SlideShare a Scribd company logo
1 of 29
1
Personal Data Protection Act B.E. 2562
PDPA Compliance Preparation
LawPlus Webinar
LawPlus Ltd.
30th April 2020
The information provided in this document is general in nature and may not apply to any specific situation. Specific
advice should be sought before taking any action based on the information provided. Under no circumstances shall
LawPlus Ltd. or any of their directors, partners and lawyers be liable for any direct or indirect, incidental or consequential
loss or damage that results from the use of or the reliance upon the information contained in this document. Copyright
© 2020 LawPlus Ltd.
Presentation Topics
2
I. What are the key provisions of the PDPA and how
do they apply to our company?
II. How and when can our company collect, use and
disclose personal data of employees, customers,
suppliers and the public?
III. What can we do to reduce risks of failure to comply
with the PDPA and mitigate liabilities?
3
I. What are the key provisions of the
PDPA and how do they apply to our
company?
4
PDPA Overview
• Effective in part from 28th May
2019
• Effective in full from 27th May
2020
• No implementation rules has yet
been enacted.
• Chairman and 9 Expert
Committees of PDPC are being
selected.
Effective DatesKey Provisions
• Data Subject
• Personal Data Protection
Committee (“PDPC”)
• Office of the Personal Data
Protection Committee (“OPDPC”)
• Basis for Processing Personal Data
• Extraterritorial Applicability
• Data Protection Officer (“DPO”)
• Representative of Foreign Data
Controller
• Right of Data Subjects
• Liabilities
5
PDPA Authorities
PDPC
• The Permanent Secretary of
the Ministry of Digital and
Economy and Society
(“MDES”) is now acting as
Chairman of PDPC
• The Deputy Permanent
Secretary of the MDES is now
acting as the Secretary
General of PDPC
• Chairman and Secretary
General of PDPC will be
selected and appointed
OPDPC
• To be established within
27th May 2020
• Office of the Permanent
Secretary of the MDES is
now acting as OPDPC
Expert Committee
• To be appointed within
90 days after the
appointment of the
Chairman of PDPC
6
Within
27 May 2020
Start
27May2019
Appointment of Selection
Committee to select Chairman and
9 Expert Committees of PDPC
Cabinet establishes criteria for
selection of Chairman and 9
Expert Committees of PDPC
Selection and appointment of
Chairman and 9 Expert
Committees of PDPC
PDPC issues
implementation rules
PDPA Implementation Timeline
1 2 3 4
7
Key Parties
Data
Controller
Data Subject
and
Personal Data
Data
Processor
• a person / juristic person
• having the power and duties to make
decisions as to the collection, use, or
disclosure of Personal Data
• a person / juristic person
• who collects, uses, or discloses
Personal Data on behalf of a
Data Controller
• any information relating to a data subject
• enables the identification of data subject,
whether directly or indirectly
8
Key Relations
Data Subject
Data Controller
Data Processor
Expert Committee
Data Protection
Officer
OPDPC
PDPC
9
Types of Personal Data
Name
Address
Identification/Passport No.
Personal Phone No.
Bank / Credit cards
Personal Email address
IP Address
Cookies
Online Identifiers
PersonalData
Racial or Ethnic Origin
Political Opinions
Religious or Philosophical Beliefs
Sexual Orientation/Behaviour
Criminal Records
Health and Disability
Trade Union Membership
Genetic
Biometric
SensitiveData
any other data as prescribed by the PDPC
10
Businesses Which Are Subject to PDPA
• All businesses in Thailand regardless of
where collection, use, or disclosure
(process) of Personal Data takes place
• All businesses outside Thailand if the
collection, use, or disclosure of Personal
Data of data subjects who are in
Thailand with the following activities:
(1) the offering of goods or services to the
data subjects who are in Thailand,
irrespective of whether or not any
payment is made by the data subjects.
(2) the monitoring of the data subject’s
behavior, where the behavior takes
place in Thailand.
Extraterritorial Applicability
11
Rights of Data Subjects
Right to Be Notified - get information
what data is collected, how data is going to be
used (where stored, who will have access)
Right to Access Data
Right to Modify Data
Right to Transfer and Data Portability
Right to Delete Data
Right to Object and Withdraw Consent
12
Data Protection Officer and Representative
Duties of Data Protection Officer (DPO)
• advising Data Controller or Data Processor and their employees with
respect to any collection, use or disclosure of personal data;
• Reviewing the operation of Data Controller or Data Processor in
relation to their compliance with the PDPA;
• coordinating with the OPDPC; and
• maintaining the confidentiality of the Personal Data obtained.
• Data Controller or Data Processor who (1) engages in a business of
collecting, using or disclosing Sensitive Personal Data or (2) handles a
large amount of personal data to be prescribed by the PDPC must
appoint a DPO.
• Data Controller and Data Processor outside Thailand who collect, use or
disclose a number of personal data which include sensitive personal data
must appoint a local representative in Thailand without a limit of
liabilities.
Who Must Appoint a DPO?
Who Must Appoint a Representative?
13
Maximum Administrative Fines
If personal data is breached:
PDPA
FINES
OR
Data Controller
must report it to
the OPDPC within
hours
Face a fine up to
72 THB5 Million
14
II. How and when can our company
collect, use and disclose personal
data of employees, customers,
suppliers and the public?
15
Consent (Section 19)
Asking permission from data
subject
Contract (Section 24(3))
Required to fulfill contractual
obligations
Legal Obligations
(Section 24(6))
Required to establish, defend
and enforce legal rights
Vital Interest
(Section 24(2))
To save lives
Public Task
(Section 24(4))
Government work
Legitimate Interest
(Section 24(5))
Legitimate interests of Data
Controller outweigh privacy
rights of data subject
Basis for Processing Personal Data
16
