Employee Personal Data Protection Policy (Internal Use). This Policy is established for internal use within the Company to govern the collection, use, disclosure, or other processing of employees’ personal data. It also sets out guidelines for employees of the Company who are required to perform any actions involving personal data in the course of their duties.
Goal
Following the enactment of the Personal Data Protection Act B.E. 2562 (2019), which came into effect on June 1, 2022, the Company places great importance on compliance with applicable laws, including the protection of employees’ personal data. To ensure that the collection, use, disclosure, and retention of employees’ personal data are carried out in accordance with the requirements of the aforementioned law, the Company has established this Employee Privacy Policy for Internal Use. This Policy applies to any processing of employees’ personal data within the Company and serves as a guideline for employees who are required to handle or process personal data in the course of their duties.
2. Scope of the Policy and Practice Guidelines
This Policy and its guidelines are established to set out the Company’s framework for handling employees’ personal data. It also provides guidance for employees who have duties, responsibilities, or assignments involving the handling or processing of personal data as a result of the enforcement of the Personal Data Protection Act B.E. 2562 (2019). Under this Policy, the Company may act as either a Data Controller or a Data Processor, as defined under the law, depending on the circumstances.
3. Definitions
Personal Data means any information relating to an identified or identifiable natural person ("Data Subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Sensitive Data means Personal Data pertaining to racial or ethnic origin, political opinions, cult, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data, or any data which may affect the Data Subject in the same manner, as prescribed by the Committee.
– Data Subject means a natural person who is the owner of the Personal Data.
- Data Controller means a person or a legal entity that has the authority and responsibility to make decisions regarding the collection, use, or disclosure of personal data.
– Data Processor means a Person or a legal entity that operates in relation to the collection, use, or disclosure of Personal Data pursuant to the orders given by or on behalf of a Data Controller, where such Person or legal entity is not the Data Controller.
– The Office means the Office of the Personal Data Protection Commission.
– The Committee means the Personal Data Protection Committee.
– The Company means YIPINTSOI NEXT COMPANY LIMITED and its affiliates.
– Employee means any individual whom the Company has agreed to employ under an employment agreement, regardless of the title or designation used.
4. Key Elements of the Employee Personal Data Protection Policy
4.1 The Company regards the protection of personal data as a matter of utmost importance, including the personal data of its employees.
4.2 Accordingly, the Company will collect, use, or disclose employees’ personal data only to the extent necessary for administrative purposes or for lawful purposes. Such purposes include, but are not limited to, the following:
For human resource management, employee welfare, and occupational health administration.
– For use in bidding, proposals, or submissions to clients, or for conducting the Company’s business in accordance with its business objectives.
For marketing activities or corporate public relations where it may be necessary to present information relating to employees.
– For submission or disclosure to government authorities as required by applicable laws or as requested or ordered by competent government officials, such as tax submissions to the Thai Revenue Department.
If it becomes necessary to collect personal employee data beyond the purposes specified above, the Company will notify employees and obtain additional consent on a case-by-case basis.
4.3. The Company may Collect, Use, or Disclose Personal Data solely in accordance with the specified purposes.
4.4. The Company shall clearly define the duties of data collectors, data processors, data custodians, data users, and approvers of data use, including verification procedures, to ensure that Personal Data is securely maintained and utilized in good faith.
4.5. The Company may Collect, Use, or Disclose Personal Data only upon receiving explicit written consent or consent via electronic means from the Data Subject.
4.6. The Company may Collect, Use, or Disclose Personal Data without obtaining consent from the Data Subject in the following cases:
To prevent or suppress a danger to a person's life, body, or health.
2) It is necessary for the performance of a contract, such as an employment contract.
3) It is necessary for the legitimate interests of the Company, such as CCTV recordings.
4) It is for compliance with applicable laws for the Company, such as submitting data to the Revenue Department or complying with labor protection laws.
4.7. The Company shall not Collect, Use, or Disclose Sensitive Data of Employees, except in the following cases:
1) Explicit consent is obtained in writing or via electronic means from the data subject.
2) To prevent or suppress a danger to life, body, or health of the Person, where the Data Subject is incapable of giving consent for any reason.
3) This is information that is disclosed to the public with the explicit consent of the Data Subject.
