Aller à l’essentiel de l’information

Bibliothèque des disclosuresGuide pratique pour chaque information à publier

GRI 418: Customer Privacy·Disclosure GRI 418-1

Substantiated complaints concerning breaches of customer privacy and losses of customer data

Guide pratique pour préparer cette information. Utilisez cette fiche pour identifier les données à préparer, vérifier les affirmations et organiser les preuves. Pour les exigences exactes, reportez-vous toujours à la source officielle Global Reporting Initiative.

Statut juridique

GRI 418: Customer Privacy 2016 remains the applicable published GRI Topic Standard and is effective for reports or other materials published on or after 1 July 2018.

Passeport publié

Dernière révision le 2026-08-03
RK Révisé par Dr Ross KurinkoLinkedIn Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS expert GRI Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert 15+ years on FTSE 100 & Fortune Global 500 disclosures Canary Wharf, London Support pédagogique LRA · Non publié ni approuvé par Global Reporting Initiative

Norme

GRI 418: Customer Privacy

Disclosure GRI 418-1 · 2016

En vigueur

2018-07-01

Source officielle : Ouvrir ↗

Dernière révision

2026-08-03

Support pédagogique LRA · Non publié ni approuvé par Global Reporting Initiative

Objet de l’information

This disclosure requires the organization to report the total number of substantiated complaints concerning breaches of customer privacy, categorized as:

complaints received from outside parties and substantiated by the organization; and

complaints from regulatory bodies.

It also requires the total number of identified leaks, thefts or losses of customer data.

A substantiated complaint is either a qualifying written statement from a regulatory or similar official body identifying a breach or a complaint lodged with the organization that the organization has recognized as legitimate.

Complaint counts and customer-data incident counts are separate measures. A data incident does not need to result in a complaint, and one data incident can result in several complaints.

If no substantiated complaints were identified, a brief statement is sufficient. The organization must still report any identified leaks, thefts or losses of customer data.

The organization must also indicate if a substantial number of the reported breaches relates to events in preceding years.

Policies, cybersecurity controls, affected-customer counts, financial losses and remediation actions can provide additional context but do not replace the required information.

Ce support pédagogique LRA aide à préparer l’information. Pour les exigences exactes, reportez-vous toujours à la source officielle Global Reporting Initiative.

Avant de commencer

Avant de commencer

Une courte liste de contrôle avant de préparer cette information — cochez chaque point une fois réglé.

Préparation

Informations clés à préparer

Champ à préparer Ce qu’il faut recueillir Indice de preuve Responsable
Outside-party complaints substantiated by the organization Complaints concerning customer-privacy breaches lodged by external parties and recognized as legitimate. Complaint register, investigation outcome and substantiation decision. Privacy / Customer Complaints / Legal
Complaints from regulatory bodies Qualifying written complaints or statements from regulators or similar official bodies identifying customer-privacy breaches. Regulator correspondence, decision and legal review. Privacy / Regulatory Affairs / Legal
Total substantiated complaints Reconciled sum of the two complaint-source categories. Controlled complaint calculation and duplicate check. Sustainability Reporting
Identified customer-data leaks, thefts or losses Total number of unique identified events involving customer data. Privacy and security incident register, forensic findings and breach records. Information Security / Privacy
Customer population Confirmation that consumers and relevant B2B customers are covered. Data classification and customer-system mapping. Privacy / Data Governance
Preceding-year connection Whether a substantial number of the reported breaches relates to events in preceding years. Event, complaint, identification and resolution dates. Privacy / Legal
Zero-complaints statement Brief statement where no substantiated complaints were identified. Complete complaint search and sign-off. Privacy / Compliance
Methodology and exclusions Counting units, reporting dates, duplicates, non-customer data and reasons for omission. Methodology paper and exception log. Sustainability Reporting
+ Afficher les sous-éléments de GRI 418-1 (liste de travail LRA)