• Any collection, use and disclosure of personal
data cannot be made without express consent of
the data subject.
• Consent for collection and use of personal data
may be at any time revoked.
• Consent may be given either in writing or by
electronic means.
Consent General
Consent – General Principles
17
1. contain the purpose of the collection, use or
disclosure;
2. be clearly distinguishable from other matters; and
3. be made in a clear and plain language that is easy to
understand and is not misleading to the data subject.
Request for Consent – Its Basic Requirements
Request for
Consent
must
18
Consent – Its Exceptions
Exceptions
of Consent
1. preventing harm to life or the
health of an individual
2. lawful activities of non-profit
organizations
3. preparing historical or statistical
documents for the public benefit
4. carrying out duties to benefit of
the public or to perform
functions as allocated by the
State
5. complying with contractual
obligations
6. complying with the PDPA,
other laws and public policy
objectives (health and
research)
7. establishing and enforcing
and upholding legal claims
8. protecting the legitimate
interests of the employer.
19
Mitigation of Risks – What Business Should Do
Mitigation
of Risks
1. compile information on how it
collects, uses and discloses
personal data, which requires
notice to data subjects
2. determine potential impacts on
the business if consent is
withdrawn
3. create a data retention policy for
various types of personal data
collected
4. create a data privacy policy
in line with the notice and
consent requirements
5. identify situations where
consent is required and
where exemptions may
apply
6. prepare and review its online
and offline consent request
to make it comply with
PDPA.
20
Basis for Processing Personal Data without Consent (Section 24)
Vital Interest
Contractual Obligation Legal Obligation / Public Task
• Employers transfer personal data of
employees internally for internal
administration.
• Businesses record CCTV footage of
visitors for security reason.
Legitimate Interest
• E-commerce businesses collect and use
names and addresses of customers to
deliver products to them.
• Hotels keep passport information of
customers for the Immigration Office.
• Employers disclose employees’ wages to
the Revenue Department and the Social
Security Office.
• Hospitals disclose patient record to
other hospital for emergency
treatment.
21
Limitations on Personal Data Collection, Use and
Disclosure
Purpose
Limitation
Any use of the collected
personal data outside the
notified purpose is prohibited.
Source
Limitation
Personal data can be
collected from data subject
only, except in certain
situations.
Proportionality
Limitation
Personal data can be
collected only in the amount
necessary to accomplish the
intended and lawful purpose
notified to the data subject.
22
III. What can we do to reduce risks
of failure to comply with the
PDPA and mitigate liabilities
23
Major Pitfalls to Avoid
Lack of legal documents required for PDPA
compliance
No clear understanding of where personal data
is kept or who owns it
Cannot identify legal basis for collection, use or
disclosure of personal data
No clear understanding of roles and obligations
of Data Controller and Data Processor
No PDPA compliance team, no DPO
24
ASSESSMENT & PLAN DETERMINATION MEASUREMENT
REVISION & CREATION IMPLEMENTATION TRAINING &
MAINTAINING
PDPA
Compliance
Existing Privacy Policy, Privacy Notice
and Consent Form should be
reviewed and revised. If no
compliance documents, they should
be prepared and ready to be used .
Revision and Creation of
Privacy Policy and Other
Compliance Documents
To determine and implement
technical and internal policy,
procedures and record
keeping
Data Management Process
and Operation System
Key members of the management
and the compliance team are
trained and advised about the PDPA
and its potential impacts on the
business.
Legal Advice &Training
To assess risk criteria, risk
level and to generate
suitable plan to comply with
the PDPA.
Risk Assessment &
Data Treatment Plan
To determine legal
basis and applicable
obligations
Legal Basis & Data
Analysis To locate, quantify and
categorize the existing
collected personal data
and the current personal
data flow.
Data Mapping
Major Measures to Do
25
Privacy Policy – Questions for Key Provisions
• What are the personal data collected and processed?
• Where is the source of the data?
• What are the purposes and legal basis for data collection and
processing?
• How to collect and process the data?
• How the data is stored and what is the data retention period?
• What are the rights of the data subject?
• How to contact the Data Controller, representative and DPO?
• What are data security measures?
26
Privacy Notice – Questions for Key Provisions
• What are the data collected and processed and how?
• Where is the source of the data?
• What are the purposes and legal basis for data collection and use?
• How the data is stored and what is the data retention period?
• What are the rights of the data subject?
• How to contact the Data Controller, representative and DPO?
• What are the polices on cookies?
• What are data security measures?
• What are the marketing activities?
27
The quick brown fox jumps over the lazy dog.
THB ≤ 500,000
Section 87
Offences in
relation to
Sensitive Data by
Data Controller
and Data
Processor.
Sections 83 & 86
Offences in
relation to core
duties of Data
Controller and
Data Processor to
Data Subjects.
Sections 82 &
85
Offences in
relation to duties
of Data Controller
and Data
Processor to
protect rights of
Data Subjects.
Section 89
Failure of a person
to comply with the
order of the PDPC
or to facilitate the
PDPA officials.
Major Administrative Fines
THB ≤ 1millionTHB ≤ 3millionTHB ≤ 5million
28
Q&A
kowit.somwaiya@lawplusltd.com
prasantaya.bantadtan@lawplusltd.com
usa.ua-areetham@lawplusltd.com
29
Unit 1401, 14th Floor, 990 Abdulrahim Place, Rama IV Road, Bangkok 10500, Thailand
Tel. +66 (0)2 636 0662, Fax +66 (0)2 636 0663
www.lawplusltd.com

