SlideShare a Scribd company logo
1 of 29
1
Personal Data Protection Act B.E. 2562
PDPA Compliance Preparation
LawPlus Webinar
LawPlus Ltd.
30th April 2020
The information provided in this document is general in nature and may not apply to any specific situation. Specific
advice should be sought before taking any action based on the information provided. Under no circumstances shall
LawPlus Ltd. or any of their directors, partners and lawyers be liable for any direct or indirect, incidental or consequential
loss or damage that results from the use of or the reliance upon the information contained in this document. Copyright
© 2020 LawPlus Ltd.
Presentation Topics
2
I. What are the key provisions of the PDPA and how
do they apply to our company?
II. How and when can our company collect, use and
disclose personal data of employees, customers,
suppliers and the public?
III. What can we do to reduce risks of failure to comply
with the PDPA and mitigate liabilities?
3
I. What are the key provisions of the
PDPA and how do they apply to our
company?
4
PDPA Overview
• Effective in part from 28th May
2019
• Effective in full from 27th May
2020
• No implementation rules has yet
been enacted.
• Chairman and 9 Expert
Committees of PDPC are being
selected.
Effective DatesKey Provisions
• Data Subject
• Personal Data Protection
Committee (“PDPC”)
• Office of the Personal Data
Protection Committee (“OPDPC”)
• Basis for Processing Personal Data
• Extraterritorial Applicability
• Data Protection Officer (“DPO”)
• Representative of Foreign Data
Controller
• Right of Data Subjects
• Liabilities
5
PDPA Authorities
PDPC
• The Permanent Secretary of
the Ministry of Digital and
Economy and Society
(“MDES”) is now acting as
Chairman of PDPC
• The Deputy Permanent
Secretary of the MDES is now
acting as the Secretary
General of PDPC
• Chairman and Secretary
General of PDPC will be
selected and appointed
OPDPC
• To be established within
27th May 2020
• Office of the Permanent
Secretary of the MDES is
now acting as OPDPC
Expert Committee
• To be appointed within
90 days after the
appointment of the
Chairman of PDPC
6
Within
27 May 2020
Start
27May2019
Appointment of Selection
Committee to select Chairman and
9 Expert Committees of PDPC
Cabinet establishes criteria for
selection of Chairman and 9
Expert Committees of PDPC
Selection and appointment of
Chairman and 9 Expert
Committees of PDPC
PDPC issues
implementation rules
PDPA Implementation Timeline
1 2 3 4
7
Key Parties
Data
Controller
Data Subject
and
Personal Data
Data
Processor
• a person / juristic person
• having the power and duties to make
decisions as to the collection, use, or
disclosure of Personal Data
• a person / juristic person
• who collects, uses, or discloses
Personal Data on behalf of a
Data Controller
• any information relating to a data subject
• enables the identification of data subject,
whether directly or indirectly
8
Key Relations
Data Subject
Data Controller
Data Processor
Expert Committee
Data Protection
Officer
OPDPC
PDPC
9
Types of Personal Data
Name
Address
Identification/Passport No.
Personal Phone No.
Bank / Credit cards
Personal Email address
IP Address
Cookies
Online Identifiers
PersonalData
Racial or Ethnic Origin
Political Opinions
Religious or Philosophical Beliefs
Sexual Orientation/Behaviour
Criminal Records
Health and Disability
Trade Union Membership
Genetic
Biometric
SensitiveData
any other data as prescribed by the PDPC
10
Businesses Which Are Subject to PDPA
• All businesses in Thailand regardless of
where collection, use, or disclosure
(process) of Personal Data takes place
• All businesses outside Thailand if the
collection, use, or disclosure of Personal
Data of data subjects who are in
Thailand with the following activities:
(1) the offering of goods or services to the
data subjects who are in Thailand,
irrespective of whether or not any
payment is made by the data subjects.
(2) the monitoring of the data subject’s
behavior, where the behavior takes
place in Thailand.
Extraterritorial Applicability
11
Rights of Data Subjects
Right to Be Notified - get information
what data is collected, how data is going to be
used (where stored, who will have access)
Right to Access Data
Right to Modify Data
Right to Transfer and Data Portability
Right to Delete Data
Right to Object and Withdraw Consent
12
Data Protection Officer and Representative
Duties of Data Protection Officer (DPO)
• advising Data Controller or Data Processor and their employees with
respect to any collection, use or disclosure of personal data;
• Reviewing the operation of Data Controller or Data Processor in
relation to their compliance with the PDPA;
• coordinating with the OPDPC; and
• maintaining the confidentiality of the Personal Data obtained.
• Data Controller or Data Processor who (1) engages in a business of
collecting, using or disclosing Sensitive Personal Data or (2) handles a
large amount of personal data to be prescribed by the PDPC must
appoint a DPO.
• Data Controller and Data Processor outside Thailand who collect, use or
disclose a number of personal data which include sensitive personal data
must appoint a local representative in Thailand without a limit of
liabilities.
Who Must Appoint a DPO?
Who Must Appoint a Representative?
13
Maximum Administrative Fines
If personal data is breached:
PDPA
FINES
OR
Data Controller
must report it to
the OPDPC within
hours
Face a fine up to
72 THB5 Million
14
II. How and when can our company
collect, use and disclose personal
data of employees, customers,
suppliers and the public?
15
Consent (Section 19)
Asking permission from data
subject
Contract (Section 24(3))
Required to fulfill contractual
obligations
Legal Obligations
(Section 24(6))
Required to establish, defend
and enforce legal rights
Vital Interest
(Section 24(2))
To save lives
Public Task
(Section 24(4))
Government work
Legitimate Interest
(Section 24(5))
Legitimate interests of Data
Controller outweigh privacy
rights of data subject
Basis for Processing Personal Data
16
• Any collection, use and disclosure of personal
data cannot be made without express consent of
the data subject.
• Consent for collection and use of personal data
may be at any time revoked.
• Consent may be given either in writing or by
electronic means.
Consent General
Consent – General Principles
17
1. contain the purpose of the collection, use or
disclosure;
2. be clearly distinguishable from other matters; and
3. be made in a clear and plain language that is easy to
understand and is not misleading to the data subject.
Request for Consent – Its Basic Requirements
Request for
Consent
must
18
Consent – Its Exceptions
Exceptions
of Consent
1. preventing harm to life or the
health of an individual
2. lawful activities of non-profit
organizations
3. preparing historical or statistical
documents for the public benefit
4. carrying out duties to benefit of
the public or to perform
functions as allocated by the
State
5. complying with contractual
obligations
6. complying with the PDPA,
other laws and public policy
objectives (health and
research)
7. establishing and enforcing
and upholding legal claims
8. protecting the legitimate
interests of the employer.
19
Mitigation of Risks – What Business Should Do
Mitigation
of Risks
1. compile information on how it
collects, uses and discloses
personal data, which requires
notice to data subjects
2. determine potential impacts on
the business if consent is
withdrawn
3. create a data retention policy for
various types of personal data
collected
4. create a data privacy policy
in line with the notice and
consent requirements
5. identify situations where
consent is required and
where exemptions may
apply
6. prepare and review its online
and offline consent request
to make it comply with
PDPA.
20
Basis for Processing Personal Data without Consent (Section 24)
Vital Interest
Contractual Obligation Legal Obligation / Public Task
• Employers transfer personal data of
employees internally for internal
administration.
• Businesses record CCTV footage of
visitors for security reason.
Legitimate Interest
• E-commerce businesses collect and use
names and addresses of customers to
deliver products to them.
• Hotels keep passport information of
customers for the Immigration Office.
• Employers disclose employees’ wages to
the Revenue Department and the Social
Security Office.
• Hospitals disclose patient record to
other hospital for emergency
treatment.
21
Limitations on Personal Data Collection, Use and
Disclosure
Purpose
Limitation
Any use of the collected
personal data outside the
notified purpose is prohibited.
Source
Limitation
Personal data can be
collected from data subject
only, except in certain
situations.
Proportionality
Limitation
Personal data can be
collected only in the amount
necessary to accomplish the
intended and lawful purpose
notified to the data subject.
22
III. What can we do to reduce risks
of failure to comply with the
PDPA and mitigate liabilities
23
Major Pitfalls to Avoid
Lack of legal documents required for PDPA
compliance
No clear understanding of where personal data
is kept or who owns it
Cannot identify legal basis for collection, use or
disclosure of personal data
No clear understanding of roles and obligations
of Data Controller and Data Processor
No PDPA compliance team, no DPO
24
ASSESSMENT & PLAN DETERMINATION MEASUREMENT
REVISION & CREATION IMPLEMENTATION TRAINING &
MAINTAINING
PDPA
Compliance
Existing Privacy Policy, Privacy Notice
and Consent Form should be
reviewed and revised. If no
compliance documents, they should
be prepared and ready to be used .
Revision and Creation of
Privacy Policy and Other
Compliance Documents
To determine and implement
technical and internal policy,
procedures and record
keeping
Data Management Process
and Operation System
Key members of the management
and the compliance team are
trained and advised about the PDPA
and its potential impacts on the
business.
Legal Advice &Training
To assess risk criteria, risk
level and to generate
suitable plan to comply with
the PDPA.
Risk Assessment &
Data Treatment Plan
To determine legal
basis and applicable
obligations
Legal Basis & Data
Analysis To locate, quantify and
categorize the existing
collected personal data
and the current personal
data flow.
Data Mapping
Major Measures to Do
25
Privacy Policy – Questions for Key Provisions
• What are the personal data collected and processed?
• Where is the source of the data?
• What are the purposes and legal basis for data collection and
processing?
• How to collect and process the data?
• How the data is stored and what is the data retention period?
• What are the rights of the data subject?
• How to contact the Data Controller, representative and DPO?
• What are data security measures?
26
Privacy Notice – Questions for Key Provisions
• What are the data collected and processed and how?
• Where is the source of the data?
• What are the purposes and legal basis for data collection and use?
• How the data is stored and what is the data retention period?
• What are the rights of the data subject?
• How to contact the Data Controller, representative and DPO?
• What are the polices on cookies?
• What are data security measures?
• What are the marketing activities?
27
The quick brown fox jumps over the lazy dog.
THB ≤ 500,000
Section 87
Offences in
relation to
Sensitive Data by
Data Controller
and Data
Processor.
Sections 83 & 86
Offences in
relation to core
duties of Data
Controller and
Data Processor to
Data Subjects.
Sections 82 &
85
Offences in
relation to duties
of Data Controller
and Data
Processor to
protect rights of
Data Subjects.
Section 89
Failure of a person
to comply with the
order of the PDPC
or to facilitate the
PDPA officials.
Major Administrative Fines
THB ≤ 1millionTHB ≤ 3millionTHB ≤ 5million
28
Q&A
kowit.somwaiya@lawplusltd.com
prasantaya.bantadtan@lawplusltd.com
usa.ua-areetham@lawplusltd.com
29
Unit 1401, 14th Floor, 990 Abdulrahim Place, Rama IV Road, Bangkok 10500, Thailand
Tel. +66 (0)2 636 0662, Fax +66 (0)2 636 0663
www.lawplusltd.com