Comment le préparer

Confirm the GRI reporting boundary.
Apply the official definitions of customer privacy, breach of customer privacy and substantiated complaint.
Identify the relevant consumer and B2B customer-data populations.
Consolidate potentially relevant complaints from customer service, privacy, legal and regulatory systems.
Separate outside-party complaints from regulatory-body complaints.
Confirm which outside-party complaints were recognized as legitimate.
Confirm which regulator communications meet the substantiated-complaint definition.
Consolidate customer-data leaks, thefts and losses from privacy, security, operational-risk and third-party records.
Remove duplicate complaints and duplicate data incidents.
Keep complaints and data incidents as separate counting populations.
Calculate the two complaint-source totals.
Calculate the total number of identified customer-data leaks, thefts or losses.
Review event and identification dates to determine whether a substantial number of breaches relates to preceding years.
Prepare the zero-complaints statement where applicable.
Reconcile every published figure to controlled records.
Apply a reason for omission where required information cannot be reported.
Verify the disclosure against GRI 418-1(a)–(c) and compilation requirement 2.1.

Demander les données

Request the disclosure evidence

Traduisez l’information en une question métier interne, puis adaptez-la au vocabulaire de votre organisation.

Please provide the GRI 418-1 complaint and customer-data incident records for [reporting period]. For each complaint, include: controlled complaint ID; date received; source — outside party or regulatory body; complainant type; customer population involved; privacy issue; applicable law or voluntary standard; substantiation status; basis for recognizing the complaint as legitimate; underlying event date; reporting-period classification; and source-record reference. For each customer-data incident, include: controlled incident ID; leak, theft or loss classification; customer-data population; underlying event date; identification date; third-party involvement; linked complaints; affected-customer count as optional context; and source-record reference. Please provide the reconciled totals for the two complaint categories and the separate customer-data incident total.

Use the organisation's own role and document names, but preserve the defined GRI terms and the scope described above.

Meilleure demande

Please provide the GRI 418-1 complaint and customer-data incident records for [reporting period]. For each complaint, include: controlled complaint ID; date received; source — outside party or regulatory body; complainant type; customer population involved; privacy issue; applicable law or voluntary standard; substantiation status; basis for recognizing the complaint as legitimate; underlying event date; reporting-period classification; and source-record reference. For each customer-data incident, include: controlled incident ID; leak, theft or loss classification; customer-data population; underlying event date; identification date; third-party involvement; linked complaints; affected-customer count as optional context; and source-record reference. Please provide the reconciled totals for the two complaint categories and the separate customer-data incident total.

Rédigez votre information

Des notes qui transforment les données en information publiée

Modèles pédagogiques LRA — adaptez-les à votre organisation et vérifiez la source officielle avant validation.

Note méthodologique

Substantiated complaints were identified using the GRI definition. Outside-party complaints were counted when recognized as legitimate by the organization. Regulatory-body complaints were identified separately. Customer-data leaks, thefts and losses were counted as unique events.

Note de contexte

Keep mandatory GRI Requirements, GRI recommendations and additional LRA preparation controls clearly distinguished. Apply a GRI 1 reason for omission where required information cannot be reported.

Centre de téléchargement

Outils et formulaires de préparation

Outils de préparation professionnels pour GRI 418-1 — gratuits avec l’adhésion à LRA Community. Inscrivez-vous une fois (c’est gratuit) et tous les téléchargements se débloquent, avec la Bibliothèque des informations, les modèles et l’assistant IA LRA.

Gratuit · Membres de la Community

Préparation à l’assurance

Pour chaque affirmation, vérifiez les preuves

Affirmation Risque Preuves à vérifier
We applied the GRI definition of a substantiated complaint.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
We applied the GRI definition of a breach of customer privacy.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
The customer population includes relevant consumers and B2B customers.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Employee-only and supplier-only privacy matters were not included automatically.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Outside-party complaints were reported separately from regulatory-body complaints.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Every outside-party complaint counted was recognized as legitimate by the organization.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Every regulatory-body complaint is supported by a qualifying written statement or complaint.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Regulator enquiries and information requests were not classified automatically as complaints.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Complaint topics were not used as substitutes for the two required source categories.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Duplicate complaint records submitted through several channels were removed.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
The customer-data total contains identified leaks, thefts or losses rather than all cybersecurity incidents.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Every customer-data incident counted involved customer data.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Customer-data incidents were counted independently from complaints.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Affected customers, records and notification letters were not counted as incidents.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
One event classified as both a leak and a loss was not double counted.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Incidents involving third-party processors were assessed consistently under the reporting methodology.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Complaints and data incidents use documented reporting-period rules.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
The underlying event date and identification or substantiation date are retained.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
We assessed whether a substantial number of reported breaches relates to preceding-year events.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
We did not replace the preceding-years indication with an unsupported percentage threshold.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Where no substantiated complaints were identified, the zero statement is supported by a complete search.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
A zero-complaints statement did not cause customer-data incidents to be omitted.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
All counts are exact whole numbers and were not estimated or rounded.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
The published counts reconcile to controlled complaint and incident registers.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Any unavailable required information is addressed through the applicable GRI reason-for-omission requirements.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.

