Personal Data Protection Policy
M31 upholds the principles of integrity and respect for personal privacy. The Company strictly complies with the Personal Data Protection Act and other related laws and regulations, and is committed to establishing a sound personal data management and protection mechanism to ensure the security and confidentiality of personal data. The Company has established the “Personal Data Protection Management Regulations” to implement stringent privacy and data protection measures, build a data governance framework, set data standards, enforce access control mechanisms, and establish data ownership review procedures. These ensure the availability, integrity, and confidentiality of personal data throughout its collection, processing, and utilization.
This policy applies to the Company, all subsidiaries, business locations, customers, suppliers, employees (including part-time, interns, and contractors), and any individuals providing personal data, as well as third parties entrusted by the Company to collect, process, or use such data.To effectively manage data protection risks, the Corporate Governance Task Force under the Sustainability Development Committee is responsible for supervising and implementing compliance with the ‘Personal Data Protection Management Regulations.’ The Legal Department provides regulatory and legal support, while data management units are responsible fo maintaining and protecting the data under their control.
The Governance Task Force convenes annual and ad hoc meetings to enhance cross-department communication, ensure compliance, and provide necessary resources and support for data protection activities.Employees or stakeholders who have questions or complaints related to personal data protection may contact the Corporate Governance Task Force. Individuals may request to inquire, review, or obtain copies of their personal data. The responsible data unit shall respond or make a decision within fifteen (15) days, with the possibility of an extension of another fifteen (15) days when necessary, with written notice to the applicant.
Personal Data Protection Implementation in 2025
To enhance company-wide data protection awareness and ensure compliance, the Company carried out the following measures in 2025:
1. Conducted 2 Personal Data Protection Management Meetings to review progress and improvement plans.
2. Organized employee training sessions totaling 276 participants / 138 hours, Participation Rate 92.2%, achieving a 100% passing rate in post-training assessments.
3. Recorded zero (0) complaints or incidents of data breaches or information security anomalies.
The Company will continue to strengthen data governance and privacy protection mechanisms, implement risk management and legal compliance, and safeguard the personal data of customers, employees, and partners — striving to be a trusted and responsible enterprise.
Corporate Governance Performance
For four consecutive years, the Company has received the honor of being ranked among the top 5% of listed companies in the “Corporate Governance Evaluation System”, demonstrating our achievements in various aspects, including “Protecting Shareholders Rights and Interests and Treating Shareholders Equally”, “Strengthening Board Structure and Operations,” “Enhancing Information Transparency”, and “Practicing Corporate Social Responsibility”.
Annual status of complaints and whistleblowing are as follows: