CDL Hospitality Trusts - Sustainability Report 2025

SUSTAINABILITY & GOVERNANCE 116 SUSTAINABILITY REPORT In FY 2025, CDLHT recorded strong performance across all corporate governance and compliance indicators. There were zero cases of misconduct, corruption, bribery, or non-compliance reported across the portfolio. During the year, there were also no incidences of anticompetitive behaviour or violations of antitrust or monopoly legislation. CDLHT did not incur any fines or sanctions relating to these matters. In addition, there were no instances of non-compliance with social and environmental laws and regulations. CDLHT continues to reinforce these outcomes through ongoing training, including policy briefings during new employee orientation and regular updates on applicable policies and regulatory developments, and remains committed to maintaining zero incidents of non-compliance. In 2025, one whistleblowing report was received and was promptly escalated to the ARCs in accordance with the Managers’ whistleblowing procedures. The report was reviewed in accordance with established protocols and was assessed to be unsubstantiated. There were no breaches of applicable laws, regulations or internal policies, hence no further action was required. The Managers remain committed to maintaining effective whistleblowing channels to encourage the reporting of concerns in good faith, while ensuring that all reports are handled in a fair, objective and confidential manner. Cybersecurity and Data Privacy Approach Digitalisation and technology are integral to CDLHT’s business operations and growth, involving the management of significant volumes of sensitive tenant and guest information. This data can be exposed to cybersecurity risks, including potential unauthorised access, which could result in financial loss, operational disruption, reputational damage and legal or regulatory consequences if compromised. Accordingly, robust cybersecurity and data privacy measures are essential to safeguarding information assets and maintaining investor and stakeholder confidence. In addition, appropriate preventive control measures are in place, and employees are required to complete regular online cybersecurity and data privacy training to ensure ongoing awareness of secure IT practices, phishing threats, and data protection requirements. These measures are essential to maintaining a secure environment and mitigating risks across property systems. The Managers have implemented a Data Protection Handbook to safeguard personal data in accordance with the relevant legal requirements outlined in the Personal Data Protection Act and the Securities and Futures Act in Singapore. Furthermore, lessees and property managers are expected to comply with applicable local data and privacy laws within their respective jurisdictions. Performance In FY 2025, the Data Protection Officer received no complaints about data privacy breaches. Portfolio properties are expected to uphold appropriate data protection practices in accordance with applicable requirements across their respective operating jurisdictions.

RkJQdWJsaXNoZXIy NTkwNzg=