Privacy Policy
ASE Technology Holding Co, Ltd (“Company”) values the importance of privacy and personal data protection. This Policy on the Protection of Privacy and Personal Data (the “Policy”) is adopted by Company in accordance with the Personal Data Protection Act of Taiwan, Enforcement Rules of the Personal Data Protection Act of Taiwan, EU General Data Protection Regulation (GDPR) and applicable laws and regulations on the protection of privacy and personal data in the United States (U.S.), China and other countries or areas where Company and its subsidiaries (collectively “ASEH”) operate, to guide and manage the compliance by ASEH. The Policy aims to protect the privacy and personal data of persons interacting with ASEH including customers and suppliers, visitors, website users, investors or shareholders, and job applicants (”data subject”). ASEH shall commit to collecting, processing and using personal data in strict accordance with the Policy and requesting ASEH’s suppliers (vendors, contractors, external consultants) to respectively comply with the Policy and cooperate with ASEH to protect the privacy and personal data, securing the rights and interests of data subject.
A. Purpose of Collection, Processing and Use
- Business operation: via email or through other channels, to perform works, cooperate or communicate, negotiate or folfill contracts, etc.
- Commercial marketing: via email, website or through other channels, to provide business information or cooperation channels relevant to ASEH, or respond to or communicate related matters.
- Security management: through appropriate measures to ensure the security of data, personnel and the facility.
- Website maintenance and communication: to improve the function and services of the company’s website, provide the latest information related to business and investment, or respond to website user’s inquiries.
- Recruitment and job applicant interviews
- Where it is necessary to fulfill statutory obligations
- Where it is necessary to assist public authorities in performing statutory duties: such as investigation of illegal activities, prevention or investigation of criminal cases.
- Where it is necessary to assert, exercise or protect ASEH’s legal rights
- To conduct various operational management procedures
B. Collection, Processing and Use of Personal Data
- Under specific circumstances, ASEH may collect, process and use certain personal data as follows:
- ASEH may collect, process and use the personal data of personnel communicating, collaborating or conducting any interaction with ASEH in the course of business-related functions through meetings, activities or other business channels, as follows:
- Personal information including name, gender, employer and business title
- Contact information including telephone number and e-mail address
- Other information that may be used to directly or indirectly identify the personnel
- To ensure the safety and security of both the personnel and workplace environment, ASEH may collect, process and use the personal data of persons entering ASEH facilities for the purpose of performing job duties or business visits, as follows:
- Personal information including name, gender, employer, business title, ID/passport number or other forms of identification and facial photography
- Contact information including correspondence address, telephone number and e-mail address
- Other information necessary for furthering public interests
- ASEH may collect, process and use the personal data of persons visiting the company’s website and utilizing the web services (subscription to e-news, online inquiries and online reporting systems), as follows:
- Personal information including name, gender, employer, business title, ID/passport number or other forms of identification and facial photography
- Contact information including correspondence address, telephone number and e-mail address
- Other information that may be used to directly or indirectly identify the website user, such as website user’s relation with Company
- Data collected by Cookies
- ASEH may collect, process and use the personal data of individuals making investment enquiries about the Company through phone, e-mail or any communication channels or persons who become shareholders of the Company, as follows:
- Personal information, including name, gender, employer, business title, ID/passport number or other forms of identification and facial photography
- Contact information, including correspondence address, telephone number and e-mail address
- Other information that may be used to directly or indirectly identify them
- ASEH may collect, process and use the personal data of job applicants for vacant positions at ASEH, as follows:
- Personal information, including name, gender, birth date, ID /passport number or other forms of identification and facial photography
- Expertise and experience, including educational background and occupation, language ability and other professional skills or qualification certificates
- Contact information, including correspondence address, telephone number and e-mail address
- Other information that may be used to directly or indirectly identify the job applicant
- Other information necessary for furthering public interests
- ASEH shall not collect, process and use sensitive personal data including medical records, healthcare, physical examination and criminal records except for the following situations:
- Where it is expressly required by applicable laws and regulations
