S
StarWave

1 Overview

StarWave Entertainment is committed to maintaining the highest standards of transparency and accountability in how we collect, share, and disclose information. This document outlines our comprehensive approach to information management.

Our Commitment

At StarWave Entertainment, we believe that trust is the foundation of every relationship — whether with our audiences, partners, talent, or employees. This Information Sharing & Disclosure policy reflects our unwavering commitment to handling all information with integrity, transparency, and the highest level of care.

Policy Objectives

  • Ensure transparent communication about how information is shared and disclosed
  • Maintain compliance with global data protection regulations including GDPR, CCPA, and emerging frameworks
  • Establish clear protocols for third-party information sharing and vendor management
  • Protect sensitive production, financial, and personal data throughout its lifecycle
  • Provide stakeholders with clear understanding of their rights and available recourse
  • Implement robust security measures to prevent unauthorized disclosure
✅

Policy Status: This document is actively maintained and reviewed quarterly. The latest review was completed on January 15, 2025, by our Compliance & Legal Division.

Guiding Philosophy

Our approach to information sharing is guided by three core principles: Transparency First — we believe stakeholders deserve to know how their information is used; Minimal Necessary — we only share what is essential for each specific purpose; and Accountability Always — every information decision is documented and answerable.

2 Scope & Applicability

This policy applies to all information handling activities across StarWave Entertainment's global operations, encompassing every division, subsidiary, and partner engagement.

Covered Entities

This policy governs information practices across all StarWave Entertainment entities and operational areas:

  • StarWave Productions — Film, television, and streaming content production
  • StarWave Live — Concerts, award ceremonies, and live event management
  • StarWave Studios — VFX, animation, and post-production services
  • StarWave Interactive — Gaming, VR experiences, and digital content
  • StarWave Talent — Artist management and representation services
  • StarWave Distribution — Content licensing and worldwide distribution
  • StarWave Music — Music production, publishing, and recording

Applicable Parties

This policy governs information handling for the following groups:

  • Employees & Contractors — All personnel working for or on behalf of StarWave
  • Talent & Artists — Actors, musicians, directors, writers, and creative professionals
  • Audience Members — Customers, subscribers, event attendees, and platform users
  • Business Partners — Co-production partners, distributors, and licensees
  • Suppliers & Vendors — Technology providers, facility operators, and service providers

Information Types Covered

This policy addresses the handling of multiple categories of information:

  • Personal Data — Names, contact details, identification documents, payment information
  • Production Data — Scripts, storyboards, unreleased content, production schedules
  • Financial Data — Revenue reports, budget details, investment information, royalty structures
  • Business Data — Strategic plans, partnership terms, audience analytics, market research
  • Technical Data — Source code, proprietary software, security credentials, infrastructure details
â„šī¸

Global Applicability: While this policy is governed by California law, it is designed to meet or exceed the requirements of data protection laws worldwide, including GDPR (EU), PIPEDA (Canada), LGPD (Brazil), and PDPA (Singapore).

3 Data Classification

All information at StarWave Entertainment is classified into four security levels, each dictating specific handling, sharing, and disclosure requirements.

Classification Level Description Examples Sharing Requirement
LEVEL 4 — RESTRICTED Most sensitive information requiring highest security controls Unreleased scripts, executive compensation, security credentials, pending acquisitions Need-to-know only with executive approval
LEVEL 3 — CONFIDENTIAL Sensitive business and personal data with limited distribution Talent contracts, financial projections, audience personal data, production budgets Authorized personnel with documented consent
LEVEL 2 — INTERNAL Business information for internal use only Production schedules, internal communications, operational procedures, analytics data Employees and authorized partners only
LEVEL 1 — PUBLIC Information approved for public dissemination Press releases, published content, marketing materials, public event details No restrictions — freely shareable
âš ī¸

Classification Enforcement: Any unauthorized sharing or disclosure of information above its authorized classification level constitutes a policy violation and may result in disciplinary action up to and including termination and legal proceedings.

Reclassification Process

Information classification may be changed as project phases evolve. For example, a Level 4 (Restricted) script may become Level 1 (Public) after theatrical release. Reclassification requires:

  • Written request from the information owner or project lead
  • Review and approval by the department head
  • Documentation of the reclassification decision and rationale
  • Notification to all parties previously granted access

4 Information Sharing Principles

Our information sharing framework is built on six foundational principles that guide every sharing decision and interaction.

