Privacy and Personal Data Protection Policy

Sustainability Policies » Corporate Governance Policy

Privacy and Personal Data Protection Policy

To implement the protection and management of personal data and privacy, prevent infringement of personal rights, and promote the reasonable use of personal data, Quanta Computer Inc. and its affiliated companies (hereinafter referred to as "the Company" or "Quanta") have established this "Privacy and Personal Data Protection Policy" (hereinafter referred to as "this Policy") in accordance with the privacy and personal data protection laws and regulations applicable in the countries or regions where they operate.

Scope of Application

This Policy applies to, but is not limited to, all employees of the Company, as well as customers, suppliers, contractors, and personnel of cooperating third parties.

Definition of Personal Data

Personal data includes, but is not limited to: name, gender, date of birth, address, telephone number, email address, employer, job title, national identification number/passport or other document number, bank account information, facial photographs, surveillance camera recordings, applicants’ educational background, work experience, professional certifications, and any other information that can directly or indirectly identify an individual.

Collection and Use of Personal Data

The Company may collect or obtain personal data when data subjects interact with us or establish a business relationship with us, such as when the data subject voluntarily provides information or contacts us, during business transactions and contract performance, through direct interactions such as meetings/exhibitions/business visits, through collaborative projects, or through information publicly disclosed by the data subject. In addition, personal data may also be lawfully obtained from third parties (such as supervisors or law enforcement authorities).
The purposes for which the Company collects, processes, and uses personal data include: providing and maintaining websites, systems, products, and services; compliance reviews; operations and management (suppliers/finance/human resources, etc.); information system administration; health and safety management (access control, surveillance recordings, login records, etc.); surveys; investigation procedures and legal compliance; service improvement; fraud prevention; and the assertion and protection of legal rights.
In principle, the Company only uses personal data within the scope necessary for specific purposes and does not engage in secondary use. However, this limitation does not apply where required by law or by requests from regulatory or judicial authorities, for assisting in the prevention of illegal activities, or where necessary to preserve legal claims and defenses.

Rights of Data Subjects

With respect to their personal data, data subjects may, subject to legal requirements, exercise the following rights with the Company:

  • The right to choose whether to consent or refuse, in whole or in part, to the collection, processing, and use of their personal data for specific purposes (opt-in).
  • The right to request that the collection, processing, and use of personal data for specific purposes be partially or completely ceased and to request deletion or destruction of such data (opt-out).
  • The right to inquire about or request access to their personal data and to request copies of such personal data.
  • The right to request supplementation or correction of their personal data.
  • The right to request that we transfer or transmit certain personal data to the data subject or another service provider if we collected the personal data based on the data subject’s consent.
  • The right to lodge a complaint with the regulatory authority responsible for personal data protection related to the data subject’s personal data.

Third-Party Disclosure Requirements

The Company will properly manage collected personal data and take necessary measures to prevent leakage, loss, or damage. Except within the scope of authorization agreed upon in writing with relevant parties, personal data will not be provided or disclosed to third parties.
Where disclosure to a third party is required for business purposes, the Company will first verify the identity of the third party. Unless exempted from notification by law, the Company will notify the data subject and obtain consent. Only the minimum amount of information necessary will be disclosed, and the third party will be required to manage such information in compliance with applicable laws and may not use it beyond the entrusted purpose, nor reproduce, retain, transfer, sell, lease, or disclose it in any form.

Retention of Personal Data

The Company retains personal data only for the reasonable period necessary to fulfill the purposes of collection, comply with legal obligations, perform contractual obligations, or carry out business operations. Unnecessary personal data will not be retained. Retention periods are determined in accordance with applicable laws, contracts, business needs, and internal regulations. Once the specific purpose no longer exists, the retention period expires, or continued retention is no longer necessary, the Company will cease collection, processing, and use of the data and will delete, destroy, de-identify, or take other appropriate measures.

Protection of Personal Data

Quanta establishes and implements appropriate management and organizational security control measures in accordance with applicable laws and regulations to reduce the risks of accidental or malicious destruction, loss, alteration, unauthorized disclosure, unauthorized access, or other unlawful processing of personal data during the course of processing. The Company adopts reasonable and appropriate measures including, but not limited to, firewalls, intrusion prevention, access controls, data encryption, and other necessary cybersecurity equipment and management mechanisms to protect the security of websites, systems, and personal data. Access to personal data is restricted to authorized personnel within the scope of business necessity, and relevant personnel are required by law/policy to sign confidentiality agreements.
Quanta adopts a zero tolerance stance toward any violation of this Policy. Upon receiving a report, the Company will immediately accept the case and conduct a thorough investigation and handling process. Once a violation is verified, corresponding disciplinary actions will be taken within the scope of applicable laws and the Company's internal regulations, depending on the severity of the circumstances. In serious cases, employment may be terminated, and judicial authorities may be notified as necessary to pursue legal responsibility.
Privacy and personal data protection are also key focus areas of Quanta's risk management and internal control framework. The Company has established internal audit mechanisms for specific business activities and, based on the results of overall risk assessments, conducts audits and follows up on improvement actions for relevant topics when necessary, continuously enhancing protection measures. In addition, the Company plans in the future to engage external professional organizations to conduct audits in order to verify the effectiveness of system operation and implementation.

Responsible Units

Each unit shall manage different types of privacy and personal data matters according to the nature of its business responsibilities: the Human Resources management unit is responsible for the protection of employees' personal data; management personnel within each business unit are responsible for the management of customers' personal data under their handling; and the information security and information management units are responsible for cybersecurity protection related to data transmission and associated systems. Each department shall also implement necessary privacy and security protection measures appropriate to its business context and provide grievance mechanisms. Upon receipt of a complaint, the department shall promptly accept, process, and investigate the matter to ensure comprehensive and compliant personal data management.