Policies TransUnion maintains numerous policies to align our programs and practices with ESG expectations and legal requirements, where applicable. Global Information TransUnion maintains a Global Information Security Policy which outlines the governance structure, Security Policy processes and precautions taken to keep data safe. Our policy outlines our expectations of associates and our information security strategy and is consistent with ISO/IEC 27001:2013 information technology standards. We require all associates to complete annual information security trainings and attest to our Information Security Policy. Privacy Policy TransUnion maintains a Global Privacy Policy that requires compliance with all applicable data privacy laws. To ensure consumer privacy, we also maintain processes and systems for the collection, use, disclosure, handling, storage, processing, access and security of personal information. Code of Business Our Code of Business Conduct acts as the cornerstone for how we work and reflects our belief in Conduct doing business the right way. Our Code of Business Conduct outlines the behavior we expect from our associates, as well as vendors and other third parties. All associates annually attest to the Code of Business Conduct. The Code of Business Conduct specifically prohibits: human and labor rights violations; discrimination; bribery, money laundering and quid pro quo payments to government officials; anticompetitive behavior; and self-dealing when a conflict of interest arises. Conflict of The policy prohibits employees and members of the Board of Directors from engaging in activities that Interest Policy conflict with the interests of TransUnion, and is intended to identify potential conflicts of interest and establish guidelines and procedures for addressing conflicts of interest when they arise. Human Rights and At TransUnion, we seek to treat all individuals fairly and create an inclusive environment. Our policy and Labor Standards practices align with the principles of the Universal Declaration of Human Rights, the United Nations Global Compact, the International Labour Organization and all applicable laws. Wellness, Health TransUnion supports a healthy and safe workplace for all associates. Our policy sets forth standards that and Safety Policy support the long-term physical and mental well-being of all associates. Environmental Our global Environmental Policy outlines TransUnion’s commitments and main impact areas — Policy reducing energy use in data centers and waste in our office spaces. Enterprise Risk TransUnion’s Enterprise Risk Management Policy is consistent with best practices and sets forth the Management Policy risk management structure and definitions. In addition, the policy outlines mechanisms for oversight, monitoring and reporting. Whistleblower Policy TransUnion’s Whistleblower Policy outlines the processes and protections to associates in calling out potential legal or ethical violations. Political Engagement Policy Our Political Engagement Policy addresses TransUnion’s political contributions, governance of our Political Action Committee, lobbying positions and industry associations. APPENDIX TRANSUNION | 2021 SUSTAINABILITY REPORT 55

Sustainability Report | TransUnion Flipbook - Page 55 Sustainability Report | TransUnion Flipbook Page 54 Page 56