Basic Policy
on Information Security
The 2nd RETAILING Group is involved in a wide range of businesses through our online services and network of stores across Japan, and we handle important information assets including personal customer information in our daily business operations. To ensure that we can continue to provide our stakeholders with safe and secure services, it is essential that we maintain a solid understanding regarding the importance of information security, so that we can protect information from various threats and manage and operate the information securely and appropriately.
Based on this understanding, all officers and employees of the 2nd RETAILING Group strive to appropriately handle, manage, protect, and maintain information assets according to this Basic Policy on Information Security.
1.
Information Security System
and Ongoing Improvement
We appoint an Information Security Manager to supervise our information systems, and establish a Risk Management Committee composed of Directors, Operating Officers, and Operating Managers. We also establish a CSIRT (Cyber Security Incident Response Team) that acts as the core organization that handles and prepares for incidents. At normal times, the CSIRT promotes technical countermeasures such as system attack monitoring, periodic vulnerability diagnosis, and surveys of new technologies. The team also accumulates specialized expertise via operational activities and conducts ongoing reviews of handling procedures in order to strengthen the response capability of the entire group. These efforts enable us to build a system for accurately understanding the status of information security across the entire group and swiftly implementing the required countermeasures. We also strive to continuously improve information security measures according to information security evaluations, environmental changes, and the emergence of new risks.
* For certain subsidiaries, the operational structure may differ in part based on equivalent separate policies.
2.
Compliance
with Laws and Regulations
We comply with laws, guidelines, and regulations regarding information security, and establish and ensure compliance with corresponding internal rules.
All of our officers and employees must comply with these rules, and anyone found to be in violation of this policy or our internal rules regarding information security will be disciplined as stipulated in the internal rules.
3. Management of Information Assets
We implement appropriate management to ensure the confidentiality, integrity, and availability of all the important information assets we hold (including personal information and specific personal information).
We strive to securely manage information assets in order to protect the assets from threats such as leaks, interference with legitimate use, erasure, or data modification due to unauthorized access, and thereby prevent impacts on our business operations and loss of trust from society.
4.
Education and Training
on Information Security
We periodically provide ongoing education and training to ensure that all our officers and employees have a correct understanding regarding the importance of information security. This enables us to improve and maintain an understanding of information security across the entire organization.
5.
Prevention and Handling
of Security Incidents
In order to protect information assets from internal and external threats, we implement the required security monitoring and strive to prevent accidents and incidents before they occur. If an information asset intrusion or incident should occur, we strive to minimize damage by acting quickly, and swiftly and appropriately investigate the cause and implement preventive measures.
6. Information Security Audits
We periodically conduct audits via an internal audit or external audit framework to objectively evaluate our information security efforts, check compliance with this policy and internal regulations, and confirm that our information security management system is being appropriately maintained and operated.
Established on August 20, 2026
Revised on October 1, 2026