More Related Content

What's hot

Data Protection Act 1998 (amended 2000)
Data Protection Act 1998 (amended 2000)Data Protection Act 1998 (amended 2000)
Data Protection Act 1998 (amended 2000)The Pathway Group
 
Pdpa presentation
Pdpa presentationPdpa presentation
Pdpa presentationAlan Teh
 
Urgensi RUU Perlindungan Data Pribadi
Urgensi RUU Perlindungan Data PribadiUrgensi RUU Perlindungan Data Pribadi
Urgensi RUU Perlindungan Data PribadiEryk Budi Pratama
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacylegalPadmin
 
GDPR training
GDPR training GDPR training
GDPR training ASL
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overviewJane Lambert
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysiakhenghoe
 
Privacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program ImplementationPrivacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program ImplementationEryk Budi Pratama
 
Tietosuojavaatimukset markkinointiviestinnässä
Tietosuojavaatimukset markkinointiviestinnässäTietosuojavaatimukset markkinointiviestinnässä
Tietosuojavaatimukset markkinointiviestinnässäHarto Pönkä
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochureJean Luc Creppy
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk- Mark - Fullbright
 

What's hot (20)

Data Protection Act 1998 (amended 2000)
Data Protection Act 1998 (amended 2000)Data Protection Act 1998 (amended 2000)
Data Protection Act 1998 (amended 2000)
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Pdpa presentation
Pdpa presentationPdpa presentation
Pdpa presentation
 
Urgensi RUU Perlindungan Data Pribadi
Urgensi RUU Perlindungan Data PribadiUrgensi RUU Perlindungan Data Pribadi
Urgensi RUU Perlindungan Data Pribadi
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data Privacy
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
18 Tips for Data Classification - Data Sheet by Secure Islands
18 Tips for Data Classification - Data Sheet by Secure Islands18 Tips for Data Classification - Data Sheet by Secure Islands
18 Tips for Data Classification - Data Sheet by Secure Islands
 
