Information and Cybersecurity and Privacy Protection

                        

In 2025, cybersecurity remains a critical priority for BJC as the Group continues to expand its digital operations and adopt emerging technologies, including AI-driven solutions and cloud-based systems. The increasing complexity of cyber threats, such as ransomware, phishing, data breaches, and third-party risks, may impact business operations, customer trust, and corporate reputation.


BJC recognizes the importance of protecting personal and business data across its retail, consumer goods, healthcare, packaging, and supply chain businesses. The Group continues to strengthen its cybersecurity governance through investments in advanced security systems, data protection measures, threat monitoring, access controls, and employee awareness programs.


BJC also regularly reviews and updates its cybersecurity policies and practices to align with evolving technologies, regulatory requirements, and emerging cyber risks, ensuring effective risk management and business continuity.

 

 

 

Information and Cybersecurity Privacy Protection Management Approach

 

BJC places importance on information and cybersecurity to support digital business operations and protect information assets across the organization. BJC has established the Information and Cyber Security Policy and Personal Data Protection Policy to strengthen data security, ensure data integrity, and prevent cyber threats and unauthorized access. These practices are aligned with applicable legal requirements, including the Personal Data Protection Act B.E. 2562 (PDPA), as well as internationally recognized standards such as ISO/IEC 27001 and the NIST Cybersecurity Framework.

 

To strengthen governance and oversight, BJC has established the Information Security and Cybersecurity Governance Committee at the Board level, comprising board members with knowledge and experience in information technology, cybersecurity, digital transformation, and enterprise risk management. The Committee is chaired by Mr. Tevin Vongvanich, who has prior experience overseeing IT strategy, cybersecurity risk management, and digital infrastructure at the board level, with direct exposure to enterprise IT operations at PTT ICT Solution Company Limited. Mr. Aswin Techajareonvikul further supports the Committee with his expertise in technology management, digital innovation, and big data applications. In particular, C Smart Solution (CSS), a data analytics company in which BJC has a joint investment, focuses on big data development, and Mr. Aswin plays an active role in reviewing CSS’s business performance and evaluating technology-related projects and innovations prior to implementation. The Committee is responsible for overseeing cybersecurity governance, information security risks, regulatory compliance, and strategic technology direction across BJC.


In addition, the management team plays an active role in implementing cybersecurity policies, monitoring cybe rsecurity risks and driving continuous improvement of cybersecurity practices across business operations. Management regularly reports cybersecurity performance, risk assessments and key incidents to the Board-level Committee to ensure effective oversight and timely response to evolving cyber threats.
BJC has also appointed Mr. Surachai Hirannitichai, Group Chief Digital Technology, as Chief Information Security Officer (CISO). The CISO is responsible for establishing and implementing the Company’s information security strategy, cybersecurity framework, risk management practices and incident response capabilities to ensure the protection, confidentiality, integrity and availability of information assets and technology systems across the organization.


Operational execution is managed through 

•    Group Digital Cybersecurity and Compliance responsible for safeguarding the BJC’s digital ecosystem, strengthening cyber resilience and regulatory compliance, and enhancing threat intelligence, security monitoring, and incident response capabilities across BJC’s corporate, manufacturing, and retail operations. 
•    The Data Protection and Security Governance Working Group also supports the implementation of data protection and information security initiatives under the oversight of the Board-level committee.

 

Information Security and Cybersecurity Management Structure

 

 

Information and Cybersecurity Policy

 

BJC Group’s Information and Cyber Security Policy establish the framework for protecting information assets, information technology systems, and business operations across the organization. The policy emphasizes the protection of data confidentiality, integrity, and availability, while preventing cyber threats, data breaches, and unauthorized access. It applies to directors, executives, employees, contractors, and all related parties who access or manage company information and digital systems.


The policy is aligned with applicable legal requirements and internationally recognized standards, including the Personal Data Protection Act B.E. 2562 (PDPA), ISO/IEC 27001, and the NIST Cybersecurity Framework. To strengthen cyber resilience and support secure business operations, BJC has implemented governance structures, cybersecurity controls, and operational measures such as access management, data encryption, vulnerability assessments, penetration testing, security monitoring, business continuity planning, and disaster recovery processes.


In addition, BJC promotes cybersecurity awareness and responsible data handling across the organization through continuous communication, training, and employee engagement, reinforcing a strong culture of information security throughout the Group.

