Our privacy principles
Accountability
We are accountable for living up to our commitments throughout Vodafone and with our partners and suppliers.
Fairness and lawfulness
We comply with privacy laws and act with integrity and fairness. We actively engage with stakeholders to shape better, more meaningful privacy laws and standards.
Choice and access
We let people make simple, meaningful choices about their privacy. We allow them to access, update or delete their personal data, where appropriate.
Security safeguards
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, use, modification or loss.
Privacy by design
Respect for privacy is a key component in the design, development and delivery of our products and services.
Openness and honesty
We communicate clearly about our actions that may impact privacy, we ensure our actions reflect our words and we are open to feedback.
Responsible data management
Personal data is governed with appropriate management practices. We carefully select external partners, limit disclosure and ensure it is not stored for longer than necessary, or required by applicable laws.
Balance
We work to minimise privacy impacts, when we are required to balance the right to privacy against other obligations necessary for a free and secure society.
Our approach to privacy
Our operating model
Our experienced team of privacy specialists ensure compliance with data protection laws and our policies in the countries where we operate.
We apply a process-based model to managing privacy risks across the data lifecycle. We work closely with corporate security and cyber security, products, IT and digital, networks, HR, finance, supply chain and other teams to ensure end-to-end coverage.
Our dedicated security teams ensure technical and organisational information security measures to protect personal data against unauthorised access, disclosure, loss or use during transit and at rest.
A privacy first approach
All our products, services and processes are subject to privacy impact assessments as part of their development and throughout their lifecycle. We maintain personal data processing records, supplier privacy compliance, data breach management and individual rights processes, as well as internal and international data rransfer compliance frameworks and training and awareness programmes.
Our teams monitor and influence regulatory and industry developments and work to build and maintain relationships with local data protection authorities and other key stakeholders.
Privacy training for all
Our privacy control frameworks are subject to continuous risk-based improvements. As well as introducing global privacy control updates, our privacy module is part of our mandatory ‘Doing What’s Right’ training. Every employee must complete the training within six weeks of joining Vodafone and then every two years. We have also refined training for high-risk roles aimed at teams with a key role in personal data processing. With the updated approach we aim to achieve 90% completion on both types of training across all target groups across our global footprint.
The effectiveness of control implementation is subject to regular reporting and testing by the privacy and internal audit teams. Any findings are subject to remedial actions by the responsible control operator, and completion is monitored.
POLICY
Governance
Monitoring and response
We monitor compliance with privacy controls and have an experienced team to manage incidents.
Our privacy controls are subject to rigorous and regular evidence-based testing by our privacy governance, risk and compliance team. In addition, our internal audit team performs reviews selected privacy controls and relevant business activities. Possible findings are subject to mitigation plans and heightened monitoring.
Our processes ensure any identified incidents are contained and steps taken to mitigate negative effects. We notify regulators as well as customers, as required.