Overview of Policies and Guidelines

United   Internet provides an overview of the internal policies and guidelines that aim to prevent, reduce, or remedy actual and potential impacts for those sustainability matters that have been identified as material. At the same time, the goal is to address and mitigate risks and leverage opportunities. The people responsible for implementing the policies and guidelines constantly monitor their effectiveness.

Compliance Guidelines

Description of the compliance management system (CMS)

Determination of roles and responsibilities in the CMS

Compliance monitoring

Group-wide

Corporate Compliance

Intranet

Data Privacy Policy

Ensuring a uniform level of data privacy at United   Internet

Compliance with the GDPR

Personal data is processed on the basis of the objective of data minimization

Personal data is processed on the basis of previously defined purposes

Personal data is stored for as short a period as possible and for as long as necessary, etc.

Segment-specific

Law Enforcement Affairs & Privacy

General Data Protection Regulation (GDPR)

Intranet

Company Cars Policy

Rules for electrifying the vehicle fleet

Group-wide

Commercial Services

Intranet

Management Guidelines

Strengthening of responsible behavior by management and focus on role models and team culture

German Corporate Governance Code

Code of Conduct for Business Partners

Requirements to be met by business partners: compliance, integrity, fair competition, information security and data privacy, and intellectual property

Social and environmental due diligence requirementsiEnvironmental protection and climate change mitigation

Group-wide and segment-specific

Corporate Compliance and Corporate Procurement

UN Guiding Principles on Business and Human Rights

Company website

Policy Statement   

Principles for respecting human rights and environmental due diligence obligations

Risk assessment for own area of business

Risk assessment for supply chain

Preventive measures, remedies, and controls

Group-wide and segment-specific

Corporate Compliance

Universal Declaration of Human Rights, German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz – LkSG), OECD Guidelines for Multinational Enterprises on Responsible Business Conduct

Company website

Whistleblower Protection Policy

Information on how to submit whistleblower reports

Description of reporting channels

Protection for whistleblowers

Group-wide

Corporate Compliance

The German Whistleblower Protection Act (Hinweisgeberschutzgesetz – HinSchG) is the implementation into German law of the EU Whistleblowing Directive (EU Directive 2019/1937), German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz – LkSG)

Intranet

Information Security Management System (ISMS)

Safeguarding the product environment against unauthorized access and misuse

Segment-specific

Group Information Security Officer (GISO) and Segment Information Security Officers (SISOs)

ISO 27001, BSI IT-Grundschutz, BSI C5

Intranet

Group Policy on the Deployment of Contract Workers

Ensuring an efficient decision-making and procurement process

Determination of responsibilities

Ensuring compliance with the law when deploying contract workers

Group-wide

Corporate Procurement

German Employee Leasing Act (Arbeitnehmerüberlassungsgesetz – AÜG)

Intranet

Group Policy on Device Use

Enabling long-term use, refurbishment, and recycling of internal hardware

Group-wide

Corporate IT Services

Intranet

Group Anti-corruption Policy

Rules for accepting and giving gifts and contributions, descriptions of type of gifts and contributions, impacts of breaches

Group-wide

Corporate Compliance

German Anti-corruption Act (Gesetz zur Bekämpfung der Korruption)

Intranet

ArtificiaI Intelligence Guideline

Introduction of AI requirements analysis during procurement and development processes

Ensuring release procedure for AI systems

Establishment of training offerings to ensure adequate AI skills

Group-wide

Corporate Compliance, Corporate Privacy & Corporate Legal

Regulation (EU) 2024/1689 on artificial intelligence (AI Act)

Intranet

Guidelines for Implementing Supply Chain Due Diligence (SCDD)

Organizational structures and workflows for implementing the LkSG

Clarity about governance structures

Appropriate and effective implementation of due diligence obligations

Group-wide

Corporate Compliance

German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz – LkSG)

Intranet

Editing Guidelines

Rules for editorial staff; these are made transparent for the public and published

Segment-specific

Guidelines on Dealing with Reports of Compliance Violations and Conducting Internal Investigations

Legal basis for internal investigations

Workflow for investigations

Roles and responsibilities

Rules of conduct for internal investigations

Group-wide

Corporate Compliance

German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz – LkSG)

Intranet

Source to Contract Policy – S2C

Guidelines and principles for operational and strategic purchasing

Tendering process

Rules governing demand management, product group management, supplier management, and contract management

Segment-specific

Head of Source to Contract

Intranet

Code of Conduct for employees

Interacting with staff, interacting with customers, information handling, competition law and anti-corruption, conflicts of interest, protection of company property, communication, interacting with public authorities, and compliance at United   Internet

Group-wide

Corporate Compliance

ILO labor and social standards

UN Guiding Principles on Business and Human Rights German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz – LkSG) German General Act on Equal Treatment (Allgemeines Gleichbehandlungsgesetz – AGG)

Intranet

Compensation Policy

Ensures comparable, legally compliant, and fair compensation

Group-wide

Corporate Compensation & Benefit

Policy/guidelines

Description

Scope of application

Responsibility for implementation

National and international standards and legislation

Availability