 

 

 

The Chief Information Security Officer (CISO), who also serves as Group Chief Digital Technology, is responsible for establishing and implementing BJC Group’s information security strategy, cybersecurity framework, governance structure, risk management practices, and incident response capabilities to ensure the confidentiality, integrity, and availability of information assets and technology systems across the organization. The CISO oversees enterprise-wide cybersecurity management across digital platforms, applications, manufacturing operations, and retail businesses, while driving cybersecurity resilience and regulatory compliance in alignment with business objectives and internationally recognized standards.


Under the CISO’s leadership, the Group Digital Cybersecurity and Compliance function is responsible for safeguarding BJC Group’s digital ecosystem through proactive cyber defense, threat intelligence, security monitoring, vulnerability management, and incident response capabilities across corporate, manufacturing, and retail operations. The function also supports compliance with applicable laws, regulations, and cybersecurity standards, while continuously strengthening cyber resilience across the Group.


In addition, BJC promotes a strong cybersecurity culture and employee awareness through continuous communication, online learning programs, cybersecurity training, and awareness campaigns aimed at enhancing responsible digital practices and reducing cyber risks across the organization.

 

Personal Data Protection Policy

 

Personal Data Protection Policy establishes the framework for managing, protecting, and processing personal data across the organization in compliance with the Personal Data Protection Act B.E. 2562 (PDPA). The policy applies to all business operations, including suppliers and related parties, and emphasizes the protection of personal data confidentiality, integrity, and security throughout the data lifecycle.
BJC has established governance structures, including a Data Protection Office and designated Data Protection Officer (DPO), to oversee personal data protection practices, regulatory compliance, risk management, and data breach response across the organization. The Group implements operational controls such as data classification, access management, consent management, data retention procedures, breach notification processes, and Data Protection Impact Assessments (DPIA) to strengthen personal data protection and privacy management.

 

The DPO is responsible for monitoring compliance with applicable data protection laws and regulations, including the Personal Data Protection Act B.E. 2562 (PDPA), and overseeing the effectiveness of the Group’s data protection framework. Key responsibilities include:

  • Advising the organization on personal data protection requirements, regulatory obligations, and best practices. 
  • Overseeing the implementation and periodic review of personal data protection policies, procedures, and controls.
  • Monitoring compliance through internal assessments, audits, and Data Protection Impact Assessments (DPIA). 
  • Coordinating data breach management and supporting timely incident response and regulatory notification processes. 
  • Maintaining records of data processing activities and supporting transparency and accountability across the organization. 
  • Coordinating with regulatory authorities and relevant stakeholders on personal data protection matters. 
  • Supporting the protection of data subjects’ rights, including rights related to access, correction, deletion, objection, and data portability. 

The DPO operates independently with appropriate authority, resources, and access to management to effectively perform oversight responsibilities and support the continuous improvement of BJC’s data protection framework. 
In addition, BJC promotes awareness and accountability regarding personal data protection through continuous communication, employee training, and monitoring processes, while conducting internal and external audits to support compliance with applicable regulations and recognized standards.

 

Privacy Policy

 

BJC has established a Privacy Policy to demonstrate its commitment to protecting the privacy rights and personal data of individuals in accordance with the Personal Data Protection Act B.E. 2562 (PDPA). The policy outlines the types of personal data collected, used, or disclosed by the Company, the purposes and legal basis for processing, data retention periods, and the rights of individuals under applicable data protection laws.

BJC also provides Privacy Notices to ensure that individuals whose personal data is processed by the Company are informed of relevant data processing activities, applicable safeguards, and available channels for exercising their rights. Individuals may contact the designated Data Protection Officer (DPO) through established communication channels to exercise rights relating to access, correction, deletion, objection, restriction of processing, and data portability, as permitted under applicable laws.


To strengthen governance and ensure consistent implementation across the organization, BJC has established governance structures, including a designated Data Protection Officer (DPO), to oversee personal data protection practices, regulatory compliance, risk management, and data breach response. 


In addition, the Company has implemented a Personal Information Consent Procedure to provide operational guidance for employees responsible for obtaining and managing consent in a lawful, transparent, and accountable manner.

