Governance

Trust

SDGs

Customer Privacy and Security

SKS attaches places great importance on the protection of customer information and has established the Personal Data Security Maintenance Plan and Post-Termination Data Handling Method to clearly define employees' responsibilities and obligations regarding personal data protection. Relevant measures are publicly disclosed on the Company's website to ensure customers are fully informed of their rights and protections. If a customer suspects a personal data breach, they can report it through the customer service center, the website's contact email, or business locations. The receiving department will notify the relevant units based on the operational risk incident procedure, and these units will further determine whether it constitutes a personal data breach. Once confirmed, the incident will be handled and reported in accordance with the Personal Data Security Maintenance Plan and Post Termination Data Handling Method.

Personal Data Protection Operating Results in 2023
Personal Data Response Team

Regularly review the appropriateness of regulations related to personal data protection and management.

Personal Data Security Maintenance Plan

Establish annual personal data protection management projects and schedules, and report this to the competent authorities.

Affidavit of Personal Data Protection

Employees and collaborating vendors who have access to personal data during outsourced operations are periodically notified and required to sign the affidavit.

Education and training

Since 2011, personal data protection-related education programs have been arranged for all levels of management and employees. Since 2016, regulations and case studies related to the Personal Data Protection Act have been included in new employee training.

Educational Training for Personal Data Protection and Compliance
2023 Company-wide (including branch company)
Training Target
Head office personnel
Training Hours (hr/ppl)
0.5
NO. of Participants (ppl)
1144
Attendance rate (%)
100
Work Plan for 2023
  1. Continuously conduct education and training on personal data protection during the annual new employee training sessions at the headquarters, aiming to prevent personal data leakage.
  2. Enhance data security protection and conduct cross-departmental assessments to explore the feasibility of adopting the ISO 27001 Information Security Management System.