Skip to content
ทีมทนาย Notary Public บริษัท Thai Notary Law & Service — ทนายผู้ได้รับใบอนุญาตทำคำรับรองลายมือชื่อและเอกสารจากสภาทนายความในพระบรมราชูปถัมภ์

ทีมทนายผู้ได้รับใบอนุญาต Notarial Services Attorney

ใบอนุญาตจากสภาทนายความในพระบรมราชูปถัมภ์

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายอนุตรีย์ Miss Anutaree

    ทนายอนุตรีย์Miss Anutaree

    Notarial Services Attorney • Sworn Translator

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายจิรพันธ์ Mr. Jirapan

    ทนายจิรพันธ์Mr. Jirapan

    Notarial Services Attorney • Corporate Counsel

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายจิรศักดิ์ Mr. Jirasak

    ทนายจิรศักดิ์Mr. Jirasak

    Notarial Services Attorney • Litigation

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายปฏิภาณ Mr. Patipan

    ทนายปฏิภาณMr. Patipan

    Notarial Services Attorney • Immigration

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายวราวุธ Mr. Warawut

    ทนายวราวุธMr. Warawut

    Notarial Services Attorney • Real Estate

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายวิวัฒน์ Mr. Wiwat

    ทนายวิวัฒน์Mr. Wiwat

    Notarial Services Attorney • Family & Marriage

จัดทำ Privacy Policy + Cookie Notice · Privacy Policy & Cookie Notice — ค่าบริการโปร่งใส + fixed fee + retainer พร้อม on-call 24/7

Thai Notary Law & Service ให้บริการ PDPA Compliance ครบวงจร — DPO outsource, DPMS platform, DPIA, RoPA, DSAR, breach response 24/7, PDPC defence, และอบรม; ลูกค้ากว่า 200+ ราย ครอบคลุม healthcare, banking, e-commerce, education, SaaS หน้านี้เน้นบริการ จัดทำ Privacy Policy + Cookie Notice — ต่อโครงการ; ครอบคลุม website + app + offline; Deliverable: Privacy Policy TH + EN (แยก customer/employee/vendor), Cookie Notice + banner CMP implementation, layered notice + just-in-time consent หลักสูตรอบรมของเรามีทะเบียนกับ PDPC + สถาบันฝึกอบรม (DPO Certification 16 ชม.) — ผู้ผ่านการอบรมได้รับ certificate ที่ยอมรับในการแต่งตั้ง DPO ตาม PDPA ม.41(4); alumni network 800+ คน ทุก engagement ระบุ scope + fee + SLA + indemnity clause; ปฏิบัติตาม PDPA, PDPC guideline, GDPR, APEC CBPR, ASEAN Data Protection Framework, และ ISO 27701 _locale: th_

CIPP/E + CIPM + CIPT
IAPP certified ครบทุก certification สำหรับ multi-jurisdiction
DPMS platform included
RoPA + DPIA + DSAR + vendor DPA + incident log ครบใน SSO
Fixed monthly retainer
ไม่มี hourly billing surprise + 20 ชม./เดือน + unlimited email
ISO 27701 Lead Auditor
audit + certify DPMS ตามมาตรฐานสากล
Multilingual training
TH + EN + 中文 + 日本語 + 한국어 — head office/branch coverage
AI Act ready
prep for AI Act ไทย + EU AI Act + APEC CBPR

