Last updated: 2022-06-02 | 482 Views |
No. 018 / 2022
PRIVACY NOTICE FOR EMPLOYEE
Aeroklas Company Limited, a subsidiary of EPG: Eastern Polymer Group Public Company Limited, respects employees' privacy rights and also realizes the importance to protect personal data, which must be sufficient to prevent the infringement of privacy rights of the relevant data subject. Therefore, the Company has hereby prescribed and announced the policy of the processing of personal data and the details related to collecting, using, or disclosing personal data as follows:
1. Purpose for collecting, using, or disclosing personal data
The Company will collect, use or disclose personal data if deemed necessary for the Company's human resource management under the following objectives:
1.1 Use in the preparation of employment contracts, employment conditions agreements, compliance with employment contracts, employee registration, employee orientation, compensation payments, accident insurance, compliance with regulations, assigning work, repositioning employees, dispatching employees to a subsidiary of companies or affiliates, training, assessing performance, managing and supervising the health and safety of employees.
1.2 Labor relations, work discipline, and use in compliance with the Company's human resource management regulations.
1.3 For the legitimate interests of human resource management, data analysis, manpower allocation, personnel development, promotion, bonus, wage adjustment, retirement, arrangement of hospital welfare, medical records, providing insurance benefits, and other interests of employees. For example, hospitals, canteens, gymnasiums, recreational activities, activities in various areas for employees, internal communications, external contacts, registration operations, authorization, making credentials, public documents, preparing reports, submitting information to government and/or regulatory agencies, verifying identity and verifying the accuracy of the data received from employees, analyzing and establishing a database of previous employment and/or opinions, communication, sending news and public relations, improving the working environment, providing facilities, maintaining information security, creating user accounts, identifying to access the work system, and accessing information systems, security, preventing accidents and crimes, auditing and dealing with complaints and fraud for various lawsuits or disputes.
1.4 To prevent and suppress harm to employees' life or health, such as through emergency contacts, communicable disease control, and prevention through emergency contacts.
1.5 To perform duties in the execution of the mission and benefit to the public or to perform duties of the granted state powers.
1.6 To communicate public relations activities within the Company's group such as training, seminars, recreational activities to help society, meetings, booths, preparation of various annual reports, etc.
2. Personal Data Processing Basis
The Company will process personal data, on a lawful data processing base, as follows:
2.1 Processing on a contractual basis.
2.2 Processed on a legal basis
2.3 Processed basis of the Company's legitimacy
2.4 Processed basis of the consent of the personal data subject.
2.5 Processed on another basis legitimacy
3. Personal data Collecting, Using, or Disclosing
Collecting, using, or disclosing of personal data is as follows:
3.1 Information and documents related to the employee, for example Resume or Curriculum Vitae (CV), and cover letters, job application, including supporting documents and interview evaluation comments.
3.2 Contact information for employees. For example, first name, last name, domicile address, current address, residence information, phone number, email, social media information, and people who can be contacted if non-relatives and other contact persons in urgent cases.
3.3 Employee information. For example, date of birth, age, height, weight, blood type, nationality, race, religion, gender, marital status, military status, ordination history, health information, interests, opinions, and other details such as referral information. Information on relatives or friends who work in the company, convenience in case of going to work in other provinces, etc.
3.5 Photograph or motion picture for identification purposes and safety in the workplace, including the activities of the Company.
3.6 Information about education, activities during education, ability, potential development, and other employee qualifications. For example, education degree, period of education, GPA institution/university, training, test results, and professional qualifications. The ability to use languages and computers, drive a vehicle with a driver's license, and other skills and qualifications. Information from references provided by employees.
3.7 Information about previous employments. For example, company name/address, working hours, position, detailed salary and compensation welfare received, nature of work, and the reason for leaving.
3.8 Information about employee’s characteristics. For example, character, behavior, attitude, aptitude, skills, leadership abilities, the ability to work with others, emotional intelligence, corporate commitment, etc. This information may be obtained from observation and analysis during work performance or participation in activities.
3.9 Information that employees choose to share and disclose through the Company's systems, applications, tools, questionnaires, assessments, and documents.
3.10 Copies of documents that can be used to identify employees. For example, ID cards, passport, driver's license, house registration, and other documents issued by government agencies.
