Employment Termination: Navigating Confidentiality Breaches and Fair Practices

The Supreme Court, Decision No. 7189/2562, ruling in a high-profile labor case has shed a spotlight on the intricate interplay between employee confidentiality obligations and fair employment termination practices. The case involved an offshore petroleum company that terminated the employment of a training instructor after allegations of disclosing confidential company information. This decision offers valuable insights and lessons for both employers and employees alike.

Confidentiality Obligations: A Sacrosanct Duty

The court’s ruling reinforced the fundamental principle that employees have a sacrosanct duty to protect their employer’s confidential information and trade secrets. Unauthorized disclosure or mishandling of such sensitive data can constitute grounds for disciplinary action, including termination of employment. This obligation extends beyond the employee’s tenure with the company, underscoring the enduring nature of confidentiality responsibilities.

Defining Confidential Information: A Contextual Approach

The court adopted a contextual approach in defining what constitutes confidential information in this case. It scrutinized the nature of the information disclosed by the plaintiff-employee, specifically the audit reports from a third-party training organization. The court determined that these reports contained sensitive data pertaining to the defendant-company’s operations, training standards, and were protected by a non-disclosure agreement between the company and the third-party organization.

Notably, the agreement between the employer-defendant and the employee-plaintiff explicitly stipulated confidentiality obligations, whereby the plaintiff agreed to safeguard the defendant’s information and data. This agreement underscored the paramount importance the defendant placed on protecting and preserving information related to its business operations.

However, the plaintiff’s submission of the document containing the defendant’s organizational and managerial information, aimed at ensuring the defendant’s training and assessment standards, to the plaintiff’s personal email account raised significant concerns. This action facilitated the potential unauthorized transmission or removal of such information without the defendant’s ability to monitor or track its dissemination.

Consequently, the court viewed the plaintiff’s actions as a breach of duty, constituting dishonest conduct and an unauthorized disclosure of the defendant’s confidential information. This intentional act was deemed to have caused harm to the employer and amounted to a violation of disciplinary regulations governing workplace behavior.

photography of person peeking

Fair Termination Practices: Striking the Right Balance

While acknowledging the employer’s right to terminate employment for breaches of confidentiality, the court emphasized the importance of following fair termination procedures. This includes providing proper notice, adhering to labor laws, and ensuring that the termination is not considered unfair, retaliatory, or discriminatory. The court’s decision serves as a reminder that even in cases of confidentiality breaches, employers must exercise due diligence and uphold principles of fairness and equity.

Burden of Proof: A Stringent Standard

In cases of employment termination, the court placed a stringent burden of proof on the employer to demonstrate that the termination was justified and in compliance with applicable laws and regulations. The employer must provide clear and convincing evidence to substantiate the grounds for termination, particularly in cases involving confidentiality breaches, where the consequences for the employee can be severe.

Balancing Interests: A Delicate Equilibrium

The court’s ruling highlights the need to strike a delicate balance between the employer’s legitimate interest in protecting confidential information and trade secrets, and the employee’s right to fair treatment and due process during termination proceedings. This equilibrium ensures that both parties’ interests are safeguarded and that employment relationships are governed by principles of fairness, transparency, and mutual respect.

Confidentiality Policies and Procedures: A Proactive Approach

The court’s decision underscores the importance of employers implementing robust confidentiality policies and procedures. Clear guidelines, training programs, and well-defined consequences for breaches can help prevent confidentiality issues from arising in the first place. Additionally, ensuring that employees understand and acknowledge these policies can strengthen the employer’s position in the event of a dispute.

Employee Responsibilities: Upholding Trust and Integrity

For employees, this case serves as a reminder of the gravity of their confidentiality obligations and the potential consequences of breaching such trust. Employees must exercise utmost care in handling sensitive information and refrain from any unauthorized disclosure or misuse. Maintaining professional integrity and upholding the confidentiality of employer information is not only a legal obligation but also a ethical responsibility.