ขอบเขต compliance ที่ครอบคลุมทุก processing activity

บริการ จัดทำ Privacy Policy + Cookie Notice (Privacy Policy & Cookie Notice) ต่อโครงการ; ครอบคลุม website + app + offline · Timeline: 10 วัน · ฐาน PDPA ม.23 + PDPC Cookie Notification 2565 การ notify breach ต่อ PDPC ภายใน 72 ชม. เรามี playbook ที่ทดสอบแล้ว + forensic partner ที่ preapproved — เข้าถึงทีมได้ 24/7 ผ่าน hotline; SLA garantie triage ภายใน 4 ชม. + containment ภายใน 12 ชม. + notification ภายใน 60 ชม. (buffer 12 ชม. ก่อนเส้นตาย) เมื่อพูดถึง ขอบเขต compliance ที่ครอบคลุมทุก processing activity สิ่งที่ผู้บริหารและ DPO ควรเข้าใจคือ PDPA ไม่ใช่แค่เรื่องกฎหมาย — เป็น business enabler ที่ช่วยให้บริษัทได้ trust จากลูกค้า, ผ่าน enterprise procurement, เข้าถึงตลาด EU/US ที่ต้อง GDPR compliance, และป้องกันความเสียหายทั้งค่าปรับ (สูงสุด 5 ล้าน) reputation และ business disruption จาก breach
  • DPMS platform (SSO + role-based) รวม RoPA + DPIA + DSAR + vendor DPA
  • 72-hour breach playbook + forensic partner + 24/7 hotline
  • DPO team IAPP CIPP/E + CIPM + CIPT + ISO 27701 Lead Auditor
  • training TH/EN/中文/日/韓 พร้อม e-learning สำหรับ new hire
  • CMP + Google Consent Mode v2 + Meta Pixel consent
กรณีศึกษาจากลูกค้าจริง: SaaS B2B ระดับ enterprise ที่ต้องขายให้ EU: เรา uplift compliance จาก PDPA ไป GDPR + ISO 27701 certification — closed deal €2.5M กับลูกค้าเยอรมันภายใน 6 เดือน

Deliverable หลัก: Privacy Policy TH + EN (แยก customer/employee/vendor); Cookie Notice + banner CMP implementation; layered notice + just-in-time consent; translation 6 locale เพิ่มเติม (option)

quarterly compliance audit + management report

บริการ จัดทำ Privacy Policy + Cookie Notice (Privacy Policy & Cookie Notice) ต่อโครงการ; ครอบคลุม website + app + offline · Timeline: 10 วัน · ฐาน PDPA ม.23 + PDPC Cookie Notification 2565 DPO team ของเราประกอบด้วย IAPP CIPP/E, CIPP/A, CIPM, CIPT ครบทุก certification + IRCA ISO 27701 Lead Auditor + Thai PDPA Certified DPO ตาม PDPC standards — ทีมเดียวในไทยที่ครอบคลุมทั้ง PDPA + GDPR + APEC CBPR + ASEAN Data Protection Framework เมื่อพูดถึง quarterly compliance audit + management report สิ่งที่ผู้บริหารและ DPO ควรเข้าใจคือ PDPA ไม่ใช่แค่เรื่องกฎหมาย — เป็น business enabler ที่ช่วยให้บริษัทได้ trust จากลูกค้า, ผ่าน enterprise procurement, เข้าถึงตลาด EU/US ที่ต้อง GDPR compliance, และป้องกันความเสียหายทั้งค่าปรับ (สูงสุด 5 ล้าน) reputation และ business disruption จาก breach
  • DSAR SLA 30 วัน — 100% response rate ใน portfolio ลูกค้า
  • training TH/EN/中文/日/韓 พร้อม e-learning สำหรับ new hire
  • quarterly audit report + PDPC guideline update + roadmap adjustment
  • DPO team IAPP CIPP/E + CIPM + CIPT + ISO 27701 Lead Auditor
  • DPMS platform (SSO + role-based) รวม RoPA + DPIA + DSAR + vendor DPA
กรณีศึกษาจากลูกค้าจริง: โรงเรียนนานาชาติ 800 นักเรียน: เรา implement children data safeguard + parental consent workflow + LMS DPA + alumni marketing consent — ไม่มี complaint จากผู้ปกครองในเวลา 18 เดือน