GDPR training
GDPR training GDPR training
GDPR training
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
GDPR
GDPRGDPR
GDPR
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
Privacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program ImplementationPrivacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program Implementation
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
DPDP Act 2023.pdf
DPDP Act 2023.pdfDPDP Act 2023.pdf
DPDP Act 2023.pdf
 
Tietosuojavaatimukset markkinointiviestinnässä
Tietosuojavaatimukset markkinointiviestinnässäTietosuojavaatimukset markkinointiviestinnässä
Tietosuojavaatimukset markkinointiviestinnässä
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 

Similar to PDPA Compliance Preparation LawPlus Webinar

General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsWSO2
 
Update on Laws and Practices 2020
Update on Laws and Practices 2020Update on Laws and Practices 2020
Update on Laws and Practices 2020LawPlus Ltd.
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
The 22nd Legal Forum Seminar (Nov 2021)
The 22nd Legal Forum Seminar (Nov 2021)The 22nd Legal Forum Seminar (Nov 2021)
The 22nd Legal Forum Seminar (Nov 2021)LawPlus Ltd.
 
Data protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quizData protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quizDeborahchiesa
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017CloudWATCH Consortium
 
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]TrustArc
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsUlf Mattsson
 
General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6 General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6 Jim Kaplan CIA CFE
 

Similar to PDPA Compliance Preparation LawPlus Webinar (20)

General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
Update on Laws and Practices 2020
Update on Laws and Practices 2020Update on Laws and Practices 2020
Update on Laws and Practices 2020
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
The 22nd Legal Forum Seminar (Nov 2021)
The 22nd Legal Forum Seminar (Nov 2021)The 22nd Legal Forum Seminar (Nov 2021)
The 22nd Legal Forum Seminar (Nov 2021)
 
Data protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quizData protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quiz
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
Pdpa2010 & GDPR (part 5)
Pdpa2010 & GDPR (part 5) Pdpa2010 & GDPR (part 5)
Pdpa2010 & GDPR (part 5)
 
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
 
General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6 General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6
 

More from LawPlus Ltd.

Z001.0909.fdi in thailand
Z001.0909.fdi in thailandZ001.0909.fdi in thailand
Z001.0909.fdi in thailandLawPlus Ltd.
 
Impacts of RCEP on Thailand Trade and FDI
Impacts of RCEP on Thailand Trade and FDIImpacts of RCEP on Thailand Trade and FDI
Impacts of RCEP on Thailand Trade and FDILawPlus Ltd.
 
PCT Refiling (Chinese Version)
PCT Refiling (Chinese Version)PCT Refiling (Chinese Version)
PCT Refiling (Chinese Version)LawPlus Ltd.
 
Filing PCT National Phase Patent Applications in Thailand
Filing PCT National Phase Patent Applications in ThailandFiling PCT National Phase Patent Applications in Thailand
Filing PCT National Phase Patent Applications in ThailandLawPlus Ltd.
 
Eelectronic Meeting Law
Eelectronic Meeting LawEelectronic Meeting Law
Eelectronic Meeting LawLawPlus Ltd.
 
FDI in Thailand Webinar
FDI in Thailand WebinarFDI in Thailand Webinar
FDI in Thailand WebinarLawPlus Ltd.
 
Z001.0724.E meeting Update
Z001.0724.E meeting UpdateZ001.0724.E meeting Update
Z001.0724.E meeting UpdateLawPlus Ltd.
 
Emergency Decree on Electronic Meetings B.E. 2563
Emergency Decree on Electronic Meetings B.E. 2563Emergency Decree on Electronic Meetings B.E. 2563
Emergency Decree on Electronic Meetings B.E. 2563LawPlus Ltd.
 
Overview of IP Laws
Overview of IP LawsOverview of IP Laws
Overview of IP LawsLawPlus Ltd.
 
Re-filing of Registered Trademarks in Myanmar
Re-filing of Registered Trademarks in MyanmarRe-filing of Registered Trademarks in Myanmar
Re-filing of Registered Trademarks in MyanmarLawPlus Ltd.
 
Update on Laws and Practices 2019
Update on Laws and Practices 2019Update on Laws and Practices 2019
Update on Laws and Practices 2019LawPlus Ltd.
 
Visa work Permit Laws Update
Visa work Permit Laws UpdateVisa work Permit Laws Update
Visa work Permit Laws UpdateLawPlus Ltd.
 
