The Personal Data Protection Act (PDPA)

Visa questions, companies, work permits, employment, insurance, banking and finance, and legal issues.
User avatar
Big Boy
Moderator
Moderator
Posts: 45347
Joined: Fri Nov 04, 2005 7:36 pm
Location: Bon Kai

The Personal Data Protection Act (PDPA)

Post by Big Boy »

This law comes into force in Thailand tomorrow, and from what I can see it looks to be a mess. I wonder if it is just yet another Thai law that will be ignored, or if somebody will actually try to enforce it. Penalties for non-compliance include a maximum prison term of six months or a fine of up to 500,000 baht. Illegal abuse of personal data carries up to one year in jail or a fine of as much as 1 million baht.

My son often enters his students into competition, where essential information often includes (list follows for Tapatalk users):
  • name
  • date of birth
  • phone number
  • e-mail address
  • ID card number
  • passport number
  • weight
  • height
Disclosure of any of the above are now deemed illegal.

Exemptions are granted in cases of: Fulfilling contractual obligations involving the data subject; serving the public interest, such as statistical research to protect the public health; and serving legitimate interests, such as prevention of danger to an individual.

I guess, in the future, my son will be handing entry forms to students, and telling them to get on with it. My son also maintains a database holding the above information. I guess, with the exception of name, which is pretty fundamental to everything people based, that needs to be scrapped as well.

My son can't be unique. How are others going to be dealing with this law?
Championship Stoke City 3 - 0 Plymouth Argyle :cry: :cry: :cry: :cry:

Points 48; Position 20
User avatar
PeteC
Moderator
Moderator
Posts: 30147
Joined: Tue Mar 23, 2004 7:58 am
Location: All Blacks training camp

Re: The Personal Data Protection Act (PDPA)

Post by PeteC »

I think disclosure is legal with the person's consent. I've seen that said in a few articles. I'll keep my eyes open for more details.
Governments are instituted among Men, deriving their just powers from the consent of the governed. Source
User avatar
STEVE G
Hero
Hero
Posts: 12911
Joined: Mon Apr 03, 2006 3:50 am
Location: HUA HIN/EUROPE

Re: The Personal Data Protection Act (PDPA)

Post by STEVE G »

There's been a similar law in the EU and UK since 2018, I have to do a course about it every year.
If Thailand is the same, it's more about not storing personal data that you don't legitimately need and not passing it on to others. It's basically about stopping companies from harvesting data and selling it on.
User avatar
PeteC
Moderator
Moderator
Posts: 30147
Joined: Tue Mar 23, 2004 7:58 am
Location: All Blacks training camp

Re: The Personal Data Protection Act (PDPA)

Post by PeteC »

Here's one example below.

phpGBOIwBAM.jpg
phpGBOIwBAM.jpg (57.19 KiB) Viewed 349 times
Governments are instituted among Men, deriving their just powers from the consent of the governed. Source
User avatar
PeteC
Moderator
Moderator
Posts: 30147
Joined: Tue Mar 23, 2004 7:58 am
Location: All Blacks training camp

Re: The Personal Data Protection Act (PDPA)

Post by PeteC »

If the student is a minor under 18 I'm assuming the consent has to come from a parent.
Governments are instituted among Men, deriving their just powers from the consent of the governed. Source
User avatar
Big Boy
Moderator
Moderator
Posts: 45347
Joined: Fri Nov 04, 2005 7:36 pm
Location: Bon Kai

Re: The Personal Data Protection Act (PDPA)

Post by Big Boy »

PeteC wrote: Tue May 31, 2022 2:43 pm Here's one example below.


phpGBOIwBAM.jpg
HaHa, I thought great, a consent form that I could copy for my son to adapt. The QR Code produced https://qrco.de/bd244p (I'll let you guys work that out for yourselves :laugh: ), but then I changed the final P to upper case (as it was on my scanner). I now have something we can work with - thanks Pete.

On this same subject, and probably part of the same act, I saw a couple of days ago it will no longer be possible to post photos without permission of every person in the photo. I also run a football fan page. Are they saying photos like this will be illegal from tomorrow?
crowd.jpg
crowd.jpg (140.5 KiB) Viewed 313 times
I posted the above photo when it was still legal (still legal until tomorrow). Does this mean the next time I feature in a published crowd scene, I can sue the arse off the photographer?

The PC fairies seem to have won. The lunatics are running the asylum :cuss:
Championship Stoke City 3 - 0 Plymouth Argyle :cry: :cry: :cry: :cry:

Points 48; Position 20
User avatar
PeteC
Moderator
Moderator
Posts: 30147
Joined: Tue Mar 23, 2004 7:58 am
Location: All Blacks training camp

Re: The Personal Data Protection Act (PDPA)

Post by PeteC »

I think it's okay if everyone has a mask on. :duck:
Governments are instituted among Men, deriving their just powers from the consent of the governed. Source
User avatar
PeteC
Moderator
Moderator
Posts: 30147
Joined: Tue Mar 23, 2004 7:58 am
Location: All Blacks training camp

Re: The Personal Data Protection Act (PDPA)

Post by PeteC »

I reduced the announcement from FB and subsequently the QR code was reduced as well. Here is a bigger size in case easier to scan and anyone else needs an example.

Screen Shot 2022-05-31 at 15.49.47.png
Screen Shot 2022-05-31 at 15.49.47.png (123.6 KiB) Viewed 305 times
Governments are instituted among Men, deriving their just powers from the consent of the governed. Source
User avatar
Big Boy
Moderator
Moderator
Posts: 45347
Joined: Fri Nov 04, 2005 7:36 pm
Location: Bon Kai

Re: The Personal Data Protection Act (PDPA)

Post by Big Boy »

PeteC wrote: Tue May 31, 2022 3:41 pm I think it's okay if everyone has a mask on. :duck:
LOL, I thought that when I viewed the post as well :laugh:

Seriously though, the world is going mad.
Championship Stoke City 3 - 0 Plymouth Argyle :cry: :cry: :cry: :cry:

Points 48; Position 20
User avatar
Big Boy
Moderator
Moderator
Posts: 45347
Joined: Fri Nov 04, 2005 7:36 pm
Location: Bon Kai

Re: The Personal Data Protection Act (PDPA)

Post by Big Boy »

PeteC wrote: Tue May 31, 2022 3:51 pm I reduced the announcement from FB and subsequently the QR code was reduced as well. Here is a bigger size in case easier to scan and anyone else needs an example.


Screen Shot 2022-05-31 at 15.49.47.png
Or, instead of scanning the QR Code and clicking the resultant link, you could just use the URL that all roads lead to https://www.bangkokpattayahospital.com/ ... cy-en.html
Championship Stoke City 3 - 0 Plymouth Argyle :cry: :cry: :cry: :cry:

Points 48; Position 20
User avatar
PeteC
Moderator
Moderator
Posts: 30147
Joined: Tue Mar 23, 2004 7:58 am
Location: All Blacks training camp

Re: The Personal Data Protection Act (PDPA)

Post by PeteC »

Here's an abbreviated version of requirements/consent from a law office that may be helpful.

https://www.lawplusltd.com/2019/10/data ... e-consent/
Governments are instituted among Men, deriving their just powers from the consent of the governed. Source
User avatar
PeteC
Moderator
Moderator
Posts: 30147
Joined: Tue Mar 23, 2004 7:58 am
Location: All Blacks training camp

Re: The Personal Data Protection Act (PDPA)

Post by PeteC »

Police advise public on new personal data protection law

https://www.bangkokpost.com/thailand/ge ... ection-law
Governments are instituted among Men, deriving their just powers from the consent of the governed. Source
User avatar
Big Boy
Moderator
Moderator
Posts: 45347
Joined: Fri Nov 04, 2005 7:36 pm
Location: Bon Kai

Re: The Personal Data Protection Act (PDPA)

Post by Big Boy »

LOL another defamation type scam. If I feel personally damaged by somebody taking my photo in a crowd, I can sue the publisher of that photo. Bonkers.
Championship Stoke City 3 - 0 Plymouth Argyle :cry: :cry: :cry: :cry:

Points 48; Position 20
User avatar
Big Boy
Moderator
Moderator
Posts: 45347
Joined: Fri Nov 04, 2005 7:36 pm
Location: Bon Kai

Re: The Personal Data Protection Act (PDPA)

Post by Big Boy »

PeteC wrote: Tue May 31, 2022 4:40 pm Here's an abbreviated version of requirements/consent from a law office that may be helpful.

https://www.lawplusltd.com/2019/10/data ... e-consent/
Thank you. I'm already in the process of drafting something for my son.
Championship Stoke City 3 - 0 Plymouth Argyle :cry: :cry: :cry: :cry:

Points 48; Position 20
User avatar
PeteC
Moderator
Moderator
Posts: 30147
Joined: Tue Mar 23, 2004 7:58 am
Location: All Blacks training camp

Re: The Personal Data Protection Act (PDPA)

Post by PeteC »

What is PDPA, Thailand's new data law?

https://www.bangkokpost.com/business/23 ... -data-law-

Thailand's drive to provide more comprehensive online safety for individuals begins today with enforcement of the Personal Data Protection Act (PDPA).

Major firms welcomed the enforcement as it was pushed back twice because of the pandemic.

What does Thailand's first law governing data protection entail?

