Personal Data Protection Notice for External Parties

Group 5
Stakeholders
including the Company's directors and former directors, shareholders, investors, analysts, members of the mass media, community leaders, and participants in the Company's CSR activities and other activities



Data Processing

1. Personal data collected, used, disclosed, and/or cross-border transferred

     The Company will collect, use, disclose, and/or cross-border transfer the following Personal Data of the stakeholders.

     1.1 The Company's directors and former directors

     General Personal Data, such as the first name, last name, job position, address, date of birth, telephone number, email address, information on the national identification card or passport, signature, height, weight, photographs, motion images from video recording or closed-circuit television (CCTV), audio recordings from meetings, social media account information (such as the LINE ID), car information (such as the car plate number, brand, model, and color), and other Personal Data you provide to the Company;

     Sensitive Personal Data, including religion, blood type, health data (such as chronic diseases, disability information, history of medicine and food allergies, body temperature, and symptoms), for the purpose of disease (including the COVID-19) screening, and biometric data (such as facial recognition data), which the Company has obtained consent from you or as necessary and permitted by laws;

     Work-related information, such as job position, workplace, the date of work commencement as a PTTEP director, remuneration information, remuneration deduction, tax payments, and other work-related Personal Data you provide to the Company;

     Payment information, such as bank account number and details;

     Technical data, such as the username and password used to access the system, IP address, Media Access Control data, log files, cookies data, historical system usage data, website usage data, operating systems and platforms, and other technologies on devices used to access the platform, as well as other Personal Data regarding the use of the Company's system; and

     Personal Data of a third party, including the first name, last name, addresses, telephone numbers, information on the national identification cards, ages, securities holding information (if any) of the spouse, child, father, mother and sibling, and other Personal Data of a third party you provide to the Company.

     If you provide the Personal Data of a third party as mentioned above to the Company, you must ensure that you are authorized to do so, and are authorized to allow the Company to process such Personal Data under this Notice. You are also responsible to inform the third party of this Notice, and/or obtain consent from such person, if required by law, or rely on other legal basis.

     If the Company needs to collect, use, disclose, and/or cross-border transfer your Personal Data to use as the database of your performance of duties as a director, the refusal to provide necessary Personal Data may prevent the Company from performing its obligations or fulfilling your requests, restrict your eligibility for some benefits, affect the Company's or your performance of legal obligations, and prevent the Company from wholly and partially performing the duties or obligations it has with you.

     1.2 Other stakeholders, including shareholders, investors, analysts, members of the mass media, community leaders, and participants in the Company's CSR activities and other activities

     General Personal Data, such as the first name, last name, job position, address, date of birth, telephone number, email address, photographs, motion images from video recording or closed-circuit television (CCTV), audio recordings from meetings and/or lectures, information on the national identification card or passport, securities holder registration number, signature, first or last name change certificate, social media account information (such as the LINE ID, WhatsApp profile, or Facebook profile), car information (such as the car plate number, brand, model, and color), weight, height, clothing and apparel sizes, and other Personal Data you provide to the Company;

     Sensitive Personal Data, including religion, health data (such as chronic diseases, disability information, history of medicine and food allergies, body temperature, and symptoms), for the purpose of disease (including the COVID-19) screening, which the Company has obtained consent from you or as necessary and permitted by laws;

     Payment information, such as bank account number and details;

     Technical data, such as the username and password used to access the system, IP address, Media Access Control data, log files, cookies data, historical system usage data, website usage data, operating systems and platforms, and other technologies on devices used to access the platform, as well as other Personal Data regarding the use of the Company's system; and

     Personal Data of a third party, including the first name, last name, address, and telephone number of the contact person, and other Personal Data of a third party you provide to the Company.

     Remarks: In the case that you are asked to provide supporting documents that contain Sensitive Personal Data, such as race and religion, for the purpose of identity verification, and such data are unnecessary for the operation, you may redact your Sensitive Personal Data before delivering these documents to the Company. If the Sensitive Personal Data contained in the documents received by the Company is not redacted, the Company reserves the right to redact it. In this case, no Sensitive Personal Data will be deemed to be collected by the Company from you.

     If you provide the Personal Data of a third party as mentioned above to the Company, you must ensure that you are authorized to do so, and are authorized to allow the Company to process such Personal Data under this Notice. You are also responsible to inform the third party of this Notice, and/or obtain consent from such person, if required by law, or rely on other legal basis.

     If you are a minor under the age of 10 or a quasi-incompetent person or an incompetent person, the Company will ask your legal guardian or curator to perform acts on your behalf, and to give consent to the Company to perform such acts.

