IT Security, Cybersecurity, and Personal Data Protection
Goal and Performance Highlights

Performance
Goal
Challenges and Opportunities
Central Pattana continues to invest in digital technologies to transform processes, using technology enablers to enhance the use of data analytics and forecasting capabilities. In line with our Omnichannel strategy, this digital transformation helps create a seamless customer experience, boosts efficiency in customer and tenant services, reduces business risks, strengthens supplier collaboration and simplifies employee workflows.
However, these benefits come with information technology risks, data theft, cybercrime, and personal data breaches. Moreover, compliance with data protection laws, such as the Personal Data Protection Act B.E. 2562 (PDPA), presents an ongoing challenge due to the complexity of the regulatory requirements and the need for strict legal adherence. However, these advancements also bring potential risks including data theft, cybercrime and personal data breaches due to insufficient cybersecurity measures. Such threats could result in business disruptions, resource losses, complaints, legal actions, reputational damage and a decline in stakeholder trust.
Management Approach and Value Creation
Central Pattana Public Company Limited places utmost importance on information security, cybersecurity, and personal data protection as a means of building stakeholder trust, including customers, partners, shareholders, and all related parties. The company is committed to aligning its operations with international standards and strictly complying with relevant laws and regulations. In addition, the Risk Policy Committee helps ensure that critical information is protected from constantly evolving cyber threats.
Cybersecurity and personal data protection have been defined as critical organizational risk indicators. The Company monitors and reports performance in these areas regularly to the Board of Directors to strengthen risk management on an ongoing basis. In addition, an IT Security team has been established under the leadership of Central Group's Chief Information Security Officer (CISO), who plays a key role in setting cybersecurity strategies and coordinating with relevant internal and external parties. The Company also prioritizes the appointment of board members with expertise in information technology to enhance the Board's oversight capabilities in a rapidly evolving digital landscape.
| Governance Level | Reporting Frequency |
|---|---|
| Board Level | As scheduled |
| Management Level | Quarterly |
| Operational Level | Monthly |
| Audit Level | Ongoing |
- Oversee the availability of information systems, both hardware and software
- Manage data center security systems, including physical disaster-prevention systems for emergencies
- Coordinate with the Risk Management Unit for annual emergency response drills simulating system failure scenarios
- Serve as an equivalent to a Security Operations Center (SOC)
- Monitor threats and inspect access to the organization's network and information systems
- Respond swiftly to threats or abnormal events, conduct incident analysis, and implement preventive measures to prevent damage to the Company
- Conduct monthly security reviews and vulnerability assessments, and promptly remediate severe and critical vulnerabilities
- Compile incidents and corrective actions for incident reports to Central Group's CISO
- Define information security policies, standards, and implementation practices for software system development across the organization, along with training programs to build employee awareness and understanding
- Ensure information security in accordance with the organization's risk profile, based on CIA principles covering confidentiality of Company information, personal data protection (PDPA), and criteria for selecting products, system developers, and software for organizational use
- Ensure cybersecurity compliance with legal obligations and international standards such as the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) and Center for Internet Security Controls (CIS Controls)
- Collaborate closely with Central Group's Data Protection Officer (DPO)
- Coordinate business continuity testing in case of information system failures
- Perform random audits related to: (1) Program access control (2) Data confidentiality (3) Data integrity in systems
Executive Oversight and Governance
Central Pattana Public Company Limited places importance on cybersecurity and personal data protection governance. These areas are defined as key risk indicators for the Board of Directors, with performance regularly monitored and reported. The Company has also established an IT Security team under the leadership of Central Group's Chief Information Security Officer (CISO) to drive cybersecurity strategies for maximum effectiveness. In addition, the Company has a policy to recruit directors with expertise in information technology to ensure that its business operations can effectively respond to technological challenges.
Cybersecurity Management Standards and Guidelines
The Company places high importance on protecting personal data, covering all customer touchpoints including retail stores, websites, mobile applications, customer service centers, online communication channels, and other locations where stakeholders' personal data may be collected.
In addition, the Company obtains consent from data subjects before collecting, using, or disclosing personal data. It has also developed a personal data management system to effectively monitor, control, and protect customer data, supported by measures for responding to data breach incidents rapidly.
Personal Data Protection and Legal Compliance
The Company has established the Information Security Policy, Privacy Policy, Cookie Policy, Data Recording, Reporting and Retention Policy, and information security standards as operational guidelines for employees across the organization and all stakeholder groups. The Company also continues to develop and enhance the information security management system, using ISO 27001:2013 and NIST SP800-53 as operating frameworks. These frameworks cover the security of Company data and information systems, including hardware, software, and networks.
In collaboration with Central Group, the Company has established a Personal Data Protection Unit and appointed a Data Protection Officer to oversee responsibilities and define a working framework in compliance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA). Business units exchange information on data breaches and jointly discuss preventive measures. The Privacy Policy is publicly accessible on the Company's website and prominently displayed in customer service areas at shopping centers and other locations where personal data is collected. A detailed manual has also been developed to guide the management of all activities involving personal data processing, ensuring compliance with relevant laws, regulations, and the Privacy Policy. The Company also communicates cyber risks to employees to build awareness and understanding.
To strengthen employee knowledge, the Company provides online training courses, including CPN-Personal Data Protection Act (PDPA 2019) and CRC-Personal Data Protection Act. The Company has also developed and maintained the Record of Processing Activities, implemented Consent Management, established Data Subject Rights Management, defined personal data retention periods under the Data Retention Policy, prepared relevant legal documents such as the Data Processing Agreement, and established the Personal Data Breach Procedure.