The PDPA is Thailand's first law created to govern data protection. It sets forth requirements for data controllers and data processors, including both public and private entities, on how to receive consent from data subjects before processing, collecting or disclosing personal data.

Data subjects also have the right to request access to their personal data and demand for such data to be erased. They also have the right to object to the collection, usage or disclosure of their personal data.

The act, which has seven chapters and 96 sections, was published in the Royal Gazette on May 27, 2019, with a one-year grace period allowing stakeholders to adjust.

Data protection officers (DPO) must be appointed for government bodies and firms with large-scale data processing. A DPO is responsible for helping the organisation ensure that subjects' personal data is processed in compliance with the PDPA requirements and serves as a contact point for PDPA issues with the authorities and data subjects.

What is considered personal data?

The definition of personal data, as defined in the Royal Gazette, is translated as "any information relating to a person that enables that person to be identified, whether directly or indirectly. This does not extend to information related to deceased persons in particular."

The PDPA is meant to prevent and thwart the misuse of personal data. The act is among the 12 digital-related laws the Thai government introduced as part of its digital economy transformation roadmap.

Digital Economy and Society Minister Chaiwut Thanakamanusorn said the new law would play a crucial role in supporting a digital-driven economy. The government projects digital-related business to generate 30% of GDP in five years.

What are the penalties for breaching Thailand's PDPA?

The Royal Gazette outlines three types of liabilities: criminal, civil and administrative. The penalties are subject to the extent and types of violations, ranging from a few thousand baht to 5 million.

Phongphan Polyiem, a lecturer and lawyer who specialises in human resources and Thai labour law, provided a few examples during a seminar on the PDPA that could result in fines of up to 500,000 baht and/or imprisonment for up to six months.

He said taking someone's photo directly off Google to edit and/or add messages, whether it is supporting or criticising the person, is considered a violation of the PDPA. Posting about someone's illness and health data on social media platforms or issuing a notice to a specific employee through a mass Line group chat with other employees in it are also examples of violations.

The criminal penalties include fines of up to 1 million baht and/or imprisonment for up to one year, while non-compliance with administrative rules could result in fines of up to 5 million baht and punitive damages up to twice the amount of the actual damages.

Is Thailand ready to implement the PDPA?

According to a PDPA readiness survey by the Thai Board of Trade and the University of the Thai Chamber of Commerce, only 8% of almost 4,000 businesses interviewed said they have taken measures to be fully compliant with the law, while 31% indicated they have not even started the process of compliance.

Somchai Lertsutiwong, chief executive of Advanced Info Service, the country's biggest mobile operator by subscriber base, said the company has been studying, developing and improving tools and processes to ensure compliance since the PDPA was published in 2019. He said the company is now fully ready for the legislation's enforcement.

Stephen James Helwig, interim chief corporate affairs officer for Total Access Communications (DTAC), the country's third-biggest mobile operator, said the company implemented its privacy policy and readiness projects since the General Data Protection Regulation came into effect in Europe in 2018. This means DTAC collects, stores and manages users' personal data in compliance with the PDPA, while its policy details the opportunities clients have to monitor and manage their personal data.

"The enforcement of the PDPA on June 1 marks a milestone for privacy protection and data security for customers in Thailand," Mr Helwig said.

As for international firms, Alibaba Cloud, the cloud computing service arm of Chinese e-commerce giant Alibaba Group, recently launched its first data centre in Thailand last month with 1.06 billion baht in registered capital.

Tyler Qiu, Thailand country manager for the firm, said the data centre secured ISO 27001 and ISO 20000 certificates. It is compliant with Thailand's PDPA regulations and the financial regulatory guidelines issued by the Bank of Thailand.

However Pranontha Titavunno, a board director of the Federation of Thai Industries, said the majority of small businesses that have suffered from the impact of the pandemic over the past two years are still unprepared for PDPA compliance.

What is the government's position on enforcement?

The government said the enforcement of penalties would be relaxed in the first year of implementation if violators did not intend to commit a wrongdoing, as it is a transitional period when the development of understanding about the law and mediation for disputes would still be required.

Paiboon Amornpinyokiat, a member of the Personal Data Protection Committee legal subcommittee, said in the first year of the PDPA's implementation, the authorities will focus only on issuing warnings to violators and urging them to comply with the guidelines.

The core task in the first year is to protect people's rights to data protection, while ramping up efforts to boost understanding of the law among related parties, he said.

"The government wants the law to support the digital economy -- it is not intended to seek money from fines for the state," Mr Paiboon said.

He said a subordinate regulation would be issued to spare small and medium-sized enterprises from being obliged to comply with the PDPA's practices on the recording of processing activities.
Governments are instituted among Men, deriving their just powers from the consent of the governed. Source
Post Reply