Preamble

The purpose of the integrated Information Security and Data Protection Management System (IDSMS) is to protect all information against unauthorized access, loss and manipulation, while taking legal, economic and technological requirements into account. Information security is part of corporate policy; management and employees share responsibility.

Objective and Purpose

This policy defines the principles and framework conditions for ensuring an appropriate and sustainable level of protection for information that is relevant to Edelweiss’s safe operations and business success. Information security is an integral part of all corporate processes and is based on the ISMS in accordance with ISO/IEC 27001:2022 and the DPMS in accordance with ISO/IEC 27701:2019.

Scope

This policy is binding for all employees, managers, service providers and partners of Edelweiss Air AG. Outsourced services and systems are also subject to the same security requirements.

Information

Information includes all forms of knowledge, whether digital or analogue, such as texts, data, images or media. Edelweiss’s information security specifically covers:

  • Data relevant to legal and regulatory requirements
  • Critical business processes whose failure could cause economic damage
  • Intellectual property such as licences and patents

Information Security Objectives

The objective is to protect all relevant information while considering the core protection goals:

  • Confidentiality – protection against unauthorized access
  • Integrity – ensuring correct and complete processing
  • Availability – ensuring needs-based accessibility

In summary, the following information security objectives can be derived from the core protection goals and the extended requirements relevant to Edelweiss:

  • Safeguard trust
  • Ensure compliance
  • Ensure data protection
  • Protect sensitive information
  • Operational and process security
  • Risk-based security management
  • Accident and incident prevention
  • Flight operations safety

Requirements and Information Security

All regulatory, legal and contractual requirements are fulfilled, in particular:

  • EASA Part-IS (EU Implementing Regulation 2023/203), EU Implementing Regulation 2019/1583, NASP 19
  • Swiss FADP & EU GDPR
  • ISO/IEC 27001:2022
  • ISO/IEC 27701:2019
  • PCI DSS, IOSA, CO Art. 728
  • Customer contracts

Principles

Information Security Management

Information security management is aligned with international standards, in particular ISO/IEC 27001, and is binding for all internal and external employees as well as contractual partners and suppliers.

Commitment

Edelweiss is committed to consistently applying and further developing the Information Security and Data Protection Management System. This is an integral part of corporate processes and is implemented in accordance with the Safety Policy. Technical and organizational measures are introduced to identify, assess and manage information security risks.

Risk Management

All information assets are identified, and risks are analyzed and assessed. Based on this assessment, management prioritizes the risks and implements measures to reduce them to an acceptable level. Detailed requirements are set out in the Information Security Risk Management Policy.

Information Security Classification

Edelweiss applies a risk-based approach and classifies all information on a mandatory basis. Classification and the corresponding handling instructions protect corporate assets. Details and instructions are defined in the implementation provisions for information classification.

Security Awareness

Security objectives and measures are communicated at least annually. New employees, contractual partners and suppliers are familiarized with the security requirements and informed of their responsibilities.

Implementation of EASA Part-IS Requirements

Edelweiss integrates the requirements of EASA Part-IS as part of the OMM.

Integrated Management System

Edelweiss manages information security and data protection in business and flight-safety-relevant processes through an integrated management system in accordance with ISO/IEC 27001:2022, ISO/IEC 27701:2019 and legal requirements. Information security and data protection are treated equally and within shared processes. Technical, organizational and legal requirements are consistently fulfilled and synergies are used.

Data Protection

In addition to the protection goals, the following data protection principles apply:

  • Lawfulness & transparency
  • Purpose limitation
  • Data minimization & storage limitation
  • Accuracy
  • Integrity & confidentiality

Information Security Incidents

All employees must report information-security-related events immediately in accordance with the established reporting system. Critical incidents are handled and documented by the ERO or specialized units.

Roles and Responsibilities

Responsibilities are assigned according to the principle of accountability:

  • Board of Directors: Strategic responsibility
  • Executive Board: Steering and approval
  • ISO: ISMS leadership and coordination with the Group
  • DPO: Monitors compliance with data protection regulations and coordinates with the Group
  • Process Owner / Application Manager: Implementation in day-to-day operations
  • End users: Compliance with security requirements
  • Risk Management: Identification, assessment and management of risks

Monitoring and Improvement of Effectiveness

The effectiveness of the IDSMS is monitored through defined KPIs, regular internal audits and management reviews. External audits or certification assessments are carried out where required. The results feed into the continuous improvement process.

Sanctions

Violations of this policy may result in disciplinary, civil or criminal consequences. By signing the compliance commitment, all employees acknowledge the validity of this policy.

Approval and Entry into Force

This document is the short version of the Information Security Policy dated 01.06.2026 and has been classified as public.

sig. Bernd Bauer, 28.05.2026

sig. Christoph Schröter, 28.05.2026