Customer Data Sharing Management and Privacy Protection Policy

TOP

SinoPac Financial Holding Co., Ltd. (hereinafter referred to as "the Company") and the financial institution subsidiaries listed in the first point of this policy (hereinafter referred to as "subsidiaries") uphold the principles of integrity, kindness, professionalism, and innovation. Committed to developing high-quality financial products and services, providing a secure transaction environment, and respecting the confidentiality of customer data, the Company aims to enhance customer convenience, strengthen risk management, promote cross-industry collaboration among financial institutions, and ensure customers’ rights and interests. In accordance with the Personal Data Protection Act, the Financial Institutions Data Sharing Guidelines, and other relevant laws and interpretations, this "Customer Data Sharing Management and Privacy Protection Policy" is established to outline the customer data sharing management system and principles for the Company and its subsidiaries. The following information is provided:

I. Subsidiaries sharing customer data include:
● SinoPac Commercial Bank Co., Ltd.
● SinoPac Securities Co., Ltd.
● SinoPac Futures Co., Ltd.
● SinoPac Securities Investment Service Co., Ltd.
● SinoPac Securities Investment Trust Co., Ltd.

Overseas subsidiaries or foreign branches of the Company and its subsidiaries are excluded.

II. Purpose of Customer Data Sharing
The Company and its subsidiaries may share customer data for the purpose of identifying risks, conducting risk management, enhancing customer convenience such as reducing redundant data entry, or collaborating on business operations.

Details regarding the companies participating in customer data sharing, the purpose and the content of customer data sharing are provided in the attached Appendix. Any additions or changes will be announced and disclosed on the respective participating companies' websites.

III. Scope of Shared Customer Data
With customer consent in advance, customer data that the Company or its subsidiaries may share with the others includes basic customer information, identity verification data, account information, transaction records of financial products or services, negative information, Know Your Customer (KYC) data, value-added data by financial institutions, electronic communication history records (such as IP addresses), or other data agreed upon by the customers and cooperating companies. If the shared customer data involves non-public information such as identity verification data or negative information that significantly impacts customer rights and interests, the Company or its subsidiaries should conduct necessary verification or provide additional measures to enhance customer data protection.

IV. Customer Data Protection Measures
Customer data is securely stored in the Company and its subsidiaries' databases. Additionally, in accordance with the internal management regulations set by the Company and its subsidiaries, access to data is controlled, and unauthorized personnel are prohibited from obtaining or altering customer data. The Company and its subsidiaries employ encryption in data transmission through secure mechanisms and have installed firewalls to prevent unauthorized intrusion, safeguarding customer data from illegal access.

V. Protection of Customer Rights and Interests
The Company and its subsidiaries, in accordance with this policy, will conduct customer data sharing with clear and appropriate purposes, adhering to legality and ethical standards to avoid potential biases or differential treatment of customers under similar conditions. If customers request to cease data sharing or have complaints or disputes arising from data sharing operations conducted by the Company or its subsidiaries, they may notify the subsidiaries in writing, via email, or by contacting the customer service center. Based on the customer's notification, the subsidiaries will promptly cease the customer data sharing or promptly investigate and inform the customer, within a reasonable working period.

This policy was last updated on January 30, 2024. However, in order to respond to changes in the social environment and laws, as well as technological advances, and to protect the rights and interests of customers, the Company reserves the right to revise this policy from time to time and to update it as soon as possible by announcing it to customers on the website of the Company.

Appendix

The names of the Company and its subsidiaries Purposes and Contents of Customer Data Sharing
SinoPac Financial Holding Co., Ltd.
  1. To provide the Company and its subsidiaries with access to customer data, minimizing the need for customers to redundantly fill out and provide personal information.
  2. To integrate and analyze customer data from participating companies, offering value-added, innovative, or customized services.
  3. To enhance collaboration on risk prevention of transactional risk management within SinoPac Financial Group, integrating risk information from the Company and its subsidiaries to strengthen risk management of customers.
SinoPac Commercial Bank Co., Ltd.
SinoPac Securities Co., Ltd.
SinoPac Futures Co., Ltd.
SinoPac Securities Investment Service Co., Ltd.
SinoPac Securities Investment Trust Co., Ltd.