The Company takes the following technical, administrative, and physical measures to ensure the security of personal information and to prevent its loss, theft, leakage, alteration, or damage:
① Technical Measures
1. Installation and Updating of Security Programs
To prevent the leakage or damage of personal information, the Company regularly backs up data, installs and updates antivirus programs, and conducts inspections to ensure that users’ personal information and data are protected from unauthorized access or damage.
2. Encryption of Personal Information
Users’ personal information is protected by passwords and encrypted data, and personal information is safely transmitted and received over networks through encrypted communication and similar security methods.
3. Retention and Tamper Prevention of Access Records
The Company retains and manages access records to personal information processing systems for at least two years and employs security features to prevent the alteration, theft, or loss of such records.
4. Access Control and Restrictions on Personal Information
The Company manages and restricts access to personal information through the granting, modification, and revocation of access rights to databases that process personal information, thereby preventing unauthorized internal or external access.
② Administrative Measures
1. Establishment and Implementation of Internal Management Plans
The Company establishes internal management plans and reviews their implementation each year, including the designation of a Personal Information Protection Officer and the operation of an internal organization responsible for personal information protection.
2. Operation of a Dedicated Organization
The Company operates a dedicated department to ensure that all employees comply with legal obligations regarding personal information protection, and the department continuously carries out administrative and technical protection measures.
3. Regular Employee Training
To enhance awareness of personal information protection, the Company provides regular training to all executives and employees.
③ Physical Measures
1. Access Control for Unauthorized Personnel
The Company designates separate physical storage locations for personal information processing systems and establishes control procedures to prevent unauthorized persons from gaining access.
2. Use of Locking Devices for Document Security
Documents and auxiliary storage media containing personal information are stored in secure locations equipped with locking devices.
3. Subscription to Personal Information Protection Liability Insurance
The Company has subscribed to personal information protection liability insurance to ensure compensation for any damage suffered by users in the event of a personal information breach.
④ In addition to the measures required by law, the Company also implements the following activities to further enhance the security of personal information:
1. Acquisition of Personal Information Protection Certifications: Personal Information and Information Security Management System (ISMS-P), Excellent Web and System Certification for Personal Information Protection (ePRIVACY PLUS)