Data Security and Privacy

Governance

We maintain valuable information and technology assets—data, systems and applications—that are critical to our operations and our success as an enterprise. Our businesses have both an increasing reliance on IT systems and a growing digital footprint as a result of changing technologies, connected devices, digital offerings and remote work policies. We also prioritize data security and privacy in connection with our digital innovation efforts; security and privacy considerations are incorporated into the design and operation of connected products and digital solutions.

We take a coordinated approach to cybersecurity and data protection. The corporate center provides governance and enterprise standards, while operating companies lead implementation, particularly for their own information assets, digital systems and connected products. Our Board has established a risk management process to identify and manage material risks at the enterprise level, including the potential impact of key cybersecurity threats. The full Board meets with the Senior Vice President & Chief Digital Officer ("CDO") and the Chief Information Security Officer ("CISO") at least annually to discuss our cybersecurity efforts. The Board also periodically receives targeted briefings related to cybersecurity and reviews our incident response capabilities. The CDO is responsible for overseeing corporate-wide data security and the CISO is responsible for developing, implementing and enforcing security policies to manage our overall cybersecurity risks.

We leverage a cross-functional Data Privacy Council that meets to discuss developments in global privacy law and to implement changes as needed to facilitate regulatory compliance. We also require third‑party service providers with access to our systems or data to comply with applicable information security and data protection requirements.

Policies

Our Global Data Privacy Policy sets forth the principles that govern our treatment of personal data. Our policy on the Acceptable Use of Dover Electronic Equipment, Systems and Data governs the use and protection of information about our company and information that is stored on our computers and mobile devices. Our policies restrict individuals’ access to personal data to those that need such access to accomplish a business objective and allow access only as necessary.

Actions and Initiatives

Operational Privacy and Security: Dover manages data security and privacy-related risks through a combination of ongoing monitoring, defined governance practices and operational controls. Our security personnel conduct regular assessments of our threat landscape and continuously monitor systems and other technical security controls. With support from third-party advisors, the team regularly reviews and updates information security policies and procedures to maintain alignment with regulatory requirements and effectively manage data privacy and security risks.

From an operational perspective, we use vulnerability scanning tools to assess potential cybersecurity risks across our businesses. We correlate the results, monitor activities based on threat modeling analysis and monitor any actions in progress with the system owners based on assigned timelines for remediation. In addition, our online employees participate in cybersecurity, information security and privacy training at least annually. Still, patch and vulnerability management, including for products and information assets, remains a complex and key risk that can lead to exploits, security breaches and service disruption. Below we discuss some key initiatives to mitigate this risk.

Digital Products and Services Security: Our businesses increasingly complement our product component or equipment offerings with digital solutions, such as connected products, sensors and software. We recognize the various factors driving customer demand for strong product security, including evolving regulatory requirements, cybersecurity requirements, industry-specific guidance, business needs and the desire to manage the supply chain. We believe that integrating security measures into our digital products and services can help to differentiate our product offerings and increase relevance with our customers.

Our product security efforts are informed in part by industry security standards such as ISA 62443, UL 2900-1 and certain standards from the National Institute of Standards & Technology. As part of our efforts, we conduct risk assessments and prioritize security validation of our products. For example, we conduct security testing and remediation on a risk-based, prioritized basis prior to releasing certain products into the market, as well as periodically post-release to discover potential issues in code, firmware and protocols and to consider potential security patches or future version updates. We have received System and Organization Controls 2 ("SOC 2") certifications for some of our digital service offerings and continue to strive to meet similar requirements for other solutions.

Implementing Data Privacy Safeguards: Dover implements technical and organizational safeguards to protect personal data, including deploying security tools, restricting access based on role and maintaining physical security controls to prevent unauthorized access, disclosure, loss or damage. We define and enforce access controls and data use limitations across our systems and products so that personal data is used only for legitimate business purposes.

Additionally, we operationalize compliance with applicable privacy and data protection laws, including the EU General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) where relevant, by embedding requirements into our policies, procedures and system controls. Our teams monitor regulatory developments with support from external advisors and update our controls, processes and documentation to address new or evolving requirements.

Dover incorporates privacy considerations into product development by embedding review checkpoints and data protection requirements throughout the lifecycle. We also conduct due diligence and impose contractual requirements on suppliers and business partners that handle personal data and monitor their compliance with applicable data protection standards.

Data Privacy Policy Highlights

Our employees are instructed to:

Data Privacy Do's and Don'ts Graphic