ทำ Privacy Lifecycle ตั้งแต่สมัครงาน → ทำงาน → ประเมิน/Payroll → สวัสดิการ → CCTV/Biometric → ออกจากงาน → retention/deletion
เรื่องนี้คืออะไร และต้องตรวจใครบ้าง
พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562; ประกาศ PDPC เรื่อง security, ROPA, breach ฯลฯ ฉบับปัจจุบัน
- controller/processor
- privacy notice
- lawful bases (contract, legal obligation, legitimate interest ฯลฯ) และเหตุใด consent ไม่ใช่คำตอบทุกเรื่องใน employment
- sensitive data ม.26 เช่น สุขภาพ ความพิการ สหภาพ ประวัติอาชญากรรม พันธุกรรม/biometric
- recruitment background checks
- payroll/SSO/insurer/vendor transfer
- CCTV
- attendance/face data
- access control
- retention
- employee rights
- breach response
- cross-border transfer เมื่อใช้ cloud
- For every HR processing activity, identify controller and processor roles, purpose, legal basis, recipients, retention, and access rights.
- Consent is not the default basis for all employment processing; use contract, legal obligation, legitimate interests, or another basis only where its conditions are met.
- Health, union, criminal-record, genetic, and biometric data are sensitive data under section 26 and require necessity and an applicable exception.
- Assess and document every breach. Where risk to rights and freedoms exists, notify the PDPC without delay and, where feasible, within 72 hours after awareness; where risk is high, also notify affected data subjects without delay and provide mitigation guidance.
หลักตัดสินที่ต้องใช้
- กำหนดผู้ควบคุม/ผู้ประมวลผล วัตถุประสงค์ ฐานกฎหมาย ผู้รับ ระยะเก็บ และสิทธิการเข้าถึงทุกกิจกรรม HR
- consent ไม่ใช่ฐานเริ่มต้นทุกเรื่องในการจ้างงาน; ใช้สัญญา หน้าที่กฎหมาย ประโยชน์โดยชอบ หรือฐานอื่นเมื่อเข้าองค์ประกอบ
- ข้อมูลสุขภาพ สหภาพ ประวัติอาชญากรรม พันธุกรรม และชีวมิติมีเงื่อนไขมาตรา 26 และต้องจำกัดความจำเป็น
- เมื่อเกิดเหตุละเมิด ให้ประเมินและบันทึกความเสี่ยง; หากเสี่ยงต่อสิทธิและเสรีภาพให้แจ้งสำนักงาน PDPC โดยไม่ชักช้าและเท่าที่ทำได้ภายใน 72 ชั่วโมงนับแต่ทราบเหตุ และหากมีความเสี่ยงสูงให้แจ้งเจ้าของข้อมูลพร้อมแนวทางเยียวยาโดยไม่ชักช้า
- For every HR processing activity, identify controller and processor roles, purpose, legal basis, recipients, retention, and access rights.
- Consent is not the default basis for all employment processing; use contract, legal obligation, legitimate interests, or another basis only where its conditions are met.
- Health, union, criminal-record, genetic, and biometric data are sensitive data under section 26 and require necessity and an applicable exception.
- Assess and document every breach. Where risk to rights and freedoms exists, notify the PDPC without delay and, where feasible, within 72 hours after awareness; where risk is high, also notify affected data subjects without delay and provide mitigation guidance.
มุมบริษัทและฝ่าย HR: จากหลักกฎหมายสู่การปฏิบัติ

data map + purpose + legal basis + retention + recipient; least privilege; DPA กับ vendor; consent ต้อง freely given เมื่อจะใช้จริง
- data map + purpose + legal basis + retention + recipient
- least privilege
- DPA กับ vendor
- consent ต้อง freely given เมื่อจะใช้จริง
- ช่วยชีวิต/หยุดความเสี่ยงหรือจำกัดเหตุรั่วไหลก่อน แล้วจึงรักษาหลักฐานและสอบสวน
- ติดตาม corrective action ถึงวันปิดจริง ไม่จบที่การเขียนรายงาน
- Maintain a data map linking purpose, lawful basis, retention period, recipients, and access rights. Apply least privilege, use appropriate processor terms with vendors, and seek consent only where it can be freely given and withdrawn.
