PLIC Corp., Ltd. and Its Affiliates
No. PDPA 001/2026
Personal Data Protection Policy PLIC Corp., Ltd. and Its Affiliates
PLIC Corp., Ltd. and Its Affiliates (CCTV Privacy Notice)
PLIC Corp., Ltd. and its affiliated companies (the “Company”) recognize and place great importance on privacy and the protection of personal data of personnel, customers, business partners, and associates. The Company complies with applicable laws and international standards to prevent misuse of personal data collected by the Company. Therefore, the Company hereby announces this Policy as follows:
1. Scope of the Policy
This Personal Data Protection Policy aims to explain how the Company collects, uses, and discloses your personal data, including your rights in relation to such personal data. The Company is responsible for safeguarding the security of the data it provides and/or receives from you.
2. Definitions
2.1 “Company” means Plic Corporation Co., Ltd. and its affiliated companies, including their authorized representatives.
2.2 “Personal Data” means any information relating to a person that enables the identification of such person, whether directly or indirectly, including data provided to the Company for the performance of services under contractual conditions. Personal Data is categorized into two types:
2.2.1 General Personal Data
Includes first name–last name, nickname, date of birth, age, address, telephone number, fax number, username, email, national ID number, passport number, social security number, driver’s license number, taxpayer identification number, bank account number, education history, employment history, vehicle registration, land title deed, fingerprints, voice recordings, photographs, and data of deceased persons.
2.2.2 Sensitive Personal Data
Means personal data classified as sensitive under the Personal Data Protection Act B.E. 2562 (2019), which the Company collects, uses, discloses, or transfers abroad only upon obtaining lawful consent from the data subject. Examples include race, ethnicity, political opinions, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, labor union information, genetic data, biometric data (e.g., facial recognition, iris scans, fingerprint scans for identity verification), or any other data as prescribed by the Personal Data Protection Committee.
2.2.3 “Data Controller (DC)”
Means a juristic person who is a service recipient of the Company and/or a company that directly collects personal data from data subjects and has authority to decide on the collection, use, or disclosure of personal data.
2.2.4 “Data Processor (DP)”
Means a person or entity that collects, uses, or discloses personal data on behalf of or under the instructions of the Data Controller in accordance with service agreements, without being a Data Controller.
2.2.5 “Data Subject (DS)”
Means a living natural person who is identified or identifiable by personal data. This excludes juristic persons such as companies, associations, foundations, or other legal entities.
3. Collection of Personal Data
3.1 The Company will collect and retain your personal data by lawful and fair means, only to the extent necessary for its operations and as permitted by law.
3.2 As a Data Controller, the Company will obtain your consent prior to collecting your personal data, except where:
- It is for public interest archiving, research, or statistics with appropriate safeguards.
- It is necessary to prevent or suppress danger to life, body, or health.
- It is necessary for the performance of a contract.
- It is required by law, court order, or lawful authority, or for legitimate interests.
- It is for your benefit and consent cannot be obtained at that time.
- It is for investigation by inquiry officials or court proceedings.
- It is required under applicable laws (e.g., PDPA, Electronic Transactions Act, Telecommunications Business Act, Anti-Money Laundering Act, Civil and Criminal Codes, Procedural Codes, etc.).
3.3 The Company may collect your personal data from other sources where necessary and with your consent, to ensure accuracy and improve service quality.
3.4 The Company may request additional information to ensure that your data remains accurate and up to date.
4. Use of Personal Data
4.1 As a Data Controller, the Company will use or disclose your personal data only with your consent and in accordance with its stated purposes. Employees are prohibited from disclosing your data beyond such purposes, except under the same legal bases stated in Clause 3.2.
4.2 The Company may engage external IT service providers to store personal data, provided such providers implement appropriate security measures and do not process data beyond the Company’s instructions.
4.3 In certain cases, the Company may allow external persons or entities to access personal data as necessary and in line with Company purposes, subject to prior consent.
5. Cross-Border Transfer of Personal Data
5.1 The Company may transfer your personal data to affiliated companies or other entities abroad where necessary for contractual performance, legal compliance, prevention of danger to life or health, or significant public interest.
5.2 The Company may store your data on servers or cloud systems operated by third parties and use third-party software or platform services for data processing. Unauthorized access will not be permitted, and appropriate security measures will be required.
5.3 For international transfers, the Company will comply with applicable data protection laws and ensure adequate safeguards to protect your rights.
6. Security Measures
The Company implements appropriate security measures and develops information security systems in compliance with legal standards. Employees and external service providers must strictly adhere to these measures.
If you suspect unauthorized disclosure, loss, theft, or misuse of your personal data, please notify the Company immediately.
7. Rights of Data Subjects
7.1 You may submit a request to access your personal data and inquire about its use at the Company’s office. The Company will respond within 30 days or within a reasonable timeframe.
7.2 Subject to legal conditions, you have the following rights:
7.2.1 Right of access and to obtain copies.
7.2.2 Right to rectification.
7.2.3 Right to data portability.
7.2.4 Right to object to processing, unless the Company has lawful grounds.
7.2.5 Right to erasure or anonymization, unless retention is legally required.
7.2.6 Right to withdraw consent (without affecting prior lawful processing).
7.2.7 Right to lodge a complaint if the Company violates the PDPA.
Requests may be submitted at the Company’s office or via email: pramuk@plic.co.th. The Company will respond within 30 days or a reasonable timeframe, subject to legal limitations.
8. Retention Period and Withdrawal of Consent
8.1 The Company retains personal data only as long as necessary for its purposes or legal claims.
8.2 The Company implements systems for deletion or destruction upon expiration of retention periods, contractual terms, controller instructions, or withdrawal of consent, unless retention is required by law.
9. Cookies Policy
When you visit www.plic.co.th or www.plicthermo.co.th, information regarding your visit may be collected in the form of cookies. By accessing these websites, you consent to the use of cookies as described below.
What Are Cookies?
Cookies are small text files stored on your computer that collect standard internet log information and visitor behavior data. They identify you as a user but do not reveal your name or personal details unless you provide such information.
Purpose of Cookies:
- To remember your preferences (e.g., language, region).
- To improve future website experience.
- To analyze website performance and advertising effectiveness.
- To enhance security and prevent unauthorized account access.
Managing Cookies:
You may configure your browser to refuse cookies (see www.aboutcookies.org). However, some website features may not function properly. Refusing advertising cookies does not eliminate ads but may make them less relevant.
This Cookies Policy may be updated periodically to comply with applicable regulations.
10. Policy Governance
The Company complies with the Personal Data Protection Act B.E. 2562 (2019) and has appointed a Data Protection Officer (DPO) to oversee compliance with data protection laws and related regulations. The Company continuously promotes awareness among employees to ensure adherence to policies and legal requirements.
Any amendments to this Policy will be announced on the Company’s websites:
www.plic.co.th / www.plicthermo.co.th
Announced on 23 February 2026
(Takao Okubo)
Managing Director