Core Principles

  • Principle of Minimal Necessary Disclosure: We share only the minimum amount of information necessary to accomplish a specific, legitimate business purpose. No more, no less.
  • Principle of Informed Consent: Whenever personal data is shared, the individual must be informed of what data is being shared, with whom, for what purpose, and must provide explicit consent where required by law.
  • Principle of Purpose Limitation: Information shared for one purpose cannot be repurposed or shared for a different purpose without obtaining new, specific consent from the data subject.
  • Principle of Data Minimization: We collect and share only data that is directly relevant and necessary. We do not engage in excessive data collection or sharing practices.
  • Principle of Accuracy & Currency: We maintain accurate, up-to-date information and correct errors promptly. Sharing inaccurate or outdated information is strictly prohibited.
  • Principle of Accountability & Audit: Every information sharing event is logged, documented, and subject to regular audit. We maintain a complete chain of custody for all shared data.

Contextual Sharing Guidelines

Different contexts require different sharing approaches:

  • Production Collaboration: Scripts and production materials are shared on a strict need-to-know basis with NDAs required for all external collaborators
  • Marketing & Promotion: Content previews and promotional materials are shared only through approved channels and according to approved release schedules
  • Talent Management: Artist and performer data is shared only with relevant production teams and always with the talent's awareness and consent
  • Business Development: Financial and strategic information shared with potential partners requires board-level approval and formal NDAs
  • Audience Engagement: Viewer data is shared with analytics providers only in aggregated, anonymized form unless specific consent for individual-level data is obtained
â„šī¸

Decision Framework: When in doubt about whether information can be shared, follow this simple test: (1) Is there a legitimate business need? (2) Is the sharing necessary to fulfill that need? (3) Have proper approvals been obtained? (4) Are security safeguards in place? If any answer is "no," the sharing should not proceed.

5 Disclosure Process

All information disclosure at StarWave Entertainment follows a structured, multi-step process to ensure compliance, accuracy, and proper authorization.

Standard Disclosure Workflow

1

Disclosure Request Submission

Submit a disclosure request through the StarWave Compliance Portal specifying the information to be disclosed, the recipient, the purpose, and the legal or business justification.

2

Classification & Impact Assessment

The Compliance team reviews the request, classifies the data involved, and assesses the potential impact of disclosure — including regulatory, reputational, and competitive considerations.

3

Authorization & Approval

Based on data classification and impact assessment, the appropriate level of approval is obtained — ranging from department head (Level 2) to executive committee (Level 4).

4

Secure Transfer & Documentation

The information is transferred through approved secure channels. A complete record of the disclosure — including what was shared, with whom, when, and under what authorization — is logged in the Compliance Registry.

5

Follow-Up & Verification

Post-disclosure, the Compliance team verifies the information was received correctly and confirms the recipient's understanding of handling requirements. Periodic audits ensure ongoing compliance.

Emergency Disclosure

In cases requiring immediate disclosure (e.g., legal mandates, safety concerns, regulatory inquiries), an accelerated process is available:

  • Immediate Notification: Contact the Compliance Hotline at +1 (555) 123-HELP immediately
  • Verbal Authorization: In urgent situations, verbal authorization from a designated executive is acceptable, to be followed by written confirmation within 24 hours
  • Minimal Compliance: Even in emergencies, only the minimum necessary information should be disclosed to fulfill the urgent need
  • Retroactive Documentation: All emergency disclosures must be fully documented within 48 hours
🚨

Prohibited: No employee may circumvent the disclosure process or share restricted information without proper authorization. Violations will be investigated and may result in immediate termination and legal action.

6 Third-Party Information Sharing

StarWave Entertainment carefully manages information sharing with third parties through rigorous vendor assessment, contractual safeguards, and ongoing monitoring.

