Governance

Our Information Security Policy, data privacy policies, and Information Assets Protection Policy govern our cybersecurity procedures.

The Company’s Information Security Committee (ISC) oversees the Company’s information security program and develops and approves related policies. Chaired by our Chief Information Officer and co-chaired by our VP, Global Information Security & Governance, the ISC is a cross-functional group that includes our Chief Legal and Administrative Officer, our Data Privacy Officer, as well as senior leaders and key representatives from the Company’s Information Technology (IT), Legal Affairs, Physical Security, Risk Management, Internal Audit and Human Resources departments.

To support compliance with applicable privacy laws and regulations, monitor and mitigate risks associated with data privacy breaches and oversee the ethical and responsible use of third-party artificial intelligence (AI) systems and tools across the organization, the ISC oversees data privacy and AI governance through the Data Privacy and AI Governance Subcommittee. Led by our Data Privacy Officer, the Subcommittee comprises representatives from functions involved in privacy matters across the organization.

Both the ISC and the Data Privacy and AI Governance Subcommittee meet quarterly and on an ad hoc basis and report major developments to the Company’s Compliance Steering Committee. The Compliance Steering Committee, in turn, provides quarterly updates to the Board of Directors’ Corporate Governance and Social Responsibility Committee. In addition, the Chief Information Officer provides quarterly information security reports to the Board’s Audit and Finance Committee and a full report on IT strategy and cybersecurity to the Board each year.

Approach

Information Security Policy

Our Information Security Policy sets out expectations for protecting Gildan’s information systems and information assets and applies across Gildan and its subsidiaries. It is designed to protect the confidentiality, integrity, and availability of Company and customer data, reduce the potential impact of security incidents, support compliance with applicable requirements, and promote the continuous improvement of our information security practices. 

The policy establishes responsibilities for managing information security risks, protecting access to systems and data, identifying and addressing vulnerabilities, maintaining security awareness and training, responding to cybersecurity incidents, and supporting business continuity and disaster recovery. 

Information security responsibilities apply across our workforce. Employees and contractors are expected to follow applicable requirements and report suspected security concerns. We also assess information security risks associated with third-party service providers and include appropriate security requirements in relevant contractual arrangements.

Information Assets Protection Policy

Our Information Assets Protection Policy establishes a framework for identifying and protecting Gildan’s sensitive and critical proprietary information against unauthorized use or disclosure. It applies to employees and third parties involved in creating, handling, transferring, or storing Gildan information. 

The policy requires information to be assessed based on its sensitivity and criticality and protected through appropriate safeguards throughout its lifecycle. Known or suspected incidents involving sensitive information must be promptly reported. The policy is also subject to periodic review and compliance auditing. 

We leverage ISO 27001 and the National Institute of Standards and Technology (NIST) Cybersecurity Framework to efficiently manage information security risks and align our information security policies with industry best practices. We also collaborate with external partners and government agencies to help ensure our information systems and management team remain up to date. 

Our Montreal headquarters and data centres are ISO 27001-certified.

 

All Gildan administrative and office employees receive mandatory annual online training on information protection and cybersecurity. Training includes guidance on protecting the Company from cybersecurity threats and reporting security incidents. We provide ongoing awareness activities and conduct phishing exercises covering 100% of our technology-enabled employees several times a year. Certain groups that work with sensitive information, such as our Finance and Human Resources teams, receive additional training. Employees are regularly reminded to report suspicious activity or the loss of sensitive information to our IT and Legal departments.

Data privacy

Where appropriate, necessary, and in connection with our business, we collect and use certain confidential and personal information regarding employees, customers, business partners, vendors, and other third parties. 

Gildan’s internal privacy policy and Employee Privacy Handbook outline the requirements for the privacy and protection of personal information under Gildan’s control and guide our efforts to protect this information. These requirements apply to all Gildan employees and contractors who process personally identifiable information. 

We conduct internal audits of compliance with our internal privacy policy as part of our risk-based audit plan. We also work with third-party auditors to audit our compliance.

Responsible use of AI

We believe AI can improve efficiency, productivity and effectiveness across our business, while recognizing the need for appropriate governance, safeguards, and human oversight.  

Our internal Artificial Intelligence Policy helps ensure the safe and ethical use of AI across our operations. We believe AI can improve efficiency, productivity, and effectiveness across our business, while recognizing the need for appropriate governance, safeguards, and human oversight. 

The policy establishes requirements for the responsible use of AI by employees and third parties acting on Gildan’s behalf. It addresses data privacy and cybersecurity, human oversight and accountability, transparency and fairness, appropriate use, and intellectual property risks. 

To support responsible AI adoption, Gildan maintains a cross-functional governance approach involving stakeholders from areas such as information security, privacy, legal, human resources and technology. This governance helps assess regulatory, cybersecurity, privacy, and ethical considerations associated with AI use cases. 

AI-related risks are also considered as part of the review and onboarding of AI-enabled technologies and services, with the involvement of appropriate stakeholders, including Information Security, Legal, and Information Technology. 

Employees remain accountable for work supported by AI, and AI-generated results must be reviewed for accuracy and reliability. These expectations are communicated through our annual information protection and cybersecurity awareness training program. Certain AI use cases involving personal or confidential information, employment-related decisions, individuals, or Company risk require additional review and approval. 

The policy is periodically reviewed and updated to reflect developments in technology, regulation, and industry best practices.