- Where it is necessary to fulfill statutory obligations with maintenance and protection measures that are appropriate and secure
- Where it is necessary to assist the public authority in performing its statutory duties of investigating illegal activities, preventing or investigating criminal cases
- Consent is given by the data subject
- Unless notification may be waived in accordance with the applicable laws and regulations, ASEH shall inform the data subject of the followings:
- The personal data to be collected, processed and used
- Specific Purpose of collection, processing and use of personal data
- Data subject may base on the various Specific Purposes and decide to consent or reject, in whole or in part, the collection, processing and use of requested and/or suggested personal data by ASEH (opt-in)
- Data subject rejecting collection, processing and use of personal data by ASEH, or providing inaccurate or incomplete personal data for ASEH to collect, process and use may result in ASEH’s inability to provide the data subject with specific or complete information, feedback or services
- ASEH shall collect, process and use personal data to the extent not exceeding the necessary scope of Specific Purpose and ensure the collection, processing and use of personal data that have legitimate and reasonable connection with Specific Purpose. The data subject may base on the various Specific Purposes and request, in whole or in part, the cessation of the collection, processing and use of personal data by ASEH, or deletion/destruction of personal data collected, processed or used by ASEH (opt-out) and ASEH shall proceed in accordance with such request
C. Third Party Disclosure
- ASEH may disclose personal data to third parties under the following circumstances:
- The third party is a public authority:
- Where it is necessary to fulfill statutory obligation
- Where it is necessary to assist the public authority (the Court, Prosecutor/Policy/Investigation Bureau, or national or local government agency, etc.) in performing its statutory duties of investigating illegal activities, preventing or investigating criminal cases
- Where it is necessary to assert, exercise or protect ASEH’s legal rights
- At the request of the data subject
- The third party is a private legal entity (including Company’s subsidiaries), private institution or organization, or individual persons:
- Where it is necessary to fulfill statutory obligation
- Where it is necessary to assert, exercise or protect ASEH’s legal rights
- For the use to the extent not exceeding the necessary scope of the Specific Purpose
- At the request of the data subject
- ASEH shall manage third party disclosures in compliance with the following:
- Verifying the identity of the third party
- Notifying data subject and obtaining his/her consent unless notification may be waived in accordance with applicable laws and regulations (e.g. notification or consent may prevent the public authority from performing statutory duties)
- Disclosing minimal and only necessary personal data, and requiring third parties to comply with applicable laws and regulations on personal data protection
D. Accuracy of Personal Data
ASEH shall take measures that are reasonable and necessary to maintain the accuracy of personal data and, proactively or at the request of the data subject, supplement or correct personal data.
E. Retention and Security of Personal Data
- ASEH shall retain personal data for a reasonable period of time not exceeding the necessary scope of Specific Purpose, which in principle does not exceed 5 years. Unless continuous retention of personal data is expressly required by applicable laws and regulations or necessary for ASEH to perform duties or business, or has the consent of the data subject, ASEH shall, proactively or at the request of the data subject, cease the collection, processing and use of personal data, or delete/destruct personal data if collection, processing and use is no longer necessary, the legitimate and reasonable connection with Specific Purpose no longer exists, or the laws and regulations on retention become not applicable.
- ASEH shall establish appropriate and secure measures to manage the storage, processing, transmission, retention, access privileges of personal data and data storage/transfer tools. ASEH shall commit to safeguarding personal data to prevent damage, loss, theft, leakage, unauthorized access, copies, use or alteration. The measures include:
- Using appropriate and secure networks and tools for data transmission and storage, such as encryption software (SSL or HTTP) to transfer data and setting up firewalls
- Classifying personal data according to level of security to ensure that the collection, processing and use of such data do not exceed the necessary scope of the Specific Purpose, and preventing access by unauthorized personnel
- Classifying personal data according to results of risk assessments, and adopting appropriate management procedures for the collection, processing, use and disclosure of such data
F. Cross-Border Transfer
Personal data may be transferred among and used by ASEH’s subsidiaries located in different countries to the extent not exceeding the original scope of the Specific Purpose. ASEH shall manage the transfer and use of personal data in accordance with the Policy and applicable privacy and personal data laws and regulations in the countries where the personal data is transferred and used.
