You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 1, 2019

The Reach and Liabilities of the Personal Data Protection Act

Bangkok Post: Human Resources Watch

Earlier this year, Thailand enacted its Personal Data Protection Act (PDPA), which was published in the Government Gazette on 27 May 2019. Most parts of the PDPA will become effective one year after this, on 27 May 2020. As the PDPA will have broad impact across multiple aspects of most businesses—including their human resources operations—lawmakers provided this one-year period for those affected to prepare for compliance with the PDPA.

While the definitions and mechanics of the law in relation to HR operations were covered in a previous Human Resource Watch column (29 April 2019), this article will take a closer look at the civil, criminal, and administrative penalties applicable in the event of non-compliance with the PDPA.

It is important for employers to understand that these liabilities apply to them even if they outsource their company’s HR work. Some employers misunderstand that if they turn over their HR functions to an HR service provider, the employer will not have any liability under the PDPA. Indeed, even if HR functions are outsourced, the employer will still have the same liabilities under the PDPA if the HR service provider breaches the PDPA.

For instance, if an employer assigns an outsourced provider to manage the paying of wages and calculation of social security deductions, where the providers must collect, use or disclose the personal information of employees, both the employer and the HR service provider will be acting in roles defined by the PDPA. In this scenario, the employer would be considered a ‘data controller’, while the HR service provider would be considered a ‘data processor.’ Therefore, both the employer and the HR service provider will have potential liability under the PDPA.

If the employer or HR service provider violates a PDPA provision, such as selling employees’ personal information to a financial institution or other third party without the employees’ consent, the employer as data controller would not only be liable for paying compensation to the employees who own the personal information, but could also face criminal penalties and administrative liability under the PDPA. In addition, the HR service provider, as a data processor, could face civil liability.

The PDPA provides for three types of potential liability for violation of its provisions:

1. Civil Liability

Employers or HR service providers who are found to have violated the PDPA must pay compensation to the employees who own the personal information and who received damages from the violation, regardless of whether the violation was done intentionally or negligently, except where the offender can prove that the damages were caused by force majeure or the employees’ own actions. In addition, offenders who can prove that the violation was a result of their compliance with an order of a government officer exercising his or her duties under the law will not be liable. The compensation includes all necessary expenses associated with actual or likely damages, whether for purposes of prevention or mitigation.

In addition, the court is entitled to award punitive civil damages, up to two times the amount of actual damages.

The prescription period for claiming compensation under the PDPA is three years from the date that the employees who own the personal information became aware of the violation and the identity of the offenders, or ten years from the date on which the violation of the personal data took place.

2. Criminal liability

If an employer as data controller violates the PDPA by the use or disclosure of personal information without consent in a manner that is likely to cause the other person to suffer any damages, impair his or her reputation, or other reason, the offender will face imprisonment of up to six months, a fine of up to Baht 500,000, or both.

In addition, if the offender uses or discloses personal information in order to receive unlawful benefits (or secure benefits for others), the criminal penalties that the offender will face include imprisonment for up to one year, a fine of up to Baht 1 million, or both.

The criminal offence under the PDPA is a compoundable offence, which means that it can be settled by negotiation and agreement between the parties before a court issues a final judgment.

In a case where the offender is a juristic person and the offence occurs as a result of the order or act of any director, manager, or other person in a role of responsibility, those persons must be liable for the relevant penalties. Likewise, these persons can also be penalized for their omission of an instruction or act resulting in the commission of the offence by the juristic person.

3. Administrative liability

The PDPA also imposes administrative liability on any offender in the form of an administrative fine from Baht 500,000 to Baht 5 million, depending on the nature of the violation. The PDPA establishes an expert committee with the authority to order offenders to pay an administrative fine, issue an order for rectification, or issue a warning to the offender. In determining whether to impose an administrative fine, the expert committee will consider the severity of the circumstances of the offence, the size of the business of the data controller (e.g., an employer) or data processor (e.g., HR service provider or HR department), or other circumstances.

It is possible that specific classes of data controller could be exempted from the application of all or part of the provisions of the PDPA (in addition to the excepted activities, on which see the previous article on this topic). However, these exemptions would have to be made by royal decree.

As it stands now, though, exceptions for classes of person have not been promulgated, and employers should not expect that they will be automatically exempt from PDPA compliance. Recent news from Europe of companies being heavily fined for their violations of the EU’s General Data Protection Regulation (upon which much of the PDPA is based) underline the dangers of continuing to neglect the protection of personal data. With Thailand only months away from joining the EU and other jurisdictions around the world in implementing a robust data protection regime, businesses must ensure the compliance of all of their operations—including in-house or outsourced HR functions—to avoid such costly penalties.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks. The original story can be viewed on the Bangkok Post website.

