Privacy Notice
On Procurement, Inventory Management and Contract Administration


Electricity Generating Authority of Thailand (EGAT) conducts and disseminates this Privacy Notice (Notice to Data Subjects) with a view to elaborating on the collection, use or disclosure of Personal Data including the suitable measures to safeguard and manage the Personal Data of any natural or juristic persons who are business partners, contractors, suppliers/service providers, consultants, outsource employees, proprietors, or those interested in acquiring the procurement documents; or any natural or juristic persons who have proposed or won a bid for procurement or who have been selected for the procurement and other bidders, including directors, representatives, and appointees of, or those acting for, the aforesaid persons, referees, contact persons in case of emergency, and family members of the aforesaid Data Subjects, in accordance with the Personal Data Protection Act B.E. 2562 (the “2019 PDPA”)

EGAT is at liberty to review and alter this Privacy Notice to ensure proper protection of the Personal Data. In the event of any significant change in this Privacy Notice, EGAT will keep the Data Subjects informed by appropriate means of communication.

1.  Definitions

“Business Partners” means any natural or juristic persons who are business partners, contractors, suppliers/service providers, consultants, outsource employees, proprietors, or those interested in acquiring the procurement documents; or any natural or juristic persons who have proposed or won a bid for procurement or who have been selected for the procurement and other bidders, including directors, representatives, and appointees of, or those acting for, the aforesaid persons, family members of the aforesaid Data Subjects, referees, and contact persons in case of emergency.

 “Personal Data” means any information relating to a person, which enables the identification of such Person, whether directly or indirectly, but not including the information of the deceased persons in particular. 

“Sensitive Personal Data (SPD)” means the Personal Data as defined in Section 26 of the 2019 PDPA, pertaining to racial, ethnic origin, political opinions, cult, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data, or of any data which may affect the Data Subject in the same manner as prescribed by the Personal Data Protection Committee.

“Data Protection Officer (DPO)” means any person designated by EGAT as a data protection officer under Section 41 of the 2019 PDPA.

“Data Subject” means a natural person whose personal data is collected, used or disclosed by EGAT.

2.  Purposes of Collecting, Using, or Disclosing of Personal Data

2.1  Legal Basis for Collecting, Using, or Disclosing of Personal Data
  
EGAT will collect, use, or disclose Personal Data limited to the extent necessary in relation to the scope of this Privacy Notice, as follows:

2.1.1  In the case of general Personal Data:

1)  it is when EGAT has obtained the Data Subject’s consent, where such consent is required by law;

2)  it is for preventing or suppressing a danger to a person’s life, body or health;

3)  it is necessary for the performance of a contract to which the Data Subject is a party, or in order to take steps at the request of the Data Subject prior to entering into a contract;

4) it is necessary for the performance of a task carried out in pursuance of EGAT’s public interest, or it is necessary for the exercising of official authority vested in EGAT;

5)  it is necessary for the legitimate interests of EGAT or any other natural or juristic person, except where such interests are overridden by the Data Subject’s fundamental right of his/her personal data; and

6)  it is necessary for compliance with a law to which EGAT is subjected.

2.1.2  In the case of Sensitive Personal Data (SPD):

It may be necessary for EGAT to collect the Sensitive Personal Data, in which case EGAT will always seek prior explicit consent of the relevant Data Subject, except the following areas where such consent is not required, as stipulated in the 2019 PDPA:

1)  it is to prevent or suppress a danger to life, body or health of a person, where the Data Subject is incapable of giving consent by whatever reason;

2)  it is information that is disclosed to the public with explicit consent of the Data Subject;

3)  it is necessary for the establishment, compliance, exercise or defense of legal claims; or

4)  it is necessary for compliance with a legal obligation to achieve the purposes with respect to the assessment of working capacity of the employee, or the public interest in the public health such as protecting against cross-border dangerous contagious disease or epidemics which may be contagious or pestilent and the employment protection.

2.2  Purposes for Collecting the Personal Data in order to Use or Disclose of Personal Data

EGAT will be collecting a Data Subject’s Personal Data for numerous purposes, depending on the relationship between that Data Subject and EGAT, as follows:

2.2.1  For procurement, inventory management and contract administration:

1)  For the purpose of EGAT’s procurement, inventory management and contract administration, the vendor’s registration, the evaluation and announcement of the final evaluation result or the selected party for the procurement, the execution of contracts, the exercise of contractual rights and fulfillment of contractual obligations, the management of contracts and acceptance of supplies, the assessment of the Business Partners’ performance, the contract amendment, the termination of contracts, the inventory management, the disposal of used supplies, and other actions required in accordance with the Public Procurement and Supplies Administration Act B.E. 2560 (2017), other laws, rules, regulations, and procurement directly involving commerce and inventory management, and other relevant EGAT regulations.

