Personal Data Protection Policy
Effective from 1 August 2026
Introduction
This policy establishes the principles and approach used by Green Capital Company Limited and its subsidiaries (collectively, the “Company”) to protect personal data in accordance with applicable personal data protection laws and good corporate governance.
The Company recognises the importance of privacy and is committed to lawful, transparent and accountable processing of personal data.
Objectives
- Establish minimum principles and standards for personal data protection.
- Ensure that collection, use and disclosure are lawful, fair and transparent.
- Support appropriate group-wide data governance.
- Protect data-subject rights and build stakeholder confidence.
Scope
This policy applies to directors, executives, employees and persons acting for or on behalf of the Company when collecting, using or disclosing personal data.
Definitions
- Personal Data means information that can identify an individual directly or indirectly.
- Data Subject means the individual to whom personal data relates.
- Data Controller determines the purposes and means of processing.
- Data Processor processes personal data under a controller's instructions.
- Processing includes collecting, using, disclosing or otherwise handling personal data.
- Cookies are small data files stored on a user's device when using a website.
- Personal Data Protection Laws include Thailand's Personal Data Protection Act B.E. 2562 (2019) and related subordinate legislation.
- Data Protection Officer (DPO) means the person appointed to oversee compliance and provide advice on personal-data processing.
Personal Data Protection Principles
The Company processes personal data lawfully, fairly and transparently; for clear and limited purposes; with appropriate accuracy, retention and security controls.
Collection of Personal Data
The Company may collect personal data directly from data subjects for services, communication, recruitment and contracts, or from lawful sources such as government agencies, business partners and third parties.
Data may also be collected through websites, applications and electronic channels using cookies or similar technologies. Details are provided in the relevant privacy notice and Cookie Policy.
Processing of Personal Data
Personal data is processed only as necessary for business operations, organisational management, services, contracts, communications, security, product and service improvement, legal compliance and other lawful purposes.
Disclosure of Personal Data
The Company may disclose personal data to third parties where necessary for stated purposes and as permitted by law, with appropriate security safeguards. Relevant privacy notices provide further details.
Data Subject Rights
Data subjects may exercise rights provided by law, including access, rectification, deletion, withdrawal of consent, portability, restriction and other applicable rights, subject to legal conditions and the Company's request process.
Security
The Company maintains appropriate organisational, technical and physical safeguards against unlawful or unauthorised loss, access, use, alteration or disclosure, and reviews those safeguards regularly.
Data Protection Impact Assessments
A data protection impact assessment is conducted when processing is likely to create a high risk to individual rights and freedoms, including large-scale or sensitive-data processing and the use of new technologies.
Personal Data Breach Management
The Company maintains measures to prevent, detect and manage personal data breaches, assess their impact and notify regulators and/or affected individuals where required by law.
Records of Processing Activities
The Company maintains and updates records of processing activities to support governance, oversight and evidence of legal compliance.
International Data Transfers
Where personal data must be transferred outside Thailand, the Company follows applicable legal requirements and implements appropriate safeguards, such as destination-country assessments or recognised contractual measures.
Legal Compliance
The Company processes personal data in accordance with applicable personal data protection laws and related requirements. Additional details may be provided in relevant privacy notices.
Deletion and Destruction
Personal data is deleted or destroyed when its retention period expires or when it is no longer relevant or necessary for the stated processing purpose, in accordance with appropriate standards.
Data Protection Officer
The Company has appointed a Data Protection Officer to advise, monitor and oversee compliance with personal data protection laws.
Policy Review and Changes
This policy is reviewed periodically and when laws, practices or business operations change. Material changes will be communicated through appropriate channels.