Dossier de preuves à préparer

Lacunes fréquentes dans les rapports

The two required complaint-source categories are not reported separately.
Complaint topics are used instead of outside-party and regulatory-body categories.
Only complaints received from customers are reported.
Regulatory-body complaints are omitted.
Regulator enquiries are counted automatically as complaints.
Outside-party complaints are counted before they are recognized as legitimate.
Partially upheld complaints are treated inconsistently.
The total number of identified leaks, thefts or losses of customer data is missing.
All cybersecurity incidents are presented as customer-data incidents.
Employee-data incidents are included.
Affected customers or records are counted instead of events.
Data incidents are omitted because no complaint was received.
Complaints and data incidents are combined into one total.
One data event is counted several times as a leak, theft and loss.
A zero-complaints statement is used as though it also meant zero data incidents.
The report says no complaints were received rather than no substantiated complaints were identified.
B2B customer data are excluded.
Third-party processor incidents are omitted without a methodology.
A prior-year percentage is disclosed without addressing the GRI substantial number requirement.
A substantial connection to preceding-year events is not indicated.
Complaint and incident counts are estimated or rounded.
The published figures cannot be reconciled to source records.

Exemples

Exemples illustratifs

Synthétiques, rédigés par LRA — ils ne proviennent ni d’un rapport d’entreprise ni du texte d’une norme.

Illustrative example 1

Illustrative synthetic example — Retail banking
During 2026:
nine complaints received from outside parties were substantiated by the Bank;
one complaint was received from a regulatory body; and
five leaks, thefts or losses of customer data were identified.
Six of the ten substantiated complaints related to one privacy breach that occurred in the preceding reporting period. The Bank therefore concluded that a substantial number of the reported breaches related to preceding-year events.

Synthetic LRA illustration. Replace every figure and fact with the reporting organisation's evidence.

Illustrative example 2

Illustrative synthetic example — Healthcare services
Seven outside-party complaints concerning patient-data handling were received. None was recognized as legitimate after investigation, and no complaints were received from regulatory bodies.
The organization therefore identified no substantiated complaints.
Separately, two losses of customer data were identified and reported under Disclosure 418-1(b).

Synthetic LRA illustration. Replace every figure and fact with the reporting organisation's evidence.

Illustrative example 3

Illustrative treatment — Regulatory complaint
A data-protection authority issued a written statement identifying a breach of customer privacy. The complaint was reported in the regulatory-body category without waiting for the organization to mark it as upheld.

Synthetic LRA illustration. Replace every figure and fact with the reporting organisation's evidence.

Illustrative example 4

Illustrative treatment — One incident, several complaints
One customer-data leak caused 14 separate substantiated customer complaints. The organization reported 14 complaints under 418-1(a) and one data leak under 418-1(b).

Synthetic LRA illustration. Replace every figure and fact with the reporting organisation's evidence.

Rapports d’entreprises

Comment les entreprises publient GRI 418-1 en pratique

Exemples de pratiques de publication complètes et partielles. Ce sont des analyses fondées sur des preuves, non des modèles à recopier.

Rapports réels publiés
Transportadora de Gas Internacional S.A. E.S.P.
Oil and Gas · Colombia · 2025
Ouvrir le rapport →

TGI’s Integrated Sustainability Report 2025 contains a dedicated GRI 418-1 table that follows the required structure:

complaints received from outside parties and substantiated by the organization;

complaints from regulatory authorities; and

identified leaks, thefts or losses of customer data.

