Personal Information Security Management Measures

1. Formulation of Basic Policy

To prevent and address unauthorized access to personal information, as well as the leakage, loss, or damage of personal information, we will establish internal regulations and strive to implement security measures.
To achieve these objectives, we are taking the following measures.

2. Establishment of Rules Governing the Handling of Personal Data

・We have established regulations regarding information security and are committed to ensuring the appropriate protection of information assets and information security.

3. Organizational Security Management Measures

・We have appointed a “Chief Information Security Officer (CISO)” from among our executive officers and have established an Information Security Measures Committee.
Through this, we actively work to accurately assess the status of information security at the company-wide level and promptly implement necessary measures.
・We have appointed a “Personal Information Protection Manager” and have established a system to promptly report any incidents, such as leaks, to the Information Management Officer.

4. Personnel Security Measures

・We conduct regular training for all executives and employees to ensure thorough implementation and continuous improvement of information security initiatives.
Additionally, provisions regarding the confidentiality of personal information are included in our employment regulations.

5. Physical Security Measures

・We have implemented measures to prevent the theft or loss of equipment, electronic media, and documents containing personal data.

6. Technical Security Measures

・We implement access controls to limit the scope of personal information databases and other data that staff members may handle.

7. Assessment of the External Environment

・When entrusting personal information to external contractors, we exercise strict oversight in the selection and supervision of such contractors.