Cross-Border Transferring of Personal Data

Pursuant to our previous articles on the PDPC Notification on Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 28 of the PDPA (Draft Notification on Section 28) and the PDPC Notification on Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 29 of the PDPA (Draft Notification on Section 29) (collectively referred to as the Draft Notifications), whereby at the time were drafts for public hearing. Now, the Personal Data Protection Committee (PDPC) in Thailand has announced the official version of Draft Notifications, the effective date of which shall be on 24 March 2024. This article herein then intends to outline the essential differences between the Draft Notifications and their respective official versions.

Subordinate regulation pursuant to Section 28 of the PDPA:

As we have discussed in length regarding the provision of Section 28 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA) prescribing a condition under which the data controller may cross-border transfer personal data, that is, if the destination country or international organization is deemed to have an adequate personal data protection standard, otherwise, other exemption would have to be relied upon (e.g., consent form the data subjects), and that what was deemed as adequate personal data protection standard, more information can be studied at the Draft Notification on Section 28. The official version and the draft version are substantially the same, except for the defined terms, which were added to exclude the sending or transferring of personal data of the following nature: (1) the sending or transferring of personal data by an intermediary as a data transit; (2) the sending or transferring of personal data that was done between the computer systems or data storages, provided that no third-party has access to such personal data. Examples of the exempted activities include the sending or transferring of personal data by the cloud computing service provider. By this exclusion, it releases intermediary and cloud computing service providers, as well as controllers or processors, burden compliance burdens.

Subordinate regulation pursuant to Section 29 of the PDPA:

In continuation to our previous article on the Draft Notification on Section 29, where we discussed that the PDPA provides two additional mechanisms for the cross-border transferring of personal data, that is (1) cross-border transfer of personal data within inter-affiliate companies, provided that the personal data protection policy (Binding Corporate Rules or BCR) is reviewed and certified; and (2) where in absence of whitelist country (i.e., per Section 28) and the BCR has not been reviewed or certified, a data controller may cross-border transfer personal data provided that an appropriate safeguard that ensure the enforceability of personal data subject’s rights and a legally remedial measures has been put in place.

modern fiber optic device with colorful plastic connectors

We have also discussed that the appropriate safeguard could be achieved through the use of the Model Contractual Clause, namely (1) ASEAN Model Contractual Clauses for Cross-Border Data Flows; or (2) Standard Contractual Clauses for the Transfer of Personal Data to Third Countries issued pursuant to Articles 46 (1), (2) (c), and 28 (7) of Regulation (EU) 2016/679 or the European Union General Data Protection Regulation, commonly known as GDPR. The official version of subordinate regulation pursuant to Section 29 of the PDPA entails the required elements to be in such Model Contractual Clause. Notable elements required to be in the Model Contractual Clause include but not limited to the (1) measures for notifying the sending or transferring of personal data to the data subject; (2) measures for limiting the sending or transferring of personal data; (3) measures for specifying responsibility for the sending or transferring of personal data to be included in the contract; (4) measures to maintain security in the sending or transferring of personal data; (5) measures for ensuring effective remedial measures; and others. Moreover, revisions/amendments to the Model Contractual Clause are possible, provided that such revision/amendment is not contrary to the required elements as samples. Please be reminded that the Model Contractual Clause may be used as an alternative to the reviewed and certified BCR. Data controllers and processors have the choice to adopt the method deemed appropriate to their normal business operation.

The development of these subordinate regulations will not only change the course of normal business operations but also the paradigm of personal data protection in the digital era. Unifying the cross-border transferring of personal data’s requirements with those of international standards will not only ease Thai data controllers or data processors’ compliance with the PDPA and other personal data protection regulations internationally but also, allow the foreign data controller or data processor to easily comply with the Thai requirements, indirectly promoting the investment in Thailand.  

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Subordinate Regulations for Enhanced Security Measures under the PDPA

Introduction:

The Personal Data Protection Committee (PDPC) in Thailand has recently announced two important notifications as part of its ongoing efforts to enforce the Personal Data Protection Act B.E. 2562 (2019) (PDPA) and ensure robust information privacy practices. These subordinate regulations, namely the PDPC Notification Concerning the Security Standard for Personal Data under the Responsibility of Data Controllers Exempted from the Enforcement of the PDPA, and the PDPC Notification Concerning the Appropriate Security Measures to Protect the Rights and Freedom of the Data Subject in the Processing of Personal Data for Purposes Relating to the Preparation of the Historical Documents or the Archives for Public Interest, are set to come into effect on March 7, B.E. 2567 (2024).

PDPC Notification Concerning the Security Standard for Personal Data under the Responsibility of Data Controllers Exempted from the Enforcement of the PDPA:

Following our previous coverage on this topic – PDPC notification on security standards for personal data controllers exempted from PDPA, the PDPC conducted a public hearing to gather input and evaluate the imposition of obligations on data controllers exempted from the PDPA. The official version of the notification has been published, and its provisions are identical to those previously discussed. For more details, please refer to our earlier article on the PDPC notification on security standards for personal data controllers exempted from the PDPA in the link above.

two person standing under lot of bullet cctv camera

PDPC Notification Concerning the Appropriate Security Measures to Protect the Rights and Freedom of the Data Subject in the Processing of Personal Data for Purposes Relating to the Preparation of the Historical Document or the Archives for Public Interest:

Section 24 (1) of the PDPA exempts certain data controllers from obtaining prior consent from data subjects when collecting, using, or disclosing personal data for the preparation of historical documents or archives for public interest purposes. However, these data controllers are still obligated to implement specific security measures to safeguard the personal data of individuals. The following summary outlines the key security measures:

  1. Implementation of Organizational, Technical, and Physical Safeguards: Data controllers must establish and maintain appropriate organizational, technical, and physical safeguards to ensure that personal data processing is limited to purposes directly connected to the preparation of historical documents or archives for public interest.
  2. Suitable Security Measures: Data controllers must implement security measures that effectively prevent unauthorized or unlawful loss, access, use, alteration, correction, or disclosure of personal data, in accordance with Section 37 (1) of the PDPA.

Additionally, data controllers may consider pseudonymization or encryption of personal data, where applicable, to minimize the risk of exposure. However, such additional safeguards should not compromise the intended purposes of preparing historical documents or archiving and must be assessed based on the specific contexts of personal data processing and the associated risks involved.

Conclusion:

The introduction of these subordinate regulations by the PDPC highlights its commitment to enhancing personal data security measures in Thailand. By providing guidance on security standards and appropriate measures, these regulations reinforce the enforcement of the PDPA and safeguard the rights and freedoms of individuals with regard to their personal data. It is crucial for organizations to understand the nature of their personal data processing activities and undertake a case-by-case interpretation and consideration to ensure compliance with these regulations. As Thailand continues to prioritize data protection, these measures lay a strong foundation for fostering a culture of responsible and secure handling of personal data in the country.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Data Protection Officer: Guidelines and Assistance for Designation

Introduction:

This article provides an overview of the obligations and requirements surrounding the designation of a Data Protection Officer (DPO) in accordance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA) B.E. 2566 (2023). It also outlines the consequences of failing to designate the DPO and offers assistance in evaluating the necessity of designating the DPO, selecting a suitable candidate, and fulfilling the DPO’s obligations and responsibilities.

Appointment and Notification of the Data Protection Officer:

The Personal Data Protection Committee (PDPC) has recently published a Notification on the Appointment of the Data Protection Officer, which came into force on December 13, 2023. This Notification, in conjunction with Section 41 of the PDPA, requires certain data controllers and processors to designate the DPO. In addition to designating the DPO, data controllers, and processors who are required to do so must also provide the DPO’s information, including contact details, to both the data subjects and the office of the PDPC.

Guidance and Support:

To assist data controllers and processors in understanding their obligations regarding the DPO designation and the submission of DPO’s information, the PDPC has issued a form for submitting the DPO’s information to their office. This form requires various details, such as the general information of the data controller or processor, the name and contact information of the DPO, and more. The PDPC has also provided a checklist to determine whether the designation of DPO is necessary.

Importance of Compliance:

It is crucial for data controllers and processors to carefully assess whether they are required to designate the DPO, as failure to do so may result in administrative liability, including fines of up to one million Baht.

Assistance Offered:

Navigating the intricacies of determining the need for DPO can prove daunting, particularly for individuals without a legal background who may encounter difficulties interpreting relevant laws. To address this challenge, our services extend to evaluating the necessity of appointing the DPO, offering guidance on selecting an appropriate candidate, and providing advice on the extensive obligations and responsibilities associated with the role. Furthermore, we offer support in the submission of the DPO’s pertinent information to the office of PDPC.

Conclusion:

Compliance with the PDPA’s requirements regarding the DPO designation is essential for data controllers and processors. By understanding their obligations and seeking appropriate assistance, organizations can ensure they meet their legal responsibilities while protecting the personal data of individuals.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPC Notification on Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 28 of the PDPA

The Office of the Personal Data Protection Commission (“PDPC”) conducted a public hearing on the draft PDPC Notification on the Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 28 of the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) (“Notification”). The public hearing was conducted between 27 October 2023 to 10 November 2023.

Section 28 of the PDPA prescribes a condition under which the data controller may cross-border transfer personal data, that is, if the destination country or international organization is deemed to have an adequate personal data protection standard, otherwise, other exemptions would have to be relied upon (e.g., consent from the data subject). In this regard, the Notification aims to set out the criteria by which the PDPC may deem a country or international organization to have an adequate personal data protection standard.

Article 5 of the Notification prescribes that the determination of adequate personal data protection standards shall be based on:

  1. Whether the destination country or international organization has a legal protection mechanism equivalent to or higher than those prescribed under Thai law or not. Specifically, the data controller’s obligations, personal data protection mechanisms, the enforcement of the data subject’s rights, and effective remedial measures.
  2. Whether there is an agency or organization with the duty and power to enforce the personal data protection laws in the destination country or international organizations, provided that such shall not be lower than that of Thailand.

Additionally, the Notification also prescribes that the data controllers may submit for the PDPC’s determination if such a destination country or international organization is of adequate personal data protection level or that the PDPC may gather the information themselves. The publication of a list of countries the PDPC deems to have adequate personal data protection (otherwise known as a whitelist country) will be closely monitored and updated.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPC Notification on Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 29 of the PDPA

PDPC Notification on Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 29 of the PDPA

The Office of the Personal Data Protection Commission (“PDPC”) conducted a public hearing on the draft PDPC Notification on the Criteria for Protection of Personal Data Sends or Transfers to a Foreign Country According to Section 29 of the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) (“Notification”). The public hearing was opened between 27 October 2023 to 10 November 2023.

In addition to the exemptions for cross-border transfer of personal data provided in Section 28 of the PDPA (i.e., whitelist countries and other exemptions), Section 29 provides two additional mechanisms for the cross-border transferring of personal data, that is (1) cross-border transfer of personal data within inter-affiliate companies, provided that the personal data protection policy (also known as “Binding Corporate Rules” or “BCR”) is reviewed and certified by the PDPC; and (2) where in the absence of whitelist country (i.e., per Section 28) and the BCR has not been reviewed and certified by the PDPC, a data controller may cross-border transfer personal data provided that an appropriate safeguard that ensures the enforceability of personal data subject’s rights and a legally remedial measures has been put in place.

In this regard, the Notification sets out the required characteristics of the BCR and the appropriate safeguard as follows:

  1. The legitimacy and enforceability of BCR against the juristic person, natural person, involving data controllers, data processors, and receivers of personal data within the same affiliated company, provided that such enforceability shall be extended to the employees and personnel involved in the transferring and receiving of personal data.
  2. The terms that ensure the protection of personal data, the rights of the data subject, and the right to file a complaint in relation to the transferred personal data.
  3. The security measures shall be in accordance with those prescribed under the personal data protection law.

The referred to appropriate safeguard could be in the form of either (1) a data transfer agreement; (2) a personal data collection, use, and disclosure certification; or (3) a bilateral agreement between international organizations or agencies.

