Data Privacy Breaches: Duty to Report to the Regulator

A data privacy breach refers to the unauthorized access, use, disclosure or destruction of personal data, either by an individual or by an organization. Data privacy breaches can occur in a variety of ways, including hacking, malware attacks, insider threats or simply human error.

Data privacy breaches can have serious consequences for both individuals and organizations. For individuals, a data privacy breach can lead to the theft of personal information, such as financial data or identity information, which can be used for fraud or identity theft. For organizations, data privacy breaches can lead to legal and regulatory consequences, as well as damage to their reputation and financial losses.

Under the General Data Protection Regulation (GDPR), a data privacy breach is defined as any unauthorized access, use, disclosure or destruction of personal data. This includes both accidental and intentional breaches. If an organization experiences a data privacy breach, it is required to notify the relevant supervisory authority and the individuals whose personal data has been breached. In Thailand, Personal Data Protection Committee (“PDPC”) has officially announced on how to report an incident of personal data breach to the Office of Personnel Data Protection (“Announcement”) which describes Data Controller’s duty to notify of data breach under Section 37(4) of Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) where this Announcement shall come into force and effect since this date of the announcement, i.e. 15 December 2022.

As we all know, the Data Controller is required to notify the Office of PDPC of any personal data breach without delay and, where feasible, within 72 hours. A data breach shall have the meaning as a breach of security measures that results in unauthorized or illegal loss, access, use, amendment, alteration or disclosure of personal data, whether committed intentionally, negligently, unauthorizedly, unlawfully, through computer crime, cyber threat, flaw or other means occurred by the act of the Data Controller, Data Processor, employee, staff, contractor, agent, any related person or any other factors resulting in the Confidentiality Breach, Integrity Breach and/or  Availability Breach.

When Data Controller becomes aware of or is informed of a personal data breach, the Data Controller shall evaluate the reliability of such breach without delay, whether the breach has occurred or reasonably being suspected by taking into account of organizational, technical and physical measures to confirm that a personal data breach has actually occurred. The Data Controller must conduct a risk assessment of all potential consequences for the Data Subject. For a high-risk case, the Data Controller must act independently or instruct the Data Processor to take preventive, suspending or corrective actions to ensure that the data breach is terminated or has no further impact. Furthermore, if a confirmed or reasonably suspected data breach is considered to jeopardize the Data Subject’s rights and liberties, the Data Controller must notify the Office of PDPC without delay and, where feasible, within 72 hours of becoming aware of it. Plus, the Data Controller must notify such high-risk data breaches and the remedial measures of the Data Subject as well.

security logo

Since 72 hours may be insufficient for the Data Controller and Data Processor to collect all data resulting in an inability to notify the Office of PDPC in time, in this case, the Data Controller shall prepare a reason clarification along with all documents mentioned in this Announcement and submit the same to the Office of PDPC within 15 days of becoming aware of such breach in order to have Office of PDPC consider exempting the Data Controller from liability under Section 37(4) of the PDPA, respectively.

As a result, Data Controllers and Data Processors should thoroughly read the Announcement in order to comply with the PDPA and protect the personal data that are being collected.

Author: Panisa Suwanmatajarn, Managing Partner

What the Data Controller needs to do when a Personal Data Breach occurs

The Personal Data Protection Committee (“PDPC”) is currently considering issuing a Personal Data Protection Announcement on how to report an incident of personal data breach to the Office of PDPC and whether it needs to report to the Data Subject.

According to Section 37(4) of Personal Data Protection Act B.E. 2562 (“PDPA”), a Data Controller has to notify the Office once there is a data breach without delay or within 72 hours after having become aware of the data breach. The data breach may be occurred by the Data Controller, Data Processor, Representative, any related person, or any other factors, such as an accidental, technological and computer processing system, computer crime, or cyber threat, who acts willfully, negligently, unauthorizedly, or unlawfully, affecting the completeness and accuracy of the personal data and the rights of the Data Subject. The Data Breach Category is divided into three types which are the leak of confidential personal data (Confidentiality Breach), the personal data misfiling (Integrity Breach), and inaccessibility of personal data, which can result in permanent inaccessibility or destruction (Availability Breach).

woman wearing hooded pullover hoodie facing tablet computer

At the same time, the Data Controller is required to check its security measures in all aspects, including Organizational Measures, Technical Measures, and Physical Measures. And conduct a risk assessment of all possible effects on the Data Subject considering whether the data breach is likely to result in a high risk to the Data Subject’s rights and freedoms, the risk assessment factors as stated in the Announcement, if so, Data Controller is required to notify the Data Subject without delay, along with the remedial measures.  In case where Data Controller cannot contact Data Subject for any reason, the data breach notification to Data Subject can be carried out on a public platform, such as social media or any other means by which the public can become aware of such notification. However, Data Controller is not required to notify the Office if such data breach is unlikely to result in a risk to the rights and freedoms of the Data Subject due to the reasons such as personal data being anonymous information that cannot be used to identify the Data Subject, unusable personal data due to adequate technological security measures or other reliable reasons according to the law.

