(Revised June 2026)
This revision of the Statement on Data and Information Protection is intended to supplement and refine the Company’s existing related policies, with the objective of continuously enhancing the Company’s framework regarding Environmental, Social and Governance matters.
The principal revisions covered in this update involve the following topics:
· Scope of data protection policy (Refers to main topic page);
· Consent policy for use of consumer data for secondary purposes (Refers to II. Protection of Personal Information Rights and Interests);
· Data protection programs covering suppliers and business partners (Refers to III-iii Third Party Management);
· Responsibility for privacy and data security (Refers to III-iii Third Party Management);
· Privacy enhancing technologies and initiatives (Refers to III-iii Third Party Management);
· Measures to address data breaches (Refers to III-iv Comprehensive Response Plan, proactive and reactive measures for data security);
· Scope of employee training on privacy and data security (Refers to IV. Employee Training) and;
· Frequency of audits of information security system (Refers to V-i Information Security Audit).
Please refer to the sections under the corresponding headings below for the specific links to the relevant policies.
CITIC Securities Company Limited (hereinafter referred to as “CITIC Securities”, or the “Company”) deeply recognizes the importance of corporate data security and personal information protection for the financial services industry, and regards it as the core cornerstone of the Company's compliance operation. In order to effectively protect the legitimate rights and interests of customers and regulate the entire process of data processing, the Company formulates and issues this statement in accordance with applicable laws and regulations including the Securities Law of the People's Republic of China, the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, the Personal Information Protection Law of the People's Republic of China, the Measures for the Administration of Information Technology of Securities and Fund Institutions, and Measures for Cybersecurity and the Information Security in the Securities and Futures Industry.
This Statement applies to all departments, business lines, branches and holding subsidiaries of CITIC Securities, as well as all domestic and overseas regions of operation, including CITIC Securities, CITIC Securities Shandong, CITIC Securities International, CITIC Goldstone, CITIC Securities Investment, CITIC Futures, CITIC Securities South China, and China AMC.
I. Organizational Structure and Management System
The Company has established a three-level digital organization structure of "Decision-making Tier, Management Tier and Operational Tier":
Decision-making Tier: The Company’s Digitalization Committee serves as the leading and supreme deliberative body for corporate digitalization initiatives, and is responsible for the Company's data governance, digitization operation and management, information technology governance and network and information security.
Management Tier: A special working group is set up under the digitization committee, responsible for formulating management systems related to data governance, data security protection and personal information protection of the Company, coordinating and promoting various departments to carry out various work, and improving the level of data security governance.
Operational Tier: An execution system composed of the Information Technology Center, Compliance Department, and various business lines, ensures the effective implementation of management requirements throughout the entire business process.
The Company has established a company level data security and personal information protection system applicable to all employees in various departments, business lines, branches, and all operational areas, including the Administrative Measures for Data Governance, Administrative Measures for Personal Information Protection, Administrative Measures for Cybersecurity and supporting Implementing Rules for Data Security Management of CITIC Securities and other accompanying management and implementation rules, which cover all business systems, data assets and information.
The scope of management covers all business systems, data assets and information processing activities of the Company. Based on its own business characteristics, the Company has formed a network security management system that meets regulatory requirements, domestic and foreign standard basis, and internal management needs. The Company has formulated security policies covering physical security, network security, application security, data security and supply chain security domains.
The Company has obtained ISO 27001 Information Security Management System (ISMS) certification. All business systems have completed classification and assessment in compliance with national requirements for Cybersecurity Classified Protection.
II. Protection of Personal Information Rights and Interests
Except where required by laws, regulations or mandatory orders from competent government authorities, the Company shall share data with third parties only for lawful, legitimate, necessary and specified purposes related to transaction and service fulfillment, and upon obtaining customers’ explicit consent.
The Company fully guarantees the rights and interests of customer information subjects, and promises to take corresponding security measures to protect customer personal information in accordance with national personal information protection requirements, and provide convenient channels for exercising rights and interests:
i. Collection Principles
The Company strictly follows the principle of "specified purpose and data minimization" to collect customer data, and only collects customer information that is directly related to the provision and handling of securities business services. The collected data shall meet the needs of business operation or management, and is consistent with the content agreed in the contract and privacy policy, and shall not exceed the scope of data collection. When the relevant business is stopped or there is no need to continue data collection, data collection activities will be immediately stopped.
ii. Personal Consent Principle
The Company publishes its Privacy Policy for customers via mobile applications, official websites and other channels, clearly informing customers of the purposes, processing methods, categories and retention period of personal information, and collects and processes personal information only with customer consent.
iii. Right of Access
The Company discloses personal information processing rules through privacy protection clauses and customers may access and view the list of collected personal information.
iv. Right of Rectification
When customers discover errors in information, they can apply for correction through online or offline channels, and the Company will complete the verification and processing within 3 business days.
v. Right of Cancellation / Deletion
The Company provides a one-stop service for account closure. After the customer cancels their internet account, the Company will promptly clear their internet account information. After the customer cancels their fund account, the Company will no longer collect personal information related to the account; 'If the customer revokes consent for information processing, the Company shall immediately cease the activity of continuing to collect the customer's personal information.
The Company sets the data retention period for different types of data in accordance with the relevant provisions of the national, industry regulatory authorities, internal regulations, and time limit agreed with the personal financial information subject. Any data exceeding the stipulated retention period shall be deleted in a timely manner.
vi. Data Processing Specifications
All third parties are required to sign strict Non-Disclosure Agreements (NDAs),Data Processing Agreements(DPAs) and adopt adequate confidentiality measures. The Company undertakes not to lease, sell or disclose any personal data to third parties beyond the scope of transaction and service delivery.