The Company also places importance on complaint channels. In cases where personal data is breached by the Company, data subjects may report the incident through the online complaint channel on the corporate website or through the Customer Information Center (Call Center) at +66 (0) 2-667-5555. Such complaints are reviewed by the Internal Audit Unit, reported to the Audit and Corporate Governance Committee, and forwarded to the responsible units for resolution. If an investigation finds that the incident resulted from the Company's actions, the Company will take responsibility by providing appropriate compensation or remediation.
Cultivating a Cybersecurity Culture
To maximize the effectiveness of cybersecurity operations, the Company promotes a strong Cybersecurity Culture across the organization through the following key measures:
- Providing cyber awareness training and knowledge-building for employees at all levels to enhance awareness and reduce risks arising from unsafe behaviors.
- Conducting regular cybersecurity incident response drills to ensure that employees are prepared to respond to and resolve issues effectively.
- Developing comprehensive risk management approaches and updating them continuously to address emerging threats.
Cyber Risk Management and Cyber Insurance
Central Pattana Public Company Limited recognizes that cyber risks may arise and affect its business. The Company has therefore arranged cyber insurance to help mitigate losses in the event of unexpected incidents. It also conducts third-party risk assessments to ensure that business partners with access to Company data maintain adequate security standards.
Commitment to Sustainable Cybersecurity
Central Pattana Public Company Limited believes that robust cybersecurity and personal data protection not only mitigate business risks but also serve as critical strategies for building trust with customers and stakeholders. The Company is committed to continuously developing and elevating cybersecurity standards to remain modern and aligned with global trends, ensuring that the business can grow securely and sustainably in the digital age.
Responsible AI Governance
Central Pattana is committed to the responsible, transparent, secure, and ethical use of Artificial Intelligence (AI) to create business value while safeguarding personal data, information security, and the rights of stakeholders.
The Company integrates AI governance into its enterprise risk management, information security, and data protection frameworks, with reference to internationally recognized standards, including ISO/IEC 27001 and NIST SP 800-53. Access to data, systems, and AI-enabled tools is managed through Role-Based Access Control (RBAC), ensuring that sensitive AI systems and information are accessible only to authorized personnel with designated responsibilities.
Cybersecurity and Information Security Controls
The Company has implemented comprehensive cybersecurity measures to protect its digital infrastructure and data assets, including:
- Multi-Factor Authentication (MFA) for access to critical systems via the internet.
- BitLocker encryption on corporate devices to ensure that data remains protected in the event of loss or theft.
- Administrative privilege controls to prevent unauthorized software installation and system modifications.
- Continuous monitoring and logging of information system activities.
- Phishing reporting and alert mechanisms that enable employees to promptly report suspicious emails to the IT function.
- Regular phishing simulation exercises to assess and strengthen employee cybersecurity awareness.
- Periodic security assessments and testing to evaluate the effectiveness of security controls and identify opportunities for improvement.
Where AI is used to support analysis, recommendations, or decision-making processes, the Company requires appropriate human oversight proportional to the level of risk involved. Mechanisms are also provided for users and affected parties to request reviews, challenge outcomes, or seek reconsideration of decisions where appropriate.
In addition, the Company continuously monitors and evaluates AI system performance to identify potential model drift, assess result accuracy, and mitigate risks related to bias. AI systems and controls are reviewed and enhanced as necessary to maintain reliability and effectiveness. The effectiveness of the Company's IT security, cybersecurity, and data protection controls is independently assessed by external auditors on an annual basis, reinforcing confidence that AI governance and deployment practices remain secure, appropriate, and aligned with international best practices.
AI for Environmental Sustainability and Responsible AI Impact Management
Central Pattana leverages AI and digital technologies to enhance environmental performance, improve resource efficiency, reduce energy consumption, and support its Net Zero 2050 commitment. At the same time, the Company actively manages the environmental impacts associated with the use of AI and digital infrastructure.
Key applications include:
-
Smart Building & AI Energy Management
The Company utilizes Building Management Systems (BMS), Smart HVAC technologies, IoT devices, and AI-driven Chiller Plant Optimization to analyze operational data in real time and optimize cooling system performance according to actual demand. These solutions improve energy efficiency and contribute to greenhouse gas emissions reduction.
-
AI-powered GHG Tracking Platform
The Company promotes the use of digital platforms that enable tenants and business partners to collect, analyze, and calculate greenhouse gas emissions data. These platforms enhance the accuracy of Scope 3 emissions tracking and support collaborative carbon reduction planning across the value chain.
-
Central Pattana SERVE
Central Pattana SERVE is a digital utility monitoring and analytics platform that enables tenants to track and compare energy and utility consumption. The platform helps identify efficiency improvement opportunities and supports the continuous optimization of resource utilization.
To minimize the environmental footprint of AI, the Company promotes the use of energy-efficient digital infrastructure and service providers, supports the adoption of renewable energy where appropriate, and considers computational efficiency when selecting AI systems and models. The Company also continuously measures and evaluates the outcomes of AI implementation, including reductions in energy consumption, greenhouse gas emissions, and operational resource use. Through these efforts, Central Pattana seeks to ensure that AI serves as a responsible enabler of sustainable business growth while delivering long-term environmental value.







