Security builds trust

The purpose of this Policy is to ensure a high level of security for the customers, employees, services, products, assets, and activities of Telekom Payments (hereinafter the “Company”).

For the OTE Group and, consequently, for the Company, security and data protection are not merely a matter of complying with regulatory requirements but a fundamental element of the quality of the services provided. At the same time, they are crucial for ensuring customer trust in matters of security management.

The Company operates in a rapidly evolving market for electronic money and payment services, characterized by strong dynamics, complex processes, and strict security requirements. The increasing complexity of e-money and payment services heightens the importance of trust. New and evolving challenges and threats are emerging, such as cybercrime, as well as concerns regarding the protection of personal data. Customers, shareholders, and employees must be confident that the Company fully assumes responsibility for its assets, products, and services. It is imperative that they feel assured that all data and information entrusted to the Company are processed securely and lawfully, protected from any misuse.

The Security Policy is binding on the members of the Board of Directors, directors, managers, and all employees of the Company. It contributes to shaping a strong security culture and provides the foundation that defines all actions related to security. It is also addressed to customers and shareholders, serving as evidence of transparency and reliability in the management of security matters—as security builds trust. To achieve this, people are always placed at the center of the Company’s security strategy.

General Information Security Policy

Telekom Payments has approved the General Information Security Policy and hereby affirms its full commitment to the effective implementation and provision of adequate resources for the continuous improvement of the Information Security Management System (ISMS).

  • The General Information Security Policy aims to ensure the following:
    • Continuous protection of information against any unauthorized access.
    • Ongoing assurance of the Confidentiality of the information of Telekom Payments, its customers, and its partners.
    • Ongoing maintenance of the Integrity of the information of Telekom Payments, its customers, and its partners.
    • Ongoing assurance of the Availability of information and business processes.
    • Continuous monitoring of and compliance with the Legal and Regulatory Requirements applicable to Telekom Payments.
    • The Business Continuity Plan is maintained and tested for its effectiveness.
    • Continuous Information Security training for all employees of Telekom Payments.
    • (Confirmed or suspected) information-security and personal-data breaches are reported to the Information Security Officer , thoroughly investigated, and addressed promptly and effectively.
  • All appropriate procedures and individual information security policies have been developed and are implemented to support this policy, including technical and organizational protection measures.
  • Telekom Payments ensures continuous compliance with the requirements of ISO 27001:2022 through ongoing monitoring of the implementation of the Information Security Management System.
  • The Information Security Officer is responsible for maintaining the General Information Security Policy and for providing support and advice during its implementation.
  • All Telekom Payments personnel with managerial responsibilities are directly responsible for implementing the General Policy and for ensuring the compliance of the staff they supervise.
  • Compliance with the General Information Security Policy is mandatory for all those who work for or collaborate with Telekom Payments.
  • Any violations of the General Information Security Policy are subject to disciplinary measures. Each measure depends on the nature and impact of the violation.