Deliverable หลัก: Privacy Policy TH + EN (แยก customer/employee/vendor); Cookie Notice + banner CMP implementation; layered notice + just-in-time consent; translation 6 locale เพิ่มเติม (option)

vendor + sub-processor management + DPA chain

บริการ จัดทำ Privacy Policy + Cookie Notice (Privacy Policy & Cookie Notice) ต่อโครงการ; ครอบคลุม website + app + offline · Timeline: 10 วัน · ฐาน PDPA ม.23 + PDPC Cookie Notification 2565 การ notify breach ต่อ PDPC ภายใน 72 ชม. เรามี playbook ที่ทดสอบแล้ว + forensic partner ที่ preapproved — เข้าถึงทีมได้ 24/7 ผ่าน hotline; SLA garantie triage ภายใน 4 ชม. + containment ภายใน 12 ชม. + notification ภายใน 60 ชม. (buffer 12 ชม. ก่อนเส้นตาย) เมื่อพูดถึง vendor + sub-processor management + DPA chain สิ่งที่ผู้บริหารและ DPO ควรเข้าใจคือ PDPA ไม่ใช่แค่เรื่องกฎหมาย — เป็น business enabler ที่ช่วยให้บริษัทได้ trust จากลูกค้า, ผ่าน enterprise procurement, เข้าถึงตลาด EU/US ที่ต้อง GDPR compliance, และป้องกันความเสียหายทั้งค่าปรับ (สูงสุด 5 ล้าน) reputation และ business disruption จาก breach
  • DPMS platform (SSO + role-based) รวม RoPA + DPIA + DSAR + vendor DPA
  • indemnity clause — เบี้ยปรับจากความผิดพลาดของเรา เราจ่ายทั้งหมด
  • DSAR SLA 30 วัน — 100% response rate ใน portfolio ลูกค้า
  • SCC + BCR + safeguard cross-border 40+ ประเทศ
  • CMP + Google Consent Mode v2 + Meta Pixel consent
กรณีศึกษาจากลูกค้าจริง: ธนาคาร digital-only ที่จดทะเบียน BOT: เราสร้าง DPMS parallel กับ BOT IT Risk Guideline — pass PDPC first-year inspection + BOT audit โดยไม่มี finding

Deliverable หลัก: Privacy Policy TH + EN (แยก customer/employee/vendor); Cookie Notice + banner CMP implementation; layered notice + just-in-time consent; translation 6 locale เพิ่มเติม (option)

DSAR handling — 8 rights ตาม PDPA + SLA 30 วัน

บริการ จัดทำ Privacy Policy + Cookie Notice (Privacy Policy & Cookie Notice) ต่อโครงการ; ครอบคลุม website + app + offline · Timeline: 10 วัน · ฐาน PDPA ม.23 + PDPC Cookie Notification 2565 หลักสูตรอบรมของเรามีทะเบียนกับ PDPC + สถาบันฝึกอบรม (DPO Certification 16 ชม.) — ผู้ผ่านการอบรมได้รับ certificate ที่ยอมรับในการแต่งตั้ง DPO ตาม PDPA ม.41(4); alumni network 800+ คน เมื่อพูดถึง DSAR handling — 8 rights ตาม PDPA + SLA 30 วัน สิ่งที่ผู้บริหารและ DPO ควรเข้าใจคือ PDPA ไม่ใช่แค่เรื่องกฎหมาย — เป็น business enabler ที่ช่วยให้บริษัทได้ trust จากลูกค้า, ผ่าน enterprise procurement, เข้าถึงตลาด EU/US ที่ต้อง GDPR compliance, และป้องกันความเสียหายทั้งค่าปรับ (สูงสุด 5 ล้าน) reputation และ business disruption จาก breach
  • DPO team IAPP CIPP/E + CIPM + CIPT + ISO 27701 Lead Auditor
  • training TH/EN/中文/日/韓 พร้อม e-learning สำหรับ new hire
  • CMP + Google Consent Mode v2 + Meta Pixel consent
  • quarterly audit report + PDPC guideline update + roadmap adjustment
  • DSAR SLA 30 วัน — 100% response rate ใน portfolio ลูกค้า
กรณีศึกษาจากลูกค้าจริง: โรงพยาบาลเอกชน 250 เตียงใน กทม.: เรา implement PDPA + HIPAA-inspired safeguard สำหรับ EMR + telemedicine + wearable IoMT — audit ผ่าน JCI + HA re-accreditation ในปีถัดไป

