Bank of China Brasil understands that information is one of an organization's most important assets. It therefore adopts the relevant measures to protect this asset. Both the privacy and security of client and website visitor information are treated with due care and in accordance with the institution's Information Security Policy and Privacy and Personal Data Protection Committee. The established Information Security principles are fully adhered to by the organization's senior management. They are observed by all in the execution of their functions, including the financial institutions and other companies authorized to operate by the Central Bank of Brazil that are part of the Bank's Conglomerate.
Bank of China Brazil's information security principles:
• The senior management of the Bank's conglomerate determines that all its employees act to prevent security problems from occurring with the information under their possession or responsibility and contribute to quality business results by respecting and complying with the Information Security Policy;
• All information generated or processed through the Bank's resources or resources authorized by the Bank is the property of the Bank's conglomerate;
• Considering that the equipment and facilities owned by the Bank conglomerate must be used solely and exclusively as a working tool by those who need them to carry out their duties and in relation to the company's objectives, the Bank conglomerate reserves the right, whenever it deems it necessary and in compliance with legal precepts, to monitor, inspect or audit the information stored in such equipment and facilities or traveling through the company's network. The same precept applies to equipment and installations which, even though they are not part of the Bank's conglomerate, have been authorized to be used as a work tool where this permissionary condition is present;
• All information belonging to the Bank's conglomerate must be protected against modification, destruction and access by unauthorized persons;
• Every employee must sign a form declaring their knowledge of and full adherence to the rules and procedures of the company's Information Security Policies as well as its Code of Ethics, before being granted access to any type of information;
• The necessary measures must be taken to promptly investigate any possible cause of security problems or security incidents, as well as to minimize their damage;
• At no time will any employee be allowed to claim ignorance of this policy to justify violations or failure to comply with it.
In the event that conduct which does not adhere to this policy or non-compliance with it is identified, the Bank will take the necessary legal, technological or disciplinary measures in order to maintain adherence to it.