UNI-PCSC Sustainability Development

Information Security and Privacy Protection

President Chain Store Corporation takes advantage of the power of digital technology to make consumers’ lives more convenient. To this end, it provides customers with cash flow, logistics and information flow services with digital tools such as the 7-ELEVEN online shopping site, uniopen, ibon, OPEN Wallet, icash Pay, icash 2.0, OPENPOINT app (including iGroupbuying® and iPre-order) and MyShip. This allows consumers to make the most of President Chain Store Corporation as the base and service center for everything in life.

 

 

Cybersecurity Execution Office

The “Cybersecurity Execution Office” is the highest decision-making unit for President Chain Store Corporation’s information security management. It was originally under the “Sustainable Development Committee,” and moved under the “Integrity, Risk and Cybersecurity Management Committee” in 2023 with the Chief of Information Security as the convener. Previously known as the Cybersecurity Committee, it was renamed as the Cybersecurity Execution Office in December 2024. The “Information Security Implementation Team,” “Emergency Response Team” and “Audit Team” under the committee hold at least one review meeting a year, with the convener regularly reporting the implementation and results of information security implementation to Integrity, Risk and Cybersecurity Management Committee (Note). There were no breaches of privacy data in 2025.

(Note) The policies, specific management plans and resources invested by the Cybersecurity Execution Office can be obtained from the Company website.

 

Personal Data Protection Task Force

President Chain Store Corporation uses customer data for non-primary collection purposes, which include marketing or communications with customers in compliance with laws and with the consent of customers. We comply with relevant government regulations and information management principles to ensure that the collection and use of data must be within the scope of authorized data established by the Company, adopt appropriate technical and organizational security measures, and preserve data strictly in highly secure and stable data storage systems to fulfill the confidentiality obligations of personal data of customers and investors. In 2025, the proportion of customer personal data used by the Company for marketing and communications accounted for 99.5%. Digital technologies involve a lot of customers’ personal data. President Chain Store Corporation has established a special task force and reporting mechanism, and conducts training and internal audits to ensure the protection of consumers’ personal data.


The “Personal Data Protection Task Force” is an cross-departmental task force that regularly performs personal data inventory, risk analysis, internal system review, notification and revision, data destruction, education and training. Education and training are systemized with courses and forums for new employees and personal data liaisons of each unit to complete via testing, achieving a 100% internal training completion rate. In order to enhance the awareness and expertise of all employees regarding cybersecurity, we regularly publish cybersecurity e-newsletters to share the latest trends in cybersecurity, information on threat and protective measures. In the meantime, all subsidiaries and system contractors’ IT personnel are required to complete 3 hours of cybersecurity education and training every year. In addition to integrating personal data risk management into the overall risk management and audit mechanism of the Company, personal data protection management reports are formulated for each department, as well as adding personal data protection clauses to contracts when working with external suppliers to ensure that all operating units and suppliers comply with the Company’s personal data protection policy. President Chain Store Corporation’s internal evaluation plan and external verification system can effectively supervise and assist various departments in formulating corrective, preventive or improvement measures for non-conformities discovered during internal evaluations or audits. Records of improvement are equally made and kept. Corresponding penalties are also formulated for employees who violate the Company’s personal data management rules. Any violation will be reported to the supervisor and included in the employee’s personal performance evaluation and records.

The above figure presents the organizational structure for 2025. The working group adjusted the organizational structure effective April 1, 2026.