulness of data processing, mainly with regard to a contractual or pre-contractual relationship • establish processes for receiving data subjects' requests to exercise their rights • prepare crisis management procedures in the event of data breaches • carry out an impact assessment to identify the risks relating to the handling of personal data for all new projects • include personal data protection clauses in our contracts Keeping records of processing activities Each subsidiary is required to keep an up-to-date record of processing activities. RELATED KEY PERFORMANCE INDICATORS 120% 100% 80% 60% 40% 20% 0% 26/11/2018 Production: Linear (Projection) 26/03/2018 03/01/2018 04/04/2019 31/06/2019 Training rate Anti-bribery module: 14.1% * % of requests to exercise rights duly processed: 100% *start date: for top management on 26/11/2018 and for the sales force on 17/12/2018

RkJQdWJsaXNoZXIy MTQ0MjA1