2)  For the purpose of examining the qualifications of, and selecting, the Business Partners (including the examination of information about insolvency or bankruptcy, jointly interested bidders, and work abandoners) and for considering and approving the execution of contracts or agreements to which the Data Subject is a party or where the Data Subject is a director, representative, appointee or designated person of a party thereto.

3)  For the preparation of legal contracts, other than those for procurement and inventory management (including the consideration and examination of such contracts), the exercise of contractual rights and fulfillment of contractual obligations, the contract administration, the contract amendment, and the contract termination, such legal contracts being, for example, non-disclosure agreements, space lease agreements.

4)  For payments, disbursements, the deduction and remittance of withholding tax, and the filing of tax return in accordance with the Revenue Code of Thailand.

5)  For the purpose of building databases to be used in connection with the procurement, inventory management and contract administration, including the management of EGAT’s internal affairs such as the coordination, the administration, the improvement of the relationship between EGAT and its Business Partners, and the compliance with the Occupational Safety, Health and Environment Act and other relevant laws.

2.2.2  For management of outsource employees:

1)  For the preparation of legal contracts (including the consideration and examination of those contracts), the exercise of contractual rights and fulfillment of contractual obligations, the contract administration, the contract amendment, and the contract termination in order to seek approvals of and register the outsource employees, for example, the registration of assistant technicians prior to working for EGAT, and other relevant actions.

2)  For payments, disbursements of related expenses, the deduction and remittance of withholding tax, and the filing of tax return in accordance with the Revenue Code of Thailand.

3)  For the payment of wages, the disbursement of related expenses, and the deduction of withholding tax.

4)  For the purpose of sending the outsource employees to operate outside of EGAT, both within the country and overseas.

5)  For the purpose of applying to relevant government agencies for their approvals regarding EGAT’s power generation and related businesses as required by the applicable laws, for preparing and delivering documents about EGAT’s power generation to government agencies for their consideration and examination, and for such other actions as required by the applicable laws.

6)  For compliance with the Empowerment of Persons with Disabilities Act B.E. 2550 (2007) and other laws on the improvement of quality of life of the disabled, in the case that the outsource employees is the disabled person.

7)  For the purpose of providing health checkups and drug screening to the outsource employees prior to their employment, including medical treatment and healthcare services such as blood donation and vaccination.

8)  For the purpose of collecting data and statistics on occupational hazards of the outsource employees when the payment of compensation under the relevant laws is concerned.

2.2.3  For CSR and other activities:

1)  For the purpose of operating the EGAT Learning Center and implementing EGAT projects, including projects for social and community relation, projects on energy and environment, Royal Initiative projects, and donation projects.

2)  For the purpose of EGAT’s meetings, conferences, field trips and other activities which may require a video recording of the participants, including communications and any actions required therefor, for example, the making of promotional and PR materials, the catering, the registration of participants, the building of databases for communications purposes, the coordination, the management of  EGAT’s internal affairs, and the presentation or release of news and articles about EGAT’s meetings, conferences, field trips and other activities online and by other means.

2.2.4  For the handling of complaints, judicial proceedings, and compliance with the laws:

1)  For the purpose of handling complaints, conflicts, investigations and examination of complaints received by EGAT, including the infringements of rights or the damage caused by the act of EGAT’s Business Partners, as well as for coordinating with those concerned, providing remedy and aid to the aggrieved parties or those who have been violated or who have filed complaints, and taking other necessary steps so as to cease such complaints or conflicts.

2)  For dealing with judicial proceedings and for establishing, complying with, exercising or defending a legitimate claim.

3)  For compliance with the laws and for reporting to the relevant authorities upon receipt of summons or writs of execution from the police, government agencies, courts, or other law enforcement agencies.

2.2.5  For other relevant purposes:

1)  For the purpose of planning, reporting, assessing and analysing relevant data and information for EGAT’s operation.

2)  For the disbursement of expenses incurred in connection with EGAT’s meetings, conferences, field trips and activities.

3)  For the risk management, the protection and verification, and the management of internal affairs as required by law or EGAT’s rules and regulations, and for considering complaints of corruption or misconduct in EGAT, investigating and preventing corruption or illegal activities, and investigating the conflicts of interest and certain cases of conflicting interest.

