Roche Diagnostics Thailand
Data Privacy Notice for Attendee
This Data Privacy Notice (“Notice”) regulates the processing of personal data in compliance with Roche Diagnostics ( Thailand) Company Limited ( “Roche” , “RDT” , “ we” , “ us” or “ our” ) on the protection of personal data which Roche may collect, use, disclose or otherwise process personal data of an attendee who registers or is invited by Roche to participate Roche’s medical congress, events, meeting, sponsored programs, and initiatives, workshops and seminars in accordance with Roche Directive on the Protection of Personal Data and the Personal Data Protection Act B.E. 2562 (“PDPA”), Thailand.
We are committed to protect your personal data and fundamental privacy right under the PDPA. This Privacy Notice outlines the types of personal data Roche may collect, use and/or disclose; themeans by which Roche may collect, use, or share your personal data; steps Roche takes to protect your personal information; and choices you are provided with respect to the use of your personal information.
APPLICATION OF THIS NOTICE
1. This Notice applied to all persons engaged with Roche pertaining to an attendee who registers or is invited by Roche to participate Roche’s medical congresses, events, meetings, sponsored programs, and initiatives, workshops and seminars (hereinafter referred to as the “Data Subject” or “Attendee”) in order to fulfill Roche’s obligations to supply the medical congresses, events, meetings, sponsored programs, and initiatives, workshops and seminars to you.
PERSONAL DATA ROCHE MAY COLLECT
2. As used in this Notice, “Personal Data” means any information pertaining to a person, which enables the identification of such person, whether direct or indirect, but does not include data of dead person in particulars. Examples are name, ID number, passport number, photograph, mobile phone number, residential address, blood type, birth date, education background, religion.
3. The Personal Data which we may collect, such as:
3.1 Identification information e.g., name, surname, age, identification number, copy of ID card, passport or driving license, date of birth, signature and nationality.
3.2 Contact information e.g., address, email address, telephone numbers, and other contact details;
3.3 Work-related information e.g., position, department and license number; and
3.4 Photos and video records.
4. Other terms used in this Notice shall have the meanings given to them in the PDPA (where the context so permits).
COLLECTION, USE AND DISCLOSURE OF PERSONAL DATA
5. We collect Personal Data that: (a) you provide directly in the course of or in connection with attending medical congress, events, meeting, sponsored programs, and initiatives, workshops and seminars by online or direct registration, or from a third party who has been duly authorized by you to disclose your personal data to us (“Representative”), after (i) you or your Representative have been notified of the purposes for which your personal data is collected, and (ii) you or your Representative have provided written consent to the collection and usage of your Personal Data for those purposes; (b) collection and usage of Personal Data without consent is permitted or required by the PDPA or other laws (c) we receive from a conversation between you and Roche including phone record, message, mail, email, Roche’s website and application, or any other means; and (d) in insurance claims or other documents; (e) you have disclosed to public (e.g., on your website or other social media). In case where the consent is required, we shall seek your consent before collecting any additional Personal Data and before using your Personal Data for a purpose, which has not been notified to you (except where permitted or authorized by the PDPA or other laws). Refusal to consent may result in our delay, inconvenience, or unviability to perform the obligations between Roche and Attendee.
6. We shall process, use or disclose the Personal Data collected in compliance to the following basis of the PDPA legal framework:
6.1 Necessity for fulfilling the obligations to supply the medical congresses, events, meetings, sponsored programs, and initiatives, workshops and seminars;
6.2 To comply with any law enforcement or our legal duty;
6.3 To prevent or suppress danger to life, body or health;
6.4 When it is our legitimate interest; or
6.5 When you consent to it.
7. Your Personal Data will be collected, used or disclosed to third parties in case where it is necessary for the following purposes:
7.1 To identify, keep record and check the number of participants when you have registered through mail, fax or online in participating Roche’s medical congress, events, meeting, sponsored programs, and initiatives, workshops and seminars;
7.2 To contact you in providing information, answering questions, and contacting you about the meeting or other further activities; or
7.3 To contact you in relation to health information, campaign, dissemination of products and services appropriated as well as marketing activities; and
7.4 To use for running statistic and developing further meetings or create new project.
8. The purposes listed in the above clauses may continue to apply even in situations where your relationship with us (for example, pursuant to a contract or agreement) has been terminated or altered in any way, for a reasonable period thereafter (including, where applicable, a period to enable us to enforce our rights under any contract with you).
9. We may share your Personal Data with Roche’ s affiliates around the world. Our Roche affiliates will use your Personal Data for the same purposes as we do. A list of Roche’s affiliates is available in the current annual report, which can be found in the Investors section of www.roche.com
DATA SUBJECT RIGHTS
10. Right to Withdraw: This enables you to withdraw your consent to our processing of your personal data, which you can do at any time. We may continue to process your personal data if we have another legitimate reason or other law to do so.
11. Right to Access: This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
12. Right to Correct: This enables you to have any incomplete or inaccurate data we hold about you corrected.
13. Right to Erasure: This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have exercised your right to object to processing(see below).
14. Right to Object: This enables you to object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal data for direct marketing purposes.
15. Right to Restrict Processing: This enables you to ask us to suspend the processing of personal data about you, for example if you want us to establish its accuracy or the reason for processing it.
16. Right to Portability: This enables you to request the transfer of your Personal Data to another party.
17. To exercise any of these rights, please contact us using the information provided in this Notice.
18. The consent provided by you for the collection, use and disclosure of your Personal Data will remain in effective until the time it is being withdrawn in writing. You may withdraw consent and request us to stop using and/ or disclosing your Personal Data for any or all of the purposes listed above by submitting your request in writing or via email to us at the contact details provided in this Notice.
19. Upon receiving your written request to withdraw the consent, we may require reasonable time (depending on the complexity of the request and its impact on our relationship with you) for your request to be processed. We shall seek to process and effect your request within 30 days of receiving it.
20. Withdrawing consent may result in our delay, inconvenience, or unviability to perform the obligations between Roche and attendee.
SECURITY OF YOUR PERSONAL DATA
21. We regularly review and implement up-to-date physical, technical and organizational security measures when processing your personal data. We have internal policies and controls in place to ensure that your personal data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by our employees in the performance of their duties.
RETENTION OF PERSONAL DATA
22. We may retain your Personal Data, in most cases, we will keep