Personal Data Protection Policy
Krung Thai Electric Company Limited (“the Company”) respects the privacy rights of customers, shareholders, employees, and all related parties. To ensure full legal compliance with Thailand’s Personal Data Protection Act, the Company’s Board of Directors has approved this Personal Data Protection Policy (“Privacy Policy”) to establish clear guidelines, mechanisms, oversight measures, and proper personal data management protocols.
1. Scope of Application
This Policy applies to the Company, its employees, and all parties processing personal data on the Company’s behalf.
2. Definitions
2.1 Processing means any operation performed on personal data (e.g., collection, recording, organization, storage, adaptation, retrieval, use, disclosure, transfer, dissemination, erasure, or destruction).
2.2 Personal Data means any information relating to an identifiable natural person (e.g., name, email, phone number, IP address, images, race, religion, political opinions, genetic data, biometric data).
2.3 Data Subject means the identifiable natural person to whom personal data relates.
2.4 Data Controller means the natural or legal person with authority to make decisions regarding personal data processing.
2.5 Data Processor means the natural or legal person processing personal data on the Controller’s behalf.
2.6 Company means Krung Thai Electric Company Limited.
3. Governance Framework
3.1 The Company shall establish:
(1) An organizational structure with clear roles/responsibilities for compliance;
(2) A Data Protection Officer (DPO) as required by law.
3.2 The Company shall maintain policies, standards, guidelines, and procedures aligned with legal requirements.
3.3 Continuous monitoring processes shall ensure ongoing Policy compliance.
3.4 Regular employee training programs shall reinforce data protection awareness.
4. Data Processing Principles
4.1 Processing shall be lawful, fair, transparent, and limited to necessary purposes.
4.2 Processes shall maintain data confidentiality, accuracy, and security.
4.3 Processing records shall be maintained and updated.
4.4 Clear consent mechanisms shall be implemented.
4.5 Data accuracy verification procedures shall exist.
4.6 Data transfer agreements shall comply with legal requirements.
4.7 Cross-border transfers shall meet legal standards.
4.8 Data shall be properly destroyed when no longer needed.
4.9 Risk assessments shall be conducted regularly.
5. Data Subject Rights
The Company shall establish mechanisms for exercising legal rights (access, rectification, erasure, portability, objection, restriction).
6. Security Measures
6.1 Appropriate technical/organizational measures shall prevent unauthorized access/disclosure.
6.2 Incident response protocols shall be maintained.
6.3 Breach notification procedures shall comply with legal requirements.
7. Compliance Monitoring
7.1 The Policy shall be reviewed for ongoing legal compliance.
7.2 Documentation shall be regularly updated.
8. Roles & Responsibilities
8.1 Board of Directors oversees governance implementation.
8.2 Management ensures departmental compliance.
8.3 DPO advises on compliance and monitors implementation.
8.4 Employees must follow all data protection procedures.
9. Violation Consequences
Non-compliance may result in disciplinary action and legal penalties.
10. Contact Information
Data Protection Officer: [email protected]
Address: 1643/4 New Phetchaburi Road, Makkasan, Ratchathewi, Bangkok 10400
Phone: +66 2 333 3111
Effective Date: 31 May 2022
Supplementary Guidance:
To comply with Thailand’s PDPA B.E. 2562 (2019), stakeholders should understand these key roles:
Data Subjects should exercise their rights (right to access, rectification, erasure, portability, objection, restriction) and retain evidence of consent.
Data Controllers must lawfully determine processing purposes/methods.
Data Processors must implement appropriate security measures and report breaches.
Penalties for Violations
Criminal Penalties
- Imprisonment up to 1 year
- Maximum fine of 1 million baht
Civil Liabilities
The offender shall be liable for actual damages plus punitive compensation not exceeding twice the amount of actual damages.
Administrative Sanctions
- A fine not exceeding 5 million baht may be imposed.