The Supreme Court’s ruling in this case has far-reaching implications for both employers and employees. It underscores the significance of maintaining confidentiality in the workplace and the potential consequences of breaching such obligations. At the same time, it emphasizes the importance of fair employment practices, adherence to labor laws, and the need for employers to provide due process and proper justification when terminating employees.

As the business landscape evolves, with an increasing emphasis on data protection and trade secret preservation, this ruling serves as a timely reminder for all parties to exercise caution in handling confidential information and to understand their respective rights and responsibilities in the employment relationship. By fostering a culture of trust, transparency, and mutual respect, employers and employees can create a harmonious and legally compliant work environment, where both parties’ interests are protected, and the sanctity of confidentiality is upheld.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Cross-Border Transferring of Personal Data

Pursuant to our previous articles on the PDPC Notification on Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 28 of the PDPA (Draft Notification on Section 28) and the PDPC Notification on Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 29 of the PDPA (Draft Notification on Section 29) (collectively referred to as the Draft Notifications), whereby at the time were drafts for public hearing. Now, the Personal Data Protection Committee (PDPC) in Thailand has announced the official version of Draft Notifications, the effective date of which shall be on 24 March 2024. This article herein then intends to outline the essential differences between the Draft Notifications and their respective official versions.

Subordinate regulation pursuant to Section 28 of the PDPA:

As we have discussed in length regarding the provision of Section 28 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA) prescribing a condition under which the data controller may cross-border transfer personal data, that is, if the destination country or international organization is deemed to have an adequate personal data protection standard, otherwise, other exemption would have to be relied upon (e.g., consent form the data subjects), and that what was deemed as adequate personal data protection standard, more information can be studied at the Draft Notification on Section 28. The official version and the draft version are substantially the same, except for the defined terms, which were added to exclude the sending or transferring of personal data of the following nature: (1) the sending or transferring of personal data by an intermediary as a data transit; (2) the sending or transferring of personal data that was done between the computer systems or data storages, provided that no third-party has access to such personal data. Examples of the exempted activities include the sending or transferring of personal data by the cloud computing service provider. By this exclusion, it releases intermediary and cloud computing service providers, as well as controllers or processors, burden compliance burdens.

Subordinate regulation pursuant to Section 29 of the PDPA:

In continuation to our previous article on the Draft Notification on Section 29, where we discussed that the PDPA provides two additional mechanisms for the cross-border transferring of personal data, that is (1) cross-border transfer of personal data within inter-affiliate companies, provided that the personal data protection policy (Binding Corporate Rules or BCR) is reviewed and certified; and (2) where in absence of whitelist country (i.e., per Section 28) and the BCR has not been reviewed or certified, a data controller may cross-border transfer personal data provided that an appropriate safeguard that ensure the enforceability of personal data subject’s rights and a legally remedial measures has been put in place.

modern fiber optic device with colorful plastic connectors

We have also discussed that the appropriate safeguard could be achieved through the use of the Model Contractual Clause, namely (1) ASEAN Model Contractual Clauses for Cross-Border Data Flows; or (2) Standard Contractual Clauses for the Transfer of Personal Data to Third Countries issued pursuant to Articles 46 (1), (2) (c), and 28 (7) of Regulation (EU) 2016/679 or the European Union General Data Protection Regulation, commonly known as GDPR. The official version of subordinate regulation pursuant to Section 29 of the PDPA entails the required elements to be in such Model Contractual Clause. Notable elements required to be in the Model Contractual Clause include but not limited to the (1) measures for notifying the sending or transferring of personal data to the data subject; (2) measures for limiting the sending or transferring of personal data; (3) measures for specifying responsibility for the sending or transferring of personal data to be included in the contract; (4) measures to maintain security in the sending or transferring of personal data; (5) measures for ensuring effective remedial measures; and others. Moreover, revisions/amendments to the Model Contractual Clause are possible, provided that such revision/amendment is not contrary to the required elements as samples. Please be reminded that the Model Contractual Clause may be used as an alternative to the reviewed and certified BCR. Data controllers and processors have the choice to adopt the method deemed appropriate to their normal business operation.

