Personal Data Protection Notice for External Parties

Group 7
Other external parties 
such as regulators, official authorities, and government agencies




Data Processing

1. Personal Data collected, used, disclosed, and/or cross-border transferred

The Company will collect, use, disclose, and/or cross-border transfer the following Personal Data of external parties:

General Personal Data, such as the first name, last name, job position, address, date of birth, telephone/fax number, email address, weight, height, clothing and apparel sizes, photographs, motion images from video recording or closed-circuit television (CCTV), audio recordings from meetings, information on the national identification card or passport, signature, social media account information (such as the LINE ID), car information (such as the car plate number, brand, model, and color), and other Personal Data you provide to the Company; and

Sensitive Personal Data, including health data (such as chronic diseases, history of medicine and food allergies, body temperature, and symptoms), disability information, for the purpose of disease (including the COVID-19) screening, which the Company has obtained consent from you or as necessary and permitted by laws.

Remarks: In the case that you are asked to provide supporting documents that contain Sensitive Personal Data, such as race and religion, for the purpose of identity verification, and such data are unnecessary for the operation, you may redact your Sensitive Personal Data before delivering these documents to the Company. If the Sensitive Personal Data contained in the documents received by the Company is not redacted, the Company reserves the right to redact it. In this case, no Sensitive Personal Data will be deemed to be collected by the Company from you.

2. Sources of Personal Data

The Company may collect your Personal Data from the following sources:

1) The Company collects the Personal Data provided directly by you through an exchange of name cards, or through communication via email, telephone, fax, letters, and the Company's information technology system or electronic channels, and access to the Company's websites and applications.
2) The Company collects your Personal Data from other sources, such as that available in the public websites, or obtained from affiliated companies or PTT group companies, or other third parties.

3. Purposes of the collection, use, disclosure, and/or cross-border transfer of Personal Data

The Company collects, uses, discloses, and/or transfers your Personal Data for the following purposes:

1) To use as database for communication and appointment for consultancy, that is necessary for the Company's operations;
2) To use as database for filing relevant reports, documents, and information;
3) To use as database for the Company's activities;
4) To record images and motion images of the atmosphere in the meeting or activity areas, which will be used to to produce communication information, presentation, and internal and external public relation materials;
5) To prepare and facilitate activities, such as the preparation of meals, accommodation, parking lots, suitable activities, travel insurance, and meetings;
6) To establish legal claims, to use as evidence in the initiation and defense of legal claims, and to comply with court orders or orders from government agencies with legal authority as necessary; and
7) To maintain security of the buildings or operating areas using closed-circuit television (CCTV) recordings.

For Sensitive Personal Data, the Company collects, uses, discloses, and/or cross-border transfers your Sensitive Personal Data for the following purposes:

1) To screen diseases and assess risks of communicable diseases before attending a meeting or participating in an activity;
2) To produce reports in compliance with the reporting procedures established by the Company, or as regulators or agencies order as specified by laws; and
3) To prepare and facilitate activities, such as the preparation of meals, travel, and travel insurance.

4. Legal bases for the collection, use, and disclosure of personal data

The Company generally collects, uses, and discloses your Personal Data on the following legal bases:

1) Where it is for legitimate interests of the Company or a third party to the extent that these interests do not override the fundamental rights in your Personal Data;
2) Where it is necessary for compliance with a law;
3) Upon your consent obtained by the Company upon written request for your consent to the collection, use, and disclosure of your Personal Data; and/or
4) Other cases permissible by laws.

Only in the case of the collection, use, and disclosure of your Sensitive Personal Data, the Company relies on the following legal bases:

1) Upon explicit consent obtained by the Company from the consent form requesting for your consent to the collection, use, and disclosure of your Personal Data;
2) Where it is for vital interests to prevent or suppress any harm to the life, body, or health of a person
3) Where it is necessary for the establishment of a legal claim, compliance with, or exercise of a legal claim, or to defend a legal claim;
4) It is information that is disclosed to the public with the explicit consent of the data subject; and/or
5) Other cases permissible by laws.

5. Types of persons or organizations to whom or to which the Company discloses your Personal Data

The Company may disclose your Personal Data (only as necessary) to the following external parties or organizations for the purposes indicated in this Notice, who or which may be located in or outside Thailand.

1) Affiliated companies, partners, and PTT group companies
The Company may share your Personal Data with its affiliated companies, PTT group companies, and partnered companies, including but not limited to, PTT Public Company Limited, PTT Global LNG Company Limited, Energy Complex Company Limited, and PTT Digital Solutions Company Limited, for the purpose of risk management, information exchanges, and internal audit among group companies.

2) Outsourced service providers regarding the Company's operations
The Company may disclose your Personal Data to these persons, who may act as the data controller or data processor, such as mass media, information technology solution providers, cloud solution providers, data or document storage providers, application service providers, public relations activity and exhibition organizers, hospitals, and survey providers and data analysts.

3) Relevant government agencies
The Company may disclose your Personal Data to government officials and government agencies that have the legal authority, or for the purpose of protecting the rights of the Company or third parties, or for your own interests, such as the State Audit Office, the Comptroller General's Department, the Department of Disease Control, the Court of Justice, the Revenue Department, the Department of Mineral Fuels, the Department of Consular Affairs, embassies, and the Legal Execution Department.

4) Other external parties or organizations
The Company may disclose your Personal Data to external parties or organizations, or allow them to access your Personal Data, such as professional advisors (including legal advisors and external auditors) and external organizations to which the Company would like to carry out public relations for the purposes indicated above.