Policies
Our Global Data Privacy Policy sets forth the principles that govern our treatment of personal data. Our policy on the Acceptable Use of Dover Electronic Equipment, Systems and Data governs the use and protection of information about our company and information that is stored on our computers and mobile devices. Our policies restrict individuals’ access to personal data to those that need such access to accomplish a business objective and allow access only as necessary.
Actions and Initiatives
Operational Privacy and Security: Dover manages data security and privacy-related risks through a combination of ongoing
monitoring, defined governance practices and operational controls. Our security personnel conduct regular assessments of our threat landscape and continuously monitor systems and
other technical security controls. With support from third-party advisors, the team regularly reviews and updates information security policies and procedures to maintain
alignment with regulatory requirements and effectively manage data privacy and security risks.
From an operational perspective, we use vulnerability scanning tools to assess potential cybersecurity risks across our businesses. We correlate the results, monitor activities
based on threat modeling analysis and monitor any actions in progress with the system owners based on assigned timelines for remediation. In addition, our online employees
participate in cybersecurity, information security and privacy training at least annually. Still, patch and vulnerability management, including for products and information
assets, remains a complex and key risk that can lead to exploits, security breaches and service disruption. Below we discuss some key initiatives to mitigate this risk.
Digital Products and Services Security: Our businesses increasingly complement our product component or equipment offerings with
digital solutions, such as connected products, sensors and software. We recognize the various factors driving customer demand for strong product security, including evolving
regulatory requirements, cybersecurity requirements, industry-specific guidance, business needs and the desire to manage the supply chain. We believe that integrating security
measures into our digital products and services can help to differentiate our product offerings and increase relevance with our customers.
Our product security efforts are informed in part by industry security standards such as ISA 62443, UL 2900-1 and certain standards from the National Institute of Standards &
Technology. As part of our efforts, we conduct risk assessments and prioritize security validation of our products. For example, we conduct security testing and remediation on a
risk-based, prioritized basis prior to releasing certain products into the market, as well as periodically post-release to discover potential issues in code, firmware and
protocols and to consider potential security patches or future version updates. We have received System and Organization Controls 2 ("SOC 2") certifications for some of our
digital service offerings and continue to strive to meet similar requirements for other solutions.
Implementing Data Privacy Safeguards: Dover implements technical and organizational safeguards to protect personal data, including
deploying security tools, restricting access based on role and maintaining physical security controls to prevent unauthorized access, disclosure, loss or damage. We define and
enforce access controls and data use limitations across our systems and products so that personal data is used only for legitimate business purposes.
Additionally, we operationalize compliance with applicable privacy and data protection laws, including the EU General Data Protection Regulation (GDPR) and California Consumer
Privacy Act (CCPA) where relevant, by embedding requirements into our policies, procedures and system controls. Our teams monitor regulatory developments with support from
external advisors and update our controls, processes and documentation to address new or evolving requirements.
Dover incorporates privacy considerations into product development by embedding review checkpoints and data protection requirements throughout the lifecycle. We also conduct due
diligence and impose contractual requirements on suppliers and business partners that handle personal data and monitor their compliance with applicable data protection standards.