The development of these subordinate regulations will not only change the course of normal business operations but also the paradigm of personal data protection in the digital era. Unifying the cross-border transferring of personal data’s requirements with those of international standards will not only ease Thai data controllers or data processors’ compliance with the PDPA and other personal data protection regulations internationally but also, allow the foreign data controller or data processor to easily comply with the Thai requirements, indirectly promoting the investment in Thailand.  

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Subordinate Regulations for Enhanced Security Measures under the PDPA

Introduction:

The Personal Data Protection Committee (PDPC) in Thailand has recently announced two important notifications as part of its ongoing efforts to enforce the Personal Data Protection Act B.E. 2562 (2019) (PDPA) and ensure robust information privacy practices. These subordinate regulations, namely the PDPC Notification Concerning the Security Standard for Personal Data under the Responsibility of Data Controllers Exempted from the Enforcement of the PDPA, and the PDPC Notification Concerning the Appropriate Security Measures to Protect the Rights and Freedom of the Data Subject in the Processing of Personal Data for Purposes Relating to the Preparation of the Historical Documents or the Archives for Public Interest, are set to come into effect on March 7, B.E. 2567 (2024).

PDPC Notification Concerning the Security Standard for Personal Data under the Responsibility of Data Controllers Exempted from the Enforcement of the PDPA:

Following our previous coverage on this topic – PDPC notification on security standards for personal data controllers exempted from PDPA, the PDPC conducted a public hearing to gather input and evaluate the imposition of obligations on data controllers exempted from the PDPA. The official version of the notification has been published, and its provisions are identical to those previously discussed. For more details, please refer to our earlier article on the PDPC notification on security standards for personal data controllers exempted from the PDPA in the link above.

two person standing under lot of bullet cctv camera

PDPC Notification Concerning the Appropriate Security Measures to Protect the Rights and Freedom of the Data Subject in the Processing of Personal Data for Purposes Relating to the Preparation of the Historical Document or the Archives for Public Interest:

Section 24 (1) of the PDPA exempts certain data controllers from obtaining prior consent from data subjects when collecting, using, or disclosing personal data for the preparation of historical documents or archives for public interest purposes. However, these data controllers are still obligated to implement specific security measures to safeguard the personal data of individuals. The following summary outlines the key security measures:

  1. Implementation of Organizational, Technical, and Physical Safeguards: Data controllers must establish and maintain appropriate organizational, technical, and physical safeguards to ensure that personal data processing is limited to purposes directly connected to the preparation of historical documents or archives for public interest.
  2. Suitable Security Measures: Data controllers must implement security measures that effectively prevent unauthorized or unlawful loss, access, use, alteration, correction, or disclosure of personal data, in accordance with Section 37 (1) of the PDPA.

Additionally, data controllers may consider pseudonymization or encryption of personal data, where applicable, to minimize the risk of exposure. However, such additional safeguards should not compromise the intended purposes of preparing historical documents or archiving and must be assessed based on the specific contexts of personal data processing and the associated risks involved.

Conclusion:

The introduction of these subordinate regulations by the PDPC highlights its commitment to enhancing personal data security measures in Thailand. By providing guidance on security standards and appropriate measures, these regulations reinforce the enforcement of the PDPA and safeguard the rights and freedoms of individuals with regard to their personal data. It is crucial for organizations to understand the nature of their personal data processing activities and undertake a case-by-case interpretation and consideration to ensure compliance with these regulations. As Thailand continues to prioritize data protection, these measures lay a strong foundation for fostering a culture of responsible and secure handling of personal data in the country.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Data Protection Officer: Guidelines and Assistance for Designation

Introduction:

This article provides an overview of the obligations and requirements surrounding the designation of a Data Protection Officer (DPO) in accordance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA) B.E. 2566 (2023). It also outlines the consequences of failing to designate the DPO and offers assistance in evaluating the necessity of designating the DPO, selecting a suitable candidate, and fulfilling the DPO’s obligations and responsibilities.

