Privacy Protection and Cybersecurity Overview
Why is this Important?
The transition to the digital technology era plays a critical role in the industrial sector, particularly the energy business, where automation systems are deployed across infrastructure to enhance operational efficiency and reduce costs. However, such transformation exposes EGCO Group to heightened cybersecurity risks. Inadequate security measures may disrupt power generation continuity, undermine confidence among customers and investors, and result in financial and reputational damage. Therefore, proactively managing risks is essential to maintaining stability and stakeholders’ confidence.
EGCO Group places importance on systematically establishing information security measures. Policies are regularly enhanced to safeguard information from potential threats arising from interconnected technology systems within energy infrastructure, confidentiality, data integrity, and availability. In addition, EGCO Group conducts annual employee training to strengthen cybersecurity awareness and has appointed a dedicated working team to monitor and evaluate personal data protection performance, ensuring that all processes are prudent and compliant with applicable legal requirements.
Sustainability Material Topic: Data Security & Privacy
Stakeholder Impact on Materiality Topics
Shareholders
Government agencies/regulators
Contractors/Subcontracotrs
Communities
Society
Suppliers and Business Partners
Investors
Management Approach
Privacy Protection and Cybersecurity Target

Privacy Protection and Cybersecurity Governance
The Risk Oversight Committee stipulates an internal audit policy regarding risk management activities as well as investigating IT development-related operations regularly.
Explore more
Cybersecurity Measures
EGCO Group stipulated and published IT Security and Cybersecurity policy for every employee, including external parties providing services for EGCO Group, to use as an operational guideline on IT-related tasks, ensuring full compliance with related laws.
Explore more
IT Security/ Cybersecurity Process & Infrastructure
EGCO Group’s IT Security System was certified ISO/IEC 27001:2022 which covers processes such as grievance management, change management, document control, asset utilization monitoring, etc.
Explore more
Data Privacy Protection
EGCO Group places great importance on the data protection and privacy of employees, customers, suppliers, and every stakeholder. The Company stipulated strict internal data abuse prevention guidelines as well as established and announced the data privacy protection policy publicly.
Explore moreRelated Documents
Policies, Requirements and Performance
-
Sustainability Manual
-
Personal Data Protection Policy
-
Personal Data Protection Act (PDPA) Statement
-
End User Security Guideline
-
Information Technology Development and Cyber Security Oversight Committee
-
Privacy Notice for External Data Subjects
-
Consent Form for External Data Subjects
-
Application Form for Exercise of the Rights of Data Subject
-
Personal Data Breach Notification Form
-
IT Security and Cybersecurity Policy
-
ISO27001:2022 Certification
Performance Data
Updated as of May 2026
The information reported above was prepared in accordance with the Global Reporting Initiative Standards (GRI Standards). It has been audited by an external party and has received limited assurance through the 2025 Annual Report.