We Endeavor to Embrace Incremental Changes
ESG

NHN is dedicated to creating meaningful change in society through inclusion and responsibility, shared growth.
Information Protection
Information Protection Policy
NHN has implemented an information protection policy framework tailored to each employee's role. We conduct assessments on a regular basis, at least once a year, to ensure compliance with the policy, evaluate its effectiveness and make necessary improvements. This comprehensive framework comprises a top-level policy statement, supplemented by guidelines for different roles and responsibilities. Additionally, detailed guidelines are also prepared to provide precise instructions for implementing the higher-level guidelines, offering stringent security measures to prevent any information leakage.

Information Security Governance
NHN has appointed a Chief Information Security Officer (CISO) and a Chief Privacy Officer (CPO) as executives of its dedicated information security organization, granting them clear authority and responsibility over data security and privacy protection. Additionally, NHN operates an Information Security Committee comprised of key executives, including the CISO and CPO, to discuss and make decisions on major changes in information security governance. In order to strengthen information security and data protection, NHN maintains a dedicated information security organization while separating IT security and information protection policy entities for enhanced expertise and specialization.
Information Security Certification
NHN has obtained certifications for information security system and service stability from domestic and foreign reputable certification organizations. We spare no effort to check, manage, and operate internal systems, such as receiving verification on the personal information and information security systems from specialized national agencies.
ISMS-P

ISO/IEC 27001, 27701, 29100

ISO/IEC 27017, 27018, 27799

ISO/IEC 22301

CSAP(Cloud Security Assurance Program) Certification [IaaS, SaaS]

CSA STAR

Guaranteeing the Right to Control Personal Information
User Personal Information Management
NHN provides guidance on user and legal guardian rights and how to exercise them through the Hangame Privacy Policy. Users and legal guardians can view or rectify their personal information or that of a child under the age of 14 at any time. If users do not consent to NHN’s processing of personal data, they have the right to refuse consent or request withdrawal of membership (withdrawal of consent or deletion of personal information). Users can rectify or review their information by selecting “Edit Member Information” on Hangame’s My Page and can withdraw their membership by clicking “Withdraw Membership” upon completing the identity verification process.
Collection and Disposal of Personal Information
NHN collects only the minimum necessary personal data in accordance with legal procedures and retains it for the duration agreed upon by the data subject or as required by applicable laws. When the processing purpose is fulfilled such as membership withdrawal, the collected data is deleted without delay. Any personal data that is no longer needed is securely disposed of. If NHN receives personal information from a third party, it only collects and processes the data within the scope agreed upon. Additionally, in accordance with the Personal Information Protection Act, NHN provides data subjects with a ‘Personal Information Collection Source Notification,’ which includes details on the source of collection, the purpose of processing, and the data subject’s right to request suspension of processing.
Provision of Personal Information to Third Parties
NHN lawfully collects Hangame users’ personal information and does not use or share it beyond the agreed scope without acquiring prior user consent. However, exceptions apply when users have explicitly consented to third-party data sharing. Such cases include when participating in channeling game services, promotional events, or giveaways. Even in such cases, NHN transparently informs users about the recipient, the purpose of data sharing, the specific data provided, and the recipient’s retention and usage period. Users must provide explicit and individual consent before any information is shared. NHN strictly prohibits providing, renting, or selling personal information to third parties for any purpose other than its intended business operations.
Personal Information Management System
Information Protection Monitoring System
NHN has implemented Secumon, an integrated security log analysis system based on open-source technology in a bid to enhance data security level. This system monitors all potential pathways where information is processed, including VPN access, server and database accesses, device activity logs, administrator actions on critical information systems, and external collaboration platform access. Secumon leverages machine learning technology to set predictive thresholds and detect abnormal activities in real time. NHN swiftly identifies potential security vulnerabilities and threats through daily monitoring and takes immediate action to reinforce personal information protection. NHN is committed to establishing a differentiated personal information protection system through its specialized security technology, while enhancing the security of its entire data processing environment.
Inspection of Personal Information Processing Contractors
NHN regularly inspects and oversees the personal information protection practices of its data processing contractors for compliance with privacy regulations. NHN conducts semi-annual inspections in the first and second half of the year to assess the status of data protection and identifies areas for improvement, requesting correction as needed. NHN also carries out follow-up inspections to verify the implementation of these improvements, ensuring a continuous management system. Additionally, NHN rigorously reviews the operational status and the handling of provided data according to outsourcing contracts. Upon contract termination, NHN requires contractors to submit a report verifying data destruction confirmation to guarantee the secure disposal of personal information. ※ 2024 Operational Performance: NHN conducted personal information protection inspections for 54 data processing contractors.
Information Security Training
NHN conducts information protection training to raise the information security awareness among its employees and partners. New hires are required to take information security training as part of their employment process and we provide training on personal information protection to all types of employees, including contractors and temporary workers every year. New hires serving technical position are also provided with developer security training so that information protection practices for safe service development and operation are properly shared. We provide information protection training materials tailored to the purpose of the service to not only employees but also partners, so that all employees and members have the ability to prevent and respond to security incidents based on their understanding of information protection.