Appointment and Notification of the Data Protection Officer:

The Personal Data Protection Committee (PDPC) has recently published a Notification on the Appointment of the Data Protection Officer, which came into force on December 13, 2023. This Notification, in conjunction with Section 41 of the PDPA, requires certain data controllers and processors to designate the DPO. In addition to designating the DPO, data controllers, and processors who are required to do so must also provide the DPO’s information, including contact details, to both the data subjects and the office of the PDPC.

Guidance and Support:

To assist data controllers and processors in understanding their obligations regarding the DPO designation and the submission of DPO’s information, the PDPC has issued a form for submitting the DPO’s information to their office. This form requires various details, such as the general information of the data controller or processor, the name and contact information of the DPO, and more. The PDPC has also provided a checklist to determine whether the designation of DPO is necessary.

Importance of Compliance:

It is crucial for data controllers and processors to carefully assess whether they are required to designate the DPO, as failure to do so may result in administrative liability, including fines of up to one million Baht.

Assistance Offered:

Navigating the intricacies of determining the need for DPO can prove daunting, particularly for individuals without a legal background who may encounter difficulties interpreting relevant laws. To address this challenge, our services extend to evaluating the necessity of appointing the DPO, offering guidance on selecting an appropriate candidate, and providing advice on the extensive obligations and responsibilities associated with the role. Furthermore, we offer support in the submission of the DPO’s pertinent information to the office of PDPC.

Conclusion:

Compliance with the PDPA’s requirements regarding the DPO designation is essential for data controllers and processors. By understanding their obligations and seeking appropriate assistance, organizations can ensure they meet their legal responsibilities while protecting the personal data of individuals.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPC Notification on Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 28 of the PDPA

The Office of the Personal Data Protection Commission (“PDPC”) conducted a public hearing on the draft PDPC Notification on the Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 28 of the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) (“Notification”). The public hearing was conducted between 27 October 2023 to 10 November 2023.

Section 28 of the PDPA prescribes a condition under which the data controller may cross-border transfer personal data, that is, if the destination country or international organization is deemed to have an adequate personal data protection standard, otherwise, other exemptions would have to be relied upon (e.g., consent from the data subject). In this regard, the Notification aims to set out the criteria by which the PDPC may deem a country or international organization to have an adequate personal data protection standard.

Article 5 of the Notification prescribes that the determination of adequate personal data protection standards shall be based on:

  1. Whether the destination country or international organization has a legal protection mechanism equivalent to or higher than those prescribed under Thai law or not. Specifically, the data controller’s obligations, personal data protection mechanisms, the enforcement of the data subject’s rights, and effective remedial measures.
  2. Whether there is an agency or organization with the duty and power to enforce the personal data protection laws in the destination country or international organizations, provided that such shall not be lower than that of Thailand.

Additionally, the Notification also prescribes that the data controllers may submit for the PDPC’s determination if such a destination country or international organization is of adequate personal data protection level or that the PDPC may gather the information themselves. The publication of a list of countries the PDPC deems to have adequate personal data protection (otherwise known as a whitelist country) will be closely monitored and updated.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPC Notification on Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 29 of the PDPA

PDPC Notification on Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 29 of the PDPA

The Office of the Personal Data Protection Commission (“PDPC”) conducted a public hearing on the draft PDPC Notification on the Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 29 of the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) (“Notification”). The public hearing was opened between 27 October 2023 to 10 November 2023.

In addition to the exemptions for cross-border transfer of personal data provided in Section 28 of the PDPA (i.e., whitelist countries and other exemptions), Section 29 provides two additional mechanisms for the cross-border transferring of personal data, that is (1) cross-border transfer of personal data within inter-affiliate companies, provided that the personal data protection policy (also known as “Binding Corporate Rules” or “BCR”) is reviewed and certified by the PDPC; and (2) where in the absence of whitelist country (i.e., per Section 28) and the BCR has not been reviewed and certified by the PDPC, a data controller may cross-border transfer personal data provided that an appropriate safeguard that ensures the enforceability of personal data subject’s rights and a legally remedial measures has been put in place.

