Privacy Notice For the Employee and Officer of Group Companies of Sansiri Public Company Limited | Sansiri

Privacy Notice

For the Employee and Officer of Group Companies

of Sansiri Public Company Limited

Sansiri Public Company Limited (hereinafter referred to as “Sansiri” or “we”) has placed the great importance on personal data protection, and, to ensure that we will provide a protection to and handle your personal data in consistency with the personal data protection laws, we therefore establish this Privacy Notice to notify you the details of personal data handling, whether collection, use, and disclosure (collectively referred to as “processing”) which may be done, as well as to notify you your rights on personal data and our contact channels.

1. Type of Persons Which We Collect the Personal Data

Under this Privacy Notice, Sansiri collects personal data of the following persons.

“Officer of group companies of Sansiri Public Company Limited” means directors, employees, or other personnel of the company which its shares are held by Sansiri and shall include the employees of the company which its shares are held by Sansiri who perform a duty at Sansiri in accordance with the policy or terms of Sansiri.

2. Objectives of Collection, Use or Disclosure of Personal Data

Sansiri will collect, use, and disclose your personal data under various lawful basis for the following objectives.

  • No. Objectives Lawful Basis
    1.

    For verifying the identity as an officer of Sansiri group.

    For legitimate interests
    (Legitimate Interests)

    2.

    For coordinating relating to cooperation among Sansiri and group companies, including notifying the information in relation to business operation or activities or project among Sansiri group.

    For the performance of a contract
    (Contractual Basis)

    3.

    For coordinating with the outside organization with respect to business operation in Sansiri group.

    For the performance of a contract
    (Contractual Basis)

    4.

    For considering the acceptance of the employee to work at Sansiri, considering the acceptance of transfer of employee to be Sansiri’s employee. In case Sansiri already accepted the officer of group companies who is an employee of the company in the group companies to work at Sansiri in accordance with the criteria specified in regulations or internal terms of Sansiri, Sansiri may use your personal data for coordinating, performing the duties or proceeding with any transaction with the customers, business partners, company in Sansiri group, government sectors, state enterprise, government agencies, public organizations, independent entities established according to the law, any other agencies or persons, as a representative of Sansiri or for performing the duties assigned by Sansiri, including conclusion of contract, amendment of the contract or various agreements, authorizing or acceptance of authorization, as well as proceeding with clarification, providing the information, providing statement to the third party, or attending the trainings, seminars, academic forums, or presentation to the third party on behalf of Sansiri, including for the performance in accordance with internal procedure of Sansiri, performance evaluation, or payment of compensation for the work, or welfare.

    For the performance of a contract
    (Contractual Basis)

    For legitimate interests
    (Legitimate Interests)

    5.

    For checking the authority, authorizing or acceptance of authorization, including being used as supportive evidence of relevant transactions.

    For the performance of a contract
    (Contractual Basis)

    6.

    For collecting and using your personal data, namely name-surname, position, organization, and photograph, motion, and/or sound in connection with the performance and activities of Sansiri for publication through various channels, such as internal email of Sansiri and group companies, Sansiri’s website, Facebook, LINE, YouTube, or other online media of Sansiri or other media, such as television, printing media, and so on.

    For legitimate interests
    (Legitimate Interests)

    7.

    For applying to access and use the electronic system or opening the accessing right or the use of internet or various electronic system.

    For the performance of a contract
    (Contractual Basis)

    8.

    For proceeding with planning, reporting, and forecasting the business, risk management, supervision, and inspection, including internal inspection of the Internal Audit Office and internal management of the organization, as well as for benefits of internal operation of Sansiri relating to disbursement of the financial accounting department of Sansiri.

    For legitimate interests
    (Legitimate Interests)

    9.

    For concluding the database of stakeholders of Sansiri and/or for relationship management or coordination relating to Sansiri, including opinion surveying for analyzing and improving the operation of Sansiri.

    For legitimate interests
    (Legitimate Interests)

    10.

    For investigating, examining the internal complaint of the organization, preventing the corruption, or proceeding with any other legal proceedings, including checking and managing the complaint and accusation relating the operation of Sansiri or relevant person to ensure the transparency and justice for every party.