Privacy-related risks are integrated into BJC’s enterprise risk management framework and overseen by the Risk Management Committee. BJC has implemented operational controls and procedures, including access management, data classification, consent management, data retention practices, breach notification procedures, and Data Protection Impact Assessments (DPIA), to ensure that the collection, storage, processing, use, and disclosure of personal data are conducted in accordance with established security standards and internal controls.

 

Stakeholder Awareness and Communication

 

BJC promotes personal data protection awareness and accountability across key stakeholder groups, including customers, employees, and suppliers, through the following approaches:

  • Customers are informed through consent notices and privacy communications regarding the purposes of personal data collection, use, and processing activities. 
  • Employees receive regular information security and personal data protection training to strengthen awareness, promote responsible data handling practices, and reduce the risk of data leakage or misuse. 
  • Suppliers are required to comply with BJC’s data privacy expectations and related requirements through relevant contractual obligations. 

 

Audit and Compliance Assurance

To support compliance with applicable laws, regulations, and recognized standards, BJC conducts security and data privacy audits in accordance with ISO/IEC 27001 requirements and relevant information security practices. In addition, internal audits are performed by the Group Internal Audit Department to assess the effectiveness of information security controls, data confidentiality measures, and privacy management practices across the organization.

 

During the 2024 Internal Audit, BJC evaluated compliance with the Company's Personal Data Protection Policy, the Personal Data Protection Act (PDPA), and related privacy management processes. The audit assessed key privacy governance and operational controls, including policy implementation, Records of Processing Activities (ROPA), consent management, privacy notices, personal data retention, employee awareness, access control, information security measures, personal data breach management, and data subject rights handling. The audit concluded that the Company had established an appropriate privacy management framework and no significant findings were identified. Any observations and opportunities for improvement were addressed through corrective action plans and continuous monitoring to further strengthen the effectiveness of privacy controls. 

 

Building upon the 2024 Internal Audit, BJC continued to strengthen its privacy compliance programme through a comprehensive PDPA compliance assessment conducted from 3–28 November 2025. The assessment was carried out through the Group Internal Audit system in coordination with the designated Data Protection Officer (DPO). It covered key privacy governance and operational controls, including the approval and implementation of the Personal Data Protection Policy, formal appointment of the DPO, completeness and annual review of Records of Processing Activities (ROPA), privacy notices and collection purposes, need-to-know access controls, agreements with data processors and service providers, data retention and disposal, information security measures such as access control and encryption, and mechanisms for data subjects to exercise their legal rights. Assessment results and supporting evidence were documented in the internal GAD Web Application system to monitor ongoing compliance, facilitate continuous improvement, and ensure the effective implementation of the Company's privacy requirements across the organization.

 

 

GAD Web Application system
GAD Web Application system

 

 

Continuous Improvement

BJC regularly reviews and updates its Privacy Policy and related procedures to align with evolving legal requirements, regulatory expectations, business operations, and recognized data protection standards. Reviews are conducted periodically, following significant regulatory or operational changes, and at least annually.

 

Privacy Notices: Customer Privacy Information

 

Privacy Notices published on the Company website, consent forms, and related communication channels.
The Privacy Notices provide customers with clear information regarding:
•    The nature of information collected from customers, including data from request forms, contracts, letters, other documents, the company’s website, cookies, applications and telephone systems.
•    The duration for which the data will be collected.
•    The specific purposes for collecting and using personal data.
•    The options available to customers regarding the control of their personal data, such as the ability to correct, use, retain and process their data, including consent opt-in/out options, access requests, data transfers to other service providers and data deletion requests.
•    Data protection management, including defining authorization and access control for relevant parties.
•    Employee training programs to raise awareness of the PDPA and related laws and regulations.
•    The implementation of the customer privacy policy and measures to prevent data breaches.
•    Contracts regarding personal data protection.

In addition, Big C implements consent management processes through its Point-of-Sale (POS) system for customers participating in the Big C Big Card membership program. Customer consent records are maintained within the PDPA Management System. The system enables authorized personnel to manage consent preferences, process requests related to personal data rights, and support the deletion or withdrawal of consent where applicable.

To strengthen data protection and privacy controls, personal data is safeguarded through role-based access controls, user authorization procedures, and data masking measures for sensitive information. Big C also utilizes CRM and data management systems to monitor and control the use of customer data for secondary purposes in accordance with consent requirements and applicable privacy regulations.
 

