You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 1, 2019

The Reach and Liabilities of the Personal Data Protection Act

Bangkok Post: Human Resources Watch

Earlier this year, Thailand enacted its Personal Data Protection Act (PDPA), which was published in the Government Gazette on 27 May 2019. Most parts of the PDPA will become effective one year after this, on 27 May 2020. As the PDPA will have broad impact across multiple aspects of most businesses—including their human resources operations—lawmakers provided this one-year period for those affected to prepare for compliance with the PDPA.

While the definitions and mechanics of the law in relation to HR operations were covered in a previous Human Resource Watch column (29 April 2019), this article will take a closer look at the civil, criminal, and administrative penalties applicable in the event of non-compliance with the PDPA.

It is important for employers to understand that these liabilities apply to them even if they outsource their company’s HR work. Some employers misunderstand that if they turn over their HR functions to an HR service provider, the employer will not have any liability under the PDPA. Indeed, even if HR functions are outsourced, the employer will still have the same liabilities under the PDPA if the HR service provider breaches the PDPA.

For instance, if an employer assigns an outsourced provider to manage the paying of wages and calculation of social security deductions, where the providers must collect, use or disclose the personal information of employees, both the employer and the HR service provider will be acting in roles defined by the PDPA. In this scenario, the employer would be considered a ‘data controller’, while the HR service provider would be considered a ‘data processor.’ Therefore, both the employer and the HR service provider will have potential liability under the PDPA.

If the employer or HR service provider violates a PDPA provision, such as selling employees’ personal information to a financial institution or other third party without the employees’ consent, the employer as data controller would not only be liable for paying compensation to the employees who own the personal information, but could also face criminal penalties and administrative liability under the PDPA. In addition, the HR service provider, as a data processor, could face civil liability.

The PDPA provides for three types of potential liability for violation of its provisions:

1. Civil Liability

Employers or HR service providers who are found to have violated the PDPA must pay compensation to the employees who own the personal information and who received damages from the violation, regardless of whether the violation was done intentionally or negligently, except where the offender can prove that the damages were caused by force majeure or the employees’ own actions. In addition, offenders who can prove that the violation was a result of their compliance with an order of a government officer exercising his or her duties under the law will not be liable. The compensation includes all necessary expenses associated with actual or likely damages, whether for purposes of prevention or mitigation.

In addition, the court is entitled to award punitive civil damages, up to two times the amount of actual damages.

The prescription period for claiming compensation under the PDPA is three years from the date that the employees who own the personal information became aware of the violation and the identity of the offenders, or ten years from the date on which the violation of the personal data took place.

2. Criminal liability

If an employer as data controller violates the PDPA by the use or disclosure of personal information without consent in a manner that is likely to cause the other person to suffer any damages, impair his or her reputation, or other reason, the offender will face imprisonment of up to six months, a fine of up to Baht 500,000, or both.

In addition, if the offender uses or discloses personal information in order to receive unlawful benefits (or secure benefits for others), the criminal penalties that the offender will face include imprisonment for up to one year, a fine of up to Baht 1 million, or both.

The criminal offence under the PDPA is a compoundable offence, which means that it can be settled by negotiation and agreement between the parties before a court issues a final judgment.

In a case where the offender is a juristic person and the offence occurs as a result of the order or act of any director, manager, or other person in a role of responsibility, those persons must be liable for the relevant penalties. Likewise, these persons can also be penalized for their omission of an instruction or act resulting in the commission of the offence by the juristic person.

3. Administrative liability

The PDPA also imposes administrative liability on any offender in the form of an administrative fine from Baht 500,000 to Baht 5 million, depending on the nature of the violation. The PDPA establishes an expert committee with the authority to order offenders to pay an administrative fine, issue an order for rectification, or issue a warning to the offender. In determining whether to impose an administrative fine, the expert committee will consider the severity of the circumstances of the offence, the size of the business of the data controller (e.g., an employer) or data processor (e.g., HR service provider or HR department), or other circumstances.

It is possible that specific classes of data controller could be exempted from the application of all or part of the provisions of the PDPA (in addition to the excepted activities, on which see the previous article on this topic). However, these exemptions would have to be made by royal decree.

As it stands now, though, exceptions for classes of person have not been promulgated, and employers should not expect that they will be automatically exempt from PDPA compliance. Recent news from Europe of companies being heavily fined for their violations of the EU’s General Data Protection Regulation (upon which much of the PDPA is based) underline the dangers of continuing to neglect the protection of personal data. With Thailand only months away from joining the EU and other jurisdictions around the world in implementing a robust data protection regime, businesses must ensure the compliance of all of their operations—including in-house or outsourced HR functions—to avoid such costly penalties.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks. The original story can be viewed on the Bangkok Post website.

RELATED INSIGHTS​ 

April 3, 2023
Most employers know that terminating employees for poor job performance is not easy. But it is actually legally possible—if employers have the right approach and take specific precautionary measures. However, failing to take these precautions can mean that an employer is either stuck with an incompetent employee or on the losing end of a lawsuit for unfair termination. This article will lay out some essential considerations for employers in Thailand regarding termination of employment for poor performance. First, understand that “poor work performance” is a lack of performance or ability, or an inability to work with other employees. It does not constitute a violation of work rules or regulations. In some cases, however, an employee’s failure to act in accordance with lawful instructions or commands of the employer, resulting in poor work performance, could also be considered a violation of work rules or regulations. This may be the case if the work rules or regulations clearly state that an employee must strictly comply with the employer’s instructions or commands. Second, an employer can, in fact, terminate an employee due to poor work performance. For example, this may be possible in the following scenarios: Records show that an employee’s work performance has fallen below the employer’s required standards, and the employee has not tried to improve his or her work performance for three consecutive years. In addition, it does not appear that the employer was biased when giving ratings or scores for the employee’s work performance. The job description of the employee includes coordination with employees in other departments, but the employee has not been able to do so. Therefore, the employee was reassigned to a new job function, but the employee still did not improve. This suggests that the employee has a lack of interpersonal skills and is not
March 23, 2023
On March 19, 2023, Thailand’s new work-from-home (WFH) legislation amending the Labour Protection Act (No. 8) B.E. 2566 (2023) was published in the Government Gazette. It will come into effect on April 18, 2023. The amendment aims to enhance employee protections to accord with current global standards, provide alternative working arrangements for employers and employees, increase workforce efficiency, and strengthen employees’ job security and a better quality of life. As we detailed previously, the new WFH legislation allows employers and employees to reach agreements that permit employees to work remotely. Since there are no accompanying criminal punishments relating to this new provision, and the legislation incorporates the term “may agree,” it appears that this WFH provision is not mandatory but is primarily intended to facilitate and encourage remote working agreements between employers and employees. For more details on the WFH legislation, or on any aspect of employment law in Thailand, please contact Tilleke & Gibbins at [email protected].
February 24, 2023
Many companies have moved to Southeast Asia to benefit from the advantages of this vibrant and diverse market. The region is already a manufacturing hub for a multitude of industries—computer and automotive products in Thailand, textiles in Cambodia, and footwear and electrical goods in Vietnam, to name a few—and an increasing number of companies worldwide are reconfiguring their supply chains to include regional suppliers. A key challenge is keeping up to date with employment law trends in these jurisdictions to ensure compliance with local regulations—and avoid costly, time-consuming business interruption. Here we outline trends and recent regulatory developments in Cambodia, Thailand, and Vietnam, and consider what they mean for employers. Cambodia The Ministry of Labour and Vocational Training (MLVT) is likely to pursue a more proactive enforcement strategy in 2023. Last May, the MLVT announced companies would be required to submit a twice yearly self-declaration on labour compliance through a new online system. The self-declaration form requires companies to confirm and upload evidence of compliance, and the MLVT online system—through which the ministry can easily determine if a company is compliant –generates a report that lists all fines. Companies should comply with the self-declaration requirement and carefully review the form to understand what fines will apply for non-compliance. On 1 October 2022, regulations relating to the National Social Security Fund (NSSF) pension system came into effect, and employers and employees began making NSSF pension contributions. Over the next five years, total compulsory pension contributions will amount to 4% of an employee’s wage, half of which is paid by the employer and half deducted from the employee’s salary. The contribution wage is capped at KHR 1.2m (USD 300). Employers are currently required to pay a relatively small amount (KHR 24,000, or around USD 6). This will increase to 10.75% over
January 19, 2023
The Thai parliament has passed the so-called Work from Home Bill—formally known as Labour Protection Act (No. 8) B.E. 2566 (2023)—which amends the country’s Labour Protection Act (LPA) to reflect current circumstances. The accompanying legislative remark states that the proposed amendments to the LPA will provide additional options for work arrangements between employers and employees, upgrade the level of labor protection, increase work stability, and improve quality of life for employees in Thailand. The legislation adds a single section to the LPA providing that an employer and an employee “may agree in the employment contract” that the employee is allowed “to bring work . . . to perform at home or at the residence of the employee or anywhere that the employee can work remotely through information technology, if the nature of the work permits.” The provision further provides that employers are responsible for ensuring that remote work agreements are in writing, either physically or electronically, and may include the following details: Period of the agreement; Normal working hours, rest periods, and overtime work; Criteria for overtime work, holiday work, and various types of leave; Scope of work and control or supervision by the employer; and Responsibility for arranging supplies and equipment, including necessary costs relating to the work. The amended LPA gives employees who work from home the right to refuse contact from the employer or the supervisor beyond working hours. In addition, employers must treat remote employees equally to on-premise employees. The most notable question surrounding this legislation is whether employers must allow employees to work remotely. The phrase “may agree” suggests that employers do not have to agree to allow an employee to work remotely. Another important aspect of the amendment is that there is no criminal punishment attached to it, which suggests that the legislation