Vendor Onboarding Requirements

All third-party vendors and partners must meet the following requirements before receiving any StarWave information:

  • Data Protection Agreement (DPA): A comprehensive DPA must be executed before any data sharing begins, outlining specific obligations, security requirements, and breach notification procedures
  • Security Assessment: Vendors must pass a security assessment evaluating their data protection practices, security certifications (SOC 2, ISO 27001), and incident response capabilities
  • Subprocessor Registry: Vendors must maintain an up-to-date registry of any subprocessors and obtain prior authorization before engaging new subprocessors
  • Audit Rights: All third-party agreements include audit rights allowing StarWave to verify ongoing compliance with data protection obligations
  • Return/Destruction Certification: Upon contract completion, vendors must certify the secure return or destruction of all StarWave information

Categories of Third-Party Sharing

Category Examples Information Shared Contractual Safeguards
Technology Providers Cloud hosting, software platforms, CDN services Operational data, content files, user data DPA, SLA, security certifications required
Production Partners Co-production companies, crew agencies, studios Scripts, schedules, financial terms, talent data NDA, production agreement, confidentiality clauses
Distributors Streaming platforms, theatrical distributors, TV networks Content masters, marketing assets, audience data Distribution agreement, revenue sharing terms
Analytics & Research Audience analytics firms, market research companies Aggregated analytics, survey responses Data processing agreement, anonymization requirements
Professional Services Law firms, accounting firms, consultants Financial records, legal documents, strategic plans Engagement letter, confidentiality agreement

Ongoing Third-Party Management

  • Quarterly vendor compliance reviews
  • Annual security reassessment of critical vendors
  • Real-time monitoring of vendor security posture where available
  • Immediate notification and remediation requirements for vendor security incidents

8 Security Measures

Robust security measures protect all information throughout its lifecycle — from collection and storage to sharing, use, and eventual deletion.

Technical Security Controls

  • Encryption: AES-256 encryption for data at rest; TLS 1.3+ for data in transit; end-to-end encryption for sensitive communications
  • Access Controls: Role-based access control (RBAC) with principle of least privilege; multi-factor authentication (MFA) required for all systems
  • Network Security: Advanced firewall rules, intrusion detection/prevention systems, network segmentation, and regular penetration testing
  • Endpoint Protection: Enterprise-grade endpoint detection and response (EDR), device encryption, and mobile device management (MDM)
  • Monitoring & Logging: 24/7 security operations center (SOC) monitoring, comprehensive audit logging, and real-time threat detection
  • Secure Development: Secure SDLC practices including code review, static/dynamic analysis, and vulnerability scanning for all software

Physical Security

  • Biometric access controls for server rooms and production facilities
  • 24/7 security surveillance with 90-day video retention
  • Secure document storage with controlled access
  • Clean desk and clear screen policies in all workspaces
  • Secure destruction of physical media and documents

Incident Response

In the event of a security incident or unauthorized disclosure:

  • Detection & Containment: Immediate identification and isolation of affected systems
  • Assessment: Determination of scope, impact, and affected data
  • Notification: Internal notification within 1 hour; regulatory notification within legally mandated timeframes; affected individual notification as required
  • Remediation: Eradication of threats, system restoration, and enhanced security measures
  • Post-Incident Review: Root cause analysis and implementation of preventive measures
đŸ›Ąī¸

Continuous Improvement: Our security program is continuously assessed through annual third-party audits, quarterly penetration tests, and ongoing monitoring of emerging threats and best practices.

9 Retention & Deletion

Information is retained only as long as necessary for its intended purpose and then securely deleted or anonymized in accordance with this schedule.

Information Type Retention Period Disposition Method
Personal identification data Duration of relationship + 7 years Secure deletion / certified destruction
Payment & financial data 7 years from last transaction Secure deletion with verification
Production materials (scripts, footage) Indefinite (archived) or per contract Secure archival or contract-defined
Communication records 3 years from last activity Secure deletion
Employee records Employment duration + 7 years Secure deletion / anonymized archival
Audience interaction data 24 months from last interaction Anonymized for analytics or deleted
Security logs 12 months Automated secure deletion
Marketing consent records Duration of consent + 3 years Secure deletion upon withdrawal

Secure Deletion Standards

  • Digital Data: Multiple-pass overwriting meeting or exceeding NIST 800-88 guidelines; cryptographic erasure for encrypted data
  • Physical Media: Industrial shredding or degaussing by certified destruction services
  • Cloud Data: Verified deletion through provider APIs with certification of data removal
  • Documentation: All deletion activities are logged with date, method, data type, and authorizing individual

10 Your Rights

Depending on your location and relationship with StarWave Entertainment, you may have specific rights regarding your personal information.

