Compliance
Compliance
Compliance Management Structure
Under the leadership of the Chief Compliance Officer (CCO), the HOYA Group has established a corporate compliance function at headquarters and appointed compliance officers within each business division. These functions are responsible for developing policies and overseeing key compliance issues, including bribery and corruption, harassment, and other significant risks.
The corporate compliance function works closely with each business division to support the prevention and monitoring of these risks, as well as responses to individual cases. Through education and training programs and the operation of reporting channels, the Company seeks to prevent misconduct and ensure its early detection. Significant matters are reported to the Board of Directors.
The HOYA Helpline, the Group's internal reporting and consultation channel, is administered by the corporate compliance function. Reports received through the helpline are regularly reported by the CCO to the Audit Committee. Reports concerning Executive Officers or the CCO are handled directly under the authority of the Audit Committee, with the Audit Committee Office serving as the reporting contact point.
HOYA Helpline (Reporting and Consultation Channel)
As part of its compliance system, the HOYA Group established the HOYA Helpline in 2003 as a global reporting and consultation channel available to both internal and external stakeholders. The purpose of the system is to receive reports from employees, business partners, and other stakeholders, identify conduct that may violate applicable laws or the HOYA Code of Conduct at an early stage, protect whistleblowers, and enable prompt and appropriate corrective action. Information regarding reports received is provided quarterly by the CCO to the Audit Committee.
The HOYA Helpline provides an environment that encourages employees and stakeholders to raise concerns, including 24-hour multilingual web-based reporting, consultation services in local languages, and the option to submit reports anonymously. The Group has established operating procedures that comply with applicable laws and regulations and strictly prohibits any form of retaliation against whistleblowers or individuals seeking advice, including dismissal, salary reduction, reassignment, harassment, or other unfavorable treatment. The confidentiality of whistleblowers is protected, and the existence and details of reports are handled with the utmost discretion.
For each case, dedicated personnel within the corporate compliance function regularly monitor progress to ensure appropriate handling. Once a matter has been resolved, it is promptly recorded as a “Case Closed,” and follow-up with the reporting party is confirmed. Through these practices, the Company maintains the transparency and reliability of its reporting process and ensures that stakeholders can use the system with confidence.
In FY2025, the Group received 406 internal reports, of which 45% related to workplace environment issues and 30% concerned company policies or systems.
The recent increase in the number of reports reflects ongoing awareness-building activities regarding the helpline, improvements in accessibility and ease of use, and growing employee awareness of compliance. A certain proportion of reports consisted of inquiries and consultations intended to confirm or clarify applicable policies and rules.
Since FY2023, cases involving harassment that are initially received by the Human Resources function have also been shared with the compliance function and used organizationally to strengthen preventive measures and training programs. Through these initiatives, the Company seeks to prevent risks before they materialize by encouraging early consultation and reporting and to improve the workplace environment. Going forward, the Group will continue to maintain and enhance a reporting and consultation system that stakeholders can use with confidence.
No reports received through the internal reporting system during FY2025 involved matters that had a material impact on the Company's business.
Number of Whistleblowing Incidents (Global)
FY2021 |
FY2022 |
FY2023 |
FY2024 |
FY2025 |
|
|---|---|---|---|---|---|
Number of whistleblowing incidents |
180 |
170 |
280 |
297 |
406 |
Percentage of employees* |
0.49% |
0.39% |
0.66% |
0.63% |
0.90% |
* Ratio of whistleblowers to the total number of employees in the country where the whistleblowing and consultation system has been introduced
HOYA Code of Conduct
The Company believes that, in addition to compliance with laws and regulations, the fair and ethical conduct of each employee is essential to maintaining the trust of stakeholders.
To provide clear guidance for employee conduct, the Company established the HOYA Code of Conduct in 1997. Since then, the code has been revised periodically to reflect changes in laws, regulations, and societal expectations. As the Group's fundamental compliance policy, the code is referenced in daily business activities and utilized to raise employee awareness of compliance.
