Personal Data Protection Management Policy

Personal Data Protection Management Objectives

  1. The Company complies with the requirements of the Personal Data Protection Act and its enforcement rules to protect the processes of collecting, processing, using, storing, transmitting, and destroying personal data.
  2. The Company establishes a management organization to meet the needs of personal data management, formulating, promoting, and implementing personal data protection management.
  3. Protect the security of the Company's personal data from risks of theft, tampering, damage, loss, or leakage caused by external threats or improper management and use by internal personnel.
  4. Enhance employees' personal data protection and management capabilities, regularly conduct personal data protection awareness training to reduce operational risks and create a trustworthy personal data protection and privacy environment.
  5. The Company complies with relevant legal requirements and regulations, fulfilling the objectives and obligations of personal data protection, and maintaining and implementing the Personal Information Management System (hereinafter referred to as "PIMS").
  6. Improve the PIMS in a timely manner according to applicable laws, regulations, contracts and professional responsibilities, as well as the interests of individuals and other key stakeholders.
  7. Regularly conduct risk assessments of personal data operational processes, identify acceptable risk levels, and perform risk treatment for unacceptable risks.

Personal Data Protection Principles

  1. Fair and lawful processing.
  2. Obtained only for specified purposes and not processed in a manner incompatible with those purposes.
  3. Adequate, relevant, and not excessive.
  4. Kept accurate and up to date.
  5. Not retained longer than necessary.
  6. Compliant with the legal rights of individuals, including data subjects' right to access their data.
  7. Kept secure.
  8. Not transferred to countries where the law does not permit or where adequate protection is lacking.

Collection and Processing of Personal Data

  1. Personal data obtained or collected by the Company for operational needs, including but not limited to names, dates of birth, national ID numbers, passport numbers, characteristics, fingerprints, marital status, family, education, occupation, medical records, healthcare, genetics, sexual life, health examinations, criminal records, contact information, financial status, social activities, etc., shall comply with relevant personal data protection laws and regulations.
  2. Collect and process personal data in a manner that is not excessive, purpose-specific, relevant, appropriate, fair, and lawful.
  3. Collect only the minimum amount of personal data within the scope of legal requirements and the Company's business activities, and do not process excessive personal data.
  4. During business activities, obtain personal data only within specific purposes and personal data categories, and only collect, process, and use data consistent with organizational purposes.
  5. Process only personal data that is relevant and appropriate to the Company's business.
  6. Following the principles of lawful, fair, just, and transparent reasonable handling, collect, process, and use necessary personal data, and establish relevant management systems to reasonably handle the personal data obtained.

Use and International Transfer of Personal Data

  1. When the Company uses personal data, in addition to doing so within the necessary scope of the specific purpose under the Personal Data Protection Act, if use beyond the specific purpose is needed, it shall be handled in accordance with Article 20 of the Act; where consent of the data subject is required, the Company shall obtain such consent in accordance with the law.
  2. Personal data collected and processed by the Company shall comply with relevant personal data laws and the Company's PIMS regulations, and the use of personal data must serve the Company's operations or business needs before it may be used by responsible employees.
  3. If personal data obtained by the Company needs to be transferred internationally, it shall follow the principles of not violating major national interests, not using indirect methods to transfer or use personal data to a third country to circumvent the Personal Data Protection Act. If international treaties or agreements have special provisions, or if the data-receiving country lacks adequate personal data protection laws that may harm the rights and interests of data subjects, the Company will not conduct international transfers to protect the security of personal data.
  4. Transfer personal data to other countries or regions only under lawful and adequately protected conditions.

Access and Modification of Personal Data

When the Company receives requests for access or modification of personal data, it shall follow the Personal Data Protection Act and the Company's established procedures to conduct data subject's personal data inquiries, requests for review, requests for copies, requests for supplementation or correction, requests to stop collection, processing, or use, and requests for deletion within the legal scope.

Exceptions to Personal Data Use

Comply with relevant personal data protection laws, including exceptions under other regulations.

The Company has a duty of confidentiality for personal data held for business purposes. Apart from the data subject's request for review or the following circumstances, and in compliance with Article 20 of the Personal Data Protection Act and relevant laws, the Company shall not disclose to third parties:

  1. Judicial authorities, supervisory authorities, or police authorities requiring it for criminal investigation or evidence collection.
  2. Other government authorities requiring it for the exercise of public authority with legitimate reasons.
  3. Agencies related to public safety requiring it for emergency rescue.

The Company's use of personal data, except for data specified in Article 6, Paragraph 1 of the Personal Data Protection Act, shall be within the necessary scope of the specific purpose of collection. However, use beyond the specific purpose may be made in any of the following circumstances:

  1. Expressly provided by law.
  2. To promote public interest.
  3. To prevent danger to the life, body, freedom, or property of the data subject.
  4. To prevent significant harm to the rights and interests of others.
  5. Government agencies or academic research institutions need it for statistical or academic research purposes in the public interest, and the data has been processed by the provider or collected in a manner that cannot identify a specific data subject.
  6. With the consent of the data subject.
  7. Beneficial to the rights and interests of the data subject.

Protection of Personal Data

  1. The Company shall establish and implement PIMS to confirm the implementation of this policy; all personnel and outsourced providers shall comply with the regulations and requirements of PIMS, and regularly review the operation of PIMS.
  2. Ensure the security of all personal data and establish relevant security control measures.
  3. Personal data files shall have a management system with classified and categorized management, and security management standards shall be established for personnel who access them.
  4. To ensure the security of all personal data, access security of personal data file information systems shall be strengthened to prevent unauthorized access, maintain the privacy of personal data, establish security protection mechanisms, and conduct regular audits.
  5. For personal data files stored on personal computers, login passwords that can verify identity shall be set, and additional security measures shall be considered based on business needs and importance.
  6. Processing activities such as input, output, access, update, destruction, or sharing of personal data shall define the scope of use and access permissions.
  7. If any department of the Company encounters security incidents such as malicious destruction, damage, or operational carelessness regarding personal data files, emergency response measures shall be taken and handled according to the Company's emergency response notification procedures.
  8. The Company uses rigorous measures and policies to protect data subjects' personal data, including comprehensive training on personal data protection law and privacy protection for all employees. Any leakage of personal data will be subject to civil and criminal liability as provided by law.
  9. Outsourced providers or business partners cooperating with the Company shall sign confidentiality agreements to fully understand the importance of personal data protection and the legal liability for leakage. Any violation of confidentiality obligations will be subject to civil and criminal liability as provided by law.

Responsibilities

  1. The Company's management is responsible for establishing and reviewing the policy.
  2. Personal data managers implement this policy through appropriate standards and procedures.
  3. All personnel and contracted outsourced providers must follow procedures to maintain the personal data management policy.
  4. All personnel are responsible for reporting and handling personal data incidents and any identified vulnerabilities.
  5. Any deliberate violation of personal data protection will be subject to relevant regulations or legal action.