Information Security and Data Protection Policy
Preamble
The purpose of the integrated Information Security and Data Protection Management System (IDSMS) is to protect all information against unauthorized access, loss and manipulation, while taking legal, economic and technological requirements into account. Information security is part of corporate policy; management and employees share responsibility.
Objective and Purpose
This policy defines the principles and framework conditions for ensuring an appropriate and sustainable level of protection for information that is relevant to Edelweiss’s safe operations and business success. Information security is an integral part of all corporate processes and is based on the ISMS in accordance with ISO/IEC 27001:2022 and the DPMS in accordance with ISO/IEC 27701:2019.
Scope
This policy is binding for all employees, managers, service providers and partners of Edelweiss Air AG. Outsourced services and systems are also subject to the same security requirements.
Information
Information includes all forms of knowledge, whether digital or analogue, such as texts, data, images or media. Edelweiss’s information security specifically covers:
- Data relevant to legal and regulatory requirements
- Critical business processes whose failure could cause economic damage
- Intellectual property such as licences and patents
Information Security Objectives
The objective is to protect all relevant information while considering the core protection goals:
- Confidentiality – protection against unauthorized access
- Integrity – ensuring correct and complete processing
- Availability – ensuring needs-based accessibility
In summary, the following information security objectives can be derived from the core protection goals and the extended requirements relevant to Edelweiss:
- Safeguard trust
- Ensure compliance
- Ensure data protection
- Protect sensitive information
- Operational and process security
- Risk-based security management
- Accident and incident prevention
- Flight operations safety
Requirements and Information Security
All regulatory, legal and contractual requirements are fulfilled, in particular:
- EASA Part-IS (EU Implementing Regulation 2023/203), EU Implementing Regulation 2019/1583, NASP 19
- Swiss FADP & EU GDPR
- ISO/IEC 27001:2022
- ISO/IEC 27701:2019
- PCI DSS, IOSA, CO Art. 728
- Customer contracts
Principles
Information Security Management
Information security management is aligned with international standards, in particular ISO/IEC 27001, and is binding for all internal and external employees as well as contractual partners and suppliers.
Commitment
Edelweiss is committed to consistently applying and further developing the Information Security and Data Protection Management System. This is an integral part of corporate processes and is implemented in accordance with the Safety Policy. Technical and organizational measures are introduced to identify, assess and manage information security risks.
Risk Management
All information assets are identified, and risks are analyzed and assessed. Based on this assessment, management prioritizes the risks and implements measures to reduce them to an acceptable level. Detailed requirements are set out in the Information Security Risk Management Policy.
Information Security Classification
Edelweiss applies a risk-based approach and classifies all information on a mandatory basis. Classification and the corresponding handling instructions protect corporate assets. Details and instructions are defined in the implementation provisions for information classification.
Security Awareness
Security objectives and measures are communicated at least annually. New employees, contractual partners and suppliers are familiarized with the security requirements and informed of their responsibilities.
Implementation of EASA Part-IS Requirements
Edelweiss integrates the requirements of EASA Part-IS as part of the OMM.
Integrated Management System
Edelweiss manages information security and data protection in business and flight-safety-relevant processes through an integrated management system in accordance with ISO/IEC 27001:2022, ISO/IEC 27701:2019 and legal requirements. Information security and data protection are treated equally and within shared processes. Technical, organizational and legal requirements are consistently fulfilled and synergies are used.
Data Protection
In addition to the protection goals, the following data protection principles apply:
- Lawfulness & transparency
- Purpose limitation
- Data minimization & storage limitation
- Accuracy
- Integrity & confidentiality
Information Security Incidents
All employees must report information-security-related events immediately in accordance with the established reporting system. Critical incidents are handled and documented by the ERO or specialized units.
Roles and Responsibilities
Responsibilities are assigned according to the principle of accountability:
- Board of Directors: Strategic responsibility
- Executive Board: Steering and approval
- ISO: ISMS leadership and coordination with the Group
- DPO: Monitors compliance with data protection regulations and coordinates with the Group
- Process Owner / Application Manager: Implementation in day-to-day operations
- End users: Compliance with security requirements
- Risk Management: Identification, assessment and management of risks
Monitoring and Improvement of Effectiveness
The effectiveness of the IDSMS is monitored through defined KPIs, regular internal audits and management reviews. External audits or certification assessments are carried out where required. The results feed into the continuous improvement process.
Sanctions
Violations of this policy may result in disciplinary, civil or criminal consequences. By signing the compliance commitment, all employees acknowledge the validity of this policy.
Approval and Entry into Force
This document is the short version of the Information Security Policy dated 01.06.2026 and has been classified as public.
sig. Bernd Bauer, 28.05.2026
sig. Christoph Schröter, 28.05.2026