EGCO Group places great importance on data protection and privacy of employees, customers, suppliers, and every stakeholder. The Company stipulated strict internal data abuse prevention guidelines as well as established and announced the data privacy protection policy publicly. This is to ensure that any operation handling personal information is secure, stable, reliable, in full compliance with related laws, and is trusted by the data owner. EGCO Group has established mechanisms to ensure effective compliance with the policy as follows:

Cybersecurity and Data Risk Management

Data security is a corporate risk that requires management and monitoring. Cybersecurity and privacy policy systems are embedded in group-wide key risk factors and management.

  1. Risk management is a responsibility shared by management and employees across all levels. It requires continuous implementation even if the risks cannot be eliminated. Effective risk management enables the company to maintain control over risks at an acceptable level while fostering appropriate benefits to the company simultaneously.
  2. Information security risks refer to potential incidents that may occur in the future that affect the confidentiality, integrity, or availability of the organization’s information management system.
  3. Cyber security risks refer to potential incidents that may occur in the future as a result of cyber threats exploiting weaknesses and security gaps to attack the system, technology, equipment, and internal network systems, thereby causing damages to the company’s service and information management systems.

The risk management process comprises the following key steps:

  • Identification of risk and potential impacts on data security
  • Risk assessment
  • Risk management
  • Risk monitoring and reporting

Privacy Policy Compliance

EGCO Group has developed a personal data protection procedure to serve as a guide for safeguarding the privacy data of partners, suppliers, business partners, employees, and stakeholders. This procedure is established in compliance with the Corporate Personal Data Protection Policy and Personal Data Protection Act B.E.2562, while also aligning with EGCO Group’s risk management approaches. Parties responsible for managing privacy data are equipped with relevant regulations, case studies, and guidelines on actions to be taken in various situations to enable them to collect, utilize, manage, disclose, or dispose of the data set forth by the legislative framework. Such practice ensures the security, safety, and reliability of the company while maintaining the privacy rights of data owners.

Personal Data Protection Procedure

To ensure the reliability of privacy protection programs and alignment with the company’s privacy policy, EGCO Group assigned the Internal Audit Division and commissioned an External Auditor to conduct data privacy audits.

Internal Audits of the Privacy Policy Compliance. The Internal Audit Division conducts reviews to assess the sufficiency and appropriateness of the internal auditing system and regularly monitors privacy policy compliance to ensure alignment with the Personal Data Protection Act (PDPA). Findings of the audit will be reported to the Audit Committee for approval prior to being presented to the Board of Directors.

In 2025, the Internal Audit Division conducted the PDPA compliance internal audits across EGCO Group's 30 functions. These audits encompassed personal data management, information security management, and reviewing the corrective actions recommended in the PDPA Compliance Audit Report by ALPHASEC Company Limited.

Summary of the internal audit observations for internal control system improvement.

  • Monitoring the corrective actions recommended by the consultant.
  • Compliance audit against EGCO Group Policy and supplier’s compliance with Data Processing Agreement (DPA).
  • Guidance to grievance reporting according to regulatory requirements.
  • Personal data storage as per the guidance
  • Employees’ acknowledgment and experience regarding EGCO Group’s PDPA policy and guidance was at a good level.

Third-party Audits of the Privacy Policy Compliance: EGCO Group ensures that its operations are audited by third-party experts every three years. In 2025, EGCO Group engaged with ALPHASEC Company Limited, a third-party certified body, to conduct an audit and assessment of its personal data protection practices, covering organizational oversight, policies and procedures, training and awareness, individual rights, transparency, records of processing activities and lawful basis, third-party oversight, risk management and Data Protection Impact Assessment (DPIA), data security, and breach response. The audit scope covered all divisions of EGCO Group. The audit process took two months.

The auditor summarized that EGCO Group’s overall personal data protection practices and measures comply with Thailand’s regulation. However, the auditor provided observations and recommendations aimed at enhancing the efficiency of the EGCO Group’s personal data protection practices regarding governance structure, training programs, personal data processing, and establishment of Data Protection Impact Assessment (DPIA) policy or procedure.

Furthermore, EGCO Group conducts an annual data security review as part of External Independent Assurance of GRI 418-1 (Substantiated complaints concerning breaches of customer privacy and losses of customer data) to monitor compliance with the company’s requirements.