4)  For the purpose of checking the requests for use of EGAT’s internal IT system, Wi-Fi, and VPN made by outsiders and EGAT’s personnel and for the verification of the identity of the users of EGAT’s IT system and the visitors of EGAT’s website.

5)  For the purpose of security measures within EGAT’s compound, including the CCTV surveillance of EGAT’s compound and other areas under its responsibility, the verification of identity for entrances and exits, the making of identification cards for Business Partners, and the application for approvals to enter EGAT’s compound.

In the event that the aforesaid Personal Data are necessary for EGAT in complying with the applicable laws or in fulfilling contractual obligations, if the Data Subject refuses to give such Personal Data, then EGAT may be unable to manage the contracts or provide certain assistance to the Data Subject.

3.  Personal Data Collection

3.1  Personal Data Collected by EGAT

EGAT will collect the Personal Data of a Data Subject, including the following data and information:

3.1.1  information that can identify a person – first name, last name, identification number, driver’s licence number, passport number, date of birth, place of birth, gender, age, nationality, marital status, photograph, signature, including other information appearing on copies of identity cards, driver’s licences, passports, and other reports or documents required by law;

3.1.2  contact data – address, telephone number, e-mail address, online contact data such as Line ID, Facebook account;

3.1.3  information about financial status or financial transactions – A/C number, debit/credit card number, tax payment information, bankrupt status;

3.1.4  information about use of EGAT’s IT system or other technical information – IP address, device serial number, data collected by EGAT through cookies or similar technical measures, log information, information about uses or visits of EGAT’s website and other systems, user accounts for use of EGAT’s IT system;

3.1.5  information about education and work including training – educational record, employment history, training record, work permit, performance assessment, nature of work, professional licence, place of work, position, length of service, working hours, absence/leave record, commencement date of employment, termination date of employment;

3.1.6  information about contact with EGAT – a video recording of any contact with EGAT;

3.1.7  information about participation in EGAT’s activities – photographs, videotape, audiotape, and other information given in participation registration forms, opinion survey, or satisfaction assessment forms; and

3.1.8 other personal information – family members, referees, contact persons in case of emergency, background inspection, association membership.
In certain circumstances, EGAT may collect Sensitive Personal Data with explicit consent of the Data Subject or as permitted by law.

3.2  Personal Data of a Minor, an Incompetent Person and a Quasi-incompetent Person

In certain circumstances, EGAT may collect the Personal Data of a Data Subject who is a minor, an incompetent person, or a quasi-incompetent person. In that case, EGAT will comply with the law applicable to the collection, use or disclosure of the personal data of a minor, incompetent person, and quasi-incompetent person, which includes obtaining consent of the holder of parental responsibility over the child, the custodian, or the curator of such person, as required by law, where EGAT has no legal grounds other than seeking consent to such collection, use or disclosure.

3.3  Sources of Personal Data

Personal Data may be collected:

3.3.1  From the Data Subject directly – For example, when the Data Subject contacts EGAT to ask for some information, fills out, signs and delivers EGAT’s tender documents or takes part in the registration, the tender, and the announcement of the final evaluation result, the granting of a request prior to entering into a contract, the signing of a contract, the attachment of ancillary documents,  the questionnaires and the relevant registrations (e.g. the registration for participating of the tender), the complaints or the requests for exercise of rights made to EGAT, the contacts with EGAT by various means (e.g. via phone or e-mail), or attends meetings or missions under EGAT’s auspices, or participates in EGAT’s activities (e.g. there are photographing and video recording). Personal Data may also be automatically collected (e.g. when the Data Subject uses EGAT’s IT system or website).

3.3.2  From other sources – For example, from the employer of the Data Subject or the Data Subject’s immediate department, the official documents provided by the government, EGAT’s representative, government agencies, private agencies, or other public sources (e.g., website of the Data Subject’s employer or immediate department, information searched from the Internet).

4.  Duration of Data Storage

EGAT will not retain Personal Data for longer than is necessary for the purpose for which they are collected, used or disclosed as stated in this Privacy Notice. The principle for data storage is that Personal Data will be kept for as long as the relationship between EGAT and the Data Subject is maintained and may be kept longer as required by law or by the statute of limitations for the purpose of establishing, complying with, exercising, or defending a legitimate claim or for such other purposes as set out by EGAT’s policy or internal requirements.