ICO.Digital asset business operation.final
ICO.Digital asset business operation.finalICO.Digital asset business operation.final
ICO.Digital asset business operation.finalLawPlus Ltd.
 
LDD.cross border m&a transactions
LDD.cross border m&a transactionsLDD.cross border m&a transactions
LDD.cross border m&a transactionsLawPlus Ltd.
 
Non-disclosure, Confidentiality and IP Ownership Issues in Company Work Rules
Non-disclosure, Confidentiality and IP Ownership Issues in Company Work RulesNon-disclosure, Confidentiality and IP Ownership Issues in Company Work Rules
Non-disclosure, Confidentiality and IP Ownership Issues in Company Work RulesLawPlus Ltd.
 
Protection of Trade Secrets in Manufacturing and Technology Transfer Agreements
Protection of Trade Secrets in Manufacturing and Technology Transfer AgreementsProtection of Trade Secrets in Manufacturing and Technology Transfer Agreements
Protection of Trade Secrets in Manufacturing and Technology Transfer AgreementsLawPlus Ltd.
 
Assignment and License of IP in Joint Venture and M&A Deals
Assignment and License of IP in Joint Venture and M&A DealsAssignment and License of IP in Joint Venture and M&A Deals
Assignment and License of IP in Joint Venture and M&A DealsLawPlus Ltd.
 
Enforcement of Trademarks, Patents and Copyrights
Enforcement of Trademarks, Patents and CopyrightsEnforcement of Trademarks, Patents and Copyrights
Enforcement of Trademarks, Patents and CopyrightsLawPlus Ltd.
 
Registration of Trademarks and Patents
Registration of Trademarks and PatentsRegistration of Trademarks and Patents
Registration of Trademarks and PatentsLawPlus Ltd.
 
Overview of Thailand Intellectual Property Law and Practice
Overview of Thailand Intellectual Property Law and PracticeOverview of Thailand Intellectual Property Law and Practice
Overview of Thailand Intellectual Property Law and PracticeLawPlus Ltd.
 

More from LawPlus Ltd. (20)

Z001.0909.fdi in thailand
Z001.0909.fdi in thailandZ001.0909.fdi in thailand
Z001.0909.fdi in thailand
 
Impacts of RCEP on Thailand Trade and FDI
Impacts of RCEP on Thailand Trade and FDIImpacts of RCEP on Thailand Trade and FDI
Impacts of RCEP on Thailand Trade and FDI
 
PCT Refiling (Chinese Version)
PCT Refiling (Chinese Version)PCT Refiling (Chinese Version)
PCT Refiling (Chinese Version)
 
Filing PCT National Phase Patent Applications in Thailand
Filing PCT National Phase Patent Applications in ThailandFiling PCT National Phase Patent Applications in Thailand
Filing PCT National Phase Patent Applications in Thailand
 
Eelectronic Meeting Law
Eelectronic Meeting LawEelectronic Meeting Law
Eelectronic Meeting Law
 
FDI in Thailand Webinar
FDI in Thailand WebinarFDI in Thailand Webinar
FDI in Thailand Webinar
 
Z001.0724.E meeting Update
Z001.0724.E meeting UpdateZ001.0724.E meeting Update
Z001.0724.E meeting Update
 
Emergency Decree on Electronic Meetings B.E. 2563
Emergency Decree on Electronic Meetings B.E. 2563Emergency Decree on Electronic Meetings B.E. 2563
Emergency Decree on Electronic Meetings B.E. 2563
 
Overview of IP Laws
Overview of IP LawsOverview of IP Laws
Overview of IP Laws
 
Re-filing of Registered Trademarks in Myanmar
Re-filing of Registered Trademarks in MyanmarRe-filing of Registered Trademarks in Myanmar
Re-filing of Registered Trademarks in Myanmar
 
Update on Laws and Practices 2019
Update on Laws and Practices 2019Update on Laws and Practices 2019
Update on Laws and Practices 2019
 
Visa work Permit Laws Update
Visa work Permit Laws UpdateVisa work Permit Laws Update
Visa work Permit Laws Update
 
ICO.Digital asset business operation.final
ICO.Digital asset business operation.finalICO.Digital asset business operation.final
ICO.Digital asset business operation.final
 
LDD.cross border m&a transactions
LDD.cross border m&a transactionsLDD.cross border m&a transactions
LDD.cross border m&a transactions
 
Non-disclosure, Confidentiality and IP Ownership Issues in Company Work Rules
Non-disclosure, Confidentiality and IP Ownership Issues in Company Work RulesNon-disclosure, Confidentiality and IP Ownership Issues in Company Work Rules
Non-disclosure, Confidentiality and IP Ownership Issues in Company Work Rules
 
Protection of Trade Secrets in Manufacturing and Technology Transfer Agreements
Protection of Trade Secrets in Manufacturing and Technology Transfer AgreementsProtection of Trade Secrets in Manufacturing and Technology Transfer Agreements
Protection of Trade Secrets in Manufacturing and Technology Transfer Agreements
 
Assignment and License of IP in Joint Venture and M&A Deals
Assignment and License of IP in Joint Venture and M&A DealsAssignment and License of IP in Joint Venture and M&A Deals
Assignment and License of IP in Joint Venture and M&A Deals
 
Enforcement of Trademarks, Patents and Copyrights
Enforcement of Trademarks, Patents and CopyrightsEnforcement of Trademarks, Patents and Copyrights
Enforcement of Trademarks, Patents and Copyrights
 
Registration of Trademarks and Patents
Registration of Trademarks and PatentsRegistration of Trademarks and Patents
Registration of Trademarks and Patents
 
Overview of Thailand Intellectual Property Law and Practice
Overview of Thailand Intellectual Property Law and PracticeOverview of Thailand Intellectual Property Law and Practice
Overview of Thailand Intellectual Property Law and Practice
 

Recently uploaded

Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesHome Tax Saver
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书Fir L
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书Fs Las
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书Fir sss
 
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书SD DS
 
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一jr6r07mb
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionNilamPadekar1
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书FS LS
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书Fir L
 
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一st Las
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》o8wvnojp
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书SD DS
 
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSVIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSDr. Oliver Massmann
 
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxsrikarna235
 
Rights of under-trial Prisoners in India
Rights of under-trial Prisoners in IndiaRights of under-trial Prisoners in India
Rights of under-trial Prisoners in IndiaAbheet Mangleek
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A HistoryJohn Hustaix
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书Fir L
 
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书SD DS
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝soniya singh
 

Recently uploaded (20)

Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax Rates
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
 
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 sedition
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书
 
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
 
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSVIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
 
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
 
Rights of under-trial Prisoners in India
Rights of under-trial Prisoners in IndiaRights of under-trial Prisoners in India
Rights of under-trial Prisoners in India
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A History
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
 
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
 

PDPA Compliance Preparation LawPlus Webinar

  • 1. 1 Personal Data Protection Act B.E. 2562 PDPA Compliance Preparation LawPlus Webinar LawPlus Ltd. 30th April 2020 The information provided in this document is general in nature and may not apply to any specific situation. Specific advice should be sought before taking any action based on the information provided. Under no circumstances shall LawPlus Ltd. or any of their directors, partners and lawyers be liable for any direct or indirect, incidental or consequential loss or damage that results from the use of or the reliance upon the information contained in this document. Copyright © 2020 LawPlus Ltd.
  • 2. Presentation Topics 2 I. What are the key provisions of the PDPA and how do they apply to our company? II. How and when can our company collect, use and disclose personal data of employees, customers, suppliers and the public? III. What can we do to reduce risks of failure to comply with the PDPA and mitigate liabilities?
  • 3. 3 I. What are the key provisions of the PDPA and how do they apply to our company?
  • 4. 4 PDPA Overview • Effective in part from 28th May 2019 • Effective in full from 27th May 2020 • No implementation rules has yet been enacted. • Chairman and 9 Expert Committees of PDPC are being selected. Effective DatesKey Provisions • Data Subject • Personal Data Protection Committee (“PDPC”) • Office of the Personal Data Protection Committee (“OPDPC”) • Basis for Processing Personal Data • Extraterritorial Applicability • Data Protection Officer (“DPO”) • Representative of Foreign Data Controller • Right of Data Subjects • Liabilities
  • 5. 5 PDPA Authorities PDPC • The Permanent Secretary of the Ministry of Digital and Economy and Society (“MDES”) is now acting as Chairman of PDPC • The Deputy Permanent Secretary of the MDES is now acting as the Secretary General of PDPC • Chairman and Secretary General of PDPC will be selected and appointed OPDPC • To be established within 27th May 2020 • Office of the Permanent Secretary of the MDES is now acting as OPDPC Expert Committee • To be appointed within 90 days after the appointment of the Chairman of PDPC
  • 6. 6 Within 27 May 2020 Start 27May2019 Appointment of Selection Committee to select Chairman and 9 Expert Committees of PDPC Cabinet establishes criteria for selection of Chairman and 9 Expert Committees of PDPC Selection and appointment of Chairman and 9 Expert Committees of PDPC PDPC issues implementation rules PDPA Implementation Timeline 1 2 3 4
  • 7. 7 Key Parties Data Controller Data Subject and Personal Data Data Processor • a person / juristic person • having the power and duties to make decisions as to the collection, use, or disclosure of Personal Data • a person / juristic person • who collects, uses, or discloses Personal Data on behalf of a Data Controller • any information relating to a data subject • enables the identification of data subject, whether directly or indirectly
  • 8. 8 Key Relations Data Subject Data Controller Data Processor Expert Committee Data Protection Officer OPDPC PDPC
  • 9. 9 Types of Personal Data Name Address Identification/Passport No. Personal Phone No. Bank / Credit cards Personal Email address IP Address Cookies Online Identifiers PersonalData Racial or Ethnic Origin Political Opinions Religious or Philosophical Beliefs Sexual Orientation/Behaviour Criminal Records Health and Disability Trade Union Membership Genetic Biometric SensitiveData any other data as prescribed by the PDPC
  • 10. 10 Businesses Which Are Subject to PDPA • All businesses in Thailand regardless of where collection, use, or disclosure (process) of Personal Data takes place • All businesses outside Thailand if the collection, use, or disclosure of Personal Data of data subjects who are in Thailand with the following activities: (1) the offering of goods or services to the data subjects who are in Thailand, irrespective of whether or not any payment is made by the data subjects. (2) the monitoring of the data subject’s behavior, where the behavior takes place in Thailand. Extraterritorial Applicability
  • 11. 11 Rights of Data Subjects Right to Be Notified - get information what data is collected, how data is going to be used (where stored, who will have access) Right to Access Data Right to Modify Data Right to Transfer and Data Portability Right to Delete Data Right to Object and Withdraw Consent
  • 12. 12 Data Protection Officer and Representative Duties of Data Protection Officer (DPO) • advising Data Controller or Data Processor and their employees with respect to any collection, use or disclosure of personal data; • Reviewing the operation of Data Controller or Data Processor in relation to their compliance with the PDPA; • coordinating with the OPDPC; and • maintaining the confidentiality of the Personal Data obtained. • Data Controller or Data Processor who (1) engages in a business of collecting, using or disclosing Sensitive Personal Data or (2) handles a large amount of personal data to be prescribed by the PDPC must appoint a DPO. • Data Controller and Data Processor outside Thailand who collect, use or disclose a number of personal data which include sensitive personal data must appoint a local representative in Thailand without a limit of liabilities. Who Must Appoint a DPO? Who Must Appoint a Representative?
  • 13. 13 Maximum Administrative Fines If personal data is breached: PDPA FINES OR Data Controller must report it to the OPDPC within hours Face a fine up to 72 THB5 Million
  • 14. 14 II. How and when can our company collect, use and disclose personal data of employees, customers, suppliers and the public?
  • 15. 15 Consent (Section 19) Asking permission from data subject Contract (Section 24(3)) Required to fulfill contractual obligations Legal Obligations (Section 24(6)) Required to establish, defend and enforce legal rights Vital Interest (Section 24(2)) To save lives Public Task (Section 24(4)) Government work Legitimate Interest (Section 24(5)) Legitimate interests of Data Controller outweigh privacy rights of data subject Basis for Processing Personal Data
  • 16. 16 • Any collection, use and disclosure of personal data cannot be made without express consent of the data subject. • Consent for collection and use of personal data may be at any time revoked. • Consent may be given either in writing or by electronic means. Consent General Consent – General Principles
  • 17. 17 1. contain the purpose of the collection, use or disclosure; 2. be clearly distinguishable from other matters; and 3. be made in a clear and plain language that is easy to understand and is not misleading to the data subject. Request for Consent – Its Basic Requirements Request for Consent must
  • 18. 18 Consent – Its Exceptions Exceptions of Consent 1. preventing harm to life or the health of an individual 2. lawful activities of non-profit organizations 3. preparing historical or statistical documents for the public benefit 4. carrying out duties to benefit of the public or to perform functions as allocated by the State 5. complying with contractual obligations 6. complying with the PDPA, other laws and public policy objectives (health and research) 7. establishing and enforcing and upholding legal claims 8. protecting the legitimate interests of the employer.
  • 19. 19 Mitigation of Risks – What Business Should Do Mitigation of Risks 1. compile information on how it collects, uses and discloses personal data, which requires notice to data subjects 2. determine potential impacts on the business if consent is withdrawn 3. create a data retention policy for various types of personal data collected 4. create a data privacy policy in line with the notice and consent requirements 5. identify situations where consent is required and where exemptions may apply 6. prepare and review its online and offline consent request to make it comply with PDPA.
  • 20. 20 Basis for Processing Personal Data without Consent (Section 24) Vital Interest Contractual Obligation Legal Obligation / Public Task • Employers transfer personal data of employees internally for internal administration. • Businesses record CCTV footage of visitors for security reason. Legitimate Interest • E-commerce businesses collect and use names and addresses of customers to deliver products to them. • Hotels keep passport information of customers for the Immigration Office. • Employers disclose employees’ wages to the Revenue Department and the Social Security Office. • Hospitals disclose patient record to other hospital for emergency treatment.
  • 21. 21 Limitations on Personal Data Collection, Use and Disclosure Purpose Limitation Any use of the collected personal data outside the notified purpose is prohibited. Source Limitation Personal data can be collected from data subject only, except in certain situations. Proportionality Limitation Personal data can be collected only in the amount necessary to accomplish the intended and lawful purpose notified to the data subject.
  • 22. 22 III. What can we do to reduce risks of failure to comply with the PDPA and mitigate liabilities
  • 23. 23 Major Pitfalls to Avoid Lack of legal documents required for PDPA compliance No clear understanding of where personal data is kept or who owns it Cannot identify legal basis for collection, use or disclosure of personal data No clear understanding of roles and obligations of Data Controller and Data Processor No PDPA compliance team, no DPO
  • 24. 24 ASSESSMENT & PLAN DETERMINATION MEASUREMENT REVISION & CREATION IMPLEMENTATION TRAINING & MAINTAINING PDPA Compliance Existing Privacy Policy, Privacy Notice and Consent Form should be reviewed and revised. If no compliance documents, they should be prepared and ready to be used . Revision and Creation of Privacy Policy and Other Compliance Documents To determine and implement technical and internal policy, procedures and record keeping Data Management Process and Operation System Key members of the management and the compliance team are trained and advised about the PDPA and its potential impacts on the business. Legal Advice &Training To assess risk criteria, risk level and to generate suitable plan to comply with the PDPA. Risk Assessment & Data Treatment Plan To determine legal basis and applicable obligations Legal Basis & Data Analysis To locate, quantify and categorize the existing collected personal data and the current personal data flow. Data Mapping Major Measures to Do
  • 25. 25 Privacy Policy – Questions for Key Provisions • What are the personal data collected and processed? • Where is the source of the data? • What are the purposes and legal basis for data collection and processing? • How to collect and process the data? • How the data is stored and what is the data retention period? • What are the rights of the data subject? • How to contact the Data Controller, representative and DPO? • What are data security measures?
  • 26. 26 Privacy Notice – Questions for Key Provisions • What are the data collected and processed and how? • Where is the source of the data? • What are the purposes and legal basis for data collection and use? • How the data is stored and what is the data retention period? • What are the rights of the data subject? • How to contact the Data Controller, representative and DPO? • What are the polices on cookies? • What are data security measures? • What are the marketing activities?
  • 27. 27 The quick brown fox jumps over the lazy dog. THB ≤ 500,000 Section 87 Offences in relation to Sensitive Data by Data Controller and Data Processor. Sections 83 & 86 Offences in relation to core duties of Data Controller and Data Processor to Data Subjects. Sections 82 & 85 Offences in relation to duties of Data Controller and Data Processor to protect rights of Data Subjects. Section 89 Failure of a person to comply with the order of the PDPC or to facilitate the PDPA officials. Major Administrative Fines THB ≤ 1millionTHB ≤ 3millionTHB ≤ 5million
  • 29. 29 Unit 1401, 14th Floor, 990 Abdulrahim Place, Rama IV Road, Bangkok 10500, Thailand Tel. +66 (0)2 636 0662, Fax +66 (0)2 636 0663 www.lawplusltd.com