SECTION 10
10. Security and Retention
10.1Security Principle
Asiacom Group seeks to take reasonable and appropriate organisational and technical measures to protect personal information against unauthorised access, loss, misuse, inappropriate disclosure, alteration or destruction.
10.2Organisational and Technical Controls
Measures may include access control, responsibility allocation, internal procedures, confidentiality controls, incident response, website security, authentication, network protection, monitoring, logging and backup.
10.3Access Limitation
Access to personal information should be limited to persons, functions or authorised service providers that reasonably require the information for an approved purpose.
10.4Retention Principle
Personal information should be retained only for as long as reasonably necessary for enquiry handling, business relationship management, record keeping, security, dispute resolution or applicable legal and institutional requirements.
10.5Review and Deletion
Where information is no longer reasonably required, Asiacom Group may delete it, securely dispose of it, archive it where retention remains necessary or otherwise restrict continued use as appropriate.
10.6Security Incidents
Where a material information-security or privacy incident is identified, Asiacom Group may take steps to contain the issue, review what occurred, protect affected information, correct the relevant problem and respond to applicable requirements.