     If the Company finds that your Personal Data is collected without legal consent from your guardian or curator, it may have to reject your request and delete your Personal Data, unless it can be other legal basis which is an exception to consent can be relied on.

2. Sources of Personal Data

     2.1 The Company's directors and former directors

     The Company may collect your Personal Data from the following sources.

     1) The Company collects the Personal Data provided directly by you in photocopies, photographs, motion images, and electronic data, such as email address, telephone number, LINE ID, and through registration on, or the use of, the Company's information technology systems, and access to, or the use of the Company's websites and applications.
     2) Company collects your Personal Data from other sources, such as your secretary, officials of government agencies or state enterprises, and affiliated companies or PTT group companies, or the data is obtained from other third parties or available in the public websites, such as the website of a government agency.

     2.2 Other stakeholders, including shareholders, investors, analysts, members of the mass media, community leaders, and participants in the Company's CSR activities and other activities

     The Company may collect your Personal Data from the following sources.

1) The Company collects the Personal Data provided directly by you through registration for attendance in a meeting or participation in an activity, any power of attorney letter, or any health-related questionnaires (if any), or via email, telephone, fax, and letters, registration on, or the use of, the Company's information technology systems, and access to, or the use of the Company's websites and applications.
2) The Company collects your Personal Data from other sources, such as its securities registrar, Thailand Securities Depository Company Limited (TSD), or data available in the public websites or obtained from other third parties.

3. Purposes of the collection, use, disclosure, and/or cross-border transfer of Personal Data

     3.1 The Company's directors and former directors

     The Company collects, uses, discloses, and/or cross-border transfers your Personal Data for the following purposes:

1) To take any necssary actions relating to your performance of duties as a PTTEP director, such as organizing PTTEP board of directors meetings and shareholders meetings, considering and paying remuneration, preparing annual reports, and organizing other PTTEP activities;
2) To submit and disclose your Personal Data as required by laws or orders from government agencies and/or relevant regulators, such as the Stock Exchange of Thailand, the Securities and Exchange Commission, the Office of the National Anti-Corruption Commission, and the Ministry of Commerce's Department of Business Development;
3) To communicate about, and manage travel itineraries for external training or seminar sessions, or where you must travel to work or participate in activities held outside the Company's buildings. These travel itineraries include flight reservation, accommodation reservation, visa application, and insurance;
4) To exchange information within the Company and its affiliated companies, and the PTT group;
5) To establish legal claims, to use as evidence in the initiation and defense of legal claims, and to comply with court orders or orders from government agencies with legal authority as necessary;
6) To conduct internal audit in the Company and affiliated companies and prevent wrongdoings, to investigate complaints or claims and prevent fraud or improper behavior, and to prevent wrong or illegal acts; and
7) To maintain security of the buildings or operating areas using closed-circuit television (CCTV) recordings.

     For Sensitive Personal Data, the Company collects, uses, discloses, and/or cross-border transfer your Sensitive Personal Data for the following purposes:

1) Health data, such as chronic diseases, history of medicine and food allergies, disability information, body temperature, and symptoms, for the purpose of disease (including the COVID-19) screening, to ensure the safety of your health or occupational health while you are on duty, and ensure that food and travel plans can be appropriately prepared and arranged for you; to examine and screen diseases and assess risks of communicable diseases; or to produce reports in compliance with the reporting procedures established by the Company, or as regulators or agencies order as specified by laws; and
2) Biometric data (such as facial recognition data) to use as security database for the access to, and exit from the buildings.

     3.2 Other stakeholders, including shareholders, investors, analysts, members of the mass media, community leaders, and participants in the Company's CSR activities and other activities

     The Company collects, uses, discloses, and/or cross-border transfer your Personal Data for the following purposes:

1) To use as database for summoning meetings, registration to attend meetings, counting quorums, counting votes, paying annual dividends, and exercising other rights to which shareholders should be entitled due to their presence in shareholders meetings or being PTTEP shareholders (if applicable);
2) To use as database for communication, public relations, publication of the Company's updates, and submissiong of relevant, necessary documents and information, such as annual reports, sustainable development reports, financial reports, letters of invitation to shareholders meetings, and letters of invitation to activities;
3) To use to receive feedbacks from stakeholders in areas where the Company's projects take place, and to prepare reports as required by laws or by regulators;
4) To use as database for the Company's activities, such as visits to the Company's operations and participation in CSR activities, and to use as database to follow upon the progress and success of the Company's activities or projects;
5) To record images and motion images of the atmosphere in the meeting or activity areas, which will be used to produce communication information, presentation, and internal and external public relation materials;
6) To prepare and facilitate activities, such as the preparation of meals, travel, accommodation, parking lots, suitable activities, travel insurance, and meetings;
7) To ask for opinions, collect statistics, and analyze data for the purpose of improving and developing the Company's operations;
8) To establish legal claims, to use as evidence in the initiation and defense of legal claims, and to comply with court orders or orders from government agencies with legal authority as necessary;
9) To conduct internal audit in the Company and its affiliated companies, and PTT group companies, to follow up on suggestions, to investigate complaints or claims in order to prevent fraud or improper behavior, and to prevent wrong or illegal acts; and
10) To maintain security of the buildings or operating areas using closed-circuit television (CCTV) recordings.

For Sensitive Personal Data, the Company collects, uses, discloses, and/or cross-border transfers your Sensitive Personal Data for the following purposes:

1) To screen diseases and assess risks of communicable diseases before attending a meeting or participating in an activity, and to produce reports in compliance with the reporting procedures established by the Company, or as regulators or agencies order as specified by laws; and
2) To prepare and facilitate activities, such as the preparation of meals, travel, and travel insurance.

4. Legal bases for the collection, use, and disclosure of personal data

The Company generally collects, uses, and discloses your Personal Data on the following legal bases:

1) Where it is for the performance of a contract, or fulfilling your requests before you enter into an agreement with the Company;
2) Where it is for legitimate interests of the Company or a third party to the extent that these interests do not override the fundamental rights in your Personal Data;
3) Where it is necessary for compliance with a law;
4) Upon your consent obtained by the Company upon written request for your consent to the collection, use, and disclosure of your Personal Data; and/or
5) Other cases permissible by laws.

Only in the case of the collection, use, and disclosure of your Sensitive Personal Data, the Company relies on the following legal bases:

1) Upon explicit consent obtained by the Company from the consent form requesting for your consent to the collection, use, and disclosure of your Personal Data;
2) Where it is for vital interests to prevent or suppress any harm to the life, body, or health of a person;
3) Where it is necessary for the establishment of a legal claim, compliance with, or exercise of a legal claim, or to defend a legal claim; or
4) Where it is for compliance with a law to achieve the purposes with respect to preventive medicine, occupational medicine, medical diagnosis, the provision of health or social care, medical treatments, the management of health care, public interest in public health, and the road accident victims protection, whereby the collection of Personal Data is necessary for the Company to perform its duties, or your duties;
5) It is information that is disclosed to the public with the explicit consent of the data subject; and/or
6) Other cases permissible by laws.

5. Types of persons or organizations to whom or to which the Company discloses your Personal Data

     The Company may disclose your Personal Data (only as necessary) to the following external parties or organizations for the purposes indicated in this Notice, who or which may be located in or outside Thailand.

1) Affiliated companies, partners, and PTT group companies
The Company may share your Personal Data with its affiliated companies, PTT group companies, and partner companies, including but not limited to PTT Public Company Limited, PTT Global LNG Company Limited, Energy Complex Company Limited, and PTT Digital Solutions Company Limited, for the purpose of human resource management at the group level, risk management, information exchanges, and internal audit within group companies.
 
2) Outsourced service providers regarding the Company's operations
The Company may disclose your Personal Data to these persons, who may act as the data controller or data processor, such as payroll service providers, banks, mass media, information technology solution providers, cloud solution providers, data or document storage providers, application service providers, facial recognition solution providers, hospitals, space and car parking providers, producers of the Company's advertisements, videos, and publications, organizers, including public relations activity and exhibition organizers, hotels and/or accommodation providers, airlines, survey service providers, and data analysts.

3) Relevant government agencies
The Company may disclose your Personal Data to government officials and government agencies which have the legal authority, or for the purpose of protecting the rights of the Company or third parties, or for your own interests, such as the Stock Exchange of Thailand, the Securities and Exchange Commission, the Office of the National Anti-Corruption Commission, the Ministry of Commerce's Department of Business Development, the State Audit Office, the Comptroller General's Department, the Department of Disease Control, the Royal Thai Police, the Court of Justice, the Revenue Department, the Department of Mineral Fuels, the Department of Consular Affairs, embassies, and the Legal Execution Department.

4) Other external parties or organizations
The Company may disclose your Personal Data to external parties or organization, or allow them to access your Personal Data, such as professional advisors (including legal advisors and external auditors) and external organizations to which the Company would like to carry out public relations for the purposes indicated above.