The Notification went further to prescribe that the data transfer agreement mentioned above could be either of the following: (1) the agreement between the transferring and receiving parties with the required contractual clauses; (2) ASEAN Model Contractual Clauses for Cross-Border Data Flows; or (3) Standard Contractual Clauses for the Transfer of Personal Data to Third Countries issued pursuant to Article 46 (1), (2) (c), and 28 (7) of Regulation (EU) 2016/679 or the European Union General Data Protection Regulation, commonly known as GDPR.

The Notification consists of great details; international organizations or corporations may be required to closely monitor the development of this Notification until its publication and enforcement. It seems that PDPC has its interpretation and does not follow that of GDPR. Thus, it is necessary for the data controller that follows the practice in the EU to revisit this issue, especially those who rely upon the Standard Contractual Clauses (“SCC”).

In the EU, many EU-related companies adopted SCC, which are pre-approved contractual clauses issued by the European Commission that can be used by organizations to ensure adequate safeguards for data transfers to countries outside the EU. While SCC provides a more straightforward and less time-consuming solution for organizations, it is standardized contractual clauses that cannot be modified. BCR provides more flexibility and customization options compared to SCCs. It can be customized to align with the specific requirements of a business. Once implemented and operational, BCR is significantly easier to manage in comparison to intra-group contracts that include SCC. Additionally, BCR establishes a rigorous level of compliance with the PDPA as it requires approval from PDPC, thereby reducing the business’s vulnerability and being recognized as the benchmark for achieving compliance. It is suitable for multinational organizations with subsidiaries or affiliates in different countries.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPC Notification on Security Standards for Personal Data Controllers Exempted from PDPA

The Office of Personal Data Protection Commission (PDPC) conducted a public hearing on the draft PDPC Notification Concerning the Security Standards for Personal Data under Responsibility of Data Controllers exempted from the enforcement of the Personal Data Protection Act B.E. 2562 (2019) (PDPA) (“Notification”). This public hearing occurred from 17 October 2023 to 31 October 2023.

Under Section 4 of the PDPA, certain data controllers, including public authorities, the media, the House of Representatives, the Senate, the Parliament, the courts, and the credit bureau, are exempted from the enforcement of the PDPA. However, Section 4 paragraph 3 of the PDPA mandates that these exempted data controllers must implement security measures to protect personal data.

black android smartphone on top of white book

The draft Notification sets out the security measures that exempted data controllers must adhere to. These measures are similar to those prescribed in the PDPC’s Notification on Security Measures for the Protection of Personal Data B.E. 2565 (2022). The key measures include:

  1. Implementing organizational, technical, and physical measures to safeguard personal data, regardless of its form (physical or digital).
  2. Ensuring the confidentiality, integrity, and availability of personal data.
  3. Extending security measures to servers, software, or applications for storing or processing personal data.
  4. Implementing access control, identity proofing and authentication, need-to-know basis access, user access management, determination of user responsibilities, and personal data audit trails.
  5. Raising awareness about privacy and security among employees or users with access to personal data.
  6. Adopting pseudonymization or encryption measures to minimize the risk of unauthorized or unlawful processing of personal data.

The enforcement of these measures will be closely monitored once the draft Notification becomes enforced.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Personal Data Protection for NBTC license holders

The Notification on Protecting User Rights Regarding Personal Data, Rights to Privacy, and Freedom of Communication through Telecommunications Service (“Notification”) was approved by the National Telecommunications Commission. The Notification has been officially published in the Royal Gazette and became effective since September 4, 2023.

Key provisions of the Notification include:

Section 6 stipulates that license holders must obtain separate consent from users before using or disclosing their personal data for purposes other than operating the telecommunications business. License holders must clearly inform users about the scope and objectives of the business, the types of personal information that will be used or disclosed, and any third parties involved. Users must be provided with the option to confirm or revoke their consent. License holders must comply with the conditions specified in the notification and any additional requirements imposed by the NBTC. The language used must be clear and easily understandable, without misleading users about the purpose. Consent may be obtained in writing or through technological means. However, users’ consent or withdrawal should not interfere with their use of telecommunications services.

two person standing under lot of bullet cctv camera

Section 7 outlines the details regarding sensitive data, which includes race, ethnicity, political opinions, beliefs, sexual behavior, criminal record, health record, disabilities, union information, genetic data, biological data, and any other data specified in the Personal Data Protection Law that may affect users.

