go to main content

Personal Data Protection Policy

Personal Data Protection Policy

To regulate the collection, processing, and utilization of personal data by the Small and Medium Enterprise Credit Guarantee Fund of Taiwan (hereinafter referred to as “TSMEG”) so as to prevent infringements upon privacy rights, and to facilitate the proper use of personal data in compliance with the Personal Data Protection Act (hereinafter referred to as the “PDPA”) and its enforcement rules, the TSMEG has established this Personal Data Protection Policy (hereinafter referred to as the “Policy”) to ensure the comprehensive implementation of proper personal data protection and management.

1.1     Personal Data Protection Policy

1.1.1      Implementation of Personal Data-related Operations in Compliance with the PDPA

All personal data-related operations shall be carried out in accordance with the PDPA, TSMEG’s contracts, and TSMEG’s personal data management guidelines.

1.1.2      Enhancing Personal Data Protection Awareness through Training

Employees shall be supervised to fully implement data protection responsibilities and uphold the principle of “personal data protection is everyone’s responsibility.” Regular and appropriate training sessions are conducted to raise awareness of data protection. Employees who violate relevant data protection regulations shall be held accountable in accordance with personnel reward and disciplinary regulations.

1.1.3      Implementing Personal Data Protection Measures to Ensure Operation Continuity

All employees must comply with TSMEG’s personal data protection requirements to prevent unauthorized access, damage, or loss of data The employees and collaborating parties of TSMEG shall consistently enforce the requirements for personal data protection to safeguard Personal Data from risks such as leakage, destruction, or loss. Ongoing monitoring, reviewing, and auditing are conducted to support TSMEG’s sustainable operations.

1.2     Objectives of Personal Data Protection

1.2.1      TSMEG adopts protective measures throughout the processes of collecting, processing, using, storing, transferring, and disposing of personal data, in accordance with the PDPA.

1.2.2      A management organization is established by TSMEG to govern, enact, promote, and implement personal data protection management.

1.2.3      TSMEG seeks to ensure the security of personal data and mitigate risks such as data theft, alteration, damage, loss, or leakage resulting from external threats or improper management.

1.2.4      Regular training are provided to enhance employees’ awareness in data protection and management, reduce operational risks, and create a trustworthy data privacy environment.

1.2.5      TSMEG complies with legal obligations and requirements to fulfill its data protection responsibilities and enforces internal management standards accordingly.

1.2.6      Personal data management shall be continually improved in response to applicable laws, regulations, contracts, professional responsibilities, and the interests of individuals and relevent key parties.

1.2.7      Periodic risk assessments are conducted on the processes of personal data-related operations to identify acceptable risk levels and address any unacceptable risks accordingly.

1.3     Principles of Personal Data Protection

1.3.1      Personal data shall be processed fairly and lawfully.

1.3.2      Personal data shall only be collected for specific purposes and not used in a manner inconsistent with those purposes.

1.3.3      Personal Data collected shall be adequate, relevant, and not excessive in relation to the purpose for which it is processed.

1.3.4      Personal data shall be accurate and kept up to date.

1.3.5      Personal data shall not be retained longer than necessary.

1.3.6      Personal data shall only be accessed and used in a way that is not violating the legal rights of personal data subjects, including their rights to access their own personal data.

1.3.7      Personal data shall be protected with appropriate security measures.

1.3.8      Personal data shall not be transferred to countries or regions lacking adequate legal protection or contrary to applicable laws.

1.4     Personal Data Protection Organization

1.4.1      To effectively implement and manage personal data protection tasks, TSMEG shall establish a Personal Data Protection and Management Organization, which must include senior executives among its members. This organization is responsible for defining the duties and obligations of all members within TSMEG, preventing personal data from being stolen, altered, damaged, lost, or leaked, and ensuring compliance with relevant laws and regulations while consistently applying best practices for data protection.

1.4.2      The responsibilities and duties of relevant personnel within the Personal Information Management System (hereinafter referred to as the “PIMS”) shall be clearly defined and confirmed.

1.5     Protection of Personal Data

1.5.1      TSMEG shall establish and implement a PIMS to ensure the enforcement of this Policy. All personnel and outsourced service providers must comply with the regulations and requirements of the PIMS, and the operation of the PIMS shall be reviewed regularly.

1.5.2      Appropriate security control measures shall be implemented to ensure the security of all personal data.

1.5.3      A management framework shall be established, including a classification and grading scheme. Security management protocols shall be defined for all personnel who have access to such data.

1.5.4      To ensure the security of all personal data, access controls must be strengthened for information systems used to manage personal data files. Unauthorized access must be prevented, privacy must be maintained, and security protection mechanisms shall be established and subject to regular audits.

1.5.5      When personal data files are stored on personal computers, identifiable login passwords ,and other supplementary security measures shall be considered based on business needs and criticality.

1.5.6      The scope of use and access authorization must be defined for any activity involving the input, output, access, update, destruction, or sharing of personal data.

1.5.7      If any department of TSMEG experiences a personal data security incident, such as malicious tampering, data corruption, or operational negligence, emergency response measures must be taken immediately in accordance with TSMEG’s incident response and reporting procedures.

1.5.8      TSMEG utilizes rigorous measures and policies to protect the personal data of data subjects. All employees of TSMEG are required to undergo comprehensive training in personal data protection and privacy rights. Any leakage of personal data will be subject to civil and criminal liability in accordance with the law.

1.5.9      All outsourced service providers or business partners of TSMEG are required to sign non-disclosure agreements when cooperating with TSMEG. They must fully understand the importance of personal data protection and the legal consequences of data breaches. Any violation of confidentiality obligations shall be pursued for civil and criminal liability under applicable laws.