Social

Information Security & Data Privacy

Information Security Committee
The Coway Information Security Committee meets on a regular basis and continuously reviews amendments to applicable laws, including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection. Through this process, Coway has taken proactive steps to apply any amendments promptly to its internal policies and processes. In 2025, Coway strengthened its disciplinary standards for security violations and advanced its security inspection and monitoring architecture, thereby elevating statutory compliance, operational stability, and customer trust.
2025 Key Activities and Achievements of the Information Security Committee
Category Key Activities and Performance Evaluation Indicator Result
Regulatory Compliance
  • Reviewing personal information access records and disposal status
  • Notifying data subjects of usage details, and resolving complaints/disputes
Rate of implementing mandatory legal compliance activities 100%
Management System Operations
  • Maintaining ISO/IEC 27001 and 27701 certifications
  • Maintaining ISMS-P certification
Rate of internalizing security standards 100%
Security System Operations
  • Improving the security system operation framework
  • Reviewing access privileges and unnecessary policies in security systems
  • Auditing user/system logs and detecting operational anomalies
Rate of executing corrective action plans 100%
Information Security Incident Prevention
  • Remediating security vulnerabilities and detecting and responding to information leakage threats
  • Conducting security inspections and training across major business sites and field sales sites
Rate of responding to detected risks 100%
Awareness Raising
  • Information security campaigns and case-sharing activities
  • Distributing tailored training videos for field sales sites
Rate of implementing awareness-raising plans 100%
Training Reinforcement
  • Conducting annual disaster recovery simulation drills (IDC simulation drills) for outage scenarios
Completion rate of trainees 100%
Risk Management
  • Conducting security reviews and remediating/removing risks across Coway
  • Reinforcing security threat detection and minimizing security blind spots
Rate of taking actions to remove security vulnerabilities 100%
Internal audits
  • Reviewing the status of the information protection management framework
  • Reviewing the security management status of partners and outsourced contractors
Rate of diagnosing management levels 100%
Information Security & Data Privacy Policy
Coway places the protection of customers' personal information as its top priority and maintains a systematic information protection management framework, with related regulations organized into a policy and guideline structure to ensure consistent application across operations. To respond to the rapidly changing information protection environment and business requirements, Coway periodically reviews related regulations and enacts or revises them as needed. In 2026, to strengthen information protection governance, Coway restructured the Information Security Committee and reinforced company-wide security inspections and continuous monitoring. By linking disciplinary procedures for violations with the Disciplinary HR Committee, Coway has enhanced accountability and execution. Reflecting the latest laws and changes in the work environment, Coway also revised 14 information protection guidelines and newly established one guide, thereby strengthening the related framework. By applying the same standards not only to internal organizations but also to the sales organization, outsourced contractors, and supply chain partners, Coway continues to reinforce its company-wide information protection framework.
Proactive Information Security Risk Prevention
Security Review
Coway carries out preventive activities—including risk assessments, the formulation of protective measures, and information protection training—based on a company-wide risk management framework designed to prevent security incidents. In particular, Coway operates a security review process that considers security from the system planning stage, reflecting information protection requirements in advance before new systems are built or services are launched. Through these preventive activities, Coway reviews and improves the appropriateness of personal information handling, system vulnerabilities, and compliance with security policies in advance, thereby minimizing potential risks.
Security Review Process
Security Review Process
Regular Information Security Risk Monitoring
To substantially elevate the level of information security and data privacy, Coway operates a range of regular monitoring activities year-round. Through field-oriented initiatives—such as malicious email response drills, clean desk campaigns, and security audits of entrusted partners—Coway proactively identifies and remediates security vulnerabilities across internal employees and supply chain partners alike. Going beyond simple inspections, Coway conducts tailored training programs aligned with each activity type, simultaneously preventing security incidents and fostering security awareness across the entire company.
2025 Key Activities and Achievements
Category Activity Target Audience Result
Malicious Email Response Drills Raising employee awareness and enhancing response capabilities such as personal information theft scenarios through internal simulation training against intelligent malicious emails All employees Conducted twice a year
Clean Desk Campaign Raising security awareness among employees, preventing security incidents through clean desk campaigns, and eliminating information management vulnerabilities Headquarters (inspected by lead department), Coway R&D Center, Plants (self-inspection), and field sales sites Conducted once a year
Security Audits of Entrusted Partners Conducting checklist-based security audits and data privacy training for entrusted vendor companies Partners 332 partners participated
Information Security System Enhancements Improving information protection systems to strengthen access control and threat response monitoring for company-wide IT assets Company-wide systems 3 systems upgraded
Post-Incident Management of Information Security Risks
Personal Data Incident Response Process
To prevent the spread of damage and avoid secondary harm in the event of a personal information breach or information leakage, Coway has taken proactive steps to ensure a phased response tailored to each incident type. Personal data-related incidents are classified into Security Breach Incidents and Data Leakage Incidents (personal data leakage / internal proprietary data leakage), with optimized response measures established and operated in advance. Through continuous security monitoring and surveillance systems, any detected anomalies prompt immediate reporting of suspected security incidents to responsible personnel, while simultaneously activating an Incident Response Team (IRT) for swift initial action. Coway then carries out the following steps in sequence: fact-checking, evidence collection and preservation, and detailed analysis of the leakage path and its cause. Based on these findings, Coway establishes and implements recurrence prevention measures while promptly restoring services. The response process and outcomes are reported to the CEO and the CISO to support management's decision-making. The entire response process and outcomes are reported to the CEO and CISO to support executive decision-making. Furthermore, all response procedures are thoroughly documented and institutionalized as shared knowledge assets within the company. Lessons learned and leakage pathways are regularly disseminated through interdepartmental training, continuously reinforcing company-wide incident response capabilities.