Section 10 addresses the notification requirements for collecting personal data. Generally, license holders must inform consumers during or before collecting their personal data. However, when collecting data from other sources, license holders must notify the data subject within 30 days from the collection date. License holders are not required to notify when the collection does not require consent under Sections 6 and 7.

Section 14 states that if a violation poses a high risk to individuals’ rights and freedoms, license holders must immediately notify the NBTC within 24 hours of recognizing the violation. The notification must include a remediation measure for affected users.

Section 20 mandates that license holders must publicly announce their policies to protect users’ rights to personal information, privacy, and freedom of communication through telecommunications. These policies must be in accordance with the notification and the personal data protection law and should be displayed on the license holders’ website, place of service, application form, and service agreement. Additionally, these policies must be approved by the NBTC.

Given these revisions, it is crucial for all license holders to update their practices to ensure compliance with the personal data protection policies. The protection of personal information is of utmost importance, particularly in the telecommunications industry.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Certified Courses and Training Program for DPO and Registered Instructor

The Office of the Personal Data Protection Committee (“Office”)  has launched an Announcement of the Office of the Personal Data Protection Committee (“Committee”) Re: Criteria for Certified Courses and Training Programs for the Data Protection Officer and Registered Instructor (“Announcement”) and its guidelines on 8 August 2023 in order to provide knowledge and understanding in both legal terms and practical proceedings, for the Data Protection Officer (“DPO”) and those who are registered instructors and training agencies in order comply with the Personal Data Protection Act B.E. 2562 (2019) (“PDPA“).

This Announcement sets guidelines for 2 main matters with the details as follows:

1.Certified courses and training programs

Agencies or institutions that would like the Office to certify their courses and training programs must apply for the same via an official email at course@pdpc.or.th. After consideration, the Committee will deliver its opinion to the Secretary-General of the Personal Data Protection Committee (“Secretary-General”) for its final consideration. Those who have been certified will be published to the public.

two person standing under lot of bullet cctv camera

2.Registered instructors

While the agencies or institutions are registered per item 1, any person who would like to register himself/herself to be a registered instructor can apply for the same via email at course@pdpc.or.th. If the applicant’s qualifications meet the requirements, the applicant must attend the seminar and take some exams organized by the Office. After that, the registration process will be completed, and his/her name will be announced to the public. The registration will be valid for one year and will need to be renewed by attending further seminars.

This Announcement has been effective as of the date of publication. Currently, there is no civil liability, administrative liability, or criminal penalty applied to the agencies or institutions in case of non-compliance with the PDPA and its guidelines. The Office aims to encourage the agencies or institutions to attend the training programs to understand the provisions of PDPA and then they can distribute their knowledge to the DPO.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Types of Business and Agency in which Certain Parts of the PDPA Shall not Be Applicable

Previously, on June 1st, 2022, the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) came into force, imposing obligations on any person who collects, uses, or discloses personal data.  

A data controller is defined as a person or juristic person having the power and duties to make decisions regarding the collection, use, or disclosure of personal data. Under the PDPA, the data controller shall be imposed with various obligations, for example, notifying of personal data collection, obtaining consent (if applicable), and having in place security measures, etc.

On July 11th, 2023, the cabinet approved the Draft Royal Decree Prescribing Types of Business and Agency in which certain parts of the PDPA shall not be applicable B.E. …. (the “Draft Royal Decree”). The Draft Royal Decree is intended to exempt certain obligations of the certain types of data controller, in order to ease their usual objectives or operations. Essentially, the key provisions of this Draft Royal Decree are, (1) certain obligations under the PDPA may be exempted where the collection of personal data is for the public interest, and such government agency is authorized by law; (2) consent for disclosure of personal data may not be required where the government agency is authorized to do so according to the law; and (3) the Draft Royal Decree reaffirm the data subject’s right to file a request to the Personal Data Protection Committee (“PDPC”) for interpretation of various matters.  

white caution cone on keyboard

According to the summary of the cabinet’s minutes by the government’s spokesperson, the certain government agencies may be exempted from the obligations under Part 2 ‘Personal Data Collection’ and Part 3 ‘Use or Disclosure of Personal Data’ of the PDPA to the extent that their processing of personal data is in accordance with the exemption’s conditions and purposes of personal data processing (prescribed under the Draft Royal Decree).  

