To deliver its services, Sodexo relies on technologies that may involve the processing of client and end-user personal data, including employees of client companies, students, patients, or direct consumers of Sodexo Live!. Such use and processing can affect the privacy and professional life of these individuals.
Whether Sodexo processes personal data on behalf of clients as a data processor, or for its own purposes as a data controller, the Group applies consistent global measures, procedures, and policies.
To ensure the responsible use of personal data in full respect of applicable privacy and data protection legal requirements, Sodexo has implemented a global data protection compliance program (see description of the global program in section 6.5 of this document).
This program has been recognized by the European data protection authorities through the validation of Sodexo’s Binding Corporate Rules (BCR), which describe the procedures and policies deployed across all Group entities, strengthening Sodexo’s commitment to protecting user's personal data.
To ensure the effective implementation of the global data protection compliance program, dedicated governance has been established at both Group and country levels. This governance, detailed in the following diagram, ensures the program’s global deployment across all levels and activities of the Group.
Group data protection governance structure and compliance program
Sodexo is committed to complying with laws that may require a higher level of protection than that defined in the global data protection compliance program, and therefore adapts its analyses and requirements to these regulations.
The data protection program includes an end-to-end privacy compliance process, through which IT or digital projects involving the processing of users’ personal data are reviewed by different stakeholders. This analysis covers, in particular, information on the type of personal data processed, retention periods, security measures, and compliance with regulatory principles. This process is illustrated in the diagram presented in section 6.5 of this document.
Through the deployment of the global data protection compliance program, the Global Data Protection Office works closely with many Group functions, enabling the implementation of: