search icon SUGGESTIONS

Dear colleagues, feel free to send us your stories, news and any other contribution to suggestions@dufry.com so that we can continue to develop Dufry World as a magazine from employees for employees.

Issue 37 - December 2020

Data Leak Prevention Program

graphic graphic

By Ángel Gálvez, Global IT Security Head

As part of the IT Security Awareness program which advises employees about potential IT risks, the Dufry IT Security team recently communicated the Data Leak Prevention program (DLP) supported with relevant training within the business.

The Data Leak Prevention program is a comprehensive set of initiatives set up by the IT Security team to mitigate legal and reputational risks that may affect our business in the event that any Dufry internal, confidential or sensitive information is leaked, either by accident or negligence.

graphic graphic

In our day-to-day working practices, most of us use free storage and file transfer services that makes our lives easier. These, amongst others, include Google Drive, Dropbox, iCloud, Google Photos… and the very popular WeTransfer. These services however lack the security, control and backup measures that corporate information require, hence, the increasedrisk of losing sensitive information. There are certain liabilities and responsibilities related to the leak of information.

These are both reputational, but also legal. Thus, they may affect both Dufry and the individual responsible for the data leak. The company has very clear guidelines in the handling and classification of information, covered in the ITH-9 procedure available here and on the company´s intranet, Dufry Gate.

The DLP program therefore, is not so much to act as “data leak police” within Dufry, but is designed instead to protect both Dufry and its employees from the risk of accidentally leaking or losing sensitive information.

In order to stay safe, here are some recommendations:

  • If you need to store or transfer Dufry-related information, use the current resources and environments Dufry provide.

  • DO NOT create private accounts in public cloud sites like Dropbox, Google Drive, Google photos, Wetransfer etc. to store or transfer Dufry information.

  • DO NOT share files containing Dufry information with third parties, through public and unsecure networks and public cloud storage solutions.

  • DO NOT upload application code developed at Dufry into public sites like GITHUB or similar as this information is proprietary.

  • Check any information before sharing or sending out to make sure there is no unauthorized exfiltration of data.

Finally, please remember that Dufry has alternative solutions for file transfer and cloud hosting of sensitive information that are compliant with Dufry´s IT Security policies. The Dufry IT Security team invites anyone that needs to share this kind of information with third parties to get in contact with them using this email address itsecurity@dufry.com.

We use cookies on this website to enhance your online experience. By continuing to browse our website you agree to our Privacy & Cookie Statement and Terms of Use. Privacy & Cookie Statement and Terms of Use.