The University shall comply with the Personal Data Protection Act and other related regulations, and take appropriate measures for personal data protection and information security.
In university operations, we shall respect the rights of data subjects, collect, process, or use personal data in a reasonable, lawful, and secure manner within the scope of specified purposes. For uses beyond specified purposes, written consent shall be obtained from the data subject.
The University shall endeavor to maintain personal data in an accurate and up-to-date state, prevent data theft, leakage, tampering, or other infringements, and enhance equipment security and implement necessary safeguards to protect collected, processed, and utilized personal data.
The University shall respect data subjects' rights to exercise over their personal data, including the right to query, request access, request copies, request supplementation or correction, request cessation of collection/processing/use, and request deletion, and shall respond promptly in accordance with the Personal Data Protection Act.
The University shall strive to enhance personal data protection awareness and strengthen information security management measures, conducting personal data protection and information security training or awareness campaigns on an irregular basis each year.
The University shall establish operational standards for personal data protection and information security management, continuously develop and implement personal data protection management to ensure policy implementation.
When delegating the collection, processing, and use of personal data, the University shall properly supervise the entrusted parties, clearly stipulate responsibilities for data security and confidentiality in contracts, and require compliance with regular audits.
This declaration shall be implemented upon approval by the Personal Data Protection & Information Security Promotion Committee, and likewise for any amendments.