Supply Chain Management

Evaluation Mechanism

While enhancing customer service quality, TNP prioritizes protecting customer privacy rights and intellectual property. TNP signs confidentiality agreements with customers to safeguard their confidential information and ensures that employees adhere to confidentiality protocols during business interactions. The company conducts comprehensive assessments of the positive and negative economic and human rights impacts of customer privacy. TNP has established an Information Security Committee and achieved ISO 27001 Information Security Management System and BS 10012 Personal Information Protection Management System certifications. TNP adheres to confidentiality agreements and personal data protection laws for customer privacy.

本公司根據ISO 27001資訊安全管理系統設定評量機制,並訂定短、中長期目標,2025年未有任何侵犯客戶隱私或遺失客戶資料的投訴事件。

Reason for the Issue's Importance

Protecting customer privacy and ensuring the proper storage of customer data has become one of the most critical issues in global business operations. Violations can significantly damage a company's image and may also result in both criminal and civil liabilities.

Impact and Influence

  • 經濟實際正面衝擊:
    1. Properly handling customer privacy and establishing robust privacy protection mechanisms can enhance customer trust in the business, promoting long-term customer loyalty.
    2. Complying with privacy regulations and standards may reduce legal risks, maintain the company's reputation, and help stabilize operations.
  • Economic Potential Negative Impact:
    1. Non-compliant privacy handling and leaks will result in legal fines, increasing the company's economic costs.
    2. Privacy violations may cause customer concerns, leading to customer loss and affecting company revenue.
  • Potential Negative Impacts on Corporate Image:
    1. Privacy breaches may lead to data misuse, affecting environmental sustainability.
    2. Privacy incidents may cause social distrust in the company, leading to long-term damage to the company's image.
  • 企業形象潛在正面衝擊:
    1. Effective privacy protection measures help reduce the risk of information security breaches and mitigate the negative impact of data leaks on the business environment.
    2. Adhering to privacy protection principles allows the company to adapt better to sustainable development operations.
  • 人/人權實際正面衝擊:
    1. Actively protecting customer privacy is a manifestation of respecting individual privacy rights, which helps uphold human rights.
    2. Providing transparency in privacy information helps customers understand the company's data handling practices, contributing to the protection of human rights.
  • 人/人權潛在負面衝擊:
    1. Improper data collection and use may exacerbate information asymmetry in society, harming individuals' information autonomy.
    2. Data misuse may lead to discrimination against specific groups, affecting the principle of human rights equality.

Policy/Strategy

  • Regular information security and confidentiality advocacy. Customer-related information, including physical, data, or electronic, must not be disclosed in any form or manner.
  • Upload sensitive data to NAS with appropriate permission control and maintain a complete backup system to ensure data integrity.
  • Regular audits to establish strict confidentiality measures, preventing improper use of customer privacy and protecting customer and company interests.

Goals and Targets

  • 短期目標:
    Enhance employee training on "Privacy Protection" and "Information Security," conducting at least one session per year.
    Each unit must complete an information security selfassessment quarterly.
  • 中期目標:持續更新防火牆、防毒軟體、文件加密軟體、電腦更新,機敏郵件審核、印表機機敏文件通知的軟硬體建置與控制。
  • 長期目標:制訂「資訊安全政策」與ISO/IEC 27001、BS 10012等管理制度,確保相關資訊與文件受到完善的保護,並持續評估資訊安全架構佈署,以面對各種網路威脅與資安風險。此外,對於內部相關人員作業權限之核准與開啟,均依照各系統之相關作業規範辦理。

Management Evaluation Mechanism

The company conducts PDCA (Plan-Do-Check-Act) effectiveness evaluation mechanism according to ISO/IEC 27001.

