Information and Data Security

     Information technology is demonstrating a trend of rapid development and growth, playing an increasingly crucial role in the business operations of organizations. Consequently, the issue of cybersecurity threats has emerged as a significant risk and a considerable challenge for organizations in preparing to address them. The company acknowledges the risks associated with the security of its data and information systems, including obstacles arising from external IT system attacks and the leakage of personal and corporate data from within. These risks can adversely affect the company's operations and the personal data security of its employees, customers, and partners. The company's information technology department is responsible for overseeing and managing the organization's IT security, establishing policies and guidelines for maintaining information security, and developing systems to fortify the information system's defenses. Furthermore, the company conducts training sessions for employees and executives on information and cybersecurity to enhance their knowledge and awareness of cyber threats.

Data Privacy

      Ditto recognizes and respects the privacy rights of individuals and places great importance on the protection of personal data in all forms. Accordingly, We have established comprehensive processes and operational practices to ensure the proper handling of personal data, supported by policies and preventive measures in compliance with applicable laws, including the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), together with appropriate information security controls, use, disclosure, and retention of personal data are closely monitored and managed by the Data Protection Officer (DPO) and external advisors specializing in personal data protection. In addition, We conducts regular training programs and continuous risk assessments to strengthen awareness and ensure effective personal data management practices across the organization.

      By 2025, the company has continuously implemented data security measures, such as installing and upgrading effective cybersecurity systems, managing access rights based on necessary permissions, regularly backing up data, and establishing system recovery plans to address emergencies. This is

Information Security Policies and Procedures
Effective from February 26, 2024 onwards.
Download
Data Privacy Policy and Practices
Effective from December 10, 2024 onwards.
Download
Privacy Policy for Business Partners/External Parties, Employees, Clients, and Candidates
Effective from December 10, 2024 onwards.
Download
Personal Data Retention and Disposal Policy
Download
Customer Personal Data Security Policies and Procedures
Effective from December 10, 2024 onwards.
Download
Personal Data Protection Procedures
Download

2025 Target and Performance

Target 2568
No leakage of stakeholders’ personal data
No customer complaints regarding unauthorized use of personal data
2025 Performance
No customers were affected by data leakage, loss, destruction, or theft
No customer complaints regarding unauthorized use of personal data were reported