Notification in Case of a Personal Data Breach

 

In the event of a personal data breach, the Data Protection Officer (DPO), together with relevant functions, is responsible for assessing the nature, scope, and potential impact of the incident on affected individuals. BJC will implement appropriate mitigation measures and, where required by law, notify the Office of the Personal Data Protection Committee (PDPC) and affected individuals within the prescribed timeframe. BJC has established breach management and incident response procedures to support timely investigation, reporting, and remediation in compliance with applicable data protection regulations.

 

Cybersecurity Management Process

 

BJC places great emphasis on information security and cybersecurity governance to ensure that critical information assets, business operations and stakeholder data are effectively protected. The Company has implemented an Information Security Management System (ISMS) in accordance with ISO 27001 and integrates cybersecurity risk management into its Enterprise Risk Management (ERM) framework to strengthen organizational cyber resilience and operational continuity.

In 2025, BJC further enhanced its cybersecurity governance by adopting the National Institute of Standards and Technology (NIST) Cybersecurity Framework as an additional guideline to strengthen cybersecurity risk management, incident response, continuous monitoring and recovery capabilities in alignment with internationally recognized best practices.

BJC has established cybersecurity management processes to identify, assess, monitor and mitigate cyber risks and threats across the organization. Employees are encouraged to report suspicious cyber activities and information security incidents through multiple reporting channels, including the company secretary’s email, hotline and direct supervisors. Significant cybersecurity incidents and information technology risks are reported to the Risk Management Committee and Information Security and Cybersecurity Governance Committee at least annually to ensure appropriate oversight, timely mitigation actions and continuous improvement of cybersecurity measures.

In 2025, 100% of BJC’s IT infrastructure and information security management systems were certified.

 

Data Protection and Access Control

BJC has implemented comprehensive data protection and access control measures to strengthen information security and prevent unauthorized access, disclosure, alteration or loss of critical information assets. Key measures include:


•    A Data Loss Prevention (DLP) procedure incorporating data encryption, access control mechanisms and user activity monitoring to enhance the security of corporate data and information systems. 

•    A data classification procedure under which information is categorized into four levels: Highly Confidential, Restricted, Internal and Public. Appropriate controls are applied throughout the data lifecycle, including data creation, usage, transmission, storage and destruction, to ensure that sensitive information is securely managed in accordance with applicable regulations and internal requirements. 

•    Policies governing data ownership and usage rights, under which BJC retains ownership of all data stored or transmitted through the Company’s computer systems and networks. The Company reserves the right to access such information when necessary for security monitoring, regulatory compliance or operational purposes. At the same time, BJC respects and protects the ownership rights of customer information, external parties’ data and intellectual property in compliance with applicable laws and regulations.

 

Cybersecurity Monitoring, Inspection and Audit

 

BJC has established cybersecurity monitoring, inspection and audit processes to strengthen continuous monitoring capabilities, detect potential security threats and ensure compliance with internal policies and internationally recognized standards. The IT Security & Compliance Team is responsible for overseeing data security and cybersecurity compliance across the organization. Key responsibilities include monitoring database usage, data exportation, disclosure of information to external parties, intercompany data and software exchanges, portable storage media usage and data encryption practices.


To strengthen monitoring and detection capabilities, BJC utilizes surveillance and tracking systems, including Assure Information Protection (AIP), to monitor file and folder access, track user activities and maintain event histories related to file creation, deletion, copying and movement within the network environment. The Company also enforces security policies designed to prevent unauthorized transmission of sensitive information, including confidential documents and payroll-related files, through email or other communication channels.


In addition, regular inspections are conducted on critical data transfers and data copied to removable media, printers, shared network drives and other storage devices to reduce the risk of unauthorized disclosure or data leakage.


To maintain high cybersecurity and compliance standards, BJC conducts regular independent third-party audits and collaborates with external organizations to support standardization, cybersecurity assessments, ISO 27001 certification, vulnerability assessments and penetration testing. These assessments are conducted annually to identify potential vulnerabilities, strengthen cybersecurity resilience and support continuous improvement initiatives. All inspection and audit results are reported to the Committee to ensure ongoing oversight and alignment with evolving cybersecurity risks and international standards.

 

  • Independent external audit: ISO 27001 certification

         Upgrading to the ISO 27001:2022 version to meet the latest security requirements and achieve certification.

  • Vulnerability Assessment

      BJC maintains an information security vulnerability assessment program conducted by independent third parties as part of its business continuity and cyber incident response framework. The Company utilizes vulnerability assessment reports to identify, assess, and prioritize cybersecurity vulnerabilities based on asset criticality and vulnerability severity. Assessment results are used to implement risk-based remediation measures and prioritize corrective actions for business-critical systems, thereby strengthening the Company’s cybersecurity risk management capabilities and operational resilience.

  • Penetration Testing

       BJC conducts regular penetration testing on critical business systems in collaboration with independent third-party cybersecurity experts as part of its cybersecurity assurance program. The assessments are designed to identify and validate exploitable vulnerabilities, evaluate the effectiveness of security controls, and support risk-based remediation. In 2025, penetration testing was completed for key business applications, and all identified vulnerabilities were remediated in accordance with the Company's vulnerability management process. This approach strengthens system resilience and supports the continuous improvement of the Company's cybersecurity posture.

 

Cybersecurity and Business Continuity

 

BJC has established comprehensive cybersecurity and business continuity processes, including Disaster Recovery Plan (DRP) testing, penetration testing, vulnerability assessments, and Business Continuity Plan (BCP) exercises to ensure preparedness and effective response and recovery capabilities.

Cybersecurity testing activities are conducted at least semi-annually, while BCP exercises are performed at least annually to assess the effectiveness of response and recovery procedures, evaluate system readiness, and strengthen the Company's capability to respond to cyber incidents and business disruptions.

In 2025, DRP testing and BCP exercises were completed for all critical business functions. Findings and recommendations from these activities were reviewed and addressed through the Company's remediation and continuous improvement processes.

Results from these exercises are systematically used to enhance cybersecurity controls, incident response procedures, disaster recovery arrangements, and business continuity measures. In response to evolving cybersecurity standards, emerging threats, and lessons learned from testing activities and security incidents, BJC continuously updates its cybersecurity procedures and operational protocols to strengthen organizational resilience, minimize business disruptions, and support sustainable business operations.

 

Escalation Process for Reporting Incidents, Vulnerabilities, or Suspicious Activities
All employees and system users may report suspicious incidents or information security issues through the company’s designated channels:
 • Call: (+66) 2-146-9494
 • Email: MIS-Helpdesk@bjc.co.th
 • Email: dpo@bjc.co

All reported information will be recorded in the Incident Log and managed in accordance with the company’s incident response process. This includes escalation to the responsible departments, such as the Information Security Management Team, for prompt investigation, analysis, and resolution.

Upon resolution, follow-up reports will be prepared, and lessons-learned sessions will be conducted to prevent recurrence and strengthen the company’s security practices.

 

Number of breached occurred in 2025

The number of complaints received regarding personal data breaches and data loss

Indicators Target 2025
Total number of information security breaches 0 0
Total number of clients, customers  and employees affected by the breaches 0 0

 

As a result of efficient data management, there has been no complaint on customer privacy, no substantiated reports issued by BJC over consumer privacy violations and 4.44% of customers’ data has been used for secondary purposes in 2025.

 

Information security awareness training

BJC places strong emphasis on cybersecurity awareness and employee training to strengthen the protection of personal data, information systems and critical information assets. Regular training and internal communications are conducted to enhance employees’ understanding of cyber threats, including phishing attacks, password security and cyber risk identification, while promoting responsible cybersecurity practices and compliance with data protection requirements across the organization.

 

In 2025, BJC conducted Cybersecurity Awareness Drill Simulation Result Post-Awareness Training

Results Test 1 Test 2
Number of employees Percentage Number of employees Percentage
Total number of employees who received a phishing email 1,808 - 1,808 -
Total number of employees who opened a simulated phishing email 352 19.5 410 21.6
Total number of employees who clicked on a simulated phishing link 51 2.8 159 8.4

 

 

Information & Cybersecurity Privacy Protection Documents


Economic
PDF Information and Cyber Security Policy
331.31 KB 
PDFPersonal Information Consent Procedure
467.34 KB 
PDFBJC's Privacy Notice
338.94 KB 
PDFISO 27001
906.56 KB 
PDFBJC Privacy Policy
188.96 KB 
PDFInternal Audit Report
242.29 KB