Performance and Adjustments

2025年未有任何侵犯客戶隱私或遺失客戶資料的投訴事件。
2025年「隱私權保護」及「資訊安全」方面以傳閱紙本與抽測方式進行宣導與教育訓練。
2025年員工個資保護與資安教育宣導課程,總人數212人,完訓人數211人,佔全體比例99.5%。資訊人員完成上市櫃公司資通安全教育訓練課程共6 小時,100%通過金融研訓院測驗取得完訓證明。

Preventive or Remedial Measures

All computer equipment is installed with enterprise antivirus software, which is uniformly and regularly updated to prevent the spread of computer viruses. A firewall is in place to prevent hacker intrusions. Document data is encrypted using encryption software and stored in NAS with regular backups to ensure data storage security. An access control system is installed in the information room. All mainframe or ERP system queries and operations must be logged in with an account and password to prevent business data leakage.

Sustainable Procurement

台灣銘板自2021年著手規劃提高在地採購比率以降低運輸碳排,2022年本公司整體國內採購家數占比為94%,2023年整體國內採購家數占比為93%。考量勞務與工程請購有保固及契約期間之考量,故先規劃提高原物料在地請購占比由2022年33.7%,提高至2023年57.75%,並於2024年開始陸續增加國內勞務、工程之合作家數。本公司2025年於勞務、財物、工程之在地採購金額佔總採購金額達90.17%。後續也會透由供應商政策宣導及遴選更多國內的優良合作廠商。

TNP Company Procurement Proportions Over the Past Three Years
Contract TypeProcure ment Area202320242025年
Number of SuppliersProportion of Total Procurement Amount (%)Number of SuppliersProportion of Total Procurement Amount (%)Number of SuppliersProportion of Total Procurement Amount (%)
Labor(Contractin g and Services)Domestic24132.4325951.3123750.43
Foreign70.437191.59
Materials(Raw Materials)Domestic10157.759233.278627.68
Foreign164.94199.37198.24
Engineering(Constructi on and Equipment)Domestic91.96175.051712.06
Foreign42.490000
Total378100394100368100
Notes: Domestic refers to Taiwan; Foreign refers to regions outside Taiwan.

Supplier Environmental and Social Evaluation

台灣銘板重視環境保護與職業安全議題,推動供應商簽署「環保/職安問卷調查」及「不使用限用物質保證書」,且制定「供應商評核表」,每一年由採購課針對「當年度供應商」或「前期評核為D級之關鍵供應商」進行評核,評核項目包含材料品質、交期達成率、價格優勢、專業能力、服務配合度。針對評核總分分為A、B、C、D等級。供應商如有推行ISO 9001品質管理視為優先交易。

為落實永續供應鏈管理,本公司針對供應商,推動「供應商自評表」,篩選範疇涵蓋:品質管理、勞工人權、健康安全及環境保護評估,於2025 年期間,TNP 已完成共 79 家供應商之自評審查,所有受評供應商均展現高度合作意願,承諾配合推動節能減碳計畫;為了管理原料來源,確保符合對限用物質之要求,2025年新增9家供應商,與3間合作之供應商簽署《不使用環境有害物質保證書》。2025年所有新增供應商均透過本公司環境與社會準則篩選。

此次重點原物料供應商為105家,其中落實稽核廠商有105家,稽核率達100%,達成目標。等級A有95家,等級B有10家,無評鑑不合格廠商,此次評鑑平均得分為86.33分。
本公司每年年底定期進行供應商評鑑作業,並使用環境標準訂定供應商政策以及表列出用於篩選新供應商的環境標準。本公司訂有採購及付款循環,於遴選合作廠商前已進行供應商整體條件評估,也於供應商合約中制定相關促進顯著實際和潛在負面環境衝擊的預防、減緩和補救規範,並定期針對供應進行考核評分。

目前本公司供應商並無有違反相關對環境及人權之紀錄,若有重大缺失及不符合供應商評鑑標準之廠商,依其對環境面及社會面(人、人權)之衝擊程度,經內部評估與審核後得隨時終止或解除契約合作關係及進行補救措施以維護公司之權益。

供應商管理的相關政策,經總經理核准,並發布於本公司官網,連結為 https://esg.tnp.com.tw/supplier-management/