Messenger

PDPA

PRIVACY NOTICE
Ramkhamhaeng 2 Hospital

Ramkhamhaeng 2 Hospital recognizes the importance of protecting personal data and maintaining appropriate standards for personal data security in accordance with international standards. Therefore, the Hospital has prepared and published this Privacy Notice to inform individuals and legal entities who are involved with or interact with the Hospital. The Hospital, as a Data Controller and Data Processor, in accordance with the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), is required to comply with applicable personal data protection laws and regulations.
The Hospital may need to collect personal data of Data Subjects both directly and indirectly from information provided by the Data Subject or the Data Subject’s representative, persons involved with the Data Subject, internal departments of the Hospital, or other organizations. Such collection may also occur through telephone services, the Hospital’s website, and the downloading or uploading of information from the Hospital’s website, including documents, still images, moving images, digital media, and all forms of electronic media. The Hospital has established the following Personal Data Protection Policy:
1. This Personal Data Protection Policy shall take effect from 1 June 2022. In the event that any rules, procedures, or practices conflict with or are inconsistent with this Personal Data Protection Policy, this Personal Data Protection Policy shall prevail.
2. In cases where any matter relating to personal data protection is not specifically prescribed in this Policy, the Hospital shall comply with applicable laws, rules, regulations, requirements, and other relevant legal provisions.
3. The collection, use, or disclosure of personal data by the Hospital shall comply with the following personal data protection principles:
3.1 Personal data shall be processed lawfully, transparently, and in a manner that can be verified.
3.2 Personal data shall be processed within the scope and for the purposes specified for its collection, use, or disclosure.
3.3 Personal data shall be adequate, relevant, and limited to what is necessary in relation to the purposes of collection, use, or disclosure.
3.4 Personal data shall be accurate and, where necessary, kept up to date.
3.5 Personal data shall be retained only for as long as necessary.
3.6 Appropriate security measures shall be implemented to protect personal data.
4. The collection, use, and disclosure of personal data by the Hospital shall be carried out for legitimate operational purposes and shall rely on an appropriate legal basis for processing personal data in accordance with applicable personal data protection laws, in order to achieve the Hospital’s objectives.
5. Where the personal data collected, used, or disclosed by the Hospital includes health data, which is considered confidential personal information, such data shall not be disclosed in a manner that may cause harm or damage to the Data Subject, except where such disclosure is made at the direct request of the Data Subject or where disclosure is permitted or required by the Personal Data Protection Act or other applicable laws.
6. The collection, use, or disclosure of personal data in the Hospital’s operations shall be carried out in accordance with the purposes previously notified to the Data Subject at the time of collection, unless the Hospital has notified the Data Subject of a new purpose prior to such collection, use, or disclosure, or where such action is permitted by law.
7. The Hospital shall collect personal data only to the extent necessary and shall retain such data for a period that is necessary and appropriate to the nature of the data and the lawful purposes for which the data is processed, for as long as such purposes remain applicable.
8. Where the Hospital is required to obtain consent for the collection, use, or disclosure of personal data, such consent shall be requested in an open, clear, and explicit manner. The Data Subject shall have the right to withdraw consent at any time.
9. The Hospital shall appoint a Data Protection Officer (DPO) to perform duties as required by law and shall provide appropriate support to enable the DPO to effectively perform his or her duties.
10. For the protection of personal data, the Hospital shall implement appropriate technical, organizational, and other security measures to prevent the loss, unauthorized access, destruction, use, alteration, modification, or unauthorized disclosure of personal data. The Hospital shall review and update such security measures whenever necessary or when technological developments or changes occur, in order to maintain an appropriate and effective level of personal data security, in accordance with the Hospital’s regulations concerning personal data security measures.
11. The Hospital does not permit its officers, physicians, personnel, employees, or any other person to disclose personal data in a manner that may cause direct or indirect harm or damage to the Data Subject. In the event that any damage or harm occurs as a result of unauthorized disclosure of personal data, the person responsible for such disclosure shall be liable in accordance with all applicable laws and regulations.
12. In the event of a Personal Data Breach, all officers, physicians, personnel, and employees of the Hospital shall report the incident to the Hospital and the Data Protection Officer (DPO) within 24 hours of becoming aware of the incident.
13. Any consent previously provided by the Data Subject to Ramkhamhaeng 2 Hospital for the collection, use, or disclosure of personal data shall remain valid until the Data Subject withdraws such consent in writing. The Data Subject may withdraw consent, request the correction of personal data, or request the restriction of the use or disclosure of personal data for any particular purpose by submitting a written request to the Hospital or by contacting the Hospital via email at: PDPA@ram2-hosp.com
In addition, under the Personal Data Protection Act B.E. 2562 (2019), the Data Subject has the following rights:
1) Right to Be Informed
2) Right to Rectification: The right to request the correction of inaccurate or incomplete personal data.
3) Right to Withdraw Consent: The right to withdraw consent previously given for the processing of personal data throughout the period during which the personal data remains with the Hospital.
4) Right to Restriction of Processing: The right to request restriction of the use of personal data in certain circumstances as prescribed by law.
5) Right of Access: The right to access personal data and request a copy of such personal data, including the right to request information regarding the source of personal data that was obtained without consent, where permitted by law.
6) Right to Data Portability: The right, in certain circumstances prescribed by law, to request the transfer of personal data provided to the Hospital to another Data Controller or to the Data Subject.
7) Right to Object: The right to object to the processing of personal data in certain circumstances as prescribed by law.
8) Right to Erasure: The right to request the deletion or destruction of personal data in certain circumstances and subject to applicable legal requirements.
9) Right to Lodge a Complaint: The right to lodge a complaint where there has been a violation of or failure to comply with personal data protection laws or regulations issued pursuant to such laws.
Requests under the above rights shall be made in writing. The Hospital shall notify the Data Subject of the outcome of the request within 30 days, unless there are legal restrictions or limitations on the exercise of such rights. However, withdrawal of consent may result in insufficient information for the Hospital to process personal data for the purposes previously notified to the Data Subject and may affect the convenience or continuity of certain services. Such withdrawal shall not affect any processing or actions that have already been lawfully carried out based on the purposes for which consent was previously given.
14. Contact Information
If you, as the Data Subject, have any questions regarding this Privacy Notice or wish to exercise your rights concerning the processing of your personal data, you may contact the Data Protection Officer (DPO) at:
Address: Ramkhamhaeng 2 Hospital, 222 Ramkhamhaeng Road, Rat Phatthana Subdistrict, Saphan Sung District, Bangkok 10240, Thailand
Telephone: 0-2032-3888

