TSC's business spans multiple fields. With the continuous adoption
of information technology, its operations involve a large amount of data,
transaction information, and personal information of individuals. TSC has
implemented and continuously validated its Information Security Management
System for many years, and in 2025, it obtained the latest CNS27001:2023
(ISO27001:2022) Information Security Management System validation through a
transition. We have established and maintained a systematic and continuously
improving information security management mechanism to ensure the
confidentiality, integrity, and availability of data at all points within the
company, supply chain, and digital services, reducing the impact of information
security incidents on production, reputation, and public responsibility.
Customer Privacy
Taiwan Sugar Corporation has formulated the "Taiwan
Sugar Corporation Management Points for Personal Data Protection ",
established a "Personal Data Protection Promotion and Implementation
Team", and compiled " Manual for Personal Data Protection" in
accordance with the "Personal Data Protection Act", "Personal
Data Protection Act Enforcement Rules" and "Taiwan Sugar Corporation
Management Points for Personal Data Protection". In 2023, the "
Management Points for Personal Data Protection" Operation Form 9.1
Supervision Report Record Form was revised to add a reporting mechanism within
24 hours of receiving a report or becoming aware of a major personal data
leakage case, in order to improve the effectiveness of the management of
negative impacts related to customer privacy.
To prevent personal data from being stolen, altered,
damaged, lost or leaked, on May 22, 2025, a circular was issued to each unit in
accordance with the provisions of 7.4.2 of the "Taiwan Sugar Corporation
Management Points for Personal Data Protection" to designate a personal
data file security maintenance person to handle the maintenance of personal
data file security; and it is stipulated that each unit shall regularly conduct
personal data file inventory operations, perform audit operations based on the
"Personal Data Security Audit Checklist" and other personal data file
security maintenance measures on a yearly basis.
In January
2025, we organized the "Personal Information Security Audit Practice
Course" for comprehensive training. In February 2025, we assisted the
Human Resources Department; in July, the Merchandise Marketing Department; and
in August, the Department of Secretariat and the Department of Planning in
conducting on-site personal data audits of outsourced vendors. A total of four
outsourced vendors were audited, and all audit results complied with our
company's relevant personal data guidelines. In 2025, the Company had no
incidents involving violations of customer privacy or loss of customer data.