Personal Data Incident Response Process
Personal Data Incident Response Process
Post-Incident Management and Recurrence Prevention Framework
When a personal information incident occurs, the results of root-cause analysis derived during the incident handling process are translated into specific recurrence prevention measures and shared company-wide, ensuring that individual incidents are systematically managed to lead to organizational learning and the strengthening of management capabilities. Even after an incident, Coway continuously evaluates its security posture through ongoing security inspections and infrastructure vulnerability assessments. Furthermore, during the service operation stage, Coway conducts internal audits and policy compliance reviews to rigorously verify adherence to internal security standards and external regulatory requirements.
Coway also performs regular remediation activities for potential risks not identified through preventive measures, and in the event of a security incident or IT disaster, Coway activates a company-wide crisis management process to minimize damage and ensure business continuity, thereby protecting customer information and key assets. These post-incident management activities are systematically managed in accordance with personal information protection laws and internal standards.
Information Security Training
To enhance information protection awareness and security capabilities across all employees, Coway conducts company-wide information security training annually. In 2025, in addition to video-based training programs, Coway conducted on-site inspections and training of entrusted partners, raising the level of security management at field sales sites and elevating information security standards across all business operations.
In response to the recent increase in the use of generative AI services, the Information Security Office conducts continuous inspections and monitoring to prevent the external leakage of corporate information and security risks. To enhance employees' understanding of AI ethics and raise awareness of the safe use of AI, Coway also established and distributed the "Generative AI Usage Guide" company-wide. The guide includes key security rules that employees should observe when using AI services, such as the prohibition of inputting internal confidential data or personal data, as well as verifying copyright ownership and the credibility of generated outputs.
2025 Information Security Training
Category Schedule Target Audience Content Number of Completers
Video Training March - October Newly commissioned sales agents Training on personal data collection, use, and destruction 1,948
On-site Security Audits & Training for Entrusted Partners August - December Exclusive agencies (192) and master distributors (4) Audit of personal data management status and security training 198
Company-wide Mandatory Training March All employees Data privacy and information security 6,298
Information Security Campaign
To ensure that employees' security awareness translates into actual behavior in the workplace, Coway carries out information security campaigns continuously throughout the year. In 2025, with a focus on embedding security practices into daily operations, Coway executed various initiatives, including annual renewal reminders for the Information Security Pledge and guidance on compliant work practices.
2025 Information Security Campaigns
Category Schedule Target Audience Content
Annual Renewal of the Information Security Pledge April All employees Periodic guidance on information security compliance, including the prohibition of unauthorized use and external removal
Guidance on Security Review Vulnerability Remediation April All employees Guidance on remediation by category, including personal information protection and AWS security configuration
Guidance on Compliant Work Practices July All employees Guidance on compliance items, including the use of SSL-VPN during off-site work to prevent corporate data leakage
Phishing Caution Notice: Impersonation of Consumer Coupon Distribution July All employees
(including field sales sites)
Guidance on identifying and responding to phishing threats exploiting social issues
Caution Notice on the Use of Work PCs November All employees Sharing case studies of external security breach incidents and providing operational security guidelines, such as shutting down PCs upon leaving work
Information Security Investment
Coway recognizes information protection as a core management element rather than a cost, and continues to expand its investments to advance protection frameworks and reinforce threat response capabilities. Pursuant to the "Act on the Promotion of the Information Protection Industry," Coway has been designated as an entity subject to information protection disclosure obligations since 2022, and transparently discloses the overall information protection status, including investment scale, personnel, certifications, and key activities, on an annual basis. The purpose of the disclosure is to support a safe digital environment for users and to encourage companies to voluntarily invest in information protection. As of the end of 2025, Coway's investment in information protection totaled KRW 3.49 billion, accounting for 4.6% of its total IT budget. Key investment items include strengthening endpoint security through the adoption of an Endpoint Detection and Response (EDR) solution, as well as conducting on-site security audits of entrusted partners in collaboration with specialized security firms.
Safeguarding Personal Data Rights of Data Subjects
To enable data subjects to substantively exercise their rights regarding their personal data, Coway maintains a process framework that promptly responds to deletion requests and related grievances. In particular, Coway actively responds to requests received through the "e-Privacy Clean Service" operated by the Personal Information Protection Commission. This service enables data subjects to review their historical online registrations based on identity verification records and conveniently withdraw membership from unnecessary websites, thereby supporting autonomous data management. By continuously upgrading and expanding diverse intake channels, including external linkage channels, Coway is enhancing the level of protection for data subjects' rights.