- Protect life, stop the hazard, or contain the breach first; then preserve evidence and investigate
- Track corrective action to verified closure rather than ending with a report
เอกสารที่บริษัทควรเปิดพร้อมกัน
- การประเมินความเสี่ยง/วัตถุประสงค์และฐานการดำเนินการ
- บันทึกเหตุ เวลา สถานที่ ผู้เกี่ยวข้อง และการตอบสนองแรก
- รายงานแพทย์/การสอบสวน/บันทึกระบบตามประเภทเรื่อง
- การแจ้งหน่วยงาน มาตรการแก้ไข และหลักฐานติดตาม
- data inventory, privacy notice, lawful-basis record, ROPA, access log และ retention record
- Risk assessment or documented purpose and lawful basis
- Incident time, place, persons involved, and first response
- Medical, investigation, or system logs according to the issue
- Authority notification, corrective action, and follow-up evidence
- Data inventory, privacy notice, lawful-basis record, ROPA, access log, and retention record
มุมลูกจ้าง: ตรวจสิทธิจากเงื่อนไขและหลักฐาน
มีสิทธิได้รับ notice และใช้สิทธิตาม PDPA แต่บางการประมวลผลนายจ้างทำได้โดยไม่ต้องขอ consent เมื่อมีฐานอื่น
- มีสิทธิได้รับ notice และใช้สิทธิตาม PDPA แต่บางการประมวลผลนายจ้างทำได้โดยไม่ต้องขอ consent เมื่อมีฐานอื่น
- แจ้งเหตุทันทีผ่านช่องทางที่พิสูจน์เวลาได้และเก็บเอกสารแพทย์/ระบบ
- บันทึกความเกี่ยวเนื่องกับงานหรือผลกระทบต่อข้อมูลโดยไม่แก้ไขหลักฐานต้นฉบับ
- Employees have notice and data-subject rights, but an employer may lawfully process some data without consent when another lawful basis applies.
- Report promptly through a timestamped channel and keep medical or system records
- Record the work connection or data impact without altering original evidence
คำถามข้อเท็จจริงก่อนโต้แย้ง
- ใครอยู่ในบังคับของเรื่อง “PDPA สำหรับงาน HR” และมีข้อยกเว้นจากงาน สถานะ หรือเหตุการณ์ใด
- ข้อเท็จจริงเรื่อง controller/processor เป็นอย่างไรในวันที่สิทธิเกิด
- ข้อเท็จจริงเรื่อง privacy notice เป็นอย่างไรในวันที่สิทธิเกิด
- ข้อเท็จจริงเรื่อง lawful bases (contract, legal obligation, legitimate interest ฯลฯ) และเหตุใด consent ไม่ใช่คำตอบทุกเรื่องใน employment เป็นอย่างไรในวันที่สิทธิเกิด
- ข้อเท็จจริงเรื่อง sensitive data ม.26 เช่น สุขภาพ ความพิการ สหภาพ ประวัติอาชญากรรม พันธุกรรม/biometric เป็นอย่างไรในวันที่สิทธิเกิด
- เอกสารฉบับใดมีผลในวันเกิดเหตุ และการปฏิบัติจริงตรงกับเอกสารหรือไม่
- Who is covered by “PDPA for HR”, and what work, status, or event creates an exclusion?
- What were the actual facts about For every HR processing activity, identify controller and processor roles, purpose, legal basis, recipients, retention, and access rights. when the right arose?
- What were the actual facts about Consent is not the default basis for all employment processing; use contract, legal obligation, legitimate interests, or another basis only where its conditions are met. when the right arose?
- What were the actual facts about Health, union, criminal-record, genetic, and biometric data are sensitive data under section 26 and require necessity and an applicable exception. when the right arose?
- What were the actual facts about Assess and document every breach. Where risk to rights and freedoms exists, notify the PDPC without delay and, where feasible, within 72 hours after awareness; where risk is high, also notify affected data subjects without delay and provide mitigation guidance. when the right arose?
- Which document version applied on the event date, and did actual practice match it?
Workflow เฉพาะเรื่อง: เจ็ดจุดที่ต้องปิดให้ครบ
| FIELD | สิ่งที่ต้องทำกับเรื่องนี้ | หลักฐานขั้นต่ำ |
|---|---|---|
| Trigger | เริ่มเคสเมื่อเกิดคำขอ เหตุการณ์ หรือผล Payroll ที่เกี่ยวกับ PDPA สำหรับงาน HR | บันทึกรับเรื่องพร้อมวัน เวลา ผู้แจ้ง และช่วงสิทธิ |
| Owner | Safety/Occupational Health หรือ Data Protection Owner ร่วมกับ HR หัวหน้างาน และผู้บริหารเหตุการณ์ | ผู้รับผิดชอบ ผู้ตรวจ ผู้อนุมัติ และผู้มีอำนาจลงนาม |