Furthermore, the Data Controller must take immediate remedial action against the cause of such data breach either by restricting access to personal data or by any other means as necessary.

The data breach notification submitted to the Office must be included the details such as the number of personal data that has been leaked or violated, the name and address to contact the Data Protection Officer, consequences of a data breach, security measures that the Data Controller or Data Processor have to prevent data breach together with the remedial action in all respects, including personal, procedure and technology. In the event that the Data Controller fails to notify the Office in due time, the Data Controller must clarify reasons and details regarding the inevitability of such an offense to the Office within 15 days of becoming aware of the data breach in order for the Office to consider exempting so. The failure to comply with all of the above is an offense under the PDPA penalized by Administrative Liability with a fine of not exceeding three million Baht.

The Announcement also contains details and sample cases on data breach notification, which will guide Data Controllers in determining which cases must be reported and who must be notified. Therefore, Data Controllers should study this Announcement in order to prepare themselves in case that the data breach occurs and to be in compliance with the PDPA.

Author: Panisa Suwanmatajarn, Managing Partner

Safe Harbor: Suppression of Dissemination and Removal of Computer Data from the Computer System B.E. 2565 (2022)

Recently, the Ministerial Notification of Ministry of Digital Economy and Society (MDES) re: Procedures for the Notification, Suppression of Dissemination and Removal of Computer Data from the Computer System B.E. 2565 (2022) (the “Ministerial Notification”) was published in the Government Gazette, replacing the previous version which came into force in 2017. The Ministerial Notification lays down safe harbor procedures to be complied by service providers and social media platforms in order to be exempted from liability for cooperating, consenting, or supporting offences in relation to illegal computer data under Section 15 of the Computer Related Crime Act B.E. 2550 (2007) as amended by Computer Related Crime Act (No.2) B.E.2560 (2017) (the “CCA”).

According to the Ministerial Notification, service providers offering the following types of service could benefit from safe harbor if they can prove that they have complied with conditions specified therein.

green and white line illustration
  1. Intermediary services, for example, facilitate computer information transmission routing, transitory communication – mere conduit, provide necessary transient storage, or hosting carried out by an automatic technical process;
  2. System caching;
  3. Storing information residing on systems or network at direction of users;
  4. Linking users to computer information by using information location tools; and
  5. Social media platform.

In general, service providers/social media platforms must transmit, storing or linking computer information in their control without any modification or interference and have no collaboration in, relation to or knowledge upon illegal activities specified in Section 14 of the CCA carried out by services users or other third parties. Also, service providers must not receive direct or indirect compensation or benefit for disseminating such illegal computer information.

In addition to the above-mentioned conditions, service providers/social media platforms must also prove that they have implemented Notice & Takedown Policy, which outlines as follows:

security logo
  1. Notification procedures must be adopted by service providers for suppression of dissemination and removal of illegal computer data, providing service users or other third-party channels to report illegal activities. A take down notice must contain at least name and contact details of service providers/social media platforms and complaint form for service users to report, for example, details of alleged perpetration and damages occurred.
  2. Service users can notify illegal computer information by either filing a report or a complaint to the inquiry officer or notifying service providers/social media platforms by completing the provided complaint form.
  3. Service providers/social media platforms must respond expeditiously by suppressing the dissemination of and/or removing illegal computer data from their system as well as forwarding a copy of the complaint form to service users, members, or other relevant persons.  

Furthermore, takedown measures also available to officers by issuing an order to service providers/social media platforms who are reported by an injured person, government officials and etc. to have illegal computer contents in their control. Similar to Notice & Takedown Policy adopted by service providers, upon receiving an order from officers, service providers/social media platforms must expeditiously suppress the dissemination and/or remove illegal computer data as well as forward a copy of the complaint to service users, members, or other relevant persons under their control. However, service providers/social media platforms may file an appeal against the order to the Permanent Secretary of MDES within 30 days from the receipt of order.

