Icon

Information Security, Cybersecurity
and Personal Data Protection Governance


Information Security

Today, information technology is advancing and evolving at a rapid pace, making it an indispensable part of business
operations across organizations. However, this rapid growth is accompanied by increasing cybersecurity risks and cyber threats,
which have become one of the key challenges that organizations must be well prepared to address.

The Company recognizes the risks associated with information security and information systems, including external cyberattacks and internal data breaches,
which may adversely affect business operations as well as the security of the personal data of employees, customers, and business partners.
To address these challenges, the Company has established an Information Technology (IT) function responsible for managing cybersecurity and information security.
The Company has also implemented information security policies and guidelines, while continuously enhancing its
cybersecurity measures and protection systems to safeguard information assets and mitigate emerging cyber threats.

In addition, the Company places great importance on fostering a strong cybersecurity culture by providing regular training
and awareness programs for employees and executives. These initiatives are designed to enhance cybersecurity
awareness, strengthen capabilities in preventing and responding to cyber threats,
and ensure the effective protection of the Company's information assets and systems.
Personal Data Protection

The Company places the highest priority on the privacy and security of personal data, regardless of the form in which
such data is stored or whether it belongs to an individual or a representative of a legal entity.
The Company collects, uses, and discloses personal data with due care and in strict compliance with
applicable laws and regulations, particularly the Personal Data Protection Act (PDPA). These practices are implemented to
ensure that the Company's personal data protection standards are maintained in accordance with legal requirements and internationally recognized best practices.

The Company has established stringent policies and measures for personal data protection, while ensuring alignment with information security practices.
In addition, the Company has appointed a Data Protection Officer (DPO) and engaged professional advisors specializing
in personal data management to oversee the collection, use, disclosure, and storage of personal data in
compliance with applicable legal requirements and international standards. (Data Protection Officer: DPO) The Company continuously provides training
and awareness programs for employees, while regularly conducting privacy risk assessments and reviews to
ensure that personal data is effectively protected and managed in accordance with good governance principles.
Relevant Policies

  • Information Security Policy and Guidelines
  • Personal Data Protection Policy and Practices
  • Personal Data Protection Policy for Business Partners, External Parties, Employees, Customers, and Applicants