Deliverable หลัก: Privacy Policy TH + EN (แยก customer/employee/vendor); Cookie Notice + banner CMP implementation; layered notice + just-in-time consent; translation 6 locale เพิ่มเติม (option)

การเตรียม transition หากเปลี่ยน DPO consultant

บริการ จัดทำ Privacy Policy + Cookie Notice (Privacy Policy & Cookie Notice) ต่อโครงการ; ครอบคลุม website + app + offline · Timeline: 10 วัน · ฐาน PDPA ม.23 + PDPC Cookie Notification 2565 เรามี DPMS (Data Protection Management System) ที่ implement ตาม ISO 27701 + PDPA + GDPR — ครอบคลุม RoPA, DPIA, DSAR, incident register, training log, และ vendor DPA ครบใน platform เดียว; ลูกค้าเข้าใช้ผ่าน SSO + role-based access เมื่อพูดถึง การเตรียม transition หากเปลี่ยน DPO consultant สิ่งที่ผู้บริหารและ DPO ควรเข้าใจคือ PDPA ไม่ใช่แค่เรื่องกฎหมาย — เป็น business enabler ที่ช่วยให้บริษัทได้ trust จากลูกค้า, ผ่าน enterprise procurement, เข้าถึงตลาด EU/US ที่ต้อง GDPR compliance, และป้องกันความเสียหายทั้งค่าปรับ (สูงสุด 5 ล้าน) reputation และ business disruption จาก breach
  • SCC + BCR + safeguard cross-border 40+ ประเทศ
  • 72-hour breach playbook + forensic partner + 24/7 hotline
  • DPMS platform (SSO + role-based) รวม RoPA + DPIA + DSAR + vendor DPA
  • CMP + Google Consent Mode v2 + Meta Pixel consent
  • DPO team IAPP CIPP/E + CIPM + CIPT + ISO 27701 Lead Auditor
กรณีศึกษาจากลูกค้าจริง: โรงพยาบาลเอกชน 250 เตียงใน กทม.: เรา implement PDPA + HIPAA-inspired safeguard สำหรับ EMR + telemedicine + wearable IoMT — audit ผ่าน JCI + HA re-accreditation ในปีถัดไป

Deliverable หลัก: Privacy Policy TH + EN (แยก customer/employee/vendor); Cookie Notice + banner CMP implementation; layered notice + just-in-time consent; translation 6 locale เพิ่มเติม (option)

