SRN Sound Proof Co., Ltd. (SRN), as a leading manufacturer of thermal insulation and sound-absorbing materials in the Automotive Supply Chain, recognizes that information security is the core of building trust with our global partners. We adhere to the Personal Data Protection Act B.E. 2562 (PDPA) and the Computer-Related Crime Act (No. 2) B.E. 2560 as the highest standards in our business operations. These are integrated with international standards such as the JAMA/JAPIA Cybersecurity Guidelines Version 2.2 to protect personal data and intellectual property from cyber threats in all dimensions.
This policy covers data transmission activities and services through the Company's information systems, including SRN Connect and SRN Data Transfer, to clarify the details of data collection and processing transparently.
The Company collects personal data to the extent necessary for Authentication and Role-Based Access Control (RBAC) via SRN Connect and SRN Data Transfer systems, as follows:
SRN focuses on data management under the Information Security Audit strategy to protect organizational confidentiality (Confidentiality Management) according to the SI-AD-005 manual, with the following purposes:
The Company employs technical and administrative measures consistent with the 10 Priority Measures of the automotive standard to reduce the Window of Opportunity for system intrusions:
| Security Measure | Implementation Details |
|---|---|
| Password Management | Mandatory password change every 90 days to mitigate the risk of password leaks, with complexity requirements. |
| Access Control | Implementation of Multi-Factor Authentication (MFA) and one-time Security-Code for downloading critical data. |
| Information System Protection | Installation of Web Filtering and Gateway Security, along with regular Vulnerability Management scans. |
| Business Continuity Plan (BCP) | Compliance with the "Operational Flowchart in Case of Power Outage," with status checks within 15 minutes and clear procedures for server shutdown/data backup to maintain data integrity. |
Under the PDPA, Data Subjects have the right to control their own data to ensure transparency, as follows:
If you wish to exercise your legal rights or have any questions regarding data security measures, you may contact the Data Controller Representative Committee at:
The Company is committed to developing and updating our privacy policy to keep pace with changing circumstances and technologies, maintaining the highest level of data security standards in accordance with SRN's ideology.