PDPA Compliance สำหรับ โรงงานผลิต — ทำงานตาม PDPC guideline + GDPR + APEC CBPR — cover ทั้งไทยและ multi-jurisdiction
Thai Notary Law & Service ให้บริการ PDPA Compliance ครบวงจร — DPO outsource, DPMS platform, DPIA, RoPA, DSAR, breach response 24/7, PDPC defence, และอบรม; ลูกค้ากว่า 200+ ราย ครอบคลุม healthcare, banking, e-commerce, education, SaaS เราครอบคลุมงานทุกด้านของ PDPA — gap assessment, DPIA, RoPA, privacy policy, DPA, DPO outsource, DSAR, consent management, training, breach response, PDPC defence หลักสูตรอบรมของเรามีทะเบียนกับ PDPC + สถาบันฝึกอบรม (DPO Certification 16 ชม.) — ผู้ผ่านการอบรมได้รับ certificate ที่ยอมรับในการแต่งตั้ง DPO ตาม PDPA ม.41(4); alumni network 800+ คน อุตสาหกรรม โรงงานผลิต มีลักษณะเฉพาะ — employee data, CCTV, biometric time attendance, safety incident จึงต้อง tailored playbook _locale: th_
roadmap 12 เดือนสู่ compliance เต็มขั้น
- training TH/EN/中文/日/韓 พร้อม e-learning สำหรับ new hire
- 72-hour breach playbook + forensic partner + 24/7 hotline
- DSAR SLA 30 วัน — 100% response rate ใน portfolio ลูกค้า
- DPO team IAPP CIPP/E + CIPM + CIPT + ISO 27701 Lead Auditor
- CMP + Google Consent Mode v2 + Meta Pixel consent
DSAR handling — 8 rights ตาม PDPA + SLA 30 วัน
- CMP + Google Consent Mode v2 + Meta Pixel consent
- DPO team IAPP CIPP/E + CIPM + CIPT + ISO 27701 Lead Auditor
- DPMS platform (SSO + role-based) รวม RoPA + DPIA + DSAR + vendor DPA
- indemnity clause — เบี้ยปรับจากความผิดพลาดของเรา เราจ่ายทั้งหมด
- training TH/EN/中文/日/韓 พร้อม e-learning สำหรับ new hire
children data + sensitive data — extra safeguard
- DPO team IAPP CIPP/E + CIPM + CIPT + ISO 27701 Lead Auditor
- SCC + BCR + safeguard cross-border 40+ ประเทศ
- CMP + Google Consent Mode v2 + Meta Pixel consent
- quarterly audit report + PDPC guideline update + roadmap adjustment
- DPMS platform (SSO + role-based) รวม RoPA + DPIA + DSAR + vendor DPA
เมื่อไหร่ต้องแต่งตั้ง DPO อย่างเป็นทางการ
- DPO team IAPP CIPP/E + CIPM + CIPT + ISO 27701 Lead Auditor
- CMP + Google Consent Mode v2 + Meta Pixel consent
- training TH/EN/中文/日/韓 พร้อม e-learning สำหรับ new hire
- DSAR SLA 30 วัน — 100% response rate ใน portfolio ลูกค้า
- indemnity clause — เบี้ยปรับจากความผิดพลาดของเรา เราจ่ายทั้งหมด
quarterly compliance audit + management report
- training TH/EN/中文/日/韓 พร้อม e-learning สำหรับ new hire
- DPMS platform (SSO + role-based) รวม RoPA + DPIA + DSAR + vendor DPA
- DSAR SLA 30 วัน — 100% response rate ใน portfolio ลูกค้า
- indemnity clause — เบี้ยปรับจากความผิดพลาดของเรา เราจ่ายทั้งหมด
- DPO team IAPP CIPP/E + CIPM + CIPT + ISO 27701 Lead Auditor
AI/ML product + DPIA + algorithmic accountability
- DSAR SLA 30 วัน — 100% response rate ใน portfolio ลูกค้า
- DPMS platform (SSO + role-based) รวม RoPA + DPIA + DSAR + vendor DPA
- SCC + BCR + safeguard cross-border 40+ ประเทศ
- quarterly audit report + PDPC guideline update + roadmap adjustment
- CMP + Google Consent Mode v2 + Meta Pixel consent
PDPA vs GDPR vs APEC CBPR — จุดต่างที่ต้องรู้
- 72-hour breach playbook + forensic partner + 24/7 hotline
- SCC + BCR + safeguard cross-border 40+ ประเทศ
- DPMS platform (SSO + role-based) รวม RoPA + DPIA + DSAR + vendor DPA
- indemnity clause — เบี้ยปรับจากความผิดพลาดของเรา เราจ่ายทั้งหมด
- DSAR SLA 30 วัน — 100% response rate ใน portfolio ลูกค้า
vendor + sub-processor management + DPA chain
- training TH/EN/中文/日/韓 พร้อม e-learning สำหรับ new hire
- DSAR SLA 30 วัน — 100% response rate ใน portfolio ลูกค้า
- DPMS platform (SSO + role-based) รวม RoPA + DPIA + DSAR + vendor DPA
- SCC + BCR + safeguard cross-border 40+ ประเทศ
- quarterly audit report + PDPC guideline update + roadmap adjustment
ขั้นตอนการให้บริการ PDPA
- Respond: incident response หากเกิด breach — triage 4 ชม. + notification 72 ชม.
