You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 30, 2019

Employers Brace Themselves as New Personal Data Protection Act Looms

Bangkok Post: Human Resources Watch

The draft Personal Data Protection Act (PDPA) was approved by the National Legislative Assembly in February 2019, raising concern among business entities over the the need for increased diligence to ensure adherence to the provisions. Running a business often entails handling the personal data of employees, contractors, suppliers, customers, and others. Any personal data collected could be subject to the provisions of the PDPA, and as employee data falls under the PDPA, all businesses, should be prepare to deal with the impact of the PDPA.

Although this final version of the PDPA has not yet been endorsed by the king and published in the Government Gazette, the endorsement and publication is expected soon.

The majority of the provisions in the PDPA will only come into force a year after its publication in the Government Gazette. This transitional period will allow any entity subject to the PDPA to review and adjust their personal data–related activities.

What is Personal Data?

Personal data is broadly defined as any data about a person that enables the identification of that person, whether directly or indirectly, but specifically excluding data of the deceased. This can include a person’s name, identification card number, email address, mobile phone number, health information, payroll information, or bank account number. 

Data Controller or Data Processor?

The PDPA sets out different duties and obligations for a data controller and a data processor. A data controller is defined as any person or legal entity that has the power and duty to make decisions on whether to collect, use, or disclose personal data. In contrast, a data processor is defined as any person or legal entity that collects, uses, or discloses personal data on behalf of, or pursuant to, the instructions of the data controller. Since employers have the power to determine which categories of personal data should be collected and retained, they are therefore acting as data controllers.

Obtaining Consent

Collection, use, or disclosure of personal data is generally prohibited unless consent from the data subject has been obtained or unless it falls within an exemption prescribed under the PDPA.  The exemptions include, among others, when it is necessary to comply with a contract to which the data subject is a party, or pursuant to the requests of the data subject prior to entering into a contract; and when it is necessary for the legitimate interest of the data controller, other person, or other entity, unless such interest is less significant that the fundamental right of the data subject.

Employers, therefore, should carefully consider whether separate consent must be obtained from their employees or the language of the employment agreement is sufficient for the purpose of possessing their employees’ personal data in compliance with the PDPA.

If separate consent is required, such a request must

  1. be made prior to, or at, the time of collection;
  2. be made in writing or via electronic means;
  3. be clearly separated from other terms;
  4. be in an easily accessible format or use terms which are understandable;
  5. be written in plain language; and
  6. not be misleading or deceptive.

The PDPA, however, does not specifically require that the consent must be made in Thai language.

Sensitive Personal Data

Most companies require their employees to provide information relating to their health, race, religion, or biometric data (e.g., fingerprints). These categories of personal data are considered as sensitive personal data. The PDPA expressly prohibits the collection of such data unless explicit consent from the data subject has been obtained, or unless otherwise exempted.

One of the exemptions is where the sensitive personal data is collected for labour protection, social security, or national health security purposes, and it is deemed as necessary for the data controller or data subject to satisfy his or her rights or obligations.

It is still unclear whether collecting sensitive personal data of employees would fall within the scope of this exemption. Hence, employers should closely observe the PDPA and its subordinate regulations once they come into force.

Use of Personal Data

Personal data can only be used for the purposes for which the consent has been granted. Therefore, if the purpose of use has changed, fresh consent from the employee must be obtained.

Retention Period

Where a request for consent is required, the employer must inform employees about the period for which their personal data will be retained.

As the longest prescription period for various labour disputes, including unfair termination, is ten years from the date the claim could be enforced, employers should consider retaining their employees’ personal data until the period of prescription expires. Regardless of the length of the retention period that the employer ultimately chooses, they must ensure that this retention period is clearly communicated to the employees.

Cross-border Transfer

Companies often transfer employees’ personal data within their group of companies, some of which might be located overseas. If such transfer complies with the company’s internal policy for sharing personal data in accordance with the requirements of the PDPA, it would be exempt from the general PDPA requirement for transferring data international—i.e the employer would not need to ensure that the destination country implements an appropriate standard for personal data protection, or obtain further consent. Whether or not an internal policy renders such a transfer exempt is likely to be a matter of some dispute, and companies wishing to transfer data internationally should be particularly cautious about this exemption.

Grandfather Provision

As for employees’ personal data that has been collected prior to the PDPA coming into effect, employers may continue to use this data without the need to obtain consent, provided such data is used solely for the purpose for which it was originally collected, and that the employer complies with the PDPA when doing so.

Rights of the Data Subject

Employers should ensure that their employees have been clearly informed of their rights under the PDPA, including, but not limited to, right of access, right to data portability, right to withdraw consent, and right to erasure.

Other Obligations

Under the PDPA, the employer, as the data controller, has an obligation to ensure that any other person or entity to whom the personal data is disclosed will not use or disclose such personal data unlawfully or without authorization.

Data processors are also required to implement appropriate security measures to prevent access that would enable the use, alteration, amendment, or disclosure of the personal data unlawfully or without authorization. Therefore, where there are inappropriate security measures, it may prove difficult for an employer to escape liability in the event of a data breach.

Penalties

Non-compliance with the PDPA could lead to severe civil liabilities, administrative liabilities, and criminal penalties—the latter two including fines of up to THB 5 million, and even imprisonment.

How Should Employers Prepare?

  • Review current personal data protection policies, employment contracts, and work rules to ensure the terms will be compliant with the PDPA (and any other relevant laws). 
  • Review agreements with customers, contractors, suppliers, and any other related parties.
  • Ensure that an appropriate, PDPA-compliant system for personal data protection is in place.
  • Identify categories of personal data that are required for a business’s legitimate purposes, and only collect and retain such data.
  • Provide personal data protection training for employees.

It is essential that all employers closely observe and adhere to the PDPA and subordinate regulations once they come into force, and prepare themselves well in advance, in order to ensure their employee personal data–related activities do not violate any applicable laws. Those who fail to do so could find themselves faced with angry employees and severe penalties.

 

This article was originally published in the Bangkok Post on April 29, 2019, and is reproduced here with permission and thanks. The original can be viewed on the Bangkok Post website, or by downloading the pdf below.

RELATED INSIGHTS​ 

April 3, 2023
Most employers know that terminating employees for poor job performance is not easy. But it is actually legally possible—if employers have the right approach and take specific precautionary measures. However, failing to take these precautions can mean that an employer is either stuck with an incompetent employee or on the losing end of a lawsuit for unfair termination. This article will lay out some essential considerations for employers in Thailand regarding termination of employment for poor performance. First, understand that “poor work performance” is a lack of performance or ability, or an inability to work with other employees. It does not constitute a violation of work rules or regulations. In some cases, however, an employee’s failure to act in accordance with lawful instructions or commands of the employer, resulting in poor work performance, could also be considered a violation of work rules or regulations. This may be the case if the work rules or regulations clearly state that an employee must strictly comply with the employer’s instructions or commands. Second, an employer can, in fact, terminate an employee due to poor work performance. For example, this may be possible in the following scenarios: Records show that an employee’s work performance has fallen below the employer’s required standards, and the employee has not tried to improve his or her work performance for three consecutive years. In addition, it does not appear that the employer was biased when giving ratings or scores for the employee’s work performance. The job description of the employee includes coordination with employees in other departments, but the employee has not been able to do so. Therefore, the employee was reassigned to a new job function, but the employee still did not improve. This suggests that the employee has a lack of interpersonal skills and is not
March 23, 2023
On March 19, 2023, Thailand’s new work-from-home (WFH) legislation amending the Labour Protection Act (No. 8) B.E. 2566 (2023) was published in the Government Gazette. It will come into effect on April 18, 2023. The amendment aims to enhance employee protections to accord with current global standards, provide alternative working arrangements for employers and employees, increase workforce efficiency, and strengthen employees’ job security and a better quality of life. As we detailed previously, the new WFH legislation allows employers and employees to reach agreements that permit employees to work remotely. Since there are no accompanying criminal punishments relating to this new provision, and the legislation incorporates the term “may agree,” it appears that this WFH provision is not mandatory but is primarily intended to facilitate and encourage remote working agreements between employers and employees. For more details on the WFH legislation, or on any aspect of employment law in Thailand, please contact Tilleke & Gibbins at [email protected].
February 24, 2023
Many companies have moved to Southeast Asia to benefit from the advantages of this vibrant and diverse market. The region is already a manufacturing hub for a multitude of industries—computer and automotive products in Thailand, textiles in Cambodia, and footwear and electrical goods in Vietnam, to name a few—and an increasing number of companies worldwide are reconfiguring their supply chains to include regional suppliers. A key challenge is keeping up to date with employment law trends in these jurisdictions to ensure compliance with local regulations—and avoid costly, time-consuming business interruption. Here we outline trends and recent regulatory developments in Cambodia, Thailand, and Vietnam, and consider what they mean for employers. Cambodia The Ministry of Labour and Vocational Training (MLVT) is likely to pursue a more proactive enforcement strategy in 2023. Last May, the MLVT announced companies would be required to submit a twice yearly self-declaration on labour compliance through a new online system. The self-declaration form requires companies to confirm and upload evidence of compliance, and the MLVT online system—through which the ministry can easily determine if a company is compliant –generates a report that lists all fines. Companies should comply with the self-declaration requirement and carefully review the form to understand what fines will apply for non-compliance. On 1 October 2022, regulations relating to the National Social Security Fund (NSSF) pension system came into effect, and employers and employees began making NSSF pension contributions. Over the next five years, total compulsory pension contributions will amount to 4% of an employee’s wage, half of which is paid by the employer and half deducted from the employee’s salary. The contribution wage is capped at KHR 1.2m (USD 300). Employers are currently required to pay a relatively small amount (KHR 24,000, or around USD 6). This will increase to 10.75% over
January 19, 2023
The Thai parliament has passed the so-called Work from Home Bill—formally known as Labour Protection Act (No. 8) B.E. 2566 (2023)—which amends the country’s Labour Protection Act (LPA) to reflect current circumstances. The accompanying legislative remark states that the proposed amendments to the LPA will provide additional options for work arrangements between employers and employees, upgrade the level of labor protection, increase work stability, and improve quality of life for employees in Thailand. The legislation adds a single section to the LPA providing that an employer and an employee “may agree in the employment contract” that the employee is allowed “to bring work . . . to perform at home or at the residence of the employee or anywhere that the employee can work remotely through information technology, if the nature of the work permits.” The provision further provides that employers are responsible for ensuring that remote work agreements are in writing, either physically or electronically, and may include the following details: Period of the agreement; Normal working hours, rest periods, and overtime work; Criteria for overtime work, holiday work, and various types of leave; Scope of work and control or supervision by the employer; and Responsibility for arranging supplies and equipment, including necessary costs relating to the work. The amended LPA gives employees who work from home the right to refuse contact from the employer or the supervisor beyond working hours. In addition, employers must treat remote employees equally to on-premise employees. The most notable question surrounding this legislation is whether employers must allow employees to work remotely. The phrase “may agree” suggests that employers do not have to agree to allow an employee to work remotely. Another important aspect of the amendment is that there is no criminal punishment attached to it, which suggests that the legislation