In this regard, the Notification sets out the required characteristics of the BCR and the appropriate safeguard as follows:

  1. The legitimacy and enforceability of BCR against the juristic person, natural person, involving data controllers, data processors, and receivers of personal data within the same affiliated company, provided that such enforceability shall be extended to the employees and personnel involved in the transferring and receiving of personal data.
  2. The terms that ensure the protection of personal data, the rights of the data subject, and the right to file a complaint in relation to the transferred personal data.
  3. The security measures shall be in accordance with those prescribed under the personal data protection law.

The referred to appropriate safeguard could be in the form of either (1) a data transfer agreement; (2) a personal data collection, use, and disclosure certification; or (3) a bilateral agreement between international organizations or agencies.

The Notification went further to prescribe that the data transfer agreement mentioned above could be either of the following: (1) the agreement between the transferring and receiving parties with the required contractual clauses; (2) ASEAN Model Contractual Clauses for Cross-Border Data Flows; or (3) Standard Contractual Clauses for the Transfer of Personal Data to Third Countries issued pursuant to Article 46 (1), (2) (c), and 28 (7) of Regulation (EU) 2016/679 or the European Union General Data Protection Regulation, commonly known as GDPR.

The Notification consists of great details; international organizations or corporations may be required to closely monitor the development of this Notification until its publication and enforcement. It seems that PDPC has its interpretation and does not follow that of GDPR. Thus, it is necessary for the data controller that follows the practice in the EU to revisit this issue, especially those who rely upon the Standard Contractual Clauses (“SCC”).

In the EU, many EU-related companies adopted SCC, which are pre-approved contractual clauses issued by the European Commission that can be used by organizations to ensure adequate safeguards for data transfers to countries outside the EU. While SCC provides a more straightforward and less time-consuming solution for organizations, it is standardized contractual clauses that cannot be modified. BCR provides more flexibility and customization options compared to SCCs. It can be customized to align with the specific requirements of a business. Once implemented and operational, BCR is significantly easier to manage in comparison to intra-group contracts that include SCC. Additionally, BCR establishes a rigorous level of compliance with the PDPA as it requires approval from PDPC, thereby reducing the business’s vulnerability and being recognized as the benchmark for achieving compliance. It is suitable for multinational organizations with subsidiaries or affiliates in different countries.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPC Notification on Security Standards for Personal Data Controllers Exempted from PDPA

The Office of Personal Data Protection Commission (PDPC) conducted a public hearing on the draft PDPC Notification Concerning the Security Standards for Personal Data under Responsibility of Data Controllers exempted from the enforcement of the Personal Data Protection Act B.E. 2562 (2019) (PDPA) (“Notification”). This public hearing occurred from 17 October 2023 to 31 October 2023.

Under Section 4 of the PDPA, certain data controllers, including public authorities, the media, the House of Representatives, the Senate, the Parliament, the courts, and the credit bureau, are exempted from the enforcement of the PDPA. However, Section 4 paragraph 3 of the PDPA mandates that these exempted data controllers must implement security measures to protect personal data.

black android smartphone on top of white book

The draft Notification sets out the security measures that exempted data controllers must adhere to. These measures are similar to those prescribed in the PDPC’s Notification on Security Measures for the Protection of Personal Data B.E. 2565 (2022). The key measures include:

  1. Implementing organizational, technical, and physical measures to safeguard personal data, regardless of its form (physical or digital).
  2. Ensuring the confidentiality, integrity, and availability of personal data.
  3. Extending security measures to servers, software, or applications for storing or processing personal data.
  4. Implementing access control, identity proofing and authentication, need-to-know basis access, user access management, determination of user responsibilities, and personal data audit trails.
  5. Raising awareness about privacy and security among employees or users with access to personal data.
  6. Adopting pseudonymization or encryption measures to minimize the risk of unauthorized or unlawful processing of personal data.

