PLIC Corp., Ltd. and Its Affiliates
No. PDPA 004/2026

Subject: Establishment of Personal Data Protection Management System

Pursuant to the Personal Data Protection Act B.E. 2562 (2019)

PLIC Corp., Ltd. and its affiliates (hereinafter collectively referred to as the “Company”) have previously issued the Personal Data Protection Policy dated 23 February 2026 to ensure unified direction and compliance with the Personal Data Protection Act B.E. 2562 (2019).

The Company recognizes that the proper protection of personal data is a fundamental responsibility. Personal data of all relevant parties, including but not limited to stakeholders, directors, shareholders, employees, customers, business partners, contractors, visitors, and website users, shall be handled appropriately in accordance with applicable laws and internal regulations.

Unauthorized use, disclosure, or exploitation of personal data, or any act that may cause damage or enable identification of an individual without lawful basis or consent, is strictly prohibited and shall constitute both a disciplinary violation and a legal offense.

In order to further strengthen governance and ensure systematic control, and with the approval of the Board of Directors, the Company hereby establishes the Personal Data Protection Management System (the “PDPA Management System”) as follows:

1. Implementation and Training

The PDPA Management System, including relevant policies, regulations, procedures, manuals, and prescribed forms, shall be fully implemented and enforced throughout the Company.

The Company shall provide appropriate training to employees to ensure proper understanding and compliance. Periodic monitoring and internal review shall be conducted to ensure effective implementation.

2. Appointment of Responsible Persons

The Company shall appoint Data Controllers, Data Processors, and other responsible persons as required under applicable laws and internal regulations.
Such persons shall perform their duties in accordance with the roles and responsibilities defined under the PDPA Management System.

3. Proper Handling of Personal Data

Employees who collect, use, disclose, retain, delete, or destroy personal data shall do so only to the extent necessary for legitimate business purposes and in compliance with legal requirements.
Consent from data subjects shall be obtained where required by law.
All handling of personal data shall be conducted in accordance with the PDPA Management System and related internal regulations.

4. Disciplinary and Legal Responsibility

Any violation of the Personal Data Protection Policy, PDPA Management System, or related regulations and procedures shall be regarded as a serious disciplinary matter.
The responsible employee shall bear liability in accordance with Company regulations and applicable laws, including responsibility for any damages incurred.

Announced on 23 February 2026

(Takao Okubo)
Managing Director