TSC's
business spans multiple fields. With the continuous adoption of information
technology, its operations involve a large amount of data, transaction information,
and personal information of individuals. TSC has implemented and continuously
validated its Information Security Management System for many years, and in
2025, it obtained the latest CNS27001:2023 (ISO27001:2022) Information Security
Management System validation through a transition. We have established and
maintained a systematic and continuously improving information security
management mechanism to ensure the confidentiality, integrity, and availability
of data at all points within the company, supply chain, and digital services,
reducing the impact of information security incidents on production,
reputation, and public responsibility.
Customer Privacy
Taiwan Sugar Corporation has formulated
the "Taiwan Sugar Corporation Management Points for Personal Data Protection
", established a "Personal Data Protection Promotion and
Implementation Team", and compiled " Manual for Personal Data
Protection" in accordance with the "Personal Data Protection
Act", "Personal Data Protection Act Enforcement Rules" and
"Taiwan Sugar Corporation Management Points for Personal Data
Protection". In 2023, the " Management Points for Personal Data
Protection" Operation Form 9.1 Supervision Report Record Form was revised
to add a reporting mechanism within 24 hours of receiving a report or becoming
aware of a major personal data leakage case, in order to improve the
effectiveness of the management of negative impacts related to customer
privacy.
To prevent personal data from being
stolen, altered, damaged, lost or leaked, on May 22, 2025, a circular was
issued to each unit in accordance with the provisions of 7.4.2 of the
"Taiwan Sugar Corporation Management Points for Personal Data
Protection" to designate a personal data file security maintenance person
to handle the maintenance of personal data file security; and it is stipulated
that each unit shall regularly conduct personal data file inventory operations,
perform audit operations based on the "Personal Data Security Audit
Checklist" and other personal data file security maintenance measures on a
yearly basis.
In January 2025, we
organized the "Personal Information Security Audit Practice Course"
for comprehensive training. In February 2025, we assisted the Human Resources
Department; in July, the Merchandise Marketing Department; and in August, the
Department of Secretariat and the Department of Planning in conducting on-site
personal data audits of outsourced vendors. A total of four outsourced vendors
were audited, and all audit results complied with our company's relevant personal
data guidelines. In 2025, the Company had no incidents involving violations of
customer privacy or loss of customer data.

