NEP social >>

VAVAZ social >>

LINE
Home / Corporate Governance / Personal Data Protection Policy

Personal Data Protection Policy

PDPA B.E. 2562 Last updated March 27, 2026

NEP Realty and Industry Public Company Limited recognizes the importance of protecting your personal data as a business partner of the Company. The Company has therefore established this Privacy Policy for Business Partners with the objective of governing and managing the personal data of authorized directors, shareholders of business partners, and other contacts whose information you have provided to the Company. The Company would also like to inform you of your rights as prescribed under the Personal Data Protection Act B.E. 2562.

The Company collects, uses, and/or discloses your personal data because you have a business relationship with the Company and/or because you work for, act on behalf of, or represent a business partner.

1 What Personal Data Does the Company Collect?

“Personal Data” means any information relating to you that enables you to be identified, whether directly or indirectly, but does not include information of a deceased person. The Company may collect various types of personal data, including:

Personal InformationTitle, first and last name, gender, age, date of birth, nationality, marital status, photographs, videos, CCTV footage, educational information, information concerning your employment or the company for which you work or hold shares, copies of identification cards, copies of passports, copies of house registration documents, financial status information, vehicle information, signatures, bank account and payment information, electronic signatures, and other identification documents.
Contact InformationTelephone number, mobile phone number, fax number, address, email address, Line ID, and other similar information.
Other Information Related to the Business RelationshipInformation appearing in contracts, forms, surveys, or other documents, information regarding transactions you conduct with the Company, and computer records.
Information of Other Persons Related to YouInformation concerning your spouse or children, information concerning Company employees related to you, and other information you provide. When providing third-party information, you represent that you have the authority to do so and have informed and/or obtained consent from such persons.
Sensitive Personal DataRace appearing in identification documents, religion appearing on identification cards, trade union information, biometric data (such as fingerprints, facial recognition, and iris scans), health information, criminal records, or other information prescribed by the Personal Data Protection Committee.

2 Sources of Personal Data

The Company collects your personal data from the following sources:

  1. Information provided directly by you through signing contracts or completing forms, such as when you conduct business or transactions with the Company, interact through online platforms, websites, or mobile applications, communicate by email, telephone, questionnaires, business cards, postal mail, or during meetings and various activities.
  2. Information from the business partner for whom you work, act on behalf of, or represent.
  3. Information from the corporate group, shareholders, or third parties, such as other business partners.
  4. Information from electronic file sources.

3 Use of Your Personal Data

The Company will collect, use, and/or disclose your personal data in accordance with the nature of the relationship between you and the Company for legitimate interests, contractual purposes, or other lawful bases, in accordance with applicable personal data protection laws, ministerial regulations, ministerial notifications, or other applicable laws.

4 Disclosure of Your Personal Data

The Company will not disclose your personal data to other persons except where necessary for the Company's operations and where permitted by law, such as to the Company's shareholders, other business partners, external service providers engaged by the Company (such as cloud service providers and data analytics service providers), and the Company's advisors, including lawyers, specialized professionals, and persons assisting with the Company's business operations or the exercise of the Company's legal rights.

In certain circumstances, the Company may be required to disclose your personal data to comply with applicable laws or regulations, including to law enforcement authorities, courts, government agencies, or other third parties where the Company believes such disclosure is necessary to comply with legal obligations, protect the Company's rights, protect the rights of third parties or the safety of individuals, or detect, prevent, or address fraud, security, or safety issues. This may also include cases involving the transfer of rights or similar transactions, as well as emergencies where necessary to protect your interests.

5 Transfer of Personal Data Outside the Country

  1. The Company may send or transfer your personal data to affiliated companies or other persons in foreign countries where necessary to perform a contract to which you are a party, to take steps at your request prior to entering into a contract, to prevent or suppress danger to life, body, or health, to comply with the law, or to perform a task carried out in the public interest.
  2. The Company may store your data on servers or cloud services provided by third parties and may use third-party software or applications in the form of SaaS/PaaS to process data. However, the Company will not permit unauthorized persons to access such data and will require service providers to implement appropriate security measures.
  3. Where personal data is transferred outside the country, the Company will comply with applicable personal data protection laws and implement appropriate measures to ensure that your data is protected and that you continue to be able to exercise your legal rights. The Company will also require data recipients to process the data only to the extent necessary and to prevent unauthorized use or disclosure.

6 Data Retention Period

The Company will retain your personal data only for as long as necessary to carry out activities within the scope and purposes for which the data was disclosed and used, except where an exception applies under the Personal Data Protection Act B.E. 2562 or other applicable laws. In certain circumstances, the Company may be required to retain your personal data for a period longer than that prescribed by law.