G. Website Cookies
To improve and enhance the company’s website services, ASEH uses cookies to collect, process and use certain persona data, such as the user’s internet protocol address. To know more about our use of cookies, please refer to ASEH’s Cookie Terms.
H. Legal Rights
With respect to personal data collected, processed and used by ASEH, the data subject is entitled to the legal rights as follows:
- The right to request an inquiry or review
- The right to request a copy
- The right to supplement or correct the incomplete or incorrect personal data
- The right to request the cessation of collection, processing and use
- The right to request the deletion/destruction of personal data that is displayed or stored internally at ASEH, or publicly available on public websites, files or other forms of storage
- Where necessary and technically feasible, the right to request the transfer of personal data, in electronic and machine readable format, to designated third party data controller
- The right to report any personal data violation to public authorities in the area where the data subject is a resident or where the personal data is used
I. Others
- The protection of privacy and personal data is an integral component of ASEH’s internal control and risk management system. ASEH on an annual basis conducts risk assessments and internal compliance audits, on bi-annual basis engages independent parties to audit ASEH’s implementation of privacy and personal data protection and from to time to time, conducts supplier compliance audits to ensure full compliance with Policy and applicable laws and regulations.
- ASEH’s new employees are required to complete a training course on the protection of privacy and personal data. All employees of ASEH also receive regular updates on relevant laws and regulations governing privacy and personal data and management guidance to enhance their compliance awareness.
- ASEH adopts a zero-tolerance policy to any violation of privacy and personal data protection. Should a violation be identified after thorough investigations, ASEH shall immediately review and improve management measures, and take disciplinary actions against errant personnel and where necessary, seek indemnity or prosecution in accordance with applicable laws and regulations.
- ASEH’s employees, external parties or natural persons may file a report or complaint on suspected violations via “ Code of Conduct Compliance Reporting System” or any other updated channels announced by ASEH.
- For matters concerning the Policy or any other issues related to privacy and personal data, ASEH’s employees, external parties or natural persons may contact the following responsible department of ASEH:
ASE Technology Holding Co., Ltd.
Chief Administration Officer Office
Frequently Asked Questions (FAQ)
Q1: What is personal data?
A: Personal data is information that in general may be used to identify a natural person such as name, birth date, ID/passport number, identifiable features, fingerprints, marital status, family information, educational background, occupation, contact information, financial status, and may include additional data on medical and healthcare records, genetics, social and physiological identity, records of physical examinations, criminal records, etc.
Q2: Why does ASE need to use my personal? What/How my personal may be used?
A: Based on the types of your interaction with ASEH, ASEH may, for specific purposes, use certain information that
may be used to identify you.
Please refer to
Section A
and
Section B
for a complete description of how your personal data may be used.
Q3: Can I refuse to provide my personal data?
A: You may decide to consent or refuse, in whole or in part, to provide personal data. However, refusal to provide or
providing inaccurate or incomplete personal data may result in ASEH’s inability to provide you with specific or complete
information, feedback or services.
Please refer to
Sub-Section III of Section B
for more details.
Q4: Can I make request for my personal data?
A: You have a legal right to request, in whole or in part, ASEH to stop collecting, processing and using your
personal data, or delete/destruct your personal data and related records.
Please refer to
Sub-Section IV of Section B
and
Section H
for more details.
Q5: How do I contact ASEH to make enquiries on personal data?
A: You may contact our Chief Administration Officer Office at +886 7 3617131 #83830 or email privacy@aseglobal.com
Please refer to
Sub-section IV and V of Section I
of Policy.
This Policy may be updated from time to time. Please refer to Company’s website for the latest version. (This version was last updated on June 24th, 2022).