| Action | กำหนดผู้ควบคุม/ผู้ประมวลผล วัตถุประสงค์ ฐานกฎหมาย ผู้รับ ระยะเก็บ และสิทธิการเข้าถึงทุกกิจกรรม HR; consent ไม่ใช่ฐานเริ่มต้นทุกเรื่องในการจ้างงาน; ใช้สัญญา หน้าที่กฎหมาย ประโยชน์โดยชอบ หรือฐานอื่นเมื่อเข้าองค์ประกอบ; data map + purpose + legal basis + retention + recipient | บันทึกการตรวจองค์ประกอบ ข้อยกเว้น และการอนุมัติ |
| Documents | การประเมินความเสี่ยง/วัตถุประสงค์และฐานการดำเนินการ; บันทึกเหตุ เวลา สถานที่ ผู้เกี่ยวข้อง และการตอบสนองแรก; รายงานแพทย์/การสอบสวน/บันทึกระบบตามประเภทเรื่อง | ต้นฉบับ/สำเนาที่ตรวจสอบแหล่งที่มาและเวอร์ชันได้ |
| Deadline | หากเสี่ยงต่อสิทธิและเสรีภาพให้แจ้งสำนักงาน PDPC โดยไม่ชักช้าและเท่าที่ทำได้ภายใน 72 ชั่วโมงนับแต่ทราบเหตุ และหากมีความเสี่ยงสูงให้แจ้งเจ้าของข้อมูลพร้อมแนวทางเยียวยาโดยไม่ชักช้า | วันเริ่มนับ วันครบกำหนด และหลักฐานส่ง/รับ |
| Evidence | เชื่อมข้อเท็จจริง เอกสาร สูตร/ขั้นตอน ผลอนุมัติ และผลในระบบสำหรับ PDPA สำหรับงาน HR | decision record ผลคำนวณ/ผลดำเนินการ และ audit trail ที่มีผู้ตรวจทาน |
| Consequence | criminal record/biometric มีข้อกำหนดเฉพาะ; ห้ามทำ “ใบยินยอมครอบจักรวาล” | แผนแก้ไข ผู้รับผิดชอบ กำหนดเสร็จ และช่องทางทักท้วง |
ตัวอย่างและวิธีใช้กับกรณีจริง
- ใช้ใบหน้าเพื่อบันทึกเวลา: วิเคราะห์ความจำเป็น ฐานกฎหมาย ข้อมูลชีวมิติ ทางเลือก และมาตรการรักษาความปลอดภัย
- ส่ง Payroll ไปผู้ให้บริการ Cloud: ระบุบทบาทผู้ประมวลผล วัตถุประสงค์ สิทธิการเข้าถึง ระยะเก็บ และการโอนต่างประเทศ
- Case 1 — Test a real pdpa for hr scenario against this rule: For every HR processing activity, identify controller and processor roles, purpose, legal basis, recipients, retention, and access rights. Record the facts and evidence supporting each element.
- Case 2 — Change one material fact and test the result against this rule: Consent is not the default basis for all employment processing; use contract, legal obligation, legitimate interests, or another basis only where its conditions are met. Recalculate or rerun the workflow instead of copying the first outcome.
เริ่มจากข้อเท็จจริง → ระบุฐานกฎหมายและวันที่มีผล → ตรวจผู้ได้รับสิทธิ/ข้อยกเว้น → คำนวณหรือเดินตาม workflow → เก็บหลักฐานและทบทวนผล
อย่าเริ่มจากคำตอบสำเร็จรูป ชื่อตำแหน่ง ชื่อเงิน หรือเอกสารเพียงชิ้นเดียว แล้วตัดองค์ประกอบอื่นออก
จุดเสี่ยงและความเข้าใจผิดที่ต้องหยุดก่อน
เมื่อเห็นต่างหรือยังไม่ได้รับการแก้ไข
- กรณีอุบัติเหตุให้รักษาชีวิตและแจ้งเหตุทันที ก่อนเก็บ medical record, incident log, ภาพ และพยาน; กรณีข้อมูลรั่วไหลให้จำกัดเหตุและเก็บ system log
- ใช้ช่อง Safety/Occupational Health, HR หรือ DPO ตามประเภท และขอเลขเคส/ผลสอบสวน/มาตรการแก้ไข
- สิทธิกองทุนเงินทดแทนติดต่อ SSO; การฝ่าฝืนความปลอดภัยติดต่อ DLPW/กองความปลอดภัย; สิทธิข้อมูลส่วนบุคคลใช้ช่องเจ้าของข้อมูล/DPO และสำนักงาน PDPC ตามลำดับ
- For an accident, protect life and report immediately before preserving medical records, incident logs, images, and witnesses; for a data breach, contain the incident and preserve system logs
- Use the Safety or Occupational Health, HR, or DPO channel as appropriate and request a case number, investigation outcome, and corrective action
- For Workmen's Compensation Fund rights contact SSO; for safety violations contact DLPW or the OSH Division; for personal-data rights use the data-subject or DPO route and then the PDPC as appropriate
กฎหมายและเอกสารอ้างอิง
ตรวจทานวันที่ 14 สิงหาคม 2569 การใช้กับกรณีจริงต้องพิจารณาตัวบทที่มีผล ประกาศที่เกี่ยวข้อง และข้อเท็จจริงของแต่ละกรณี
- พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562; ประกาศ PDPC เรื่อง security, ROPA, breach ฯลฯ ฉบับปัจจุบัน
- ประกาศคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล เรื่อง มาตรการรักษาความมั่นคงปลอดภัย พ.ศ. 2565 — ราชกิจจานุเบกษา
- พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 — ราชกิจจานุเบกษา
- พระราชบัญญัติคุ้มครองแรงงาน พ.ศ. 2541 — ราชกิจจานุเบกษา
- กองนิติการ กรมสวัสดิการและคุ้มครองแรงงาน — กฎหมายคุ้มครองแรงงาน