More Related Content

What's hot

What's hot (20)

Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protection
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
 
GDPR
GDPRGDPR
GDPR
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
GDPR infographic
GDPR infographicGDPR infographic
GDPR infographic
 
Pdpa(kewal)
Pdpa(kewal)Pdpa(kewal)
Pdpa(kewal)
 
Data protection ppt
Data protection pptData protection ppt
Data protection ppt
 
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
 
GDPR: Data Breach Notification and Communications
GDPR: Data Breach Notification and CommunicationsGDPR: Data Breach Notification and Communications
GDPR: Data Breach Notification and Communications
 
China's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 DaysChina's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 Days
 

Similar to PDPA Compliance Preparation

Data protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quizData protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quiz
Deborahchiesa
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
Ulf Mattsson
 

Similar to PDPA Compliance Preparation (20)

General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
Update on Laws and Practices 2020
Update on Laws and Practices 2020Update on Laws and Practices 2020
Update on Laws and Practices 2020
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
The 22nd Legal Forum Seminar (Nov 2021)
The 22nd Legal Forum Seminar (Nov 2021)The 22nd Legal Forum Seminar (Nov 2021)
The 22nd Legal Forum Seminar (Nov 2021)
 
Data protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quizData protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quiz
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
Pdpa2010 & GDPR (part 5)
Pdpa2010 & GDPR (part 5) Pdpa2010 & GDPR (part 5)
Pdpa2010 & GDPR (part 5)
 
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
 
General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6 General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6
 

More from LawPlus Ltd.