Author: Panisa Suwanmatajarn, Managing Director

Guideline for Privacy Notice and Collection of Personal Data

By now, Data Controller should be aware that under Section 23 of the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), the Data Controller is required to notify the Data Subject of the details and purposes of the collection, use, or disclosure of personal data through a Privacy Notice before or at the time of collection. In this regard, the Personal Data Protection Commission “PDPC” has issued a guideline regarding this matter of Privacy Notice and the collection of personal data which the Data Controllers must firstly determine whether there are any specific regulations issued by other regulators governing the same matter before complying with this guideline, respectively. If there are and such regulations do not have lower standard than those of PDPA, the Data Controller must follow those regulations.

man in white crew neck shirt

Prior to preparation of the Privacy Notice, Data Controller must consider the fairness that Data Subject will receive including considering the consequences after the collection, use and disclosure of personal data and specifying the purpose of such collection in clear and plain language, not deceptive or misleading, plus, the purpose for processing personal data must be obvious, specific and lawful in order for the Data Subject to explicitly understand and aware of, particularly for the section relating the disclosure of personal data to third parties, before giving his or her consent. If there are any cases where other legal basis can be applied to the collection, use or disclosure of personal data, the Data Controller may rely upon those legal basis as well. The guideline also lists down details that should be specified in the Privacy Notice.

Section 25 of PDPA imposes the Data Controller to not collect personal data from other sources apart from Data Subject directly, however, the Data controller may do so if the following exceptions are met.

  1. The Data Controller is required to inform the Data Subject of such indirect collection within thirty days of the collection date in order to request consent from the Data Subject and process such personal data for a new purpose to which the Data Subject had never previously consented. In practice, this Data Controller who receives personal data from other sources in some cases does not need to provide details under Section 23 because the Data Controller collecting data from other sources supposes to notify it to the Data Subject in the first place. However, if Data Controller collecting data from other sources did not do so, the current Data Controller must comply with Section 23 notifying the Data Subject within thirty days as previously stated above.
  2. The current Data Controller is not required to notify the Data Subject of the Privacy Notice and obtain any consent from the Data Subject again if the Data Subject was aware of the purpose and details of personal data collection.
  3. If it is impossible for the current Data Controller to notify the Data Subject, the Data Controller must have an appropriate security system to protect the rights, freedoms and benefits of the Data Subject.
woman in black framed eyeglasses holding smartphone

In this regard, the Data Controller shall either make a public announcement and state the necessities of such personal data collection or provide the Data Protection Impact Assessment (DPIA) in order to identify and assess the risk or damage that may result from the use or disclosure of personal data.

Author: Panisa Suwanmatajarn, Managing Partner.

Rules and Policy for Transferring Personal Data to a Foreign Country under PDPA of Thailand

The Personal Data Protection Committee (“PDPC”) is currently considering for issuing a Personal Data Protection Announcement Concerning Sending or Transferring Personal Data from the Kingdom of Thailand to a Data Controller or Data Processor in a foreign country or international organization.  This draft announcement will establish various standards, including binding corporate rules (“BCR”), appropriate safeguards, certification and standard contractual clauses to protect the personal data and to have the involved parties operate legally under Personal Data Protection Act B.E.2562 (“PDPA”).

The involved parties in this announcement are from the same affiliate business or group of undertakings, including the Transferer, i.e. the Data Controller in the Kingdom of Thailand, the Transferee, i.e. either a Data Controller or Data Processor in other countries or international organizations and the Sub Data Processors (if any).

security logo

Binding Corporate Rules (“BCR”) is a data protection policy among business affiliates that may be implemented for data to be transferred to ensure that personal data will be protected and transferred in accordance with the PDPA standards. BCR must certify the Data Subject’s rights as well as specify the general principles of the PDPA. Furthermore, BCR must establish appropriate safeguards to protect personal data in terms of people, processes, and technology.

The appropriate safeguard is to prevent the unauthorized or unlawful loss, access to, use, alteration, correction or disclosure of personal data and such measures must be reviewed when it is necessary or when the technology has changed in order to efficiently maintain the appropriate security and safety. The most important is that the BCR must be effective, legally binding and enforced among parties and Sub Data Processors (if any).

Furthermore, BCR must be submitted to the Office of Personal Data Protection Committee for review and certification that it is applicable and valid. Then, sending or transferring of personal data under approved BCR to a foreign country is permitted.

