2.8 Regulatory Compliance

Regulatory Compliance (2-27)

Regulatory compliance is the key factor for sustainable business operation. TransAct strictly complies with the Personal Information Protection Act, the Labor Standards Act, the Labor Occupational Accident Insurance, the Labor Insurance Act, the National Health Insurance Act, the Enforcement Rules of the Labor Pension Act, the Occupational Safety and Health Act, the Act of Gender Equality in Employment and other relevant laws and regulations. We take the necessary measures to comply with personal data protection laws so as to handle personal data appropriately and respect workplace privacy. In order to achieve the goal of sustainable management, TransAct is committed to full regulatory compliance as the foundation of our growth and faces the increasingly stringent regulations in a responsible and proactive manner. In addition to adhering to the company's core values of sustainable management, we are also committed to protecting the rights of our employees and shareholders, fulfilling our corporate citizenship responsibilities and establishing privacy protection policies. 

Moreover, we have taken a number of measures to ensure that employees are properly informed of the laws and procedures related to personal information and workplace privacy. For example, compliance education training is one of the most important elements of our compliance program, and we hold seminars, face-to-face presentations and meetings to provide personal data processors with the proper principles and guidelines for handling personal data. Through the promotion of personal data and privacy protection issues, we strive to not only keep our employees up-to-date with the latest laws and regulations but also to further strengthen their commitment to ethical practices, thereby creating a sound compliance environment that meets common global standards. There have been no major violations of any laws and regulations since the establishment of TransAct. Therefore, we do not report any incident or case details and amount of fines here.

In order to establish the standard that staff of TransAct with reference to the the law, to establish the law communication and information system, and to supervise the operation and management rules are updated in accordance with the law and regulations in a timely manner, important laws and regulations are provided to the staff of each department of TransAct via e-mail immediately and posted on the internal website for the business reference of all colleagues.

TransAct plans to propose employer's liability insurance in Q4 2023, which, if approved by the shareholders' meeting, will provide more comprehensive protection for all employees within the organization, in addition to the existing employee group insurance coverage.

Policy Commitments (2-23)

With reference to the workplace labor environment and compliance with international human rights conventions such as the Universal Declaration of Human Rights, the International Labour Conventions, and the United Nations Global Compact, TransAct pledges that people at all levels should highly respect human rights and strive to create a labor-friendly workplace. In the event of a workplace harassment, we will set up a disciplinary committee with reference to the Regulations for Establishing Measures of Prevention, Correction, Complaint and Punishment of Sexual Harassment at Workplace to prevent the occurrence of such incidents.

TransAct highly protects the privacy of customers. In addition to the president and the senior executives have obtained ISO 27001 lead auditor qualification at the same time, everything is controlled with high international standards, the disclosure of customer privacy is strictly prohibited, and relevant strict rules for information security protection are established.

Embedding Policy Commitments (2-24)

Through internal education and training as well as occasional weekly meetings, TransAct enables employees to understand and implement the relevant human rights policies and workplace-related regulations of the company.

Customer Privacy: The ISO 27001: 2013 of the International Information Security Management System (ISMS) is used to effectively control information or data flows, improve the effectiveness of internal IT operations and help organizations manage and mitigate various threats and risks to information.