ICO.Digital asset business operation.final
ICO.Digital asset business operation.finalICO.Digital asset business operation.final
ICO.Digital asset business operation.final
LawPlus Ltd.
 

More from LawPlus Ltd. (20)

Z001.0909.fdi in thailand
Z001.0909.fdi in thailandZ001.0909.fdi in thailand
Z001.0909.fdi in thailand
 
Impacts of RCEP on Thailand Trade and FDI
Impacts of RCEP on Thailand Trade and FDIImpacts of RCEP on Thailand Trade and FDI
Impacts of RCEP on Thailand Trade and FDI
 
PCT Refiling (Chinese Version)
PCT Refiling (Chinese Version)PCT Refiling (Chinese Version)
PCT Refiling (Chinese Version)
 
Filing PCT National Phase Patent Applications in Thailand
Filing PCT National Phase Patent Applications in ThailandFiling PCT National Phase Patent Applications in Thailand
Filing PCT National Phase Patent Applications in Thailand
 
Eelectronic Meeting Law
Eelectronic Meeting LawEelectronic Meeting Law
Eelectronic Meeting Law
 
FDI in Thailand Webinar
FDI in Thailand WebinarFDI in Thailand Webinar
FDI in Thailand Webinar
 
Z001.0724.E meeting Update
Z001.0724.E meeting UpdateZ001.0724.E meeting Update
Z001.0724.E meeting Update
 
Emergency Decree on Electronic Meetings B.E. 2563
Emergency Decree on Electronic Meetings B.E. 2563Emergency Decree on Electronic Meetings B.E. 2563
Emergency Decree on Electronic Meetings B.E. 2563
 
Overview of IP Laws
Overview of IP LawsOverview of IP Laws
Overview of IP Laws
 
Re-filing of Registered Trademarks in Myanmar
Re-filing of Registered Trademarks in MyanmarRe-filing of Registered Trademarks in Myanmar
Re-filing of Registered Trademarks in Myanmar
 
Update on Laws and Practices 2019
Update on Laws and Practices 2019Update on Laws and Practices 2019
Update on Laws and Practices 2019
 
Visa work Permit Laws Update
Visa work Permit Laws UpdateVisa work Permit Laws Update
Visa work Permit Laws Update
 
ICO.Digital asset business operation.final
ICO.Digital asset business operation.finalICO.Digital asset business operation.final
ICO.Digital asset business operation.final
 
LDD.cross border m&a transactions
LDD.cross border m&a transactionsLDD.cross border m&a transactions
LDD.cross border m&a transactions
 
Non-disclosure, Confidentiality and IP Ownership Issues in Company Work Rules
Non-disclosure, Confidentiality and IP Ownership Issues in Company Work RulesNon-disclosure, Confidentiality and IP Ownership Issues in Company Work Rules
Non-disclosure, Confidentiality and IP Ownership Issues in Company Work Rules
 
Protection of Trade Secrets in Manufacturing and Technology Transfer Agreements
Protection of Trade Secrets in Manufacturing and Technology Transfer AgreementsProtection of Trade Secrets in Manufacturing and Technology Transfer Agreements
Protection of Trade Secrets in Manufacturing and Technology Transfer Agreements
 
Assignment and License of IP in Joint Venture and M&A Deals
Assignment and License of IP in Joint Venture and M&A DealsAssignment and License of IP in Joint Venture and M&A Deals
Assignment and License of IP in Joint Venture and M&A Deals
 
Enforcement of Trademarks, Patents and Copyrights
Enforcement of Trademarks, Patents and CopyrightsEnforcement of Trademarks, Patents and Copyrights
Enforcement of Trademarks, Patents and Copyrights
 
Registration of Trademarks and Patents
Registration of Trademarks and PatentsRegistration of Trademarks and Patents
Registration of Trademarks and Patents
 
