01
Personal data is determined by the possibility of identification
PDPA applies to data about an identifiable individual, collected, used or disclosed organization. Customer, employee, UBO, director, website/device and support data are included in the scope according to the facts. Business contact information and public data have special rules, but should not be automatically excluded without verification.
02
Organization and data intermediary have different responsibilities
The Organization defines the purposes and means and is responsible for a full set of obligations. Data intermediary processes data on behalf of another and directly bears primarily protection, retention and breach-notification duties, but the contract distributes operational controls and assistance to the principal organization.
- Organisation
- Purpose, notice, consent/exception, rights, security and transfer
- Data intermediary
- Processing on behalf; security, retention and incident notice
- DPO
- Governance owner and public business contact
- Business owner
- Purpose, necessity and access approval
- Vendor
- Contract, controls, sub-processing and evidence
03
Consent is not the only basis, but also not a decorative one
Collection, use and disclosure must comply with a notified reasonable purpose and applicable consent or exception. Deemed consent, legitimate interests and business improvement are used only after conditions and assessment; The withdrawal process is associated with consequences for the service.
04
Privacy notice follows customer journey
Notice explains categories, purposes, recipients, overseas transfers, retention, rights and DPO contact before the corresponding processing. Cookie banner, onboarding form, KYC, HR notice and marketing preference must not contradict the contract or actual integrations.
Each data flow must have an owner, purpose, legal route, recipients, retention and security classification.
05
Reasonable security depends on risk
MFA, least privilege, joiner/mover/leaver and admin controls.
Classification, encryption, masking and secure deletion.
Patching, logging, testing, backup and recovery.
Training, confidentiality, phishing and incident escalation.
06
Cloud and processor are registered before data transfer
Due diligence checks hosting locations, certifications, access, encryption, incident history, sub-processors and exit. Contract fixes instructions, security, confidentiality, breach timing, audit evidence, deletion/return and overseas-transfer protection.
07
Overseas transfer requires comparable protection
The company determines the destination, recipient and onward transfers, then uses a legally recognized mechanism and contractual/organisational safeguards that provide protection comparable to PDPA. Group company abroad is not an automatic exception.
- Map
- Country, recipient, dataset and purpose
- Mechanism
- Contract or other permitted basis under regulations
- Security
- Access, encryption, localization and incident route
- Onward transfer
- Limiting sub-processors and further recipients
- Evidence
- Assessment, contract and periodic review
08
Access and correction requests require a route
The Organization provides access to personal data and usage/disclosure information for the applicable period, corrects errors and omissions and takes into account exceptions, third-party data and identity verification. The retention schedule stops storage when the data is no longer needed for a legal or business purpose.
09
First contain, then determine and notify
The organization stops exposure, stores evidence, identifies affected data/individuals and assesses significant harm or scale. If the breach is notifiable, PDPC is notified as soon as practicable and no later than 3 calendar days after determination; affected individuals - as soon as practical, when required.
- 01Contain
Credentials, systems, vendor and exfiltration path.
- 02Assess
Data, people, harm, scale and ongoing risk.
- 03Notify
PDPC, individuals, partners and other regulators.
- 04Remediate
Root cause, controls, monitoring and documented lessons.
10
PDPA operating file
- 01
Data inventory, systems, vendors, countries and owners.
- 02
Purpose/consent/exception matrix and notices.
- 03
Retention, access, transfer and vendor controls.
- 04
DPO, request workflow and staff training.
- 05
Breach playbook and tabletop test at least according to the risk cycle.
+7 (495) 221 31 46