Recently, there are four decisions made from Thai Expert Committee under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) implying that there is no relaxation of PDPA enforcement.
最近,泰國專家委員會根據佛曆2562年(2019)《泰國個人資料保護法》(PDPA)做出四項決定,意味著 PDPA 的執行不會放寬。
On 18 October 2023, he Personal Data Protection Committee (PDPC) published the first decision made by the Expert Committee on the imposition of administrative measures against company pursuant to authority granted under the Notification of the PDPC Re: Rules for the Consideration of the Imposition of Administrative Penalties by the Expert Committee B.E. 2565 (2022). After that, on 19, 25 October and 15 November 2023, three additional Expert Committee decisions were published.
在2023 年 10 月 18 日,個人資料保護委員會 (PDPC) 公佈專家委員會根據《PDPC 通知: 佛曆2565年(2022)行政處分專家委員會審議規則》做出的第一個決定。在這之後,在2023年10月19日及25日以及11月15日,又發布三個專家委員會決定。
Case on 18 October 2023
2023年10月18日的案件
An insurance company appeared to have obtained the personal data of the complainant from another source prior to the PDPA becoming fully effective (i.e., June 1, 2022).
一家保險公司似乎在 PDPA 全面生效之前(即 2022 年 6 月 1 日)從其他來源取得申訴人的個人數據
The Expert Committee ordered the insurance company to:
專家委員會命令保險公司:
Ø Comply with its obligations under the PDPA regarding the collection of personal data from another source;
遵守 PDPA 規定的有關從其他來源收集個人資料的義務;
Ø Delete the personal data of the complainant;
刪除申訴人的個人資料;
Ø Take action to suppress damage, starting from the date of receiving the order;
自收到訂單之日起,採取行動抑制損害;
Ø Stipulate measures to prevent the occurrence of similar cases;
制定措施防止類似案件發生;
Ø Set forth and implement guidelines for complying with the provisions of the PDPA on the right of access, right to rectification, obligation to implement a monitoring system for the deletion of personal data.
制定並實施指導方針,以遵守PDPA有關存取權、糾正權、實施個人資料刪除監控系統義務的規定。
The Expert Committee also ordered the company to report to the Office of the PDPC the outcome of the actions taken in relation to the five items above within 30 days of receiving the order.
專家委員會也命令該公司在收到命令後30天內向PDPC辦公室報告針對上述五項採取的行動結果。
Case on 19 October 2023
2023年1月19日的案件
Complainant stating that a mobile banking application service provider did not allow him to give consent freely in the application. By the time the case came before the Expert Committee, the service provider had already amended its consent request format to be compliant with the requirements of the PDPA. Also, the complainant wanted to withdraw his complaint. As the complaint wanted to withdraw this case, it is closed.
申訴人稱一家手機銀行應用程式服務供應商不允許他在應用程式中自由表示同意。當案件提交給專家委員會時,服務提供者已經修改其同意請求格式,以符合 PDPA 的要求。此外,申訴人希望撤回申訴。由於申訴人要求撤訴,本案已結案。
Case on 25 October 2023
2023年10月25日的案件
Data controller sent to the complainant an e-mail informing that he could issue transportation card via electronic system if he must first provide his personal data in order to access the transportation card issuance system. Therefore, the complainant received another e-mail from the data controller reporting that his transportation card benefit had been suspended, and he had accepted this suspension when he gave consent to the processing of personal data as required by the data controller. This was contrary to the complainant’s understanding that the consent was for the issuance of a transportation card only, rather than for the suspension of his rights.
資料控制者向申訴人發送了一封電子郵件,通知他如果必須先提供個人資料才能存取交通卡發行系統,可以透過電子系統向他發行交通卡。因此,申訴人收到資料控制者發來的另一封電子郵件,報告其交通卡福利已被暫停,當他同意按照資料控制者的要求處理個人資料時,他就接受這項暫停。這與申訴人的理解相反,申訴人的同意只是為了發放交通卡,而不是為了中止其權利。
The data controller must notify the Office of the PDPC of the outcome of remedial actions pursuant to the above order or to take any action to suppress damage within 30 days from the date of receiving the order.
資料控制者必須在收到命令之日起 30 天內,將根據上述命令採取的補救措施的結果通知 PDPC 辦公室,或採取任何行動來抑制損害。
Case on 15 November 2023
2023年11月15日的案件
A complaint filed case to the Expert Committee stating that his name and image of his medical license were acquired by another person who pretended to be a licensed healthcare professional, which led to the service recipients and the public being misled and the complainant suffering damage to his reputation. However, the Expert Committee claimed that the complaint did not verify that the accused is a data controller who violated or failed to comply with the PDPA. Hence, the Expert Committee was unable to make a determination of the complaint.
申訴人向專家委員會申訴,指申訴人的姓名及行醫執照圖像被冒充執業醫護人員的人士取得,導致服務對象及公眾受到誤導,投訴的聲譽蒙受損失。他的聲譽然而,專家委員會聲稱,投訴並未證實被告是違反或未遵守《個人資料保護法》的資料控制者。因此,專家委員會無法就申訴作出裁決。
#personaldataprotection #personaldataprotectionact #personaldataprotectioninthailand #PDPA #個人資料保護 #個人資料保護法 #泰國個人資料保護 #thailaw #泰國法律 #泰國中文律師 #IBC法律金融會計事務所 #泰國律師 #泰國法律事務所 #泰國律師事務所 #泰國會計 #泰國審計 #泰國會計事務所 #泰國審計事務所 #法律顧問 #泰國會計師 #泰國華人律師事務所 #thaiaccountant #thailawyer #IBCFirm #ThaiLawFirm #ThaiAccountingFirm
Comments