การจัดการ cross-border transfer + SCC + BCR

บริการ จัดทำ Privacy Policy + Cookie Notice (Privacy Policy & Cookie Notice) ต่อโครงการ; ครอบคลุม website + app + offline · Timeline: 10 วัน · ฐาน PDPA ม.23 + PDPC Cookie Notification 2565 การ notify breach ต่อ PDPC ภายใน 72 ชม. เรามี playbook ที่ทดสอบแล้ว + forensic partner ที่ preapproved — เข้าถึงทีมได้ 24/7 ผ่าน hotline; SLA garantie triage ภายใน 4 ชม. + containment ภายใน 12 ชม. + notification ภายใน 60 ชม. (buffer 12 ชม. ก่อนเส้นตาย) เมื่อพูดถึง การจัดการ cross-border transfer + SCC + BCR สิ่งที่ผู้บริหารและ DPO ควรเข้าใจคือ PDPA ไม่ใช่แค่เรื่องกฎหมาย — เป็น business enabler ที่ช่วยให้บริษัทได้ trust จากลูกค้า, ผ่าน enterprise procurement, เข้าถึงตลาด EU/US ที่ต้อง GDPR compliance, และป้องกันความเสียหายทั้งค่าปรับ (สูงสุด 5 ล้าน) reputation และ business disruption จาก breach
  • DPO team IAPP CIPP/E + CIPM + CIPT + ISO 27701 Lead Auditor
  • DPMS platform (SSO + role-based) รวม RoPA + DPIA + DSAR + vendor DPA
  • SCC + BCR + safeguard cross-border 40+ ประเทศ
  • DSAR SLA 30 วัน — 100% response rate ใน portfolio ลูกค้า
  • training TH/EN/中文/日/韓 พร้อม e-learning สำหรับ new hire
กรณีศึกษาจากลูกค้าจริง: SaaS B2B ระดับ enterprise ที่ต้องขายให้ EU: เรา uplift compliance จาก PDPA ไป GDPR + ISO 27701 certification — closed deal €2.5M กับลูกค้าเยอรมันภายใน 6 เดือน

Deliverable หลัก: Privacy Policy TH + EN (แยก customer/employee/vendor); Cookie Notice + banner CMP implementation; layered notice + just-in-time consent; translation 6 locale เพิ่มเติม (option)

อบรมพนักงานให้เข้าใจและปฏิบัติจริง ไม่ใช่แค่เซ็นรับทราบ

บริการ จัดทำ Privacy Policy + Cookie Notice (Privacy Policy & Cookie Notice) ต่อโครงการ; ครอบคลุม website + app + offline · Timeline: 10 วัน · ฐาน PDPA ม.23 + PDPC Cookie Notification 2565 หลักสูตรอบรมของเรามีทะเบียนกับ PDPC + สถาบันฝึกอบรม (DPO Certification 16 ชม.) — ผู้ผ่านการอบรมได้รับ certificate ที่ยอมรับในการแต่งตั้ง DPO ตาม PDPA ม.41(4); alumni network 800+ คน เมื่อพูดถึง อบรมพนักงานให้เข้าใจและปฏิบัติจริง ไม่ใช่แค่เซ็นรับทราบ สิ่งที่ผู้บริหารและ DPO ควรเข้าใจคือ PDPA ไม่ใช่แค่เรื่องกฎหมาย — เป็น business enabler ที่ช่วยให้บริษัทได้ trust จากลูกค้า, ผ่าน enterprise procurement, เข้าถึงตลาด EU/US ที่ต้อง GDPR compliance, และป้องกันความเสียหายทั้งค่าปรับ (สูงสุด 5 ล้าน) reputation และ business disruption จาก breach
  • CMP + Google Consent Mode v2 + Meta Pixel consent
  • SCC + BCR + safeguard cross-border 40+ ประเทศ
  • DSAR SLA 30 วัน — 100% response rate ใน portfolio ลูกค้า
  • DPO team IAPP CIPP/E + CIPM + CIPT + ISO 27701 Lead Auditor
  • 72-hour breach playbook + forensic partner + 24/7 hotline
กรณีศึกษาจากลูกค้าจริง: ธนาคาร digital-only ที่จดทะเบียน BOT: เราสร้าง DPMS parallel กับ BOT IT Risk Guideline — pass PDPC first-year inspection + BOT audit โดยไม่มี finding