    For legitimate interests
    (Legitimate Interests)

    11.

    For security around building, the place, and the project of Sansiri, including card exchanging prior to the access of such area, the record of a person contacting with Sansiri, or the building, the place, and the project of Sansiri by CCTV.

    For legitimate interests
    (Legitimate Interests)

    12.

    For establishing the legal claims, authorizing, and accepting the authorization, complying with or exercising the legal claims, or defending the legal claims, proceeding with lawsuit, as well as proceeding with legal execution.

    For complying with the law
    (Legal Obligation)

    In some cases, we may collect, use, and disclose personal data of family members or other persons which you provided us. In this regard, Sansiri collects, uses, and discloses personal data of such persons under various lawful basis for the following objectives.

  • No. Objectives Lawful Basis
    1.

    In case Sansiri accepted the officer of group companies who is an employee of the company in the group companies to work at Sansiri in accordance with the criteria specified in regulations or internal terms of Sansiri, Sansiri may collect, use, and disclose personal data of family members of such employee for managing various welfares which Sansiri provides to family members of the officer of group companies, such as medical welfare, health insurance, and so on.

    For legitimate interests
    (Legitimate Interests)

    2.

    For communication in necessary or emergency cases, such as notifying the danger occurred to the officer of group companies, and so on.

    For legitimate interests
    (Legitimate Interests)

    3.

    For conducting the risk management and internal control of organization, supervision, inspection, as well as for the internal inspection of the Internal Audit Office, the good corporate governance, and internal management of organization.

    For legitimate interests
    (Legitimate Interests)

    4.

    For establishing the legal claims, authorizing, and accepting the authorization, complying with or exercising the legal claims, or defending the legal claims, proceeding with lawsuit, as well as proceeding with legal execution.

    For complying with the law
    (Legal Obligation)

    In case the personal data which Sansiri collects, for the above objectives, is necessary for the performance of a contract or for compliance with various applicable laws, if you do not provide such necessary information, Sansiri may not be able to consider for entering the transaction or managing in accordance with the contract with you (as the case may be). 

    Furthermore, in case you provide personal data of others to us, you shall be responsible for notifying such persons this Privacy Notice and/or obtaining the consent (if necessary).

3. Personal Data Which Will Be Collected

Generally, to collect your personal data, Sansiri will collect the personal data by requesting or asking for such information directly from you. However, in some cases, Sansiri may collect your personal data from other sources, such as your affiliation company, your employee, secretary or coordinator, government sectors or government agencies, or other publicly available sources, such as websites, the information can be searched on the internet, and so on.

In this regard, Sansiri collects your personal data, as follows.  

  • 3.1 General Personal Data
    1. Information enables the identification of a person (Identity Data), such as name, surname, national ID card number, passport number, date of birth, gender, age, nationality, signature, photograph, professional license number, employee code (only for the employee of Sansiri group), information of driving license, information of driving license of Sansiri’s car, username of electronic system (Username), and so on.
    2. Contact information (Contact Data), such as address, copy of house registration, telephone number, facsimile number, email, geolocation, emergency contact, social network account, LINE ID, secretary information, and so on.
    3. Financial information (Financial Data), such as bank account number, and so on.
    4. Information with respect to communication with Sansiri (Communication Data), such as information regarding date, time, and place of communication with Sansiri, video and audio recordings when contacting with Sansiri, and so on.
    5. Information with respect to the company or agencies which you are working with, such as affiliation company or agency, working place, position, position level, working period on the position level, working period on the level group, working period at Sansiri, working period at Sansiri group, retirement year, annual performance evaluation history, position history, evaluation results, success profile, result of evaluation of knowledge, ability, suitability on the duties, analyzing result of success profile, analyzing result of ability and guideline for personnel development, and so on.
    6. Information with respect to educational background, working background, trainings, expertise, and various achievements, and so on.
    7. Information with respect to personal interest.
    8. Video recording by CCTV and facial scanning for time-attendant records.
    9. Information with respect to participation of the meetings between Sansiri and group companies, including the information regarding the participation of the trainings, seminars, activities, or other projects arranged by Sansiri which the record of still photos, motion, and/or sounds may be proceeded during such meeting, training, seminar, or activity. 
    10. Other information necessary for proceeding with lawsuit or legal execution, such as marital status, property information, and so on.
    11. Opinion, recommendation, complaints.
    12. Activity history or history on participation in various projects of Sansiri.
    13. Information with respect to screening in accordance with epidemic prevention measures.
    14. Information regarding the driving behavior of Sansiri’s car.
    15. Information with respect to the use of various electronic systems of Sansiri, including information regarding the use of Application, website visiting (Browsing Information), such as website browsing history, IP address, and so on.
    16. Other personal data for facilitation as necessary, such as your preferred food or beverage, and so on.
    17. Information enables the identification of family members (father, mother, spouse, children, adopted child, brothers and sisters of full blood, brothers and sisters of half blood), namely name, surname, national ID card number, passport number, date of birth, place of birth, gender, age, signature, photograph, nationality, and so on.
  • 3.2 Sensitive Personal Data