RELATED INSIGHTS​ 

October 12, 2023
Myanmar has made important amendments to its minimum wage framework by increasing the minimum compensation for workers in both the public and private sectors. Background In May 2018, the National Committee for Setting the Minimum Wage determined that all workers in Myanmar should receive a minimum wage of MMK 4,800 per day (approx. USD 2.29), equivalent to MMK 600 per hour for an eight-hour workday. This rule applied to all workers, without differentiation in location or job. Government Workers and Organizations In September 2023, the Ministry of Planning and Finance announced that daily workers in government departments and organizations are entitled to receive an additional benefit of MMK 1,000 on top of their existing daily wage, which was already MMK 4,800. Consequently, they could earn a total of MMK 5,800 per day for eight hours of work. Private-Sector Workers On October 9, 2023, the national committee announced an increase of minimum wages for employees in the private sector. According to Notification No. 2/2023, workers at private-sector employers with more than 10 employees are now entitled to minimum compensation of MMK 5,800 per day (approx. USD 2.77)—an additional MMK 1,000 per eight-hour workday over the previously established minimum wage. The changes took effect on October 1, 2023. For more details about these changes, or any aspect of employee compensation or employment law in Myanmar, please contact Tilleke & Gibbins at [email protected].
August 18, 2023
On August 16, 2023, Laos’ Prime Minister’s Office issued Notice No. 1502/PMO, which increases the minimum wage for all workers in Laos. This increase is a continuation of the stepped increases in the minimum wage that began in mid-2022. The recent notice increases the minimum monthly wage from LAK 1,300,000 (approx. USD 66) to LAK 1,600,000 (approx. USD 82), in accordance with an agreement reached in the government’s ordinary session in July 2023. The new minimum wage rate will take effect on October 1, 2023. This is the third minimum wage increase in Laos since June 2022. Two of the main factors responsible for this heightened frequency of minimum wage increases are the depreciation of the Lao kip against foreign currencies and inflation in the price of goods for daily consumption. These stepped increases also show the government’s proactive approach toward addressing the cost-of-living crisis in Laos and its effect on low-wage workers. For more details on the new minimum wage, or on any other labor and employment matters in Laos, please contact Dino Santaniello at [email protected] or +856 21 262 355.
July 7, 2023
Tilleke & Gibbins is pleased to announce the release of Employment Law Basics in Southeast Asia. This publication serves as an indispensable resource for businesses navigating the complex landscape of employment law in Cambodia, Laos, Myanmar, Thailand, and Vietnam. Authored by Tilleke & Gibbins’ regional team of employment law specialists, the guide provides a detailed overview of key employment law topics essential for businesses operating or planning to expand their operations in Southeast Asia. From employment contracts to termination procedures, each topic is examined in depth to ensure businesses are well-equipped to comply with local regulations and protect their interests. Key topics covered in the guide include: Employment contracts Probationary period Minimum wage Social security and statutory payments Working hours Leave and holidays Work rules Termination Foreign employees Data protection Remote work AI and automation Our guide offers multinational corporations establishing a presence in the region and local enterprises alike practical insights and actionable advice tailored to the unique regulatory environments in Cambodia, Laos, Myanmar, Thailand, and Vietnam. To access the full guide, please download the PDF below.
April 28, 2023
Instead of the typical dystopian scene of flames, wastelands of shattered buildings, and robotic overlords policing the remaining humans, our actual dystopian future may be a workplace filled only with men named Jared who once played lacrosse in high school. This may sound far-fetched, but one resume-screening tool was found to be using an algorithm that concluded two factors were most determinative of job performance: the name Jared and a history of playing lacrosse in high school. The frailties of artificial intelligence (AI) systems in recruitment and hiring could transform our workforces in unpredictable ways. If employers blindly follow AI outcomes without a deeper examination of how the algorithmic decision is reached, hiring outcomes may be not only ridiculous but also discriminatory. Risks of AI-Reliant Hiring Some employers have enthusiastically embraced AI as a way to reduce costs and replace human bias in the recruitment process. Human recruiters do not have a great track record; for example, in France, discrimination in recruitment has posed such a serious problem that the government submits false work biographies with ethnic names to identify and punish employers that unreasonably reject qualified ethnic applicants. Unfortunately, AI is modeled on human thinking, so it may amplify our own prejudices and errant conclusions while giving the appearance of providing a fair and clean process. AI typically learns inductively by training on examples and historical data. Factors such as exclusion of certain groups from educational or career opportunities has often shaped this data, so AI’s decisions may amplify this past prejudice. For instance, Amazon experimented with mechanized recruitment in 2014, but abandoned these efforts prior to implementation after the AI tool selected a predominantly male workforce. The AI learned by analyzing patterns in resumes submitted to the company over the last 10 years. Since over this period