Deliverable หลัก: Privacy Policy TH + EN (แยก customer/employee/vendor); Cookie Notice + banner CMP implementation; layered notice + just-in-time consent; translation 6 locale เพิ่มเติม (option)

case study จากลูกค้าจริงในอุตสาหกรรมเดียวกัน

บริการ จัดทำ Privacy Policy + Cookie Notice (Privacy Policy & Cookie Notice) ต่อโครงการ; ครอบคลุม website + app + offline · Timeline: 10 วัน · ฐาน PDPA ม.23 + PDPC Cookie Notification 2565 การ notify breach ต่อ PDPC ภายใน 72 ชม. เรามี playbook ที่ทดสอบแล้ว + forensic partner ที่ preapproved — เข้าถึงทีมได้ 24/7 ผ่าน hotline; SLA garantie triage ภายใน 4 ชม. + containment ภายใน 12 ชม. + notification ภายใน 60 ชม. (buffer 12 ชม. ก่อนเส้นตาย) เมื่อพูดถึง case study จากลูกค้าจริงในอุตสาหกรรมเดียวกัน สิ่งที่ผู้บริหารและ DPO ควรเข้าใจคือ PDPA ไม่ใช่แค่เรื่องกฎหมาย — เป็น business enabler ที่ช่วยให้บริษัทได้ trust จากลูกค้า, ผ่าน enterprise procurement, เข้าถึงตลาด EU/US ที่ต้อง GDPR compliance, และป้องกันความเสียหายทั้งค่าปรับ (สูงสุด 5 ล้าน) reputation และ business disruption จาก breach
  • CMP + Google Consent Mode v2 + Meta Pixel consent
  • 72-hour breach playbook + forensic partner + 24/7 hotline
  • indemnity clause — เบี้ยปรับจากความผิดพลาดของเรา เราจ่ายทั้งหมด
  • training TH/EN/中文/日/韓 พร้อม e-learning สำหรับ new hire
  • SCC + BCR + safeguard cross-border 40+ ประเทศ
กรณีศึกษาจากลูกค้าจริง: SaaS B2B ระดับ enterprise ที่ต้องขายให้ EU: เรา uplift compliance จาก PDPA ไป GDPR + ISO 27701 certification — closed deal €2.5M กับลูกค้าเยอรมันภายใน 6 เดือน

Deliverable หลัก: Privacy Policy TH + EN (แยก customer/employee/vendor); Cookie Notice + banner CMP implementation; layered notice + just-in-time consent; translation 6 locale เพิ่มเติม (option)

ขั้นตอนการให้บริการ PDPA

  1. Train: employee training + certificate + e-learning สำหรับ new hire
  2. Breach: breach playbook + tabletop exercise + forensic partner ready + 24/7 hotline
  3. Respond: incident response หากเกิด breach — triage 4 ชม. + notification 72 ชม.
  4. Discover: consultation 60 นาทีฟรี — เข้าใจธุรกิจ, processing activity, current state, priority
  5. QuickWin: quick win implementation — Privacy Policy + Cookie CMP + employee training + DPO appointment
  6. Audit: quarterly compliance audit + management report + PDPC guideline update
  7. DSAR: DSAR portal + workflow + SLA 30 วัน + template response ทั้ง 8 rights
  8. Engage: engagement letter + fixed fee + SLA + indemnity clause

