You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

//
INSIGHTS
//
subscribe

Subscribe to Legal Updates from Tilleke & Gibbins

Tilleke & Gibbins provides regular updates on all of the latest legal developments in Southeast Asia, ensuring that you have the up-to-date knowledge you need to navigate the ever-changing legal landscape affecting your business. You can browse our entire library of publications below, or subscribe to receive the latest legal developments straight to your inbox.

Subscribe

* indicates required
Jurisdictions
Industries
Practices

PRIVACY POLICY FOR CLIENTS

This Privacy Policy for Clients (“Privacy Policy”) explains how Tilleke & Gibbins International Ltd., and our affiliates (collectively “Tilleke” “we” “us” “our”), collects, uses, and discloses (“process” “processing”) your Personal Data in the course of our business, in accordance with the Personal Data Protection Act (2019) (“PDPA”).

We advise you to read this Privacy Policy in its entirety.

  1. When does this Privacy Policy apply to you?

This Privacy Policy applies to you if you are an individual client, or a person associated with a corporate client (including the authorized director(s), authorized representative(s) and/or the contact person(s) of the corporate client) (“associated person”). This Privacy Policy also applies even if you have not engaged Tilleke for our services, but you contact us for any purpose, such as for inquiries, or you attend a seminar which is hosted/provided by us, or you subscribe to our communications (“prospective client”).

  1. What types of Personal Data does Tilleke collect from you?

(a)        For our clients or associated persons, we collect various types of data from you, which can be used to identify you as an individual, whether directly or indirectly (“Personal Data”), including your full name, home address, personal email address, contact number(s), place of work, job title, business email address, data contained in your identification document (e.g. identification card, passport, or driver’s license), signature, and any other Personal Data you may provide to us. The national identification card we collect from you may contain Sensitive Personal Data, i.e. blood type and/or religion;

(b)        For prospective clients, the Personal Data that we collect will normally depend on how you contact us and the purpose of such contact, which may include your full name, personal or business email address, mobile phone number, and your place of work;

(c)         When you visit our office, we will collect details pertaining to your full name, place of work, contact number(s), and car license plate number, as well as photos or motion images recorded by CCTV;

(d)        In the event that you contact us via any social media platform, including, without limitation to, Facebook and LinkedIn, we may collect Personal Data which you have provided to us via such platforms. Notwithstanding that, in the case where you contact us via social media platforms, Tilleke is not responsible for the privacy or the information security practices of such platforms. Therefore, you should carefully review the applicable privacy and information security policies and notices, for any of the websites/platforms that you use; and

(e)        In certain circumstances, we may collect the Personal Data of your family member(s) such as your spouse and children, which may include Personal Data of minors, who are under 20 years of age, when it is necessary for us to provide our legal services, including, without limitation to, services related to family law matters, immigration, and work permits.

3          Why does Tilleke collect and process your Personal Data?

Tilleke collects your Personal Data for different purposes, relying on various lawful bases, as set out below:

  • Consent:
  1. In the case of prospective clients, we may process your Personal Data in order to provide you with legal updates, articles, newsletters, or any materials in relation to your business and our services, including invitations to seminars, training, or any events, which we believe may be interest of you. In this regard, you are entitled to opt-out, or withdraw your consent, at any time by using the ‘unsubscribe’ function as provided in the email which is sent to you.

 

  1. If you are Thai national, we may need to submit your national identification card, which may contain Sensitive Personal Data, i.e. blood type and/or religion, to the government agencies, local authorities or other relevant organizations pursuant to your instructions or as required by applicable laws, rules or regulations. Further, your national identification card may be collected, used, disclosed, transferred or otherwise processed for purpose of verification of identity.

 

  1. Prior to or during the course of provision of our legal services, we may need to collect, use, disclose, transfer and otherwise process Sensitive Personal Data of minors as may be required by applicable laws, rules, or regulations. In such case, you represent that you are a parent or legal guardian of a minor who have a lawful authorization to grant explicit consent on such minor’s behalf.

 

  1. Client and prospective client may withdraw his/her consent at any time, subject to the conditions under the applicable laws. Withdrawal of consent will not affect any processing of your Personal Data for which you have lawfully provided consent prior to such withdrawal.

 

  • Contractual Necessity:
  1. To proceed with your request to engage our firm for legal services, including providing our legal services and performing our rights and duties under the engagement agreement between you and This would include the processing of your Personal Data for payment, tax, and financial matters relating to our contract or engagement. Tilleke will use the Personal Data we have to provide the services.

 

  1. Where the processing of Personal Data relies on contractual obligation as a legal basis, failure to provide required or necessary Personal Data may result in Tilleke being unable to proceed with your request to engage or enter into an agreement with Tilleke for legal services, or Tilleke may not be able to perform our rights and duties under the engagement agreement with you, either in part or in whole.

 

  • Legal Obligation:
  1. To comply with applicable law or regulation, both domestic and foreign, and to comply with order of the court, competent authorities, and/or government agencies.

 

  1. Where the processing of Personal Data relies on legal obligation as a legal basis, failure to provide required or necessary Personal Data may result in Tilleke being unable to proceed or undertake any act relating to the provision of our legal services, either in part or in whole. Further, it may cause Tilleke and/or the clients to be in violation of applicable law or regulation, or order of the court, competent authorities, and/or government agencies.

 

  • Legitimate Interest:
  1. For identification and verification purposes, including performing a conflict-of-interest review, prior to providing our services;

 

  1. To provide legal updates, articles, newsletters, or any materials in relation to your business and our services, including invitations to seminars, training, or any events, which we believe may be interest of you. We rely on our legitimate interest, whereby you are our clients who have engaged us;

 

  1. To protect our rights, property, personnel, safety, business operations, and customers, such as for instance, in the case of recording your images/movements via our installed CCTV cameras when you enter our premises or complete our entrance registration;

 

  1. To manage our information technology systems, and to ensure the adequacy of the security relating to such systems;

 

  1. To detect, prevent, investigate, and prosecute fraudulent and other criminal activity;

 

  1. To monitor and analyze our services for the purpose of risk assessment and control, and statistical and trend analysis, for compliance with the respective policies, system administration, operation, testing and support, and to operate control and management information systems; and

 

  1. For any other activities which are necessary for us to carry out our business; and

 

 (d)       Legal Claims: For the establishment, compliance, exercising, or the defense of Tilleke’s legal claims.

  1. Where does Tilleke collect your Personal Data?

(a)        Directly from you: We normally collect your Personal Data directly from you (the “Data Subject”), when you contact, communicate, or correspond with us either via email or through direct interaction. For example, we may collect your Personal Data when you register to attend a seminar, or for training, or for any event which is hosted/provided by us, or when you contact us for legal or other business inquiries.

(b)        Referring persons: We may collect your Personal Data from other persons, such as our partner firms, business partners, relevant associations and existing clients, which are permitted to contact us, or to introduce or refer you to us.

(c)         Public sources: We may collect your Personal Data which is available on public sources, such as websites that are provided by authorities (e.g. the Department of Business Development), or via websites which are provided by private operators.

(d)        Employer or others: In the case of corporate clients, we generally collect the Personal Data of associated persons through your employer or directly from you, in order to provide our services and to maintain our relationship with you.

  1. To whom does Tilleke disclose your Personal Data?

Depending on the service we are providing to you, we may disclose your Personal Data to the following parties:

  • To our affiliate companies which are located outside Thailand, for the purpose of managing your relationship with us, providing you with our services, performing our contractual obligations, and for other purposes as identified in this Privacy Policy. In this regard, please see ‘Where does Tilleke transfer your Personal Data?for more information;
  • To third party vendors, suppliers, and outsourced companies, in order to support the services we provide to you;
  • To our business partners and the relevant associations in which Tilleke is a member, including, but not limited, to partner firms, Lex Mundi, and Multilaw;
  • To any competent regulators, prosecuting, courts or other tribunals in any jurisdiction, Ministry of Commerce, the Revenue Department, Immigration Department, Labor Departments, Food and Drug Administration, and any other governmental agencies we deal with on your behalf;
  • To third parties in connection with a change of ownership in Tilleke, or any of its assets or properties; and
  • To any other persons or entities to whom Tilleke is required to make disclosure by applicable law.
  1. Where does Tilleke transfer your Personal Data?

We regularly transfer your Personal Data to our affiliates, and in certain circumstances, to third parties (e.g. service providers), which are located outside Thailand, and which may have different data protection standards to those prescribed by the data protection authority in Thailand. Notwithstanding that, we ensure that we will protect your Personal Data by implementing adequate personal data protection standards for the transfer of your Personal Data outside Thailand. We will also ensure that any entity to whom your Personal Data will be disclosed will implement adequate personal data protection standards, and where your Personal Data will be transferred within our affiliates, we will use the relevant data transfer mechanisms in accordance with the requirements of the PDPA.

 

The majority of the transfers of your Personal Data are undertaken for the purpose of the provision of our services and the management of our business. In addition, your Personal Data is mostly transferred to our affiliates, which are located in Cambodia, Indonesia, Laos, Myanmar, and Vietnam.

 

In all cases, we will transfer your Personal Data only where it is permitted and in compliance with the PDPA.

  1. For how long does Tilleke retain your Personal Data?

We retain your Personal Data for as long as is required in order to fulfil our contractual obligations, or for the performance of our services to you, and for 10 years after the cessation of our contractual relationship, or the last performance of our services, unless otherwise agreed with you in writing, or required or permitted by applicable law.

 

Where we process your Personal Data in connection with a legal obligation, your Personal Data will be retained for the duration of the prescribed legal retention period, as stipulated under the applicable law.

 

Where we process your Personal Data solely with your consent, your Personal Data will be deleted, destroyed, or de-identified, subject to the requirements and conditions prescribed by the applicable law.

  1. What are your rights in relation to your Personal Data?

You are entitled to:

(a) Request to have access to and obtain a copy of your Personal Data, and to request the disclosure of the source of the Personal Data, in the event that your Personal Data was collected without your consent;

(b) Receive your Personal Data in a commonly used and machine-readable format, and to have your Personal Data in said format transmitted to another Data Controller;

(c)   Request that your Personal Data be deleted, destroyed, or de-identified;

(d) Object to the collection, use, and disclosure of your Personal Data, and especially where such collection, use, or disclosure is for direct marketing purposes;

(e) Request that the processing of your Personal Data be suspended;

(f)   Request that your Personal Data be corrected, updated, or completed;

(g) Withdraw your consent at any time, provided that there is no other legal ground for Tilleke to continue with the processing of your Personal Data; and

(h) Lodge complaints to the competent authority.

Your request may be refused, and the exercise of your rights is subject to the limitations prescribed by law.

  1. Changes to This Privacy Policy

Tilleke may amend, change, or update this Privacy Policy from time to time, whereby Tilleke will notify you about such changes via your selected communication channel. In the event that the amendment, change, or update will affect the purposes for which your Personal Data has originally been collected, Tilleke will notify you about such changes and obtain your consent (if applicable), prior to such changes becoming effective.

  1. How can you contact us?

If you have any inquiries in relation to your Personal Data, or you would like to exercise any of your Data Subject rights, you may contact us at:

Tilleke & Gibbins International Ltd.

Supalai Grand Tower, 26th Floor
1011 Rama 3 Road, Chongnonsi, Yannawa
Bangkok 10120, Thailand

T: +66 2056 5555

E: [email protected]

 

Or you may contact our Data Protection Officer at:

 

Papitchya Supinananda

T: +66 2056 5650

E: [email protected]