Keelung Customs (KLC) reminded businesses that according to Paragraph 3, Article 48 of Personal Data Protection Act, failure to implement proper security measures, establish security maintenance plans, or define methods for handling personal data following business termination while in possession of personal data files may result in a fine ranging from NT$150,000 to NT$15 million if deemed a serious violation. Furthermore, offenders are required to rectify the violation within a designated period; failure to comply will result in additional fines for each subsequent violation.
To ensure effective supervision of the security maintenance and administration of personal information files in bonded warehouses and logistics centers, Ministry of Finance has formulated the Regulations for the Security and Maintenance of Personal Information Files in Bonded Warehouses and Logistics Centers (the Regulations). KLC will assist businesses in evaluating their compliance with the Regulations by using the “Self-inspection Checklist for Personal Data File Management in Bonded Warehouses and Logistics Centers” (Self-inspection Checklist) to systematically review the implementation of the Regulations, and promptly make improvements for any non-compliance issues. Beginning in 2023, the supervisory authority, along with information and legal departments, will form a team to conduct monthly random inspection of the completed Self-inspection Checklists. If violations involving personal data protection are identified, the business will be subject to legal penalties.
KLC called for enhancing personal data protection measures in bonded warehouses and logistics centers. Businesses qualified as Security and Safety Authorized Economic Operator (AEOS) are encouraged to consult personal data protection or information security management advisors. By fully implementing internal measures, businesses can achieve ISMS (Information Security Management System) and PIMS (Privacy Information Management System) certification. ISMS/PIMS certification not only enhances corporate reputation, but also reduces operational risks and demonstrates strong management capabilities. Therefore, KLC anticipates all businesses to actively participate in safeguarding information security.