คำถามที่พบบ่อย

DSAR ตอบภายในกี่วันและครอบคลุมสิทธิอะไรบ้าง
ต้องตอบภายใน 30 วัน (ต่ออีก 60 วันได้ถ้ามีเหตุ) หลังได้รับ request ที่ครบเงื่อนไข; PDPA ให้สิทธิ 8 ประเภท: access, rectification, erasure (right to be forgotten), restriction, portability, object, withdraw consent, complaint; ต้อง verify identity ก่อนตอบ + ให้ฟรีครั้งแรก
cookie ต้องขอ consent หรือไม่ — cookie notice พอไหม
ตาม PDPC Cookie Notification 2565: strictly necessary cookies ไม่ต้อง consent, functional/analytics/marketing/advertising cookies ต้อง prior consent (opt-in) ก่อน load; ต้องมี CMP ที่ block cookies ก่อน consent + ให้ withdraw ได้ทุกเมื่อ + เก็บ consent record; Google Consent Mode v2 บังคับใช้ตั้งแต่ March 2024
ต้องขอ consent ทุกครั้งหรือใช้ legal basis อื่นได้
PDPA มี legal basis 6 ประเภท (consent, contract, legal obligation, vital interest, public interest, legitimate interest) + สำหรับ sensitive data มี 10 basis เข้มขึ้น; ในทางปฏิบัติ consent ไม่ใช่ default — ควรใช้ contract/legitimate interest ก่อน และ reserve consent เฉพาะ marketing + sensitive data
sensitive data (medical, biometric, sexual orientation, religion) มี rule เพิ่มไหม
มี — ต้องมี explicit consent (ยกเว้น 9 กรณี เช่น life-saving, employment law, public health) + DPIA บังคับ + retention สั้นกว่า + technical safeguard เข้มขึ้น (encryption at rest + in transit + access log); biometric สำหรับ time attendance ต้อง alternative option ให้พนักงานที่ไม่ยินยอม
vendor/SaaS ที่เราใช้ (Google/Meta/AWS) ต้องเซ็น DPA ไหม
ต้อง — ทุก vendor ที่ประมวลผลข้อมูลส่วนบุคคลในนามเรา (data processor) ต้องมี DPA ตาม PDPA ม.40 ครอบคลุม: purpose, category, retention, security measure, sub-processor list, cross-border transfer, breach notification, audit right, data return/deletion; Google/Meta/AWS มี template DPA ให้ + ต้อง review + sign เพิ่มเติม
เปลี่ยน DPO consultant มาที่นี่ทำอย่างไร
เราจัด transition 30-60 วัน — ประสานกับ consultant เดิมขอ RoPA/DPIA/DSAR log/breach register/vendor list, migrate เข้า DPMS ของเรา, review compliance status, ปรับ playbook + workflow, training ทีมลูกค้า; ระหว่าง transition รับผิดชอบ compliance ต่อเนื่องรวม breach response 24/7
72-hour breach notification ต้องทำอย่างไร
หากเกิด personal data breach ที่มีความเสี่ยงต่อสิทธิ+เสรีภาพของเจ้าของข้อมูล ต้อง notify PDPC ภายใน 72 ชม. หลังรู้เหตุ (พร้อมข้อมูล: ประเภทข้อมูล, จำนวน, ผลกระทบ, มาตรการ containment); หากมี high risk ต้อง notify เจ้าของข้อมูลด้วยไม่ชักช้า; เรามี playbook + hotline 24/7 พร้อมช่วย
cross-border data transfer ทำอย่างไร
ต้องมี safeguard ตาม PDPA ม.28-29: (1) transfer ไปประเทศที่ PDPC ประกาศว่ามีมาตรฐานคุ้มครองเทียบเท่า (adequate), (2) transfer ผ่าน SCC (Standard Contractual Clauses) ที่ PDPC อนุมัติ, (3) transfer ผ่าน BCR (Binding Corporate Rules) สำหรับกลุ่มบริษัท, (4) consent explicit ของเจ้าของข้อมูล; เรารับ setup SCC + BCR
PDPA บังคับใช้ทั้งหมดเมื่อไหร่และใครต้องปฏิบัติ
PDPA มีผลบังคับใช้เต็มรูปแบบตั้งแต่ 1 มิถุนายน 2565; บังคับใช้กับ (1) ผู้ควบคุมข้อมูล/ผู้ประมวลผลข้อมูลที่อยู่ในไทย, (2) ผู้ที่อยู่นอกไทยแต่ประมวลผลข้อมูลของบุคคลในไทยเพื่อเสนอสินค้า/บริการหรือ monitor พฤติกรรม; ครอบคลุมทั้ง SME, corporate, government, และ NGO

ขอปรึกษา PDPA ฟรี 60 นาที

DPO team ตอบกลับใน 15 นาที · breach hotline 24/7 · LINE, Email, โทร

ติดต่อขอปรึกษา

เหมาะกับอุตสาหกรรม