• Have internal processes for alerting users of policy violations and providing appeals processes for affected users, • Document internal processes for determining what signals will be shared with other participants, and how signals obtained from the Lantern Program will be used, • Commit to complying with applicable privacy laws and best practices. Prospective participants may join the Lantern Program by submitting an application to the Tech Coali- tion, which veri昀椀es the company’s compliance with the Lantern Program eligibility requirements and shares the application with existing participants for their review, before approving the application. All applicants are subject to a thorough review and must be invited to join the program. 4.3 Governance The Lantern Program is governed by a multiparty agreement that sets out the framework for signal sharing between participants, and which must be signed by participants before they are able to access the Lantern database. Participants are expected to share signals in accordance with applicable laws such as data protection regulations (e.g., the EU General Data Protection Regulation). Contributions to the Lantern Program are exclusively conducted by participants. The Tech Coalition serves as the “lead party” in the program with responsibility for overseeing compliance with the terms of the Lantern Program, and reviewing the performance of participants, reviewing the quality and accuracy of signals and collating metrics related to the effectiveness of the Program. Participants are required to adopt a range of commitments with respect to the Lantern Program; namely that they will: 1. Align with the Lantern Program eligibility requirements listed above, 2. Commit to quality assurance by manually reviewing all signals shared by other participants to establish precision before taking action on them, 3. Refuse contributions to the Lantern Program from external sources such as government agencies and disclose any request or demand for intervention in the Lantern Program received, 4. Support Tech Coalition’s transparency efforts by providing metrics and feedback when requested. Participants are also expected to publish their own transparency reports. 5. Comply with applicable data protection and privacy laws. In the case of a violation of the Lantern Program requirements or participant commitments, the Tech Coalition provides timely notice of the violation to relevant participants and collaborates with participants to correct the violative action. The Tech Coalition is also empowered to remove participants from the Lantern Program for violations of the terms of the multiparty agreement, move the Lantern Program off the ThreatExchange platform to a different host platform, or terminate the multiparty agreement. BSR TECH COALITION HUMAN RIGHTS IMPACT ASSESSMENT 20

Tech Coalition Human Rights Impact Assessment of the Lantern Program - Page 20 Tech Coalition Human Rights Impact Assessment of the Lantern Program Page 19 Page 21