Information Security Policy

The Organization places the Security and Privacy of information among its primary objectives. In this context, Lottomatica Group has implemented a Safety Management System which extends to the protection of Personnel identification information and is committed to its maintenance and continuous improvement in order to guarantee the following requirements:

  • Confidentiality: information accessible only to duly authorized subjects and / or processes.
  • Integrity: safeguarding the consistency of information from unauthorized changes.
  • Availability: easy access to necessary information.
  • Control: Ensuring that information management processes and tools are secure and tested.
  • Authenticity: reliable origin of the information.
  • Privacy: guarantee of protection and control of personal identification data.

The Information Security and Privacy Management System follows the requirements of the UNI CEI EN ISO / IEC 27001: 2017 and EN ISO / IEC 27701: 2019 standards and applies to the perimeter constituted by the following two concessionary companies of the Group, to the respective fields of application:

  • Gamenet S.p.A: creation and management of the network for the telematic management of lawful gaming by means of amusement and amusement machines, as well as related activities and functions.
  • GBO Italy S.p.A: distribution and management of games with cash prizes, distributed both remotely and through points of sale, as well as production and business management processes.

The general objectives in the area of information security and privacy are as follows:

  • define and guarantee a plan for continuity of service;
  • guarantee the protection of the privacy of employees and customers and of all interested parties;
  • ensure compliance with the mandatory legislation in this area;
  • preserve and enhance the image of the company as a reliable and competent supplier.

In order to pursue the aforementioned objectives, the Management undertakes to:

  • establish corporate roles and responsibilities within your organization;
  • develop the integration of all processes that contribute to the security and protection of information and personally identifiable information;
  • monitor and prevent exposure to any threats to information and personal identification information;
  • activate programs and actions suitable for spreading awareness and culture on information security among interested parties.

The organization, the procedures, the applications, the company know-how, the commitment of the Management and the involvement at every level of the people who work for the Group, represent the essential tools to ensure the achievement of the objectives set.

In order to verify the effectiveness and efficiency, and ensure continuous improvement, our Organization undertakes to periodically check and review this Policy, the objectives and all the elements of the Information Security and Privacy Management System.