Overview of Thailand Intellectual Property Law and Practice
Overview of Thailand Intellectual Property Law and PracticeOverview of Thailand Intellectual Property Law and Practice
Overview of Thailand Intellectual Property Law and Practice
 

Recently uploaded

Contract law. Indemnity
Contract law.                     IndemnityContract law.                     Indemnity
Contract law. Indemnity
mahikaanand16
 
一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理
Airst S
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
Airst S
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
MollyBrown86
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
Airst S
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
RRR Chambers
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
ShashankKumar441258
 
一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理
Airst S
 

Recently uploaded (20)

Contract law. Indemnity
Contract law.                     IndemnityContract law.                     Indemnity
Contract law. Indemnity
 
一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx
 
Police Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. SteeringPolice Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. Steering
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
 
Relationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfRelationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdf
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
 
ARTICLE 370 PDF about the indian constitution.
ARTICLE 370 PDF about the  indian constitution.ARTICLE 370 PDF about the  indian constitution.
ARTICLE 370 PDF about the indian constitution.
 
Jim Eiberger Redacted Copy Of Tenant Lease.pdf
Jim Eiberger Redacted Copy Of Tenant Lease.pdfJim Eiberger Redacted Copy Of Tenant Lease.pdf
Jim Eiberger Redacted Copy Of Tenant Lease.pdf
 
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptxMunicipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
 
Clarifying Land Donation Issues Memo for
Clarifying Land Donation Issues Memo forClarifying Land Donation Issues Memo for
Clarifying Land Donation Issues Memo for
 
一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理
 
Performance of contract-1 law presentation
Performance of contract-1 law presentationPerformance of contract-1 law presentation
Performance of contract-1 law presentation
 
3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt
 
Hely-Hutchinson v. Brayhead Ltd .pdf
Hely-Hutchinson v. Brayhead Ltd         .pdfHely-Hutchinson v. Brayhead Ltd         .pdf
Hely-Hutchinson v. Brayhead Ltd .pdf
 

