Principle
This standard operating procedure applies to the company’s employees and authorized third parties, which may include temporary employees and work experience candidates. If a member of staff suspects a breach has occurred, he or she must notify his or her line manager as well as the Data Protection Officer (DPO). The scope of the procedure is limited to the DPO or delegates once the suspected breach has been reported to the DPO.
Definition
Data protection Officer (DPO) are responsible for overseeing a company’s data protection strategy and its implementation to ensure compliance requirement.
Data subject are the individual to whom the personal data relates.
Personal data are any information relating to an identifiable person who can be directly or indirectly identified.
Data Breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Guidelines
Breach happen such incidents may be caused by:
- Accidental loss
- Theft
- Human error e.g. email containing personal data sent to the wrong person.
- Equipment failure.
- Damage e.g. fire, flood.
- Malicious activity i.e. hacking.
Reporting a Breach
Article 37 of the Thailand Personal Data Protection Act B.E. 2562 (2019) (PDPA) requires the data owner to report breaches to the Personal Data Protection Commission Office within 72 hours of them being discovered, unless such a Personal Data breach is unlikely to result in a risk to the rights and freedoms of the persons. In some cases, they should also be informed of suspected breaches, if significant. It is therefore critical that once any member of staff or authorized third party has knowledge of a breach or suspects a breach has occurred, they contact the DPO immediately. Delays in reporting to the Personal Data Protection Commission Office must be accompanied by an explanation of the reasons for the delay. Contact us through our email address: privacy.policy@fast.co.th or the telephone number 038-348134-5 Ext. 416,403,401
Containment and recovery
The DPO and management team take the lead on investigating and managing the breach after determining whether the breach is still occurring and, if so, ensuring that appropriate steps are taken immediately to identify and implement any steps to contain the breach and minimize its impact. An initial assessment will be conducted with relevant staff to determine the severity of the breach. The DPO and management team, in collaboration with relevant staff, will determine a suitable course of action to ensure the incident is resolved.
Assessment of risks
The DPO and management team will conduct an investigation as soon as possible and, if possible, within 24 hours of the breach being discovered/reported. All data security breaches will be managed based on their severity. After the breach has been identified, the risks associated with the breach will be assessed in order to determine an appropriate response.
Considerations will be given to the following points:
- Data type (hardcopy, electronic, personal data, sensitive data)
- Nature of loss (theft, damage)
- Is the data encrypted?
- What information does the data reveal to an unauthorized party who may now have access?
- How many people are potentially affected by this loss?
- What type of people are affected, e.g. students, staff, suppliers?
- What threat is posed to these people, e.g. financial loss, personal safety?
- How far can the data be dispersed? How do we discontinue and collect all the data to prevent additional data leakage?
Notification of Breaches
Notifying the individuals
In consultation with the related person, the DPO and management team will identify individuals whose personal data has been compromised and agree on the correspondence to be sent to each subject.
The correspondence should include:
- How and when the breach occurred.
- What data was involved.
- The company’s actions.
- Advice on what steps the individual may need to take to protect themselves in light of the breach.
- Their data being compromised, for example, by changing a password or canceling a credit card.
- Has notified the Office of the Personal Data Protection Commission.
- Contact information, including a website link, if they require additional information about the incident.
Notifying the Personal Data Protection Commission Office
The Personal Data Protection Commission Office must be notified of all breaches involving a large number of individuals or where the consequences are severe within 72 hours – the DPO will be responsible for this correspondence, which should include the following information at a minimum:
- The nature of the personal data breach, including, if possible, the categories and approximate number of data subjects involved, as well as the categories and approximate number of personal data records involved.
- The name and contact information for the data protection officer or another point of contact where more information can be obtained.
- Explain the potential consequences of the personal data breach.
- Describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, mitigation measures.
Evaluation and Response
While it is critical to contain and assess the risks of a breach, the company must also evaluate the events that led to the breach as well as the effectiveness of its response. During an evaluation, the DPO will meet with department specialists and, if necessary, seek advice from the Personal Data Protection Commission Office on what steps the company should and can take to avoid a similar breach in the future.
Considerations should be given to the following:
- Was the breach caused by insufficient policies or procedures?
- Was the breach caused by insufficient training?
- Where are documents stored?
- Who has access to what data?
- Has this breach revealed potential weaknesses in other areas?
- Security of electronic information assets
Disciplinary
Employees, contractors, customer or partner organizations who act in breach of company policy and procedure may be subject to disciplinary procedures or other appropriate sanctions.
Announced on 27 May 2022