3.11 Information necessary for the performance of an employment contract, for welfare benefits analysis and administration, and for employees’ retirement, in compliance with the law.
3.12 Information about criminal records to consider the suitability of work and to maintain the Company's legitimate interests or a third person. This will be done following the process prescribed by law.
3.13 Information about accidents in case when employees have accidents during work or due to work operations and other work-related accidents.
3.14 Information required for reporting to regulatory agencies. For example, the Ministry of Labor, Stock Exchange of Thailand and The Securities and Exchange Commission, Thailand.
3.15 Employee financial information, for example, wages, salaries, income, taxes, provident funds, bank accounts, loans, tax exemptions, or deductions.
3.16 Employee information related to social security labor protection, labor relations, privileges, welfare, and benefits that employees receive or are entitled to receive in accordance with the Company's regulations and human resource management regulations.
3.17 Record of attendance, time off work, overtime and employee annual leave.
3.18 Employee's work history, job title, meeting attendance comments.
3.19 Information relating to complaints, grievances, investigations, and disciplinary action.
3.20 Health information and/or health examination results. For example, weight, height, congenital disease, blindness color, food allergy, allergy medications, blood type, medical certificate, medication dispensing history, medical expense receipts for labor protection, and welfare related to medical treatment for employees. Employee competency assessment, in compliance with relevant laws, to study and analyze the employee’s health data for other appropriate management purposes.
3.21 Biological data, such as fingerprint data and face images to be used to identify and verify the identity of the employee, and for the prevention of crime and safeguarding the legitimate interests of the Company.
3.23 Information collected from participation in Company activities. For example, participation in surveys and assessment responses.
3.24 Other personal data for lawful purposes or if information is made public, with the applicant's express consent, to achieve the objectives related to recruitment.
4. Personal data collection period
4.1 The Company will keep personal data for the period necessary to achieve the specified objectives. Considering the necessity of each type of data practice, and after the expiration of such period, the Company will destroy or delete personal data using appropriate means as determined by the Company.
4.2 The Company will keep employees' personal data throughout the period of employment and for ten years after the employment has ended to achieve the employee privacy objectives.
4.3 The Company will provide an audit system to perform the deletion or destruction of data after the retention period, or unrelated or beyond the necessity of the purpose of collecting that data.
5. Disclosure of Personal Data to Third Parties
5.1 The Company may disclose the personal data of its employees to subsidiaries and third parties. For example, transfer considerations, background audit, qualification, and the ability to follow the purpose of collecting and processing other personal data to achieve this announcement policy's objectives.
5.2 The Company will require the recipient of information to take appropriate measures to protect the employee's information, process the personal data as necessary, and take steps to prevent or disclose the information wrongfully.
6. Employee Rights
Employees have the following rights regarding personal data collected by the Company:
6.1 The right to be informed of details before employees' personal data is collected.
6.2 The right to request a copy or transfer of your personal data to the data controller.
6.3 The right to object collection of data without consent.
6.4 The right to request data suspension.
6.5 The right to request deletion or destruction of information that is no longer necessary for storage.
6.6 The right to request the updating of the personal data of employees.
6.7 The right to withdraw consent for information collected on the basis of consent.
6.8 The right to make complaints if the Company uses personal data unlawfully.
However, the refusal to provide information or withdraw consent may prevent the Company from carrying out certain employee requests, and may prevent the human resource management from operating completely. The withdrawal of consent will not affect the collection, use, or disclosure of data with consent.
7. Measures to maintain the security of personal data
To maintain security and prevent the loss, access, use, alteration, correction, or disclosure of personal data without authority or wrongdoing, the Company has established a system for collecting personal data. There is an access control mechanism and security measures in place. The Company will also arrange regular reviews of measures to ensure their effectiveness in maintaining physical, administrative and technical security.
8. Contact the Company and the Personal Data Protection Officer
If you have any questions about this Personal Data Protection Act. Policy or want to exercise any specified rights, you can contact us at:
Aeroklas Company Limited
Personal Data Protection Officer (DPO)
No. 111/1, 111/10 Moo 2 Tambol Makhamku, Amphur Nikomphattana, Rayong 21180
Telephone: 038–893599 website: www.aeroklas.com
This policy shall be effective from now onwards
Announced on May 10, 2022
Mr. Ekawat Vitoorapakorn