Sustainability Governance
Wizz Air’s governance framework ensures that environmental, social and governance considerations are systematically integrated into strategic, operational and financial decision-making. The Board of Directors provides overall direction and oversight, with ESG priorities embedded within the Company’s broader governance, risk and control framework.
The Sustainability and Culture Committee oversees the development and implementation of the sustainability agenda, monitors performance against key targets and ensures alignment with evolving regulatory requirements, including the Corporate Sustainability Reporting Directive (CSRD) and the European Sustainability Reporting Standards (ESRS). The Committee also reviews the Company’s disclosures, data quality and preparedness for assurance.
At management level, ESG is embedded through defined reporting lines, internal controls and cross-functional accountability, ensuring consistent execution across the organisation. Regular reporting, employee engagement feedback, and oversight mechanisms provide visibility of performance and support timely decision-making.
This integrated governance approach strengthens transparency, enhances the credibility and comparability of disclosures, and ensures that sustainability considerations are consistently reflected in business decisions and long-term value creation.
ESG Targets in Leadership Incentives
Wizz Air integrates sustainability and diversity objectives into leadership incentive plans. The CEO's long-term incentive plan comprises 90% share price performance and 10% ESG-related objectives, split equally between CO₂ emissions intensity performance (5%) and gender diversity (5%). This approach aligns executive remuneration with the Company's long-term strategic and sustainability objectives.
Our Core Values and the WIZZ Culture
Wizz Air’s culture is anchored in five core values which guide behaviour, decision-making and execution across the organisation. These values define expectations for professional conduct and support a consistent approach to accountability and performance. The application of these principles is supported by a structured governance framework, including established policies, internal controls and oversight mechanisms. These include a whistleblowing framework, supplier standards and internal audit processes, ensuring that ethical conduct, compliance and transparency are maintained across all areas of the business. Clear standards of conduct are reinforced through regular communication and oversight, supporting consistent implementation across the organisation and alignment with Wizz Air’s broader governance and risk management framework.
Inclusivity
We embrace diversity, engaging and collaborating with all key stakeholders to achieve our goals.
Positivity
We are an inspired and inspiring team, passionate about what we offer, using a positive mindset to unlock new ways to do things better and more efficiently.
Integrity
Doing what is right for passengers and stakeholders, holding ourselves to the highest possible standards in everything we do.
Dedication
We have an entrepreneurial “can-do” attitude, taking individual and collective ownership, and are accountable for everything we do.
Sustainability
We are committed to reducing the environmental impact of our operations and integrating sustainability considerations into our business decisions.
Contribution to UN SDGs via our relevant programmes
ENVIRONMENT
- Focus on reducing our CO₂ emissions intensity (grams per revenue passenger kilometre) through ongoing efficiency measures.
PEOPLE
- Become an employer of choice, set an example for corporate citizenship. Retain and develop talent and provide a great customer experience.
GOVERNANCE
- Put the proper organisational structure of sustainability management, systems and people in place to support our strategy and vision.
ECONOMY
- Contribute to the GDP growth of our destinations by enabling affordable connectivity. Create new jobs, drive tourism and business opportunities.
Cybersecurity and data protection
At Wizz Air, safeguarding data and ensuring cybersecurity are fundamental to our operations. We adhere to the highest standards of compliance, including the EU General Data Protection Regulation (GDPR), and align with both international and national requirements. To embed privacy by design across our processes, we have appointed a Group Data Protection Officer and work in close collaboration with a dedicated Cybersecurity Department. Together, they ensure the confidentiality, integrity, and availability of sensitive information.
Our cybersecurity framework is built on globally recognized standards such as the NIST Cybersecurity Framework, ISO 27001, PCI DSS, NIS 2 and OWASP guidelines. Wizz Air is proud to hold the Cyber Certificate of Compliance issued by the UK Civil Aviation Authority.
To stay ahead of evolving threats, we apply a layered security approach that combines prevention, detection, and recovery. This is reinforced by regular risk assessments, compliance audits, and advanced testing methods including vulnerability assessments, penetration testing, and red team exercises.
Continuous improvement is at the heart of our strategy, driven by stakeholder feedback and industry best practices, ensuring that our defenses remain robust and future-ready. We operate under a multi-layered cybersecurity approach, designed to protect the confidentiality, integrity, and availability of your data. This includes:
Prevention, Detection, and Response
We use advanced tools and processes to prevent cyber threats, detect anomalies, and respond quickly to any incidents. Recovery protocols ensure business continuity and minimal disruption.
Compliance with Global Standards
Wizz Air complies with GDPR, the EU NIS2 Directive, and EASA Part-IS requirements. We also meet PCI DSS standards for payment card security and undergo annual audits to maintain certification.
Continuous Investment
In F26, we strengthened our defenses with measures such as increased cybersecurity controls for NIS2 and Part-IS readiness. The digital internal control framework was updated to allow for enhanced controls on employee access rights and a revised security awareness programme.
Protecting Your Personal Data
Our Internal Data Protection Regulation ensures that all personal data - whether from customers, employees, or partners - is handled responsibly and securely. Key elements include:
Privacy by Design
Data protection is embedded into every process, from booking to customer service.
Clear Privacy Notices
Our Customer Privacy Notice explains how we collect, process, and safeguard your data. You can access it anytime on our website.
Incident Response and Transparency
We maintain robust detection and response capabilities. In the unlikely event of a data incident, we act immediately to contain and resolve it, and notify affected parties in line with legal requirements.