PLANET remains committed to meeting the expectations of all stakeholders—including customers, shareholders, suppliers, and employees—by continuously enhancing the effectiveness of information security and privacy management in line with international standards and regulations. In 2024, we further strengthened our information and communication security management system by deepening the implementation of ISO 27001 standards, and completed the ISO 27001:2022 version upgrade verification in 2025, enhancing the overall level of cybersecurity protection and privacy safeguards. We also expanded our efforts in digital privacy and data protection in response to emerging InfoSec threats both globally and within Taiwan.
In response to the arrival of the “Year of AI Application” in 2025, PLANET further incorporated AI into its overall governance and risk management framework. Building on its existing foundation of information security and privacy protection, the company transitioned from initial application introduction toward institutionalized governance. PLANET established an AI governance structure and risk management mechanism, clearly defining AI implementation processes and the division of roles and responsibilities through cross-departmental collaboration. It conducted risk grading and assessments based on a “data type × usage scenario” matrix. Meanwhile, the company formulated “AI Usage Guidelines” to regulate data input scope and leakage prevention measures, and established a controlled, traceable enterprise-level AI environment based on five governance principles: legality, fairness, transparency, security, and accountability. These efforts promote AI empowerment for all employees while continually strengthening the company's InfoSec resilience and sustainable competitiveness in the AI era.
No major incidents impacting operations or violating customer privacy occurred in 2025. The number of information leakage, theft loss, and customer data loss events was 0.
PLANET’s information security management system is evaluated at least once a year or is re-evaluated in case of major changes in the company. The evaluation results are presented at the management review meeting and are revised as appropriate to control and mitigate information security risks.
To ensure comprehensive protection of information and communication security, PLANET has been insured under a "Cyber Liability Insurance" policy since 2023. The renewal for the subsequent year was completed by the end of December 2025, with the coverage period from 1 January 2026 to 1 January 2027. To effectively prevent Infocomm risks, PLANET has established various InfoSec performance indicators and conducts annual reviews of their implementation.
In terms of AI risk control, the company focuses on practical operations and usage control. Through identity verification and permission management mechanisms, it ensures that AI tools are used only within the approved scope, conducts pre-evaluation and continuous review of data usage scenarios, and combines internal management and auditing tracking mechanisms to reduce data misuse, leakage, and operating risks, maintaining the safety and compliance of AI applications.
To continuously strengthen Information and Communication Security governance, PLANET upgraded the original "Information and Communication Security Management Office" to the "Information and Communication Security Management Department" in 2025. Furthermore, the "Information and Communication Security Task Force" has been established to serve as the core unit for promoting information security related tasks.
Information and Communication Security Management Department: As a dedicated department, it is responsible for daily InfoSec management, incident response, and implementation of related strategies. The department includes one InfoSec supervisor and one InfoSec officer.
Information and Communication Security Task Force: Responsible for formulating overall InfoSec policies, risk monitoring, and driving InfoSec projects. The task force comprises an Internal Audit Team, InfoSec Response Team, and Incident Reporting Team, all coordinated by the Information and Communication Security Management Department. Regular meetings are held to ensure consistency and efficiency in decision-making and execution.
Since 2022, the status of information and communication security implementation has been reported to the Board of Directors. The information and communication security implementation results (including AI governance) for 2025 were reported to the Board of Directors on December 18, 2025.
By strictly following ISO 27001 international standards to establish its information security objectives, PLANET is able to avoid the improper use, leakage, modification and destruction of information caused by human negligence and natural disasters, thus to minimize the potential risks and hazards to the company.