7 Your Rights as a Data Subject

Subject to the conditions prescribed by law, you have the following rights:

  1. Right of Access to and request a copy of your personal data, or request disclosure of the source of data that you did not provide or consent to.
  2. Right to Rectification to ensure that your personal data is accurate, current, complete, and not misleading.
  3. Right to Erasure or Destruction of your personal data or to have the data anonymized so that you cannot be identified.
  4. Right to Data Portability to receive and transfer your personal data in a commonly readable or usable format through automated tools to another organization, provided that the data is:
    • Data that you have provided to the Company; and
    • Data for which the Company has obtained your consent or which is necessary for the performance of a contract between the Company and you.
  5. Right to Object to the collection, use, or disclosure of your personal data, or to request restriction of the processing of your personal data.
  6. Right to Withdraw Consent to the collection, use, or disclosure of data that relies on your consent at any time.
  7. Right to Lodge a Complaint with the competent authority where you believe that the processing of your personal data is unlawful or inconsistent with applicable laws.

If you wish to exercise any of the above rights, please contact the Company through the “Company Contact Channels” below. The Company will consider your request and notify you of the result within 30 days from the date of receipt of the request. However, the Company may refuse to exercise your rights where permitted or required by law.

Exercising your rights will not affect the lawful collection, use, or disclosure of personal data that you have previously provided to the Company.

8 Security Measures

The Company has implemented appropriate security measures for personal data, covering administrative safeguards, technical safeguards, and physical safeguards concerning access to or control of access to personal data, in order to prevent loss, unauthorized access, use, alteration, modification, or disclosure of personal data.

The Company has implemented access controls and restrictions on the use of equipment for securely storing and processing personal data. The Company defines the rights and responsibilities of users and establishes or limits the rights of other authorized persons who may access such data in order to prevent unauthorized access, disclosure, unauthorized knowledge, or unauthorized copying of personal data, as well as theft of equipment used to store or process personal data. In addition, the Company has established measures for regularly monitoring access to, modification, deletion, or transfer of the Company's personal data.

9 Personal Data Breach Management

In the event of a personal data breach or where there is reasonable suspicion of a data leak, the Company has established procedures for managing such incidents to ensure security and minimize impacts on data subjects as follows:

When a personal data breach is detected or reported, the Company will immediately investigate and conduct a preliminary assessment to identify the types of data affected and the scope of the breach.

  1. In cases where there is no risk: Where the Company assesses that the breach poses no risk to the rights and freedoms of individuals, the Company will record the details of the incident and relevant measures in writing to serve as evidence and reference information for future review by the Company or regulatory authorities.

  2. Where there is a risk: The Company will notify the Personal Data Protection Committee Office (PDPC) of the personal data breach without delay and, where practicable, within 72 hours from becoming aware of the breach.

  3. Where there is a high risk: If the breach is likely to result in a high risk to the rights and freedoms of data subjects, the Company will notify the Personal Data Protection Committee Office (PDPC) of the breach without delay and, where practicable, within 72 hours, and will notify the affected data subjects of the breach together with the remedial measures as soon as possible.

10 Whistleblowing

You may submit a complaint or report concerns when you become aware of conduct that you reasonably believe constitutes a violation of this Privacy Policy and its guidelines. The procedures shall be in accordance with the Company's whistleblowing policy and guidelines. Complainants or whistleblowers will be protected, and their information will be kept confidential without affecting their employment position, both during the investigation process and after its completion.

11 Amendments to This Privacy Policy

The Company may amend or modify this Privacy Policy from time to time to reflect changes in applicable laws, technological developments, or other reasonable circumstances as necessary. The Company will publish the amended Privacy Policy on the Privacy Policy page before the amendments take effect.

12 Data Protection Officer

The Company has implemented measures in compliance with the Personal Data Protection Act B.E. 2562 by appointing a Data Protection Officer (DPO) to monitor the Company's operations concerning the collection, use, and disclosure of personal data to ensure compliance with the Personal Data Protection Act B.E. 2562 and other applicable personal data protection laws.

13 Company Contact Channels

You may contact the Company to exercise your rights or make inquiries regarding this Privacy Policy through the contact details provided below.

Data Protection Officer (DPO)

Head Office

41 Soi Phahonyothin 5, Phahonyothin Road, Phaya Thai Subdistrict, Phaya Thai District, Bangkok 10400

Nakhon Ratchasima Office

Navanakorn Industrial Promotion Zone, Nakhon Ratchasima, 999/5 Moo 1, Mittraphap Road, Na Klang Subdistrict, Sung Noen District, Nakhon Ratchasima 30380

Privacy Center

Tel. 044-335-520 - 21

The Company requires the Personal Data Protection Policy to be reviewed annually.

This policy shall take effect from 19 March 2026

Mr. Soontorn Pojthanamas

Chairman of the Board of Directors

NEP Realty and Industry Public Company Limited

Download Personal Data Protection Policy