5.  Disclosure of Personal Data

5.1  Natural or juristic persons to whom Personal Data may be disclosed:

In fulfilling the purposes stated in this Privacy Notice, EGAT may disclose Personal Data to the following persons:

5.1.1  EGAT’s subsidiaries for the purpose of carrying out those activities as set out in this Privacy Notice;

5.1.2  Government agencies, supervisory authorities, independent organizations, or other agencies as prescribed by law, including law enforcement officers such as courts of law, the police force, the Legal Execution Department, the Office of the Attorney General, the Office of the Auditor General of Thailand, the Office of the Personal Data Protection Committee, the Legal Execution Office, the State Enterprise Policy Office, the Provincial Employment Office, the Forest Resource Management Office No. 3 (Lampang), the Revenue Department, the Comptroller General’s Department, the Department of Labour, the Department of Labour Protection and Welfare, the Department of Empowerment of Persons with Disabilities, etc.;

5.1.3  Financial institutions for receipt of EGAT’s payments of debt or expenses, severance pay, financial aid, and compensation in relevant processes;

5.1.4  Agents, service providers, contractors and/or subcontractors who work for EGAT such as carriers, document storage and disposal providers, printing houses, IT developers, auditors, counsels, legal and tax advisors, consultants;

5.1.5  Other third parties as consented by the Data Subject, allowed by the provisions of a contract, or required by law, as the case may be, including public media and online media.

5.2  Sending or transfer of Personal Data to a foreign country 

In certain circumstances, EGAT may transfer Personal Data to foreign countries, provided that EGAT must ensure that the destination country or international organization that receives such Personal Data shall have adequate data protection standard, that EGAT takes appropriate security measures and complies with the 2019 PDPA, and that the Data Subject’s consent to such transfer is obtained, if so required by law.

6.  Rights of the Data Subject

Every Data Subject has the following rights under the 2019 PDPA:

6.1  Right to withdraw consent

The Data Subject has the right to withdraw his/her consent to the collection, use or disclosure of his/her Personal Data at any time, unless the withdrawal is limited by law or by the context of a contract existing in favour of the Data Subject.
However, such withdrawal does not affect the collection, use or disclosure of the Personal Data to which the Data Subject has previously and legitimately given his/her consent.

6.2  Right of access

The Data Subject has the right of access to his/her Personal Data under EGAT’s responsibility and may request copies thereof as well as request the disclosure of the acquisition of the Personal Data obtained without his/her consent.

6.3  Right to data portability

Where his/her Personal Data are stored in the format which is readable or commonly used by ways of automatic tools or equipment and can be used or disclosed by automated means, the Data Subject is entitled to request EGAT to send or transfer the Personal Data in such format to other Data Controllers, on an applicable legal basis.

6.4  Right to object

The Data Subject has the right to object the collection, use, or disclosure of his/her Personal Data, on an applicable legal basis.

6.5  Right to erasure

The Data Subject has the right to request EGAT to erase or destroy his/her Personal Data, or anonymize his/her Personal Data to become the anonymous data which cannot identify the data subject, on an applicable legal basis.

6.6  Right to restrict the use of Personal Data

The Data Subject has the right to request EGAT to restrict the use of his/her Personal Data, on an applicable legal basis.

6.7  Right to rectification

The Data Subject has the right to request for his/her Personal Data to be rectified so that they are accurate, up-to-date, complete, and not misleading.

6.8  Right to lodge a complaint

The Data Subject has the right to lodge a complaint with a relevant authority under the 2019 PDPA when EGAT fails to comply with such Act.

In the event that the Data Subject submits a request for the exercise of rights under the 2019 PDPA, EGAT, upon receipt of such request, will proceed with it within the period of time specified by law. However, EGAT reserves the right to decline such request, on an applicable legal basis.

7.  Security Measures

EGAT has taken appropriate and strict security measures to prevent loss or unauthorized or unlawful loss, access, use, change, alteration or disclosure of the Personal Data.
In the event that EGAT assigns any third parties to collect, use or disclose the Personal Data on its orders or in its name, EGAT will properly supervise those persons to ensure the security of the Personal Data in accordance with the 2019 PDPA.

8.  Contact Data

If the Data Subject has any questions about the protection, collection, use or disclosure of his/her Personal Data or the exercise of his/her rights as a data subject, or wishes to lodge a complaint with regard thereto, he/she can contact EGAT at:

EGAT

Address:
53 Moo 2 Charansanitwong Road.
Bang Kruai Sub-district
Bang Kruai District, Nonthaburi 11130
Phone:  1416
E-mail:  cmcegat@egat.co.th
Website:  http://cmc-center.egat.co.th

Data Protection Officer (DPO)

Address:
53 Moo 2 Charansanitwong Road.
Bang Kruai Sub-district
Bang Kruai District, Nonthaburi 11130
Phone:  1416
E-mail:  cmcegat@egat.co.th