III. Data Security Protection Measures
i. Data Lifecycle Protection Measures
The Company implements data classification and tiered protection, based on data security protection level, carries out information system construction and implements data lifecycle protection, and protects customer personal information and data security by comprehensively utilizing various data security protection tools such as data desensitization, data backup, and loss prevention for endpoints.
The Company establishes a defense-in-depth system for network and data security, deploying intrusion detection tools and security protection tools at the network layer, host layer, and application layer respectively; implements strict network host application resource request and releases management mechanisms; establishes capabilities to audit data operational activities, retains all activity logs properly, and enables full audit and traceability for internal and external data access.
The Company conducts real-world cybersecurity attack and defense exercises, tests employees' awareness of network security protection, and verifies the information system network and data security protection capabilities.
ii. Permission Control
The Company controls data access permissions in compliance with the principle of least privilege, and employees can only obtain the necessary data permissions to complete their job duties; the Company establishes an access permission application and approval mechanism for important information systems, and adjust and clear access permissions based on employee identity.
When accessing personal information, the Company establishes a least privilege access control policy, so that employees can only access the minimum necessary personal information required for their duties, and only have the minimum data operation permissions required to complete their duties. The Company also sets up an internal approval process for important operations on personal information.
iii. Third Party Management
The Company shall conduct dynamic inspection on the compliance of suppliers and business partners with the requirements of information security and data protection during the business, implementation, acceptance and other stages of the cooperation project.
While continuously improving the Company’s own data security and privacy protection level, the Company actively promotes suppliers and business partners to enhance their internal network and data security management capabilities. 'Furthermore, the Company implements strict access management, requires all suppliers and business partners to sign data security protection agreements, strictly comply with the institutional requirements and measures of CITIC Securities' network and data protection, clarify data processing boundaries and responsibilities, and improve the overall data security level.
At the same time, the Company perceives the product security risks of suppliers through network security monitoring and intelligence, and provides risk alerts to suppliers to jointly carry out risk disposal work. The Company issues remedial requirements for identified risks, oversees implementation, and requires suppliers to complete all remedial actions within the same fiscal year.
Further, the Company has established an information security risk management mechanism covering supply chain, and has set up supply chain management requirements in the Information Technology Budget and Procurement Management Measures of CITIC Securities and Network Security Management Rules of CITIC Securities. The procurement contract also stipulates the responsibility for data security of suppliers. The Company and suppliers sign Security Undertaking Letter, requiring suppliers to take effective technical measures to strengthen information security protection, establish network security emergency response mechanism, regularly conduct information security training and drills, and improve employees' information security awareness and skills. The Company has clarified the requirements for information security data security management of suppliers through the above means.
In the admission stage of suppliers, the admission evaluation of suppliers is carried out, and the enterprise qualifications and professional certificates are comprehensively evaluated; in the assessment stage, the Company conducts annual assessment and rating of suppliers; in the scoring process, the security team will deduct points from suppliers’ security ratings based on their security compliance performance, in order to urge suppliers to take on the responsibility of information security and privacy protection.
iv. Comprehensive Response Plan, Proactive and Reactive Measures for Data Security
In response to typical security incidents such as personal information leakage and data unavailability, the Company has formulated an Emergency Response Plan for cybersecurity incidents such as personal data breaches and data unavailability, which standardizes procedures for incident monitoring, fault locating, emergency response, root cause analysis, incident handling, follow-up optimization and reporting.
IV. Employee Training
The Company attaches great importance to the training and assessment of data security and privacy protection. Every year, all employees of the Company's headquarters, branches and subsidiaries shall receive training on network security and data security protection to enhance their awareness of security protection responsibility and enhance their basic skills in the fields of anti-phishing, anti-network attack and anti-data leakage capabilities.
At the same time, the Company conducts data security training for outsourced personnel in the information technology line every year. For seconded staff, the Company has clarified their network security, data security, confidentiality obligations and the use standards of confidentiality information through Information Security confidentiality Agreement, Notice on Information Security Operation of Third Party Personnel, Consent and Commitment on Information Security confidentiality Agreement and Notice on Information Security Operation of Third Party Personnel, etc., achieves 100% coverage of information technology outsourcing personnel.
V. Supervision and Incentive Mechanism
i. Information Security Audit
The Company conducts an annual external IT audit and a comprehensive IT audit every three years. The audit scope covers information technology governance, risk compliance management, information system security, operation and maintenance management, computer room management, data management, emergency management, information technology service organization management.
ii. Information Security Supervision Mechanism
The relevant senior executives of the Company take the responsibility of privacy and data security and supervise the personal information processing activities and the protective measures taken.
The Company adheres to the principle of "the data handler shall be held accountable" and clarifies the department responsible for personal information processing as the first person responsible for personal information processing.
iii. Safety Responsibility System
The Company strictly implements an information security responsibility system. Cybersecurity and data security accountability are incorporated into employee overall performance assessments. Relevant personnel shall be held accountable in the event of any security incident.
iv. Continuous Optimization
The Company establishes a customer feedback mechanism, collects information protection-related suggestions through customer service hotlines, suggestion boxes, and other channels, timely updates personal information protection clauses and regularly updates data security management systems, introduces advanced security technologies, and continuously improves protection capabilities.