Such BCR will be effective only when it binds all employees, staffs and persons concerned in transferring personal data and is subject to Thai law. An example of important requirements is the duties of the Transferor and Transferee, rights of Data Subjects, dispute resolution and liability to Data Subject and cooperation with PDPC, etc. If the Transferee fails to fulfill its obligations, the Transferor has the right to terminate transferring of data, either temporarily or permanently. Moreover, if  a dispute arises as a result of an improper duty and failure to fulfill such duty, and the Data Subject exercises his or her rights to seek for damages, the Transferor , Transferee, or Sub Data Processor must notify other parties and resolve the dispute jointly through mediation. Neither party can use the failure of the other involved parties to exclude or limit their liability as a defense.

In light of this, the Data Controller should follow up with this draft announcement that will be issued and become effective soon so that the Data Controller and other involved parties can properly and legally prepare for actions related to the protection of personal data transferred abroad.

Author: Panisa Suwanmatajarn, Managing Partner

Announcement of Ministry of Digital Economy and Society Re: Procedures on Notifying, Suspending of Publishing of Computer Data and Exporting Computer Data from System

The Cabinet acknowledged a draft Announcement of Ministry of Digital Economy and Society Re: Procedures on notifying, suspending of publishing of computer data and exporting computer data from system B.E. …. (“Announcement”) prior to its enforcement as proposed by the Ministry of Digital Economy and Society.

Key issues of draft Announcement are as follows:

black android smartphone on top of white book
  • It is to cancel the Announcement of Ministry of Digital Economy and Society Re: Procedures on Notifying, suspending of publishing of computer data and exporting computer data from system B.E. 2566 (2017)
  • The Announcement has added new definitions of terms which are “Social Media” and “Location of Illegal Data” to be in compliance with those other announcements.
  • Determining types and characters of services of service provider or social media provider being able to prove of compliance with this Announcement so that it will not be fallen under the offence of cooperation or consent in conducting the offence.
    • Service provider that is an intermediary operating service such as routing, artificial intelligence, transitory communication – mere conduit where the intermediary does not involve or contribute such as  transmitting of such computer data, making permanent copy of computer data, storing with public access at a later stage, no editing of data by the service provider and no remuneration, directly or indirectly, from publication, duplicate or modifying of such illegal data.
    • Service provider operating for storing or system caching in a computer network controlling transmission of all data from users or outsider or computer network or artificial intelligence or operating of computer network or automatic artificial intelligence with no involvement or control from service provider.
    • Service provider operating reserving of computer data in its own computer system or network where the information residing on system or network at direction of user without the service provider awareness of the illegal activity and without receiving any remuneration.
    • Service provider operating technical service for information location tools without linking to illegal source and that there is no remuneration or benefit involvement, directly or indirectly, from publication of such illegal computer data.
    • Online social media provider in communication or exchange of information between persons through technology or social network by posting, editing, publishing of computer data through service provider or outsider or automatically through computer system or artificial intelligence and the service provider does not get involved and not receive any benefit, directly or indirectly, from that illegal publishing, copying or editing of data.
    • Service provider other than (1) (2) (3) (4) (5) giving service of other internet access or connect manner through computer network.
white switch hub turned on
  • Determining notice & takedown policy arranged by service provider to avoid being charged on the ground of cooperating, consenting or acknowledging of offence.
    • Advance notice & take down policy or take down notice in writing is required to be arranged and informed to the public so that the public is able to report to the service provider to suspend or delete publication of illegal data from the computer system.
    • Upon discovery of any service provider or online social media provider publishes illegal data, the service user or outsider can notify the service provider or online social media to suspend publication or erase of illegal data through a daily report or complaint to the police officer or through a complaint form provided by the service provider or online social media.
    • Once the service provider or online social media provider receives the complaint form, it needs to take action in order to suspend the publication of illegal data and make a copy of thereof and send the same to the relevant persons under its control immediately except having reasonable ground or under force majeure event. However, it needs to be acted no later than 24 hours.
  • Determining standard measures according to the industry itself to suspend distribution or delete illegal data by order of the officer.
  • Determining appealing procedures and revocation of officer’s order in case the service provider or social media provider disagree to the order or exercise the right to argue against the officer’s order.
  • Determining litigation procedures in case that service provider or social media provider does not conduct any action according to order to suspend publication, erase or modify the illegal data. The officer must gather the relating evidence of the commission of crime and report the case to the police officer and coordinate with National Broadcasting and Telecommunication Commission or related authorities for further proceedings.

This draft Announcement aims to amend procedures on notification, suspension of publication of illegal computer data for more convenience, quality and suitability to modern technology along with notice & takedown policy or self-report. In addition, it determines more involvement of the officer to tackle the complaint and non-compliance of the service provider which reduces burden of the people or the injured party in complaining to the service provider themselves or the officer.