That being said, we also noted that the summary of the Draft Royal Decree by the government spokesperson signifies that there has been a significant amendment from the previously published version (the Ministry of Digital Economy and Society’s Results of Public Hearing Group 2). In the previous version, it was also specified the cases where other types of data controllers (i.e., not government agencies) may be exempted from certain obligations. For example, where the data controller’s purposes for processing of personal data would be tampered by complying with the personal data collection notification requirements, then such data controller may be exempted from the said obligations.  

businesspeople talking

At this stage, the approved Draft Royal Decree shall soon be published in the Royal Gazette. Monitoring of this publication and enforcement of this Draft Royal Decree may be of the essence to all data controllers and/or data processors who are subjected to the PDPA’s obligations. As the exemption may be applicable to their cases as well.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Monitoring of Personal Data or the System that Requires an Appointment of DPO

Section 41 (2) of the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) prescribed that the data controller and the data processor shall designate a data protection officer (“DPO”) if the activities of the data controller/processor in the processing of personal data require regular monitoring of personal data or the system, by reason of having a large number of personal data as prescribed and announced by the Personal Data Protection Committee (“PDPC”).  

Given that the PDPA has been in effect for a year, many organizations in Thailand are still unsure whether they are required to appoint a DPO or not. As a result, the PDPC is considering the Draft Notification of the PDPC re: data controllers and data processors who collect, use, or disclose personal data that requires regular monitoring of the personal data or the system due to a large scale of personal data that must appoint a DPO, B.E. …. (the “Draft Notification”). This Draft Notification was posted on the Law Portal on July 13th, 2023, for the public to consider and express their opinion (public hearing closes on July 27th, 2023).  

software engineer standing beside server racks

Under the Draft Notification, the PDPC intends to clarify 3 following criteria, (1) what constitutes a core activity; (2) what is meant by regular monitoring of personal data or the system; and (3) how to determine if a data controller or data processor is having a large number of personal data. The summary is as follows:  

1. Core Activities:

The core activities are defined under the Draft Notification as actions required to achieve the data controller’s or data processor’s business objectives or goals.  

2. Regular Monitoring of Personal Data or the System:

The Draft Notification deems that a data controller or data processor regularly monitors personal data or the system, if the core activities of the said data controller or data processor systematically or regularly track, monitor, or predict data subject’s behavior (i.e., profiles).  

Additionally, the Draft Notification also prescribed scenarios where the processing of personal data would automatically be deemed to require regular monitoring, example includes:

  • Processing of personal data relating to the holder of a membership card, electronic card, or any other card that allows the card service provider or any other person to review the card usage information.
  • Processing of personal data for the purpose of behavioral advertising.
  • Processing of personal data for security purposes.

3. A Large Number of Personal Data:

Further, the Draft Notification sets out the criterion in which the data controller or data processor shall determine if their processing of the personal data is considered to be on a large scale or not. The criteria are as follows: (1) the proportion of the number of data subjects and the amount of personal data; (2) the quantity and type of personal data; (3) retention period and permanence; and (4) territorial or geographical scale of personal data collection.  

black android smartphone on top of white book

Additionally, the Draft Notification also prescribed scenarios where the processing of personal data would automatically be deemed to be of a large scale, example includes:  

  • Processing personal data for the purpose of behavioral advertising through the use of search engines or social media.
  • Processing of personal data by a type 3 telecommunication business operator.

By reading this far, you probably have the idea of whether your organization would need to appoint a DPO or not, but please note that organizations whose DPO performs duties or tasks other than data protection must consider the scope of his/her duties or tasks and warrant to the PDPC office that his/her duties or tasks do not conflict with the DPO’s main duties under the PDPA. The Data Controller and Data Processor should read this Draft Notification carefully and monitor the development of this Draft Notification.

It is crucial for all data controllers and data processors to note that if subjected but fail to appoint the DPO as required by the PDPA, they may be subject to an administrative fine of up to 1 million Baht.  

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles