CCTV Privacy Notice
§ 01About this notice
Ruk-Com Co., Ltd. (“the company” or “we”) operates closed-circuit television (CCTV) for surveillance within the company’s office areas (“the premises”) to protect life, health and property. Through those cameras we collect personal data about officers, workers, customers, employees, contractors, visitors or any other person (together, “you”) who enters the company’s office premises.
This CCTV privacy notice (“the notice”) explains how we collect, use or disclose information that can identify you (“personal data”), as well as your rights, as follows:
§ 02Legal bases for processing
We collect your personal data under the following legal bases:
- Legitimate interest — for our own or another person’s legitimate interest in keeping people and property safe, where that interest is no less important than your fundamental rights over your personal data.
- Legal obligation — to comply with applicable law, such as retaining data as required by law.
- Vital interest — to prevent or stop danger to a person’s life, body or health.
§ 03Purposes of collection
We collect your personal data for the following purposes:
- 2.1 To protect your personal health and safety, including your property.
- 2.2 To protect our offices, facilities and property from damage, disruption, destruction or other crime.
- 2.3 To assist the relevant authorities in law enforcement — deterrence, prevention, investigation and legal proceedings.
- 2.4 To assist dispute resolution during disciplinary or grievance procedures.
- 2.5 To assist investigations or complaint-handling procedures.
- 2.6 To assist in bringing or defending civil proceedings, including but not limited to employment-related legal action.
§ 04Personal data we collect and use
For the purposes stated in clause 2, we install CCTV in visible positions and post signs stating that CCTV is in use at entrances and exits and in areas we consider necessary to monitor, in order to collect the following personal data when you enter the premises:
| Personal data collected |
|---|
| Still images |
| Moving images |
| Audio (only on cameras that record sound) |
| Images of your property, such as vehicles, bags, hats and clothing |
We do not install CCTV in areas where it would unreasonably infringe your fundamental rights — namely bedrooms, toilets, shower rooms, prayer rooms or staff rest areas.
§ 05Disclosure of personal data
We keep the CCTV data relating to you confidential and do not disclose it, except where necessary to fulfil the surveillance purposes stated in this notice. In those cases we may disclose CCTV data to the following categories of people or organisations:
- 4.1 Agencies with legal authority, to assist and support law enforcement or to carry out investigations, inquiries or legal proceedings.
- 4.2 Third-party service providers, where necessary to ensure the prevention of, or response to, danger to the life, body or health and property of you or others.
- 4.3 Video storage or cloud service providers acting as data processors, under a Data Processing Agreement (DPA) and appropriate safeguards.
§ 06Using footage for development and testing
In addition to the security purposes in clause 2, the company may use CCTV images or data to develop, test and improve the performance of its systems and services (for example CCTV management and display systems, video analytics or related features). This is a separate, specific purpose distinct from security surveillance, and is carried out under the following safeguards:
- Data minimisation, prioritising anonymised data or masked faces and identities wherever that is possible.
- Access restricted to necessary personnel only, in an environment segregated from production systems, with access and usage logging in place.
- No use for automated decision-making that significantly affects individuals without human oversight, and no use for marketing or disclosure to third parties for commercial purposes.
- Where processing identifiable images or biometric data is necessary (for example facial recognition, which is sensitive personal data under section 26), the company carries out a Data Protection Impact Assessment (DPIA) and establishes an appropriate legal basis, including obtaining explicit consent where the law requires it, before processing.
- Once the development and testing purpose is complete, the company deletes or destroys the data, or renders it unable to identify individuals.
§ 07Cross-border transfers
Where CCTV footage is stored or processed on cloud systems or data centres located abroad, the company puts in place appropriate protection measures under section 28 of the Personal Data Protection Act B.E. 2562 — for example Standard Contractual Clauses (SCCs) or another legally recognised mechanism — consistent with cloud privacy practice under ISO/IEC 27017 and ISO/IEC 27018.
§ 08Retention period
To fulfil the CCTV surveillance purposes set out in this notice, we keep the CCTV personal data relating to you for 30 days from the recording date. After that period we delete and destroy your personal data, except where it must be kept longer for investigation, legal proceedings or as required by law.
§ 09Personal data security
We maintain appropriate technical and organisational measures to protect your personal data from loss or unauthorised access, deletion, destruction, use, alteration, amendment or disclosure, consistent with our Information Security Policy and practices, referencing ISO/IEC 27001 (information security management) and ISO/IEC 27701 (privacy information management), as well as cloud practice under ISO/IEC 27017 and 27018 — for example access control and restriction, authentication, encryption where appropriate, logging and monitoring of access, and periodic review of these measures.
We have also established a personal data protection policy, published throughout the organisation together with practice guidelines, to maintain security in collecting, using or disclosing personal data while preserving its confidentiality, integrity and availability.
§ 10Your rights under the PDPA
The Personal Data Protection Act B.E. 2562 aims to give you more control over your personal data. You may exercise the following legal rights:
- The right to access, obtain a copy of, and request disclosure of the source of the personal data we hold about you — except where we are entitled to refuse under the law or a court order, or where your request would adversely affect the rights and freedoms of others.
- The right to request correction of personal data that is inaccurate or incomplete, so that it is accurate, current, complete and not misleading.
- The right to request restriction of the use of your personal data in the cases provided by law.
- The right to object to the collection, use or disclosure of your personal data, except where we have lawful grounds to refuse the request.
- The right to request deletion or destruction of your personal data, or its anonymisation, in the cases provided by law.
- The right to complain to the competent authority if you believe your personal data is being collected, used or disclosed in breach of the law.
§ 11Responsibility of the data controller
We allow only officers whose duties relate to collecting, using or disclosing personal data from this processing activity to access your personal data, and we require those officers to follow this notice strictly.
§ 12Changes to this notice
When updating or changing this notice, we may make the amendments we consider appropriate and will inform you through our website, with the date of the latest version shown at the end. We recommend checking regularly for the latest version, especially before entering our premises.
§ 13Contact
You can contact us about this notice at:
| Data Protection Officer (DPO) | Ruk-Com Co., Ltd. |
|---|---|
| Address | Vanit Place Ari (Building A), Unit 2703, 27th Floor, 304 Phaholyothin Rd., Samsen Nai, Phaya Thai, Bangkok 10400, Thailand |
| [email protected] | |
| Office hours | Monday–Friday, 9:00–18:00 (except public holidays) |