Issued on: 21 March 2023
Ramkhamhaeng 2 Hospital
*Reference: Personal Data Protection Act B.E. 2562 (2019)

CCTV Privacy Notice Policy
Ramkhamhaeng 2 Hospital

1. Objective
We collect personal data through the use of Closed-Circuit Television (CCTV) for the following purposes:
1.1 To protect your health and personal safety, including the protection of your property.
1.2 To protect our buildings, facilities, and property against damage, disruption, destruction, or other criminal activities.
1.3 To support relevant authorities in law enforcement activities, including deterrence, prevention, investigation, and legal proceedings.
1.4 To assist in the resolution of disputes arising during disciplinary or grievance procedures.
1.5 To assist in investigations or processes relating to the submission and handling of complaints.
1.6 To assist in initiating or defending civil claims, including, but not limited to, legal proceedings relating to employment.
2. Policy
This CCTV Privacy Notice (“Notice”) provides information regarding the collection, use, and disclosure of personal data that may identify you, as well as the legal bases for processing your personal data. We collect and process your personal data based on the following legal bases:
2.1 The necessity to prevent or suppress danger to the life, body, or health of you or another person.
2.2 The necessity for our legitimate interests or those of another person, provided that such interests are not overridden by your fundamental rights in relation to your personal data.
2.3 The necessity to comply with applicable laws and regulations relating to the safety and security of the workplace environment and the Hospital's property.
3. Scope
The Hospital collects, uses, or discloses personal data through the use of CCTV equipment installed within and around the premises of Ramkhamhaeng 2 Hospital.
4. Definitions
4.1 “Security Department” or “we” means the Security Department under the Service Support Division of the Hospital.
4.2 “Premises” means the areas within and surrounding the Hospital.
4.3 “You” means officers, personnel, customers, employees, contractors, visitors, or any other persons entering the Premises where CCTV equipment is in operation.
4.4 “Personal Data” means any information relating to an individual that enables such individual to be identified, whether directly or indirectly.
5. Responsible Departments
Security Department, Service Support Division, and Information Technology Department of the Hospital
6. Procedures
6.1 Personal Data We Collect and Use
As stated in the purposes above, we install CCTV cameras in visible locations and place CCTV warning signs at entrances and exits, as well as in other areas where we consider surveillance necessary. When you enter the Premises, the CCTV system may collect the following personal data:
1) Still images
2) Moving images or video recordings
3) Audio recordings
4) Images of your property, such as vehicles, bags, hats, clothing, and other personal belongings.
We will not install CCTV cameras in areas where surveillance may disproportionately infringe upon your fundamental rights, including bedrooms, toilets, bathrooms, or designated rest areas for personnel.
6.2 Disclosure of Your Personal Data
We will keep CCTV footage relating to you confidential and will not disclose such information except where disclosure is necessary to achieve the surveillance purposes specified in this Notice. We may disclose CCTV footage to the following categories of persons or entities:
1) Competent authorities as required or permitted by law, in order to assist and support law enforcement, investigations, inquiries, or legal proceedings.
2) Third-party service providers, where necessary to ensure the prevention or suppression of danger to the life, body, health, or property of you or another person.
6.3 Your Rights under the Personal Data Protection Act B.E. 2562 (2019)
The Personal Data Protection Act B.E. 2562 (2019) is intended to provide data subjects with greater control over their personal data. You may exercise your rights under the Personal Data Protection Act B.E. 2562 (2019), subject to the applicable provisions and conditions of the law, including the following:
1) Right of Access: You have the right to access and obtain a copy of your personal data collected by us and to request information regarding the source of such personal data, except where we are legally entitled to refuse your request, such as where required by law or a court order, or where fulfilling the request may adversely affect the rights and freedoms of another person.
2) Right to Rectification: You have the right to request the correction of inaccurate or incomplete personal data to ensure that your personal data is accurate, current, complete, and not misleading.
3) Right to Restriction of Processing: You have the right to request the restriction of the use of your personal data in any of the following circumstances:
(1) While we are verifying your request to correct your personal data so that it is accurate, complete, and up to date.
(2) Where your personal data has been unlawfully collected, used, or disclosed.
(3) Where your personal data is no longer necessary for the purposes for which it was collected, but you request that we retain the data for the establishment, exercise, or defense of your legal claims.
(4) While we are verifying whether we have legitimate grounds for collecting, using, or disclosing your personal data, or determining whether the processing is necessary for the performance of a task carried out in the public interest, following your exercise of the right to object to the collection, use, or disclosure of your personal data.
4) Right to Object: You have the right to object to the collection, use, or disclosure of your personal data, except where we have lawful grounds to refuse your request, such as where we can demonstrate compelling legitimate grounds for the collection, use, or disclosure of your personal data, or where the processing is necessary for the establishment, exercise, or defense of legal claims, compliance with legal obligations, or the performance of a task carried out in the public interest.
6.4 Retention Period of Personal Data
For the purposes of CCTV surveillance as specified in this Notice, we will retain CCTV footage relating to you for a period of 1 month from the date on which the Security Officer has completed the relevant retrospective review, or for as long as necessary to achieve the purposes specified in this Notice. The personal data may be retained for a longer period where required by applicable laws or regulations or where necessary for the establishment, exercise, or defense of legal claims. Upon expiration of the applicable retention period, we will delete, destroy, or otherwise securely dispose of your personal data in accordance with applicable laws and our data retention procedures.
6.5 Personal Data Security
We implement appropriate technical and organizational measures to protect your personal data against loss, unauthorized access, deletion, destruction, use, alteration, modification, or disclosure. These measures are implemented in accordance with our Information Security Policy and related information security practices. In addition, we have established a Personal Data Protection Policy that has been communicated throughout the organization, together with appropriate procedures and practices to ensure the security of personal data during its collection, use, and disclosure. We maintain the following fundamental principles of information security:
- Confidentiality – ensuring that personal data is accessible only to authorized persons.
- Integrity – ensuring that personal data remains accurate, complete, and protected against unauthorized alteration.
- Availability – ensuring that personal data is available to authorized persons when required.
We will periodically review this policy and this Notice at an appropriate interval to ensure that they remain suitable and effective.
6.6 Responsibilities of the Data Controller
We have restricted access to personal data to authorized personnel whose duties and responsibilities are directly related to the collection, use, or disclosure of personal data under this processing activity. Such personnel are required to strictly comply with this Notice and applicable personal data protection and information security policies.
6.7 Changes to This Privacy Notice
We may revise or amend this Notice from time to time as we deem appropriate. Any changes will be communicated through the QR Code displayed at the Hospital entrances, Security Guard Posts, and Information/Reception Desks. The effective date of the latest version of this Notice will be indicated at the end of the Notice. We recommend that you regularly review the latest version of this Notice, particularly before entering our Premises. By entering the Premises, you acknowledge this Notice. If you do not agree with the terms of this Notice, please refrain from entering the Premises. If you continue to enter the Premises after this Notice has been amended and published through the channels specified above, you will be deemed to have acknowledged the relevant changes.
6.8 Contact Information
If you have any questions or require further information regarding this Notice, please contact:
Ramkhamhaeng 2 Hospital
222 Ramkhamhaeng Road, Rat Phatthana Subdistrict, Saphan Sung District, Bangkok 10240, Thailand
Telephone: 02-032-3888
An example of a CCTV Notice Sign to be displayed in areas where CCTV cameras are installed, in order to inform data subjects before entering the monitored area.
7. Process Monitoring and Measurement
None
8. References
8.1 Personal Data Protection Act B.E. 2562 (2019)