![GRAPHIC](https://capedge.com/proxy/6-K/0001104659-23-049248/tm2313529d2_ex99-1img044.jpg)
| 43 Baozun Inc. 2022 Annual Sustainability Report ◎ Our User Privacy and Security Principles Express Consent Minimum Necessity Open and Transparent Safety Assurance Subject Participation • Explain to users the purpose, manner, scope and other regulations for the processing of personal information, and seek their express consent before collecting the information. The consent for the processing of personal information shall be a specific, clear and unambiguous expression of will given by the individual with full knowledge. • Only the minimum amount and type of personal information necessary to satisfy the original purpose shall be processed, and personal information shall be promptly deleted after the purpose is achieved. • Disclose the scope, purpose, and rules for handling personal information in a clear, understandable, and reasonable manner, with external supervision. • To have security competencies that match the security risks faced, and to take adequate management measures and technical means to safeguard the confidentiality, integrity, and usability of personal information. • Provide subjects who provide personal information with the ability to inquire, correct, and remove their personal information, as well as the means to withdraw authorized consent, cancel accounts, file complaints, etc. Employee and User Privacy Protection Baozun builds its management structure according to ISO 27701 privacy information management system, respects the rights and interests of personal data, and carries out the whole life cycle protection of personal information in all aspects such as collection, transmission and storage, use, sharing and deletion based on the principles of express consent, minimum necessity, openness and transparency, ensuring security and subject participation. We are mindful of the changes in privacy protection-related policies and continuously improve our own management in accordance with the requirements stipulated by regulations and policies. In 2022, we incorporated privacy protection components into more top-level information security system documents, including the Baozun Information Security and Privacy Policy, the Baozun Information Security and Privacy Management Manual, and the Information Security and Privacy Organization Management Regulations. We also added the Code of Management of Personal Information Disclosed to the Public, etc. to protect the privacy and security of information provided by employees to the outside world. The Company has formulated the Baozun Group Account Management System to strengthen account management further. Based on the account operations authority, the Company classifies the risk level of all store accounts operated by Baozun, assigns corresponding authorities based on job responsibilities, prohibits private sharing and operations, and carries out regular account inspections to reduce the risks caused by account management problems. In addition, we conduct user privacy protection training twice a year for all employees on the eve of the "618" and "Double 11" sales promotion events, including our user privacy security principles, User privacy data operation specifications, and violation reporting channels. The training is followed up by the Company's Information Security Management Committee,which aims to enhance employees’ awareness and ability to protect user privacy. |