PDPA Compliance Preparation

  • 1. 1 Personal Data Protection Act B.E. 2562 PDPA Compliance Preparation LawPlus Webinar LawPlus Ltd. 30th April 2020 The information provided in this document is general in nature and may not apply to any specific situation. Specific advice should be sought before taking any action based on the information provided. Under no circumstances shall LawPlus Ltd. or any of their directors, partners and lawyers be liable for any direct or indirect, incidental or consequential loss or damage that results from the use of or the reliance upon the information contained in this document. Copyright © 2020 LawPlus Ltd.
  • 2. Presentation Topics 2 I. What are the key provisions of the PDPA and how do they apply to our company? II. How and when can our company collect, use and disclose personal data of employees, customers, suppliers and the public? III. What can we do to reduce risks of failure to comply with the PDPA and mitigate liabilities?
  • 3. 3 I. What are the key provisions of the PDPA and how do they apply to our company?
  • 4. 4 PDPA Overview • Effective in part from 28th May 2019 • Effective in full from 27th May 2020 • No implementation rules has yet been enacted. • Chairman and 9 Expert Committees of PDPC are being selected. Effective DatesKey Provisions • Data Subject • Personal Data Protection Committee (“PDPC”) • Office of the Personal Data Protection Committee (“OPDPC”) • Basis for Processing Personal Data • Extraterritorial Applicability • Data Protection Officer (“DPO”) • Representative of Foreign Data Controller • Right of Data Subjects • Liabilities
  • 5. 5 PDPA Authorities PDPC • The Permanent Secretary of the Ministry of Digital and Economy and Society (“MDES”) is now acting as Chairman of PDPC • The Deputy Permanent Secretary of the MDES is now acting as the Secretary General of PDPC • Chairman and Secretary General of PDPC will be selected and appointed OPDPC • To be established within 27th May 2020 • Office of the Permanent Secretary of the MDES is now acting as OPDPC Expert Committee • To be appointed within 90 days after the appointment of the Chairman of PDPC
  • 6. 6 Within 27 May 2020 Start 27May2019 Appointment of Selection Committee to select Chairman and 9 Expert Committees of PDPC Cabinet establishes criteria for selection of Chairman and 9 Expert Committees of PDPC Selection and appointment of Chairman and 9 Expert Committees of PDPC PDPC issues implementation rules PDPA Implementation Timeline 1 2 3 4
  • 7. 7 Key Parties Data Controller Data Subject and Personal Data Data Processor • a person / juristic person • having the power and duties to make decisions as to the collection, use, or disclosure of Personal Data • a person / juristic person • who collects, uses, or discloses Personal Data on behalf of a Data Controller • any information relating to a data subject • enables the identification of data subject, whether directly or indirectly
  • 8. 8 Key Relations Data Subject Data Controller Data Processor Expert Committee Data Protection Officer OPDPC PDPC
  • 9. 9 Types of Personal Data Name Address Identification/Passport No. Personal Phone No. Bank / Credit cards Personal Email address IP Address Cookies Online Identifiers PersonalData Racial or Ethnic Origin Political Opinions Religious or Philosophical Beliefs Sexual Orientation/Behaviour Criminal Records Health and Disability Trade Union Membership Genetic Biometric SensitiveData any other data as prescribed by the PDPC
  • 10. 10 Businesses Which Are Subject to PDPA • All businesses in Thailand regardless of where collection, use, or disclosure (process) of Personal Data takes place • All businesses outside Thailand if the collection, use, or disclosure of Personal Data of data subjects who are in Thailand with the following activities: (1) the offering of goods or services to the data subjects who are in Thailand, irrespective of whether or not any payment is made by the data subjects. (2) the monitoring of the data subject’s behavior, where the behavior takes place in Thailand. Extraterritorial Applicability
  • 11. 11 Rights of Data Subjects Right to Be Notified - get information what data is collected, how data is going to be used (where stored, who will have access) Right to Access Data Right to Modify Data Right to Transfer and Data Portability Right to Delete Data Right to Object and Withdraw Consent
  • 12. 12 Data Protection Officer and Representative Duties of Data Protection Officer (DPO) • advising Data Controller or Data Processor and their employees with respect to any collection, use or disclosure of personal data; • Reviewing the operation of Data Controller or Data Processor in relation to their compliance with the PDPA; • coordinating with the OPDPC; and • maintaining the confidentiality of the Personal Data obtained. • Data Controller or Data Processor who (1) engages in a business of collecting, using or disclosing Sensitive Personal Data or (2) handles a large amount of personal data to be prescribed by the PDPC must appoint a DPO. • Data Controller and Data Processor outside Thailand who collect, use or disclose a number of personal data which include sensitive personal data must appoint a local representative in Thailand without a limit of liabilities. Who Must Appoint a DPO? Who Must Appoint a Representative?
  • 13. 13 Maximum Administrative Fines If personal data is breached: PDPA FINES OR Data Controller must report it to the OPDPC within hours Face a fine up to 72 THB5 Million
  • 14. 14 II. How and when can our company collect, use and disclose personal data of employees, customers, suppliers and the public?
  • 15. 15 Consent (Section 19) Asking permission from data subject Contract (Section 24(3)) Required to fulfill contractual obligations Legal Obligations (Section 24(6)) Required to establish, defend and enforce legal rights Vital Interest (Section 24(2)) To save lives Public Task (Section 24(4)) Government work Legitimate Interest (Section 24(5)) Legitimate interests of Data Controller outweigh privacy rights of data subject Basis for Processing Personal Data