4) It is necessary for the establishment, compliance, exercise, or defense of legal claims.
5) It is necessary to comply with a law, labor protection, social security, or other related matters.
4.8. The Employee, as the Data Subject, has the right to easily view, verify, and access their Personal Data, including requesting a copy of their Personal Data retained at any time, and has the duty to provide additional information in the event of changes to Personal Data or to submit information in the event that relevant organizations or agencies request further information.
4.9. The Company shall notify the Data Subject of the following information prior to the Collection of Personal Data:
1) The purpose for the collection, use, or disclosure of personal data. If the Company alters such purpose, the Company must notify the Data Subject and obtain consent again.
The retention period throughout the duration of the Company's employment, and the retention of Personal Data of former Employees from the date the employment relationship between the Employee and the Company terminates for a period not exceeding 10 years, in accordance with the duration prescribed by relevant laws, taking into account the statutory prescription period for legal proceedings that may arise from or relate to the documents or Personal Data collected by the Company. Upon the expiration of such retention period, the Company shall delete, destroy, or anonymize the Personal Data so that it can no longer identify the Data Subject.
3) The categories of persons or entities to whom the personal data collected by the organization may be disclosed.
4) Information concerning the organization’s contact channels, methods, and locations.
5) The rights of the Data Subject under the Personal Data Protection Act B.E. 2562 (2019).
6) If you are required to provide Personal Data to comply with a law or contract, or if it is necessary to provide Personal Data for the purpose of entering into a contract, you will be notified accordingly, including the potential consequences of failing to provide such Personal Data.
The Company shall not collect Personal Data from sources other than directly from the Employee who is the Data Subject. The Company shall maintain a clear policy prohibiting relevant Employees or those assigned to handle Employee Personal Data, such as the Human Resources Department, from collecting Personal Data from sources other than the Data Subject. Should Personal Data be obtained from another source, the Company shall notify the Data Subject within 30 days and obtain consent from the Data Subject.
4.11. The Company shall ensure that the Collected Personal Data remains accurate, up-to-date, complete, and not misleading.
4.12. The Company shall comply with lawful requests from the Data Subject, which comprise:
1) Request to access the Data Subject’s Personal Data.
Request for a copy of the Data Subject's Personal Data.
Request to restrict the use of the Data Subject's Personal Data.
4) Request to delete or destroy the Data Subject's Personal Data.
Request to disclose the acquisition of the Data Subject's Personal Data obtained without their consent.
6) Request to send or transfer the Data Subject’s Personal Data to another Data Controller, or alteration of the Data.
7) Withdrawal of consent for the Collection, Use, or Disclosure of your Personal Data.
8) Request to ensure that the Personal Data is accurate, up-to-date, complete, and not misleading.
4.13. The Company may reject the Data Subject’s request when there is a necessary ground, such as potential impact on the Personal Data of others, by recording the rejection of the request along with the reasons.
4.14. The Company shall implement appropriate security measures to protect Personal Data, not lower than the standards prescribed by law, to prevent the unauthorized or unlawful loss, access, use, alteration, correction, or disclosure of Personal Data.
4.15. The Company shall arrange for the retention and use of Personal Data in a strict and confidential manner.
4.16. The Company shall arrange for a review of security measures when necessary or when technology changes.
4.17. The Company shall arrange for regular audits of the collection, use, disclosure, deletion, or destruction of Personal Data to ensure continued compliance with the organization's policies and the law.
4.18. In the event that an external Person or agency wishes to access any Personal Data of an Employee, a written request specifying the necessity and reasons must be submitted to the Data Controller for prior approval. Disclosure or provision is prohibited without such approval.
4.19. In the event that a government agency requests an Employee's Personal Data, the Data Controller shall be notified for consideration or review prior to submission, except for routine submissions prescribed by law, such as to the Social Security Office, the Revenue Department, or the Department of Labor Protection and Welfare, which may be submitted immediately and recorded for auditing purposes.
4.20. In the event that it is necessary to transfer employee personal data abroad, an executive at the Vice President level or higher shall be the approver and shall proceed strictly in accordance with the law, solely for the purposes specified in Clauses 4.2 and 4.7(1).
4.21. The Employee Personal Data retained by the Company shall be treated as the Company’s own property. No Person shall infringe, disclose, access, utilize for personal benefit, or destroy it without approval from the Person assigned by the Company. Violators shall be subjected to the maximum penalty and/or prosecuted to the fullest extent of the law, including being liable to compensate in full for the damages incurred at the rate prescribed by law.
4.22. The retention, maintenance, use, auditing, review, approval, or any other actions regarding Personal Data under this policy shall be kept confidential as necessary and in good faith. General Personal Data of Employees shall be deemed for Internal Use, and Sensitive Data of Employees shall be deemed Confidential.
4.23. The Company shall notify the Office of any Personal Data breach within 72 hours of becoming aware of it, unless such breach poses no risk to the rights and freedoms of the Data Subject (if such breach occurs).
4.24. In the event of a high risk to rights and freedoms, the organization must notify the Data Subject of the breach and provide information on the measures taken to address it.
4.25. The Company shall prepare and maintain a record of at least the following items for inspection by the Data Subject and the Office:
The Collected Personal Data.
2) The purpose for which each category of Personal Data is collected.
3) Information regarding the Data Controller.
4) The retention period of the personal data.
5) Rights and methods to access Personal Data, including conditions for persons entitled to access Personal Data and conditions for such access.
6) The Use or Disclosure of Personal Data.
7) The denial of requests or objections.
8) Explanations regarding security measures.
4.26. The Company shall prepare and maintain a Record of Processing Activities regarding Personal Data as prescribed by the Committee.
4.27. The Company shall comply with the legal principles governing personal data protection of Thailand.
5. List of Employee Personal Data Necessary for Administration
In order for any administration of the Company related to Employee Personal Data to operate efficiently, timely, and in good faith, the organization reserves the right to request any additional Personal Data of the Employee at any time during employment.
5.1 Any Personal Data provided in the job application and supporting documents as specified by the Company will be considered necessary information for the Company to assign tasks that align with each Employee's knowledge, abilities, experience, and personal qualifications. The list of Personal Data and the reasons for its necessity will be in accordance with the documents specified by the Company.
5.2 Personal Data that the Company has the right to additionally request during employment, such as:
1) Marital status, names of spouse, and children for the provision of additional welfare or for calculating tax deductions.
2) Medical certificates, health examination results, or documents concerning medication, medical supplies, or any other equipment related to medical treatment. The Company will use these in good faith strictly in the following cases:
To provide assistance and prompt, correct treatment.
– To consider assigning or altering work assignments to suit health conditions.
– To prevent an outbreak to colleagues or the public.
3) Maps, photographs, or other information concerning the residence for considering visits during illness, maternity visits, or providing assistance for other hardships, including building good relationships with the employee’s family.
4) Registration of cars and motorcycles to authorize access to the Company’s premises or to arrange safe and adequate parking spaces.
5) Any other Personal Data that the organization deems necessary for administration or as required by law for the Company to collect in the future.
6. References
Personal Data Protection Act B.E. 2562 (2019)
– Notification of the Ministry of Digital Economy and Society Regarding Personal Data Security Standards B.E. 2563 (2020)
– Guidelines for the Protection of Personal Data for Employees for Internal Use
In the event of any processing of Employee Personal Data within the Company, and to serve as a guideline for Company Employees who have duties regarding Personal Data:
To ensure that all Company Employees prioritize compliance with the Employee Privacy Policy, or in the event that Company Employees have duties to take any action regarding Personal Data in accordance with the provisions prescribed by the Personal Data Protection Act B.E. 2562 (2019), the Company
has therefore established guidelines and requests all Employees to adopt them as an operational framework as follows:
Employees must comply with this policy if they are assigned duties to collect, use, or disclose personal data, or if they take any actions concerning personal data.
2. Standard contract forms or forms provided by the Company shall be strictly used when proceeding under Clause 1.
3. Employees shall systematically report or notify any Data Breach through the chain of command to the Data Protection Officer (DPO) or the Personal Data Protection Committee established by the Company to serve as a central unit for all policy-level operations. This is to ensure that the Company and its Employees prioritize compliance with the Company's personal data protection policies or guidelines, in alignment with and in accordance with the provisions stipulated in the Personal Data Protection Act.