In light of the Group's global operations, the code is available in 27 languages. To ensure thorough understanding and implementation throughout the Group, employees participate annually in team-based reviews of the code, online training programs, and knowledge assessment tests.
In FY2025, the completion rate for the online training and assessment program covering all Group employees was 99.5%.

Prevention of Harassment
We have established the HOYA Group Policies and Guidelines for Measures to Prevent Harassment, which set forth measures and guidelines to prevent harassment, protect the dignity of employees as an individual and prevent workplace disorder and any obstacles to work. Based on the Guidelines as well as laws and regulations in each country, we conduct education and training on harassment prevention measures targeting all employees of the HOYA Group. For managers in Japan, we conduct training on manager-oriented harassment prevention measures.
Furthermore, we conduct initiatives to instill and ingrain compliance on an ongoing basis, such as posting information via the intranet and on bulletin boards, etc., and creating awareness-raising pamphlets and posters. From time to time, we post self-check tests (Q&A) on noncompliance incidents that are likely to occur in familiar situations as well as contents for understanding the essence of compliance through in-house case studies via the intranet and on bulletin boards, etc., so that employees can check compliance again when given the opportunity to do so and thereby gain a higher level of awareness.
Privacy and Data Protection
In line with the expansion of global operations and the advancement of digitalization, the HOYA Group positions privacy and personal data protection as a key element of compliance and risk management. We also require suppliers and business partners to maintain appropriate data protection practices through contractual arrangements, including the HOYA Supplier Code of Conduct.
Governance
We have established a global privacy governance framework integrated with our compliance and risk management structure, under which privacy-related risks are managed as part of overall enterprise risk management processes. Our privacy management framework is led by the Global Head of Privacy under the oversight of the Chief Compliance Officer (CCO) and is reported to the Board of Directors at least annually, ensuring Board-level oversight and continuous enhancement of privacy management. We conduct internal audits to assess compliance with our privacy and data protection policies and work to further strengthen our governance framework.
In addition, we maintain procedures to respond to privacy incidents, including reporting, investigation, and, where necessary, notification to authorities and affected individuals. The framework is continuously reviewed and improved in response to regulatory developments, changes in the business environment, and emerging risks.
Policy Framework
Our approach to privacy and data protection is based on the Global Privacy Framework, which outlines the overall structure of HOYA’s privacy management. The framework defines governance, roles and responsibilities, and the core operational structure, and is applied across all business divisions and global operations. This is supported by a Global Data Protection Policy, which sets out the principles and requirements for the lawful and appropriate handling of personal information.
In addition, we ensure compliance with local laws and regulations while maintaining alignment with global standards.
As part of our commitment to transparency, we publish a Privacy Notice on our website explaining how personal information is used and protected. We also maintain processes to respond to requests such as access, correction, and deletion of personal information.
By applying these frameworks across the Group while taking into account the characteristics of each business, we promote an effective and globally consistent approach to privacy. This Policy also applies to all employees, contractors, and third parties who handle personal information in connection with the business activities of the HOYA Group.
Risk Management and Controls
For higher-risk handling of personal information, we conduct Data Protection Impact Assessments to identify potential risks and impacts in advance and implement appropriate mitigation measures. We also apply a privacy by design approach, ensuring that data protection considerations are incorporated into systems, products, and business processes from an early stage.
In addition, risks associated with third parties and cross-border data transfers are managed through appropriate contractual and technical safeguards.
Training and Awareness
Data protection training is mandatory for all employees and is provided at onboarding and through annual refresher training, promoting privacy awareness across the organization.
Role-based training is also provided for functions involved in higher-risk activities. In addition, organizational capability is strengthened through the ongoing development of Privacy Leads (a person responsible for supporting and implementing privacy measures in day-to-day operations within each business divisions), helping to enhance privacy management capabilities across the Group.