  • 16. 16 • Any collection, use and disclosure of personal data cannot be made without express consent of the data subject. • Consent for collection and use of personal data may be at any time revoked. • Consent may be given either in writing or by electronic means. Consent General Consent – General Principles
  • 17. 17 1. contain the purpose of the collection, use or disclosure; 2. be clearly distinguishable from other matters; and 3. be made in a clear and plain language that is easy to understand and is not misleading to the data subject. Request for Consent – Its Basic Requirements Request for Consent must
  • 18. 18 Consent – Its Exceptions Exceptions of Consent 1. preventing harm to life or the health of an individual 2. lawful activities of non-profit organizations 3. preparing historical or statistical documents for the public benefit 4. carrying out duties to benefit of the public or to perform functions as allocated by the State 5. complying with contractual obligations 6. complying with the PDPA, other laws and public policy objectives (health and research) 7. establishing and enforcing and upholding legal claims 8. protecting the legitimate interests of the employer.
  • 19. 19 Mitigation of Risks – What Business Should Do Mitigation of Risks 1. compile information on how it collects, uses and discloses personal data, which requires notice to data subjects 2. determine potential impacts on the business if consent is withdrawn 3. create a data retention policy for various types of personal data collected 4. create a data privacy policy in line with the notice and consent requirements 5. identify situations where consent is required and where exemptions may apply 6. prepare and review its online and offline consent request to make it comply with PDPA.
  • 20. 20 Basis for Processing Personal Data without Consent (Section 24) Vital Interest Contractual Obligation Legal Obligation / Public Task • Employers transfer personal data of employees internally for internal administration. • Businesses record CCTV footage of visitors for security reason. Legitimate Interest • E-commerce businesses collect and use names and addresses of customers to deliver products to them. • Hotels keep passport information of customers for the Immigration Office. • Employers disclose employees’ wages to the Revenue Department and the Social Security Office. • Hospitals disclose patient record to other hospital for emergency treatment.
  • 21. 21 Limitations on Personal Data Collection, Use and Disclosure Purpose Limitation Any use of the collected personal data outside the notified purpose is prohibited. Source Limitation Personal data can be collected from data subject only, except in certain situations. Proportionality Limitation Personal data can be collected only in the amount necessary to accomplish the intended and lawful purpose notified to the data subject.
  • 22. 22 III. What can we do to reduce risks of failure to comply with the PDPA and mitigate liabilities
  • 23. 23 Major Pitfalls to Avoid Lack of legal documents required for PDPA compliance No clear understanding of where personal data is kept or who owns it Cannot identify legal basis for collection, use or disclosure of personal data No clear understanding of roles and obligations of Data Controller and Data Processor No PDPA compliance team, no DPO
  • 24. 24 ASSESSMENT & PLAN DETERMINATION MEASUREMENT REVISION & CREATION IMPLEMENTATION TRAINING & MAINTAINING PDPA Compliance Existing Privacy Policy, Privacy Notice and Consent Form should be reviewed and revised. If no compliance documents, they should be prepared and ready to be used . Revision and Creation of Privacy Policy and Other Compliance Documents To determine and implement technical and internal policy, procedures and record keeping Data Management Process and Operation System Key members of the management and the compliance team are trained and advised about the PDPA and its potential impacts on the business. Legal Advice &Training To assess risk criteria, risk level and to generate suitable plan to comply with the PDPA. Risk Assessment & Data Treatment Plan To determine legal basis and applicable obligations Legal Basis & Data Analysis To locate, quantify and categorize the existing collected personal data and the current personal data flow. Data Mapping Major Measures to Do
  • 25. 25 Privacy Policy – Questions for Key Provisions • What are the personal data collected and processed? • Where is the source of the data? • What are the purposes and legal basis for data collection and processing? • How to collect and process the data? • How the data is stored and what is the data retention period? • What are the rights of the data subject? • How to contact the Data Controller, representative and DPO? • What are data security measures?
  • 26. 26 Privacy Notice – Questions for Key Provisions • What are the data collected and processed and how? • Where is the source of the data? • What are the purposes and legal basis for data collection and use? • How the data is stored and what is the data retention period? • What are the rights of the data subject? • How to contact the Data Controller, representative and DPO? • What are the polices on cookies? • What are data security measures? • What are the marketing activities?
  • 27. 27 The quick brown fox jumps over the lazy dog. THB ≤ 500,000 Section 87 Offences in relation to Sensitive Data by Data Controller and Data Processor. Sections 83 & 86 Offences in relation to core duties of Data Controller and Data Processor to Data Subjects. Sections 82 & 85 Offences in relation to duties of Data Controller and Data Processor to protect rights of Data Subjects. Section 89 Failure of a person to comply with the order of the PDPC or to facilitate the PDPA officials. Major Administrative Fines THB ≤ 1millionTHB ≤ 3millionTHB ≤ 5million
  • 29. 29 Unit 1401, 14th Floor, 990 Abdulrahim Place, Rama IV Road, Bangkok 10500, Thailand Tel. +66 (0)2 636 0662, Fax +66 (0)2 636 0663 www.lawplusltd.com