CSL Annual Report 2026

CSL partners with third parties to assess the effectiveness of its cybersecurity program and extends applicable cybersecurity standards to vendors and service providers. This includes assessing external partners against defined cybersecurity criteria to support alignment with CSL’s security expectations. Over the past year, CSL has made strategic investments to strengthen threat management, enhance its defensive posture, and accelerate its response to cybersecurity incidents. At the same time, emerging threats, particularly those amplified by AI, are increasing the complexity, speed and scale of cyber attacks. To address these risks, CSL will continue to invest in advanced defensive capabilities, including enhanced threat detection and response, greater use of automation and analytics, and ongoing updates to cybersecurity protocols to keep pace with the changing threat environment. Privacy CSL has maintained a strong commitment to the responsible use of personal data entrusted to us by patients, donors, employees and other stakeholders. Key highlights and performance during the financial year include: • New policies and practices: CSL maintains an enterprise-wide data privacy policy as well as standards and procedures that guide the collection, maintenance and use of personal data, and considers global legal and regulatory requirements. During the year, CSL finalised its Global Policy on Artificial Intelligence and established its AI Enterprise Governance Program to support responsible AI use across the enterprise. CSL also took steps to optimise its digital data privacy processes and privacy controls across the organisation to enhance compliance and better uphold the privacy rights of individuals. • Data privacy issues addressed: Significant efforts were made this year to comply with new and changing data privacy regulations in the jurisdictions in which we operate. Ongoing monitoring and assurance activities are undertaken to verify compliance with data privacy requirements, CSL policies, and applicable data privacy laws. • Non-compliance or breaches: CSL follows a robust Privacy Incident and Data Breach Response Procedure in dealing with possible data privacy incidents. Privacy incidents are reported to an enterprise-wide data privacy team for triage and assessment. Of the privacy incidents reported this year, three were substantiated as data privacy breaches that required reporting to data protection authorities and data subjects. CSL’s dedication to data privacy is evident in the comprehensive measures taken to protect personal data and comply with regulatory standards. + R EAD MORE AT CSL.COM/WE-ARE-CSL/ CORPORATE-GOVERNANCE 51 CSL Limited Annual Report 2025/26

RkJQdWJsaXNoZXIy MjE2NDg3