Universal Rights

Regardless of location, all individuals interacting with StarWave Entertainment have the right to:

  • Transparency: Know what information we collect, how it's used, and with whom it's shared
  • Accuracy: Request correction of inaccurate or incomplete personal information
  • Security: Expect your information to be protected by industry-standard security measures
  • Complaint Resolution: Lodge a complaint about our data practices and receive a timely, substantive response
  • Supervisory Authority: Contact applicable data protection authorities regarding any concerns

Additional Rights by Region

  • EU/UK (GDPR): Right to access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and objection to automated decision-making
  • California (CCPA/CPRA): Right to know, delete, correct, opt-out of sale/sharing, limit use of sensitive personal information, and non-discrimination
  • Canada (PIPEDA): Right to access, request correction, and challenge handling of personal information
  • Brazil (LGPD): Right to confirmation, access, correction, anonymization, deletion, portability, and revocation of consent

How to Exercise Your Rights

Submit a data request through any of these channels:

  • Online Portal: Use our Self-Service Data Request Portal at privacy.starwave.com/requests
  • Email: Send requests to privacy@starwave.com
  • Mail: StarWave Entertainment, Privacy Office, 1234 Sunset Blvd, Hollywood, CA 90028
  • Phone: +1 (555) 123-4567 (ask for the Privacy Team)

We respond to all legitimate requests within 30 days of verification. Complex requests may require up to 60 days with notification of the extension and reason.

â„šī¸

Verification: To protect your information, we verify the identity of anyone making a data request before taking action. We'll guide you through the verification process when you submit your request.

11 Frequently Asked Questions

Find answers to common questions about our information sharing and disclosure practices.

Who is responsible for information compliance at StarWave?

â–ŧ

Our Chief Compliance Officer (CCO) holds ultimate responsibility, supported by a dedicated Privacy & Data Protection team. Each division also has a designated Data Protection Officer who serves as the first point of contact for information-related questions within that division. The Compliance team reports directly to the Board of Directors to ensure independence.

How do I report a potential information security breach?

â–ŧ

Immediately contact the Security Operations Center at +1 (555) 123-4357 (available 24/7) or email security@starwave.com. All employees are encouraged to report suspected breaches without fear of retaliation. Even if you're uncertain whether something constitutes a breach, reporting it is always the right action — our team will investigate and determine the appropriate response.

Can I share unreleased production content with family or friends?

â–ŧ

No. Unreleased content is classified as Level 4 (Restricted) or Level 3 (Confidential) and may only be shared with authorized personnel on a verified need-to-know basis. Sharing unreleased content outside the authorized production team — regardless of the recipient — is a serious violation that can result in immediate termination and legal action. Screeners and review copies are distributed through our secure portal with digital watermarking and access controls.

How long does it take to process a data deletion request?

â–ŧ

Standard deletion requests are processed within 30 days. After identity verification, we will confirm receipt of your request and provide an estimated completion date. For requests involving multiple systems or complex data relationships, processing may take up to 60 days. You will receive confirmation when deletion is complete, along with documentation of what was deleted and where.

Does StarWave sell personal information to third parties?

â–ŧ

No. StarWave Entertainment does not sell personal information to third parties. We may share information with trusted service providers who assist us in our operations (such as payment processors, hosting providers, and analytics services), but these parties are contractually bound to use the information only for the specified purposes and may not sell it or use it for their own marketing. You have the right to opt out of certain sharing activities, particularly under CCPA and GDPR.

What happens if a third-party vendor experiences a data breach?

â–ŧ

All our vendor contracts require immediate notification (within 24 hours) of any security incident affecting StarWave data. Upon notification, our incident response team takes immediate action to contain the breach, assess impact, and fulfill any regulatory or individual notification obligations. We also conduct a thorough review of the vendor relationship and may terminate the contract if the incident reveals inadequate security practices.

How can talent and artists access their personal data held by StarWave?

â–ŧ

Talent and artists can access their personal data through the StarWave Talent Portal (talent.starwave.com) where they can view, update, and download their data. Alternatively, they or their representatives can submit a formal access request through the privacy team. We provide data in a commonly used, machine-readable format and can provide an explanation of automated decision-making processes where applicable.

Is this policy subject to change?

â–ŧ

Yes. As regulations evolve, business operations change, and new technologies emerge, this policy is updated to remain current and compliant. We review this policy quarterly and make updates as needed. Material changes are communicated to all affected parties through email notification, website updates, and — where required by law — direct notice. We encourage all stakeholders to review this page periodically for the most current information.

↑