Confidentiality, privacy and cybersecurity
Safeguarding confidential and personal information is core to the services Deloitte firms provide. Deloitte is committed to protecting confidential and personal information, including that of Deloitte clients and third parties, and to continually monitor regulatory and legal requirements to support compliance.
Confidentiality and privacy
The Deloitte Global Confidentiality and Privacy Office helps foster a culture across Deloitte that emphasizes the importance of protecting confidential and personal information. This office sets guidelines, develops procedures, provides consultation and training, and assesses the effectiveness of controls relating to confidentiality and privacy. The Deloitte Global Confidentiality and Privacy Office works with Deloitte Global Technology Services, including the Deloitte Global Cybersecurity organization, and the Deloitte Global Office of General Counsel, to understand, prepare for and respond to known and reasonably anticipated risks and threats facing our environment.
Consistent with industry leading practices for protecting confidential information, Deloitte has taken steps to remain secure, vigilant and resilient, including:
- Understanding the risk environment;
- Implementing policies, procedures and controls designed to protect confidential and personal information;
- Responding to potential confidentiality and privacy incidents in a timely manner; and
- Actively monitoring the effectiveness of confidentiality and privacy requirements across the Deloitte organization.
The Deloitte Global Cybersecurity organization works with the Deloitte Global Confidentiality and Privacy Office, as well as Deloitte confidentiality, privacy and cybersecurity professionals around the world to execute a strategy designed to:
- Create a cohesive, worldwide cyber program with consistent, high-quality security services;
- Extend security tools worldwide for advanced protection of highly distributed data;
- Implement and sustain technology safeguards to protect confidential and personal information;
- Prepare and implement plans to promptly recover from and restore any systems that may be adversely impacted by a cyber incident; and
- Reduce the risk of unauthorized exposure of confidential or personal information.