    In general, Sansiri does not desire to collect and use the information pertaining to religious beliefs and blood type specified on your copy of national ID card for any objective in particular. In case you provide a copy of national ID card to Sansiri, please hide such information. In case you do not hide aforementioned information, it shall be considered that you give a consent to Sansiri to hide such information and it shall be considered that the document having such hidden information is valid and enforceable in accordance with the law in all respects. In this regard, if Sansiri is unable to hide the information due to some technical restriction, Sansiri will collect and use such information as only for a part of your identity verification. 

    In the case where it is necessary to Sansiri to collect your sensitive personal data, Sansiri will request for your explicit consent, on a case-by-case basis, unless otherwise specified by law. In this regard, Sansiri may process the following sensitive personal data.

    1. Information pertaining to religious beliefs. 
    2. Health data and/or disability.
    3. Information pertaining to racial.

4. Retention Period

Sansiri will retain your personal data for the period as necessary for performing the objectives of collection, use or disclosure of the personal data specified herein. The criteria for determining the retention period are the period which Sansiri still needs to use your personal data in accordance with the objectives and may continue to retain as the period necessary for complying with the laws, or legal prescription, or for the establishment, compliance or exercise of legal claims, or defense of legal claims, or for other cases according to the policy and internal regulations of Sansiri.

5. Disclosure of Personal Data

For performing the objectives specified in this notice, Sansiri may disclose your personal data to the following third parties.

  • 5.1 Group companies of Sansiri.
  • 5.2 Government sectors, supervisory authorities, state enterprises, government agencies, public organization, independent entities established in accordance with the law, or other entities prescribed by laws, including the competent officials, such as the court, the police officers, the Revenue Department, the Land Office, the District Office, the Provincial Office, the Securities and Exchange Commission of Thailand, the Anti-Money Laundering Office, the Department of Skill Development, the Department of Labour Protection and Welfare, the Office of the Ombudsman of Thailand, the State Audit Office of the Kingdom of Thailand, the House of Representatives Affairs Committee, the Senate Committee, the Legal Execution Department, the Office of the Attorney General, the State Audit Office of the Kingdom of Thailand, the Office of the National Anti-Corruption Commission, and so on.
  • 5.3 Agencies, organizations, or persons relating to the exercise of legal claims, lawsuits, objection of the complaints or accusation, litigation of Sansiri, such as litigants, and so on.
  • 5.4 Agents, contractor/subcontractor and/or service provider performing any operation for Sansiri, such as professional consultants, transportation service providers, contractor performing marketing activities, the company providing accommodations and traveling, the companies organizing the activities, trainings, or seminars, media production contractor, contractor performing public relation activities, insurer, auditor, legal consultant, and so on.
  • 5.5 A person having business relationship (in the case where it is necessary for the performance of contract when the project or business is co-operated).
  • 5.6 Certification institutes for the management system standards. 
  • 5.7 Training participants.
  • 5.8 Shareholders, bondholders, and representatives of such persons.
  • 5.9 Bank or financial institutes.
  • 5.10 Assignee of the rights, obligations, and any benefits from Sansiri, including authorized person of such assignee, such as restructuring, merger and acquisition, demerger, or business transfer, and so on.
  • 5.11 Other third party, such as announcement of the list of selected candidates through social media channels of Sansiri or publication of photographs of activities or activity news or project news of Sansiri to the mass media and third party, and so on.
  • 5.12 Hospital or sanatorium.

6. Transfer or Disclosure of Personal Data to Other Countries

In some cases, we may be required to disclose your personal data to the other countries, which the standards of personal data protection may be different from Thailand due to there are companies in the group companies of Sansiri located in other countries, and there are business operations or transactions proceeded with foreign companies. Therefore, we may be required to disclose your personal data to these companies, including government agencies, professional consultants and persons who are relevant to or necessary to access such personal data for operating our normal business. In addition, there might be disclosure to other countries for proceeding with lawsuits or arbitration that may be done in the future. Furthermore, Sansiri may store your personal data in the computers, servers, or clouds of service providers located in other countries, and may process information by using package software or applications of service providers located in other countries. 

However, to send or transfer such information, for any case, Sansiri will comply with the Personal Data Protection Act, B.E.2562 (2019).

7. Your Rights as a Data Subject

As you are a data subject, you have the rights as prescribed by the Personal Data Protection Act, B.E.2562 (2019). In this regard, you can exercise your various rights through the channels which Sansiri specifies in Clause 9. or through Sansiri’s website. You are entitled to exercise the rights when the personal data protection law is enforced. Your rights are as follows.

  • 7.1 Right to withdraw the consent (Right to Withdraw Consent)

    In case Sansiri requests for your consent, you are entitled to withdraw the consent for processing of personal data given to Sansiri, unless such withdrawal of consent is restricted by law or contract which is beneficial for you. In this regard, the withdrawal of consent shall not affect any processing of personal data which the consent was already legally given by you.

  • 7.2 Right to access to the personal data (Right to Access)

    You are entitled to request for accessing and obtaining a copy of your personal data, which is under responsibility of Sansiri, including request Sansiri to disclose the acquisition of such information which you do not consent to Sansiri.

  • 7.3 Right to request for sending or transferring of personal data (Data Portability Right)

    You are entitled to request Sansiri to transfer your personal data provided to Sansiri in accordance with the laws.

  • 7.4 Right to object the collection, use or disclosure of personal data (Right to Object)

    You are entitled to object to the processing of information relating to you for the collection, use or disclosure of personal data that is prescribed by law.

  • 7.5 Right to erase the personal data (Erasure Right)

    You are entitled to request Sansiri to erase your personal data as prescribed by law. However, Sansiri may collect your personal data by electronic system which some of the system may be unable to be erased. In such case, Sansiri will destroy or anonymize such personal data to become anonymous data that cannot identify you.

  • 7.6 Right to request for restriction of the use of personal data (Right to Restrict Processing)

    You are entitled to request Sansiri to restrict the use of your personal data as prescribed by law.

  • 7.7 Right to request for correcting the personal data (Rectification Right)

    In case you opine that the information possessed by Sansiri is incorrect or you have changed your personal data, you are entitled to request Sansiri to correct your personal data so that your such personal data will be accurate, up-to-date, complete, and not misleading.

  • 7.8 Right to lodge a complaint (Right to Lodge a Complaint)

    You are entitled to lodge a complaint to the competent authority in accordance with the Personal Data Protection Act, B.E.2562 (2019) in the event that Sansiri violates or does not comply with such Act.

8. Amendment of this Notice

We may occasionally amend this Privacy Notice and, if there is such amendment, we will announce it on Sansiri’s website and/or invitation letter of the annual general meeting of the shareholders and/or news channels of the Stock Exchange of Thailand and/or notify you through email. In this regard, in case it is necessary to request your consent, we will proceed with requesting the consent from you additionally.

9. Contact Methods

If you have any questions or would like to ask for more information regarding the protection of your personal data, the collection, use or disclosure of your personal data, the exercise of your rights, or any complaints, you can contact Sansiri at the following channels.

Sansiri Public Company Limited
Data Protection Officer

Contact place: 59 Soi Rim Khlong Phra Khanong, Phra Khanong Nuea Sub-district, Vadhana District, Bangkok 10110
Telephone no.: 1685
Email: cs@sansiri.com