The enforcement of these measures will be closely monitored once the draft Notification becomes enforced.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Personal Data Protection for NBTC license holders

The Notification on Protecting User Rights Regarding Personal Data, Rights to Privacy, and Freedom of Communication through Telecommunications Service (“Notification”) was approved by the National Telecommunications Commission. The Notification has been officially published in the Royal Gazette and became effective since September 4, 2023.

Key provisions of the Notification include:

Section 6 stipulates that license holders must obtain separate consent from users before using or disclosing their personal data for purposes other than operating the telecommunications business. License holders must clearly inform users about the scope and objectives of the business, the types of personal information that will be used or disclosed, and any third parties involved. Users must be provided with the option to confirm or revoke their consent. License holders must comply with the conditions specified in the notification and any additional requirements imposed by the NBTC. The language used must be clear and easily understandable, without misleading users about the purpose. Consent may be obtained in writing or through technological means. However, users’ consent or withdrawal should not interfere with their use of telecommunications services.

two person standing under lot of bullet cctv camera

Section 7 outlines the details regarding sensitive data, which includes race, ethnicity, political opinions, beliefs, sexual behavior, criminal record, health record, disabilities, union information, genetic data, biological data, and any other data specified in the Personal Data Protection Law that may affect users.

Section 10 addresses the notification requirements for collecting personal data. Generally, license holders must inform consumers during or before collecting their personal data. However, when collecting data from other sources, license holders must notify the data subject within 30 days from the collection date. License holders are not required to notify when the collection does not require consent under Sections 6 and 7.

Section 14 states that if a violation poses a high risk to individuals’ rights and freedoms, license holders must immediately notify the NBTC within 24 hours of recognizing the violation. The notification must include a remediation measure for affected users.

Section 20 mandates that license holders must publicly announce their policies to protect users’ rights to personal information, privacy, and freedom of communication through telecommunications. These policies must be in accordance with the notification and the personal data protection law and should be displayed on the license holders’ website, place of service, application form, and service agreement. Additionally, these policies must be approved by the NBTC.

Given these revisions, it is crucial for all license holders to update their practices to ensure compliance with the personal data protection policies. The protection of personal information is of utmost importance, particularly in the telecommunications industry.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Certified Courses and Training Program for DPO and Registered Instructor

The Office of the Personal Data Protection Committee (“Office”)  has launched an Announcement of the Office of the Personal Data Protection Committee (“Committee”) Re: Criteria for Certified Courses and Training Programs for the Data Protection Officer and Registered Instructor (“Announcement”) and its guidelines on 8 August 2023 in order to provide knowledge and understanding in both legal terms and practical proceedings, for the Data Protection Officer (“DPO”) and those who are registered instructors and training agencies in order comply with the Personal Data Protection Act B.E. 2562 (2019) (“PDPA“).

This Announcement sets guidelines for 2 main matters with the details as follows:

1.Certified courses and training programs

Agencies or institutions that would like the Office to certify their courses and training programs must apply for the same via an official email at course@pdpc.or.th. After consideration, the Committee will deliver its opinion to the Secretary-General of the Personal Data Protection Committee (“Secretary-General”) for its final consideration. Those who have been certified will be published to the public.

two person standing under lot of bullet cctv camera

2.Registered instructors

While the agencies or institutions are registered per item 1, any person who would like to register himself/herself to be a registered instructor can apply for the same via email at course@pdpc.or.th. If the applicant’s qualifications meet the requirements, the applicant must attend the seminar and take some exams organized by the Office. After that, the registration process will be completed, and his/her name will be announced to the public. The registration will be valid for one year and will need to be renewed by attending further seminars.

This Announcement has been effective as of the date of publication. Currently, there is no civil liability, administrative liability, or criminal penalty applied to the agencies or institutions in case of non-compliance with the PDPA and its guidelines. The Office aims to encourage the agencies or institutions to attend the training programs to understand the provisions of PDPA and then they can distribute their knowledge to the DPO.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles