You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 1, 2019

The Reach and Liabilities of the Personal Data Protection Act

Bangkok Post: Human Resources Watch

Earlier this year, Thailand enacted its Personal Data Protection Act (PDPA), which was published in the Government Gazette on 27 May 2019. Most parts of the PDPA will become effective one year after this, on 27 May 2020. As the PDPA will have broad impact across multiple aspects of most businesses—including their human resources operations—lawmakers provided this one-year period for those affected to prepare for compliance with the PDPA.

While the definitions and mechanics of the law in relation to HR operations were covered in a previous Human Resource Watch column (29 April 2019), this article will take a closer look at the civil, criminal, and administrative penalties applicable in the event of non-compliance with the PDPA.

It is important for employers to understand that these liabilities apply to them even if they outsource their company’s HR work. Some employers misunderstand that if they turn over their HR functions to an HR service provider, the employer will not have any liability under the PDPA. Indeed, even if HR functions are outsourced, the employer will still have the same liabilities under the PDPA if the HR service provider breaches the PDPA.

For instance, if an employer assigns an outsourced provider to manage the paying of wages and calculation of social security deductions, where the providers must collect, use or disclose the personal information of employees, both the employer and the HR service provider will be acting in roles defined by the PDPA. In this scenario, the employer would be considered a ‘data controller’, while the HR service provider would be considered a ‘data processor.’ Therefore, both the employer and the HR service provider will have potential liability under the PDPA.

If the employer or HR service provider violates a PDPA provision, such as selling employees’ personal information to a financial institution or other third party without the employees’ consent, the employer as data controller would not only be liable for paying compensation to the employees who own the personal information, but could also face criminal penalties and administrative liability under the PDPA. In addition, the HR service provider, as a data processor, could face civil liability.

The PDPA provides for three types of potential liability for violation of its provisions:

1. Civil Liability

Employers or HR service providers who are found to have violated the PDPA must pay compensation to the employees who own the personal information and who received damages from the violation, regardless of whether the violation was done intentionally or negligently, except where the offender can prove that the damages were caused by force majeure or the employees’ own actions. In addition, offenders who can prove that the violation was a result of their compliance with an order of a government officer exercising his or her duties under the law will not be liable. The compensation includes all necessary expenses associated with actual or likely damages, whether for purposes of prevention or mitigation.

In addition, the court is entitled to award punitive civil damages, up to two times the amount of actual damages.

The prescription period for claiming compensation under the PDPA is three years from the date that the employees who own the personal information became aware of the violation and the identity of the offenders, or ten years from the date on which the violation of the personal data took place.

2. Criminal liability

If an employer as data controller violates the PDPA by the use or disclosure of personal information without consent in a manner that is likely to cause the other person to suffer any damages, impair his or her reputation, or other reason, the offender will face imprisonment of up to six months, a fine of up to Baht 500,000, or both.

In addition, if the offender uses or discloses personal information in order to receive unlawful benefits (or secure benefits for others), the criminal penalties that the offender will face include imprisonment for up to one year, a fine of up to Baht 1 million, or both.

The criminal offence under the PDPA is a compoundable offence, which means that it can be settled by negotiation and agreement between the parties before a court issues a final judgment.

In a case where the offender is a juristic person and the offence occurs as a result of the order or act of any director, manager, or other person in a role of responsibility, those persons must be liable for the relevant penalties. Likewise, these persons can also be penalized for their omission of an instruction or act resulting in the commission of the offence by the juristic person.

3. Administrative liability

The PDPA also imposes administrative liability on any offender in the form of an administrative fine from Baht 500,000 to Baht 5 million, depending on the nature of the violation. The PDPA establishes an expert committee with the authority to order offenders to pay an administrative fine, issue an order for rectification, or issue a warning to the offender. In determining whether to impose an administrative fine, the expert committee will consider the severity of the circumstances of the offence, the size of the business of the data controller (e.g., an employer) or data processor (e.g., HR service provider or HR department), or other circumstances.

It is possible that specific classes of data controller could be exempted from the application of all or part of the provisions of the PDPA (in addition to the excepted activities, on which see the previous article on this topic). However, these exemptions would have to be made by royal decree.

As it stands now, though, exceptions for classes of person have not been promulgated, and employers should not expect that they will be automatically exempt from PDPA compliance. Recent news from Europe of companies being heavily fined for their violations of the EU’s General Data Protection Regulation (upon which much of the PDPA is based) underline the dangers of continuing to neglect the protection of personal data. With Thailand only months away from joining the EU and other jurisdictions around the world in implementing a robust data protection regime, businesses must ensure the compliance of all of their operations—including in-house or outsourced HR functions—to avoid such costly penalties.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks. The original story can be viewed on the Bangkok Post website.

RELATED INSIGHTS​ 

September 13, 2021
With COVID-19 cases continuing to pose a significant threat throughout Thailand, many employers have ordered their employees to work exclusively from home in order to minimize their chances of contracting the virus. However, this luxury is not afforded to all employees—some are unable to work from home due to the nature of their work, and consequently they are placed in the precarious position of being exposed to possible infection. Thailand’s Social Security Office (SSO) understood these risks early in the pandemic and, in March 2020, issued guidelines through the Workmen’s Compensation Fund Office on employees’ entitlement to claim benefits from the workers’ compensation fund (WCF) if they contract the virus as a result of their work. The WCF provides medical-related assistance and compensation to employees who directly suffer from a work-related injury or sickness (subject to certain conditions). Falling ill with COVID-19 during the performance of work duties may constitute suffering work-related sickness, thereby allowing employees to claim compensation from the WCF by submitting the Kor Thor 16 form, a medical certificate, treatment records, records of the employee’s working hours, and other relevant documentation. Upon receiving a claim, the SSO will investigate by collecting facts and evidence from the employer, the infected employee and his or her colleagues, and any witnesses. The official will examine the employee’s duties and working conditions in detail, taking into consideration any relevant information, such as evidence regarding the employee’s travel or movements prior to falling sick. Once all the facts and evidence are gathered, the matter will be submitted to a medical subcommittee responsible for determining whether the employee’s onset of COVID-19 is due to his or her work. If the subcommittee finds that the employee’s contraction of the virus did indeed result from the performance of his or her work duties, the
August 26, 2021
Around the world, COVID-19 is continuing to threaten the health of millions, interrupt daily life, and throttle business activity. In Thailand, the latest wave of infections has been more intense than any since the beginning of the pandemic, and many businesses have been forced to close down once again. There are reasons for hope though—chief among them the increasing pace of vaccinations. Not only are the vaccines effective at preventing serious health issues, they are helping keep both employees and customers safe in business settings so that commerce, trade, and tourism can resume once again. Many in Thailand have already been vaccinated, and struggling employers are looking ahead to safely resuming full business activities, from reopening offices for employees who have been working from home, to welcoming customers and clients back to an environment that minimizes the risk of COVID-19 exposure. In anticipation of such a return to business at full capacity, many Thai employers are taking note of companies and organizations overseas boosting COVID-19 safety in workplaces by mandating vaccines and other measures, and asking whether such mandates could be imposed here in Thailand. The main legal concept to consider here is the provision in the Labor Protection Act B.E. 2541 (1998), which authorizes employers to issue “lawful and just” orders to employees. For an order to be “lawful and just,” it must be proportionate to the circumstance. In the current context of the COVID-19 pandemic, employers can refer to the Communicable Diseases Act B.E. 2558 (2015), as well as other local regulations, to provide grounds when asserting that their risk-mitigation orders are proportionate, lawful, and just. It is doubtful that a Thai court would rule that the circumstances we find ourselves in now would justify an employer requiring employees to be vaccinated, but this legal standard can
August 25, 2021
Multilaw has published the latest edition of How to Hire and Fire, a guide to the rules and regulations governing employment relationships in over 90 jurisdictions around the world. Lawyers at Tilleke & Gibbins prepared the Cambodia, Myanmar, Thailand, and Vietnam chapters of the guide, which covers the following main topics: General principles: Forums for adjudicating employment disputes, main sources of employment law, employees working for foreign companies in Cambodia or abroad for domestic companies, and data privacy. Hiring the employee: Legal requirements for employment agreements, types of agreement, secrecy and confidentiality, ownership of inventions and other IP rights, pre-employment considerations, hiring of non-nationals, hiring specified categories of individuals, and outsourcing and sub-contracting. Maintaining the employment relationship: Changes to the contract, changes in business ownership, social security, accidents at work, discipline and grievances, harassment, discrimination, equal pay, compulsory training obligations, offsetting earnings, maternity and disability leave, insurance, absence for military or public service duties, trade unions, employee strikes, and employers’ liability for actions of employees. Firing the employee: Procedures for terminating employment agreements, instant dismissal, employee resignation, termination on notice, age-related termination, force majeure automatic termination, collective dismissals, termination by agreement, directors and senior officers, rules for companies facing financial difficulties, restriction of future activities, whistleblowers, garden leave, severance payments and tax considerations, allowances, and time limits for post-termination claims. General: Specific matters unique or important to each jurisdiction. Multilaw is a global network of carefully selected, independent law firms consisting of over 10,000 commercial lawyers in more than 100 countries, able to provide expert legal advice in complex environments around the globe. The full guide is available for free on the Multilaw website.