Data Classification
a. Sensitive Data
The Company identifies and classifies sensitive data.
Appropriate security measures are implemented to protect sensitive data against unauthorised access, disclosure, alteration or loss.
b. Personal Data
The Company processes and protects personal data in accordance with applicable data protection and privacy laws.
All required consents, authorisations and legal grounds are obtained for the collection, use, processing and sharing of personal data.
c. Commercial and Internal Business Data
The Company protects the confidentiality, integrity and availability of commercial and internal business data.
Appropriate measures are implemented to safeguard trade secrets, business strategies and other critical Company information.
Data Security and Access Controls
a. Data Encryption
The Company uses appropriate encryption methods to protect sensitive data.
Encryption technologies are applied to data both in transit and at rest.
b. Authorisation and Access Controls
Access to data is restricted through authorisation controls and role-based access policies.
Users are granted access only to the data required to perform their duties.
c. Monitoring and Logging
The Company monitors its systems and regularly reviews system logs.
Logs are maintained to detect suspicious or unauthorised activities and to support investigations where necessary.
Data Backup and Recovery
a. Data Backup
The Company performs regular backups of its data.
Backup procedures and schedules are designed to support the prompt recovery of data in the event of data loss.
b. Disaster Recovery
The Company develops disaster recovery plans to prepare for emergencies and major disruptions.
Data centre backups, business continuity plans and disaster recovery tests are implemented to support operational resilience.
Data Breaches and Incident Management
a. Data Breach Notification
When a data breach is identified, the Company acts promptly and effectively to notify the relevant parties where required.
Appropriate containment, corrective and preventive measures are implemented following a breach.
b. Incident Management
The Company maintains an effective incident management process for responding to security incidents and data breaches.
Incidents are investigated, corrective actions are taken, and improvement measures are implemented to prevent recurrence.
Data Disposal and Retention Periods
a. Data Disposal Policy
The Company complies with its established data retention periods and disposal procedures.
Data that is no longer required for legal, regulatory, contractual or business purposes is securely deleted or destroyed on a regular basis.
b. Data Retention Periods
The Company ensures that data is retained in accordance with applicable legal and regulatory requirements.
Data retention periods and related requirements are defined, documented and monitored.