The current card should:

use the substantive GRI 418-1 table on report page 158 as the principal evidence;

present the exact 2025 values for all three required rows;

distinguish current-year values from the comparative figures;

remove the 202 ethics and compliance activities from the GRI 418-1 assessment;

remove Scope 3 Category 4 emissions;

remove flaring, fugitive-emissions, venting and pneumatic-source information;

assess whether the report indicates a substantial connection to preceding-year events; and

classify the disclosure based only on the privacy-complaint and customer-data rows.

The report extract shows the required GRI categories and a non-zero customer-data incident result; unrelated emissions and compliance-activity data do not contribute to Disclosure 418-1.

The official report search extract identifies the outside-party, regulator and customer-data rows.

O-Bank Co., Ltd.
Banks / Diverse Financials / Insurance · Taiwan · 2024
Ouvrir le rapport →

O-Bank’s report contains information that needs reconciliation.

The GRI content-index section states that no substantiated complaints concerning breaches of customer privacy or losses of customer data were received. Elsewhere, the report discloses two data breaches and states that 100% were personal-data breaches affecting account holders.

The card should:

retain the zero substantiated-complaints statement for Disclosure 418-1(a), subject to verifying both required complaint-source categories;

not treat the zero-complaints statement automatically as zero customer-data incidents;

identify whether the two personal-data breaches were leaks, thefts or losses of customer data under GRI 418-1(b);

reconcile pages 311 and 313;

report the customer-data incident total separately;

retain affected account holders only as supplementary context;

remove the absence of monetary legal losses as a gap; and

classify the disclosure as internally inconsistent or requiring reconciliation until the two breach records are resolved.

The current LRA card itself records both the zero statement and the two personal-data breaches, but focuses incorrectly on monetary losses.

First Financial Holding Co., Ltd.
Banks / Diverse Financials / Insurance · Taiwan · 2024
Ouvrir le rapport →

First Financial Holding’s 2024 Sustainability Report provides quantitative information relevant to GRI 418-1.

The report identifies one data breach, indicates that it was a personal-data breach and reports 592 affected account holders. It also contains a GRI 418-1 table with numeric complaint and customer-data values.

The card should:

use report page 232 as the principal source for the GRI 418-1 complaint and customer-data figures;

verify that outside-party and regulatory-body complaints are shown separately;

use pages 218 and 226 only as supporting context for the data breach and affected-account count;

report one identified data incident only if the incident meets the leak, theft or loss definition used for GRI 418-1(b);

retain 592 affected account holders as supplementary context;

remove financial losses from litigation exceeding NT$5 million;

remove whistleblowing-report discussion;

remove supplier-category information; and

classify the report based on the exact GRI 418-1 table and its reconciliation to the reported breach.

The official report source maps information security and privacy protection to GRI 418-1, while the current card introduces unrelated litigation, whistleblowing and supplier information.

Comparer côte à côte →

✓ Assistant IA LRA · Supervision humaine
Dr Ross Kurinko

Interrogez l’assistant IA de Study Studio sur cette information

Obtenez des réponses concrètes pour votre contexte de reporting. Les deux premières réponses sont gratuites — rejoignez gratuitement LRA Community pour continuer sans limite.

Essayez Comment préparer GRI 418-1 ? Quelles données dois-je collecter ? Où voir un exemple issu d’un rapport réel ? Quelles erreurs éviter ?
2 réponses gratuites

Références au référentiel

Exigences GRI applicables et informations connexes

Références disponibles du référentiel et informations voisines utiles à la préparation de cette exigence.

GRI

GRI 418-1

au sein de GRI 418 : Customer Privacy

Ouvrir la source officielle →

Connexes et exploration

Plus dans GRI 418 → Parcourir le catalogue complet → Accueil de la Bibliothèque des informations → Rechercher dans toutes les informations →

Aller plus loin · GRI 418-1

Apprenez à préparer cette information de bout en bout

This guide covers the two required complaint categories, the total number of identified customer-data leaks, thefts or losses, the conditional zero statement and the preceding-years compilation requirement.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

Explore GRI training (ESRS bundle) →
Comment cette bibliothèque est construite 312 rapports publiés indexés 63 171 pages avec citations au niveau de la page 272 fiches disclosure conçues par des praticiens
/fr/knowledge-hub/disclosure-cards/gri-418-1/