Evaluation Mechanism
The company has set up an evaluation mechanism based on the ISO/IEC 27001 Information Security Management System and established short, medium, and long-term goals. In 2025, there were no complaints about customer privacy violations or data loss.
Reason for the Issue's Importance
Impact
- Economic Actual Positive Impact
- Properly handling customer privacy and establishing robust privacy protection mechanisms can enhance customer trust in the business, promoting long-term customer loyalty.
- Complying with privacy regulations and standards may reduce legal risks, maintain the company's reputation, and help stabilize operations.
- Economic Potential Negative Impact:
- Non-compliant privacy handling and leaks will result in legal fines, increasing the company's economic costs.
- Privacy violations may cause customer concerns, leading to customer loss and affecting company revenue.
- Potential Negative Impacts on Corporate Image:
- Privacy breaches may lead to data misuse, affecting environmental sustainability.
- Privacy incidents may cause social distrust in the company, leading to long-term damage to the company's image.
- Corporate Image Potential Positive Impacts
- Effective privacy protection measures help reduce the risk of information security breaches and mitigate the negative impact of data leaks on the business environment.
- Adhering to privacy protection principles allows the company to adapt better to sustainable development operations.
- Actual positive people/human rights impact
- Actively protecting customer privacy is a manifestation of respecting individual privacy rights, which helps uphold human rights.
- Providing transparency in privacy information helps customers understand the company's data handling practices, contributing to the protection of human rights.
- Potential negative human rights impact
- Improper data collection and use may exacerbate information asymmetry in society, harming individuals' information autonomy.
- Data misuse may lead to discrimination against specific groups, affecting the principle of human rights equality.
Policy/Strategy
- Regular information security and confidentiality advocacy. Customer-related information, including physical, data, or electronic, must not be disclosed in any form or manner.
- Upload sensitive data to NAS with appropriate permission control and maintain a complete backup system to ensure data integrity.
- Regular audits to establish strict confidentiality measures, preventing improper use of customer privacy and protecting customer and company interests.
Goals and Targets
- Short-term Goals
Enhance employee training on "Privacy Protection" and "Information Security," conducting at least one session per year.
Each unit must complete an information security selfassessment quarterly. - Mid-term Goal: Continuously update firewalls, antivirus software, document encryption software, and computers. Implement hardware and software controls for sensitive email review and sensitive document notification from printers.
- Long-term Goal: Establish the Information Security Policy and management systems based on ISO/IEC 27001 and BS 10012 to ensure that relevant information and documents are adequately protected, while continuously evaluating the deployment of the information security architecture to address various cyber threats and information security risks. Furthermore, the approval and activation of access rights for relevant internal personnel are carried out in accordance with the operating procedures established for each system.
Management Evaluation Mechanism
Performance and Adjustments
In 2025, "Privacy Protection" and "Information Security" education and training were conducted through the circulation of paper materials and spot checks.
In 2025, a total of 212 employees participated in personal data protection and information security awareness training, of whom 211 successfully completed the training, accounting for 99.5% of all employees. Information security personnel completed a total of 6 hours of information security training for TWSE/TPEx listed companies, with 100% passing the examination administered by the Taiwan Academy of Banking and Finance and obtaining certificates of completion.
Preventive or Remedial Measures
Sustainable Procurement
TNP began planning in 2021 to increase its local procurement ratio to reduce transportation carbon emissions. In 2022, the proportion of our total domestic suppliers was 94%, and in 2023, it was 93%. Considering the warranty and contract periods for labor services and engineering procurement, we initially planned to increase the proportion of local procurement of raw materials from 33.7% in 2022 to 57.75% in 2023. In 2024, we gradually began increasing the number of domestic partners for labor and engineering services. In 2025, the local procurement amount for labor, finance, and engineering accounted for 90.17% of the total procurement amount. Moving forward, TNP will continue to promote supplier policies and select more excellent domestic partners.
| TNP Company Procurement Proportions Over the Past Three Years | |||||||
| Contract Type | Procure ment Area | 2023 | 2024 | 2025 | |||
| Number of Suppliers | Proportion of Total Procurement Amount (%) | Number of Suppliers | Proportion of Total Procurement Amount (%) | Number of Suppliers | Proportion of Total Procurement Amount (%) | ||
| Labor(Contractin g and Services) | Domestic | 241 | 32.43 | 259 | 51.31 | 237 | 50.43 |
| Foreign | 7 | 0.43 | 7 | 1 | 9 | 1.59 | |
| Materials(Raw Materials) | Domestic | 101 | 57.75 | 92 | 33.27 | 86 | 27.68 |
| Foreign | 16 | 4.94 | 19 | 9.37 | 19 | 8.24 | |
| Engineering(Constructi on and Equipment) | Domestic | 9 | 1.96 | 17 | 5.05 | 17 | 12.06 |
| Foreign | 4 | 2.49 | 0 | 0 | 0 | 0 | |
| Total | 378 | 100 | 394 | 100 | 368 | 100 | |
Supplier Environmental and Social Evaluation
To implement sustainable supply chain management, the Company promotes the“ Supplier Self-Assessment Questionnaire”for suppliers. The assessment scope covers quality management, labor and human rights, health and safety, and environmental protection evaluations. In 2025, TNP completed self-assessment reviews for a total of 79 suppliers. All evaluated suppliers demonstrated a high level of willingness to cooperate and were committed to supporting the implementation of energy conservation and carbon reduction initiatives. To manage raw material sources and ensure compliance with requirements regarding restricted substances, TNP added 9 new suppliers in 2025 and signed the “Declaration of Non-Use of Environmentally Hazardous Substances” with 3 cooperating suppliers. All new suppliers added in 2025 were screened in accordance with the Company's Environmental and Social Standards.
Among the key raw material suppliers, 105 suppliers were identified as suppliers subject to audit, and audits were successfully implemented for all 105 suppliers, achieving an audit coverage rate of 100% and meeting the target. A total of 95 suppliers were rated Grade A and 10 suppliers were rated Grade B. No suppliers failed the evaluation, and the average evaluation score was 86.33 points.
本公司每年年底定期進行供應商評鑑作業,並使用環境標準訂定供應商政策以及表列出用於篩選新供應商的環境標準。本公司訂有採購及付款循環,於遴選合作廠商前已進行供應商整體條件評估,也於供應商合約中制定相關促進顯著實際和潛在負面環境衝擊的預防、減緩和補救規範,並定期針對供應進行考核評分。
Currently, no suppliers have records of violating environmental and human rights standards. If significant deficiencies or noncompliance with evaluation standards occur, the company may terminate or rescind contracts based on the impact on the environment and society (including people and human rights), while implementing remedial measures to protect its interests.
The relevant supplier management policies were approved by the President and published on the Company's official website at: https://esg.tnp.com.tw/supplier-management/