- Plan: roadmap 12 เดือน + quick win 30 วัน (privacy policy, cookie notice, employee awareness)
- DSAR: DSAR portal + workflow + SLA 30 วัน + template response ทั้ง 8 rights
- QuickWin: quick win implementation — Privacy Policy + Cookie CMP + employee training + DPO appointment
- Audit: quarterly compliance audit + management report + PDPC guideline update
- Annual: annual DPO report + risk register update + roadmap adjustment
- Breach: breach playbook + tabletop exercise + forensic partner ready + 24/7 hotline
- DPMS: DPMS setup + RoPA + DPIA (high-risk) + DPA review ทั้ง vendor list
คำถามที่พบบ่อย
- เปลี่ยน DPO consultant มาที่นี่ทำอย่างไร
- เราจัด transition 30-60 วัน — ประสานกับ consultant เดิมขอ RoPA/DPIA/DSAR log/breach register/vendor list, migrate เข้า DPMS ของเรา, review compliance status, ปรับ playbook + workflow, training ทีมลูกค้า; ระหว่าง transition รับผิดชอบ compliance ต่อเนื่องรวม breach response 24/7
- บริษัทของเราต้องแต่งตั้ง DPO หรือไม่
- ต้องแต่งตั้ง DPO ตาม PDPA ม.41 หากเข้าเงื่อนไข: (1) หน่วยงานรัฐ, (2) core business เป็น large-scale monitoring, (3) core business เป็น large-scale processing of sensitive data (medical, biometric, criminal); บริษัททั่วไปที่ไม่เข้าเงื่อนไขไม่บังคับ แต่แนะนำให้มี — best practice + safety net
- DSAR ตอบภายในกี่วันและครอบคลุมสิทธิอะไรบ้าง
- ต้องตอบภายใน 30 วัน (ต่ออีก 60 วันได้ถ้ามีเหตุ) หลังได้รับ request ที่ครบเงื่อนไข; PDPA ให้สิทธิ 8 ประเภท: access, rectification, erasure (right to be forgotten), restriction, portability, object, withdraw consent, complaint; ต้อง verify identity ก่อนตอบ + ให้ฟรีครั้งแรก
- cross-border data transfer ทำอย่างไร
- ต้องมี safeguard ตาม PDPA ม.28-29: (1) transfer ไปประเทศที่ PDPC ประกาศว่ามีมาตรฐานคุ้มครองเทียบเท่า (adequate), (2) transfer ผ่าน SCC (Standard Contractual Clauses) ที่ PDPC อนุมัติ, (3) transfer ผ่าน BCR (Binding Corporate Rules) สำหรับกลุ่มบริษัท, (4) consent explicit ของเจ้าของข้อมูล; เรารับ setup SCC + BCR
- cookie ต้องขอ consent หรือไม่ — cookie notice พอไหม
- ตาม PDPC Cookie Notification 2565: strictly necessary cookies ไม่ต้อง consent, functional/analytics/marketing/advertising cookies ต้อง prior consent (opt-in) ก่อน load; ต้องมี CMP ที่ block cookies ก่อน consent + ให้ withdraw ได้ทุกเมื่อ + เก็บ consent record; Google Consent Mode v2 บังคับใช้ตั้งแต่ March 2024
- ต้องขอ consent ทุกครั้งหรือใช้ legal basis อื่นได้
- PDPA มี legal basis 6 ประเภท (consent, contract, legal obligation, vital interest, public interest, legitimate interest) + สำหรับ sensitive data มี 10 basis เข้มขึ้น; ในทางปฏิบัติ consent ไม่ใช่ default — ควรใช้ contract/legitimate interest ก่อน และ reserve consent เฉพาะ marketing + sensitive data
- vendor/SaaS ที่เราใช้ (Google/Meta/AWS) ต้องเซ็น DPA ไหม
- ต้อง — ทุก vendor ที่ประมวลผลข้อมูลส่วนบุคคลในนามเรา (data processor) ต้องมี DPA ตาม PDPA ม.40 ครอบคลุม: purpose, category, retention, security measure, sub-processor list, cross-border transfer, breach notification, audit right, data return/deletion; Google/Meta/AWS มี template DPA ให้ + ต้อง review + sign เพิ่มเติม
- sensitive data (medical, biometric, sexual orientation, religion) มี rule เพิ่มไหม
- มี — ต้องมี explicit consent (ยกเว้น 9 กรณี เช่น life-saving, employment law, public health) + DPIA บังคับ + retention สั้นกว่า + technical safeguard เข้มขึ้น (encryption at rest + in transit + access log); biometric สำหรับ time attendance ต้อง alternative option ให้พนักงานที่ไม่ยินยอม
- AI/ML product ต้องทำ DPIA หรือไม่
- ต้องทำ — AI/ML processing ถือเป็น systematic evaluation + automated decision-making ตาม PDPC guideline; DPIA ต้อง cover: purpose, data category, algorithmic explainability, bias assessment, human oversight, opt-out mechanism; หากใช้ AI ตัดสินใจที่มี legal/significant effect ต้องมี right to human review + object
ขอปรึกษา PDPA ฟรี 60 นาที
DPO team ตอบกลับใน 15 นาที · breach hotline 24/7 · LINE, Email, โทร
ติดต่อขอปรึกษา





