Personal Data Protection Notice for External Parties

Group 4
 Visitors and any external parties entering the Company's buildings, and users of, and visitors to, the Company's websites or applications


Data Processing

1. Personal data collected, used, disclosed, and/or cross-border transferred

The Company will collect, use, disclose, and/or cross-border transfer the following Personal Data of visitors and external parties entering into the Company's buildings, and users of, and visitors to, the Company's websites or applications:

General Personal Data, such as the first and last names, job position, address, date of birth, telephone/fax number, email address, photographs, motion images from video recording or closed-circuit television (CCTV), information on the national identification card or passport, signature, car information (such as the car plate number, brand, model, and color), and other Personal Data you provide to the Company;

Sensitive Personal Data, including health data for the purpose of disease (including the COVID-19) screening upon your visit or entry into the Company's buildings or operating areas, disability information, which the Company has obtained consent from you or as necessary and permitted by laws; and

Technical data, such as IP address, log files, cookies data, historical system usage data, website usage data, operating systems and platforms, and other technologies on devices used to access the platform, as well as other Personal Data regarding the use of the Company's system.

Remarks: In the case that you are asked to provide supporting documents that contain Sensitive Personal Data, such as race and religion, for the purpose of identity verification, and such data are unnecessary for the operation, you may redact your Sensitive Personal Data before delivering these documents to the Company. If the Sensitive Personal Data contained in the documents received by the Company is not redacted, the Company reserves the right to redact it. In this case, no Sensitive Personal Data will be deemed to be collected by the Company from you.

If you are a minor under the age of 10 or a quasi-incompetent person or an incompetent person, the Company will ask your legal guardian or curator to acts on your behalf, and to give consent to the Company to perform such acts.

If the Company finds that your Personal Data is collected without legal consent from your guardian or curator, it may have to reject your request and delete your Personal Data, unless it can be other legal basis which is an exception to consent can be relied on.

2. Sources of Personal Data

The Company may collect your Personal Data from the following sources:

1) The Company collects the Personal Data provided directly by you through an exchange of identification cards, completion of health-related questionnaire (if any), or through communication via email, telephone, fax, letters, and electronic channels, registration on, or the use of, the Company's information technology systems, and access to, and the use of the Company's websites and applications.
2) The Company collects your Personal Data from other sources, such as companies or agents of contact persons, or other third parties.

3. Purposes of the collection, use, disclosure, and/or cross-border transfer of Personal Data

The Company collects, uses, discloses, and/or cross-border transfers your personal data for the following purposes:

1) To use as database to for identity verification and authentication before you are allowed to enter the buildings or operating areas;
2) To maintain security of the buildings or operating areas using closed-circuit television (CCTV) recordings, and prevent any dangerous or emergency incidents in the areas;
3) To use for access to the Company's websites or applications;
4) To establish legal claims, to use as evidence in the initiation and defense of legal claims, and to comply with court orders or orders from government agencies with legal authority as necessary; and
5) To conduct internal audit in the Company and its affiliated companies, and PTT group companies, to follow up on suggestions, to investigate complaints or claims in order to prevent fraud or improper behavior, and to prevent wrong or illegal acts.

For Sensitive Personal Data, the Company collects, uses, discloses, and/or cross-border transfer your Sensitive Personal Data for the following purposes:

1) To screen diseases and assess risks of communicable diseases before visits or entry into the Company's buildings or operating areas; and
2) To produce reports in compliance with the reporting procedures established by the Company, or as regulators or agencies order as specified by laws.

4. Legal bases for the collection, use, and disclosure of personal data

The Company generally collects, uses, and discloses your Personal Data on the following legal bases:

1) Where it is for the performance of a contract, or fulfilling your requests before you enter into an agreement with the Company;
2) Where it is for legitimate interests of the Company or a third party to the extent that these interests do not override the fundamental rights in your Personal Data;
3) Where it is necessary for compliance with a law;
4) Upon your consent obtained by the Company upon written request for your consent to the collection, use, and disclosure of your Personal Data; and/or
5) Other cases permissible by laws.

Only in the case of the collection, use, and disclosure of your Sensitive Personal Data, the Company relies on the following legal bases:

1) Upon explicit consent obtained by the Company from the consent form requesting for your consent to the collection, use, disclosure, and processing of your Personal Data;
2) Where it is for vital interests to prevent or suppress any harm to the life, body, or health of a person
3) Where it is necessary for the establishment of a legal claim, compliance with, or exercise of a legal claim, or to defend a legal claim; and/or it is information that is disclosed to the public with the explicit consent of the data subject; and/or
4) Other cases permissible by laws.

5. Types of persons or organizations to whom or to which the Company discloses your Personal Data

The Company may disclose your Personal Data (only as necessary) to the following external parties or organizations for the purposes indicated in this Notice, who or which may be located in or outside Thailand.

1) Affiliated companies, partners, and PTT group companies
The Company may share your Personal Data with its affiliated companies, PTT group companies, and partner companies, including but not limited to, PTT Public Company Limited, PTT Global LNG Company Limited, Energy Complex Company Limited, and PTT Digital Solutions Company Limited, for the purpose of risk management, information exchanges, and internal audit within group companies.

2) Outsourced service providers regarding the Company's operations
The Company may disclose your Personal Data to these persons, who may act as the data controller or data processor, such as banks, information technology solution providers, cloud and data storage service providers, application service providers, hospitals, survey providers and data analysts, and space and car parking service providers.

3) Competent government agencies
The Company may disclose your Personal Data to government officials and government agencies which have the legal authority, or for the purpose of protecting the rights of the Company or third parties, or for your own interests, such as the State Audit Office, the Department of Disease Control, Royal Thai Police Headquarters, the Court of Justice, the Revenue Department, the Department of Mineral Fuels, the Department of Consular Affairs, embassies, and the Legal Execution Department.

4) Other external parties or organizations
The Company may disclose your Personal Data to external parties or organizations, or allow them to access your Personal Data, such as professional advisors (including legal advisors and external auditors) and outsourced external organizations to which the Company would like to carry out public relations for the purposes indicated above.