

Data Privacy and Information Security
We recognize that data privacy and information security practices are key elements of our customers’ experience and contribute to the safety and efficiency of our operations.
Delta is committed to handling information responsibly throughout the data lifecycle and has processes in place to assess privacy risk, integrate privacy principles into use case design and fulfill privacy requests. We also have approximately 40 Privacy Champions serving throughout our organization who act as liaisons between the business units and our Privacy team.
The Audit Committee of our Board is responsible for reviewing information security risks and providing oversight of the security and operations of our information technology (IT) systems. Our IT Risk team monitors and regularly reports on information security risk to support senior leadership in making informed business decisions. Security awareness activities are designed to go beyond annual training and include engagement and reinforcement exercises to help our employees understand that their role in protecting our company is just as important as the technologies we have in place.
Delta has established physical, electronic and managerial safeguards designed to protect the information in our care. We periodically review and update these safeguards to protect against unauthorized access to, and use of, information and to maintain its integrity. All U.S. air carriers are subject to privacy and information security laws, which vary between the countries in which we operate. We continue to update our processes to comply with applicable requirements around the world.
For additional information about our risk management, strategy and governance of information security, please see our Annual Report on Form 10-K opens in a new window for the fiscal year ended December 31, 2025, as filed with the Securities and Exchange Commission.