Professional Documents
Culture Documents
PDPA Principles, Planning Ahead - Practice for Thai Universities - กฤติยาณี บูรณต
PDPA Principles, Planning Ahead - Practice for Thai Universities - กฤติยาณี บูรณต
PDPA Principles, Planning Ahead - Practice for Thai Universities - กฤติยาณี บูรณต
16 August 2021
TODAY’S AGENDA
THE NEW NORM
WHERE TO START ?
KEY CONSIDERATIONS
CASE STUDIES
• Hybrid Classroom
• Smart Campus
Data Mapping:
5W (who what where when why) & 1H (how)
Who do we collect personal data from?
What personal data are collected, used, and disclosed?
Where is the data collected and stored?
When do we disclose personal data and to whom?
Why do we collect these personal data?
How long the data is kept?
• Contractual Basis
• Method of requesting for • How many privacy notices to
• Legitimate Interest
consent prepare?
• Legal Obligation
• When to obtain consent • Method of notifying privacy
• Vital Interest
• Parental consent notices
• Historical, research or
• Consent management • Data collected from sources
statistics
other than the data subjects
• Public interest or official
authority power
• Specific Bases for Sensitive
Elements of Consent
Data
1. in writing or via electronic
Example system
2. freely given
3. unconditional Example
The collection of necessary
personal data in relation to the 4. clearly distinguishable
5. intelligible and easily Consider relying on the
enrollment of a student could rely disproportionate effort exception?
on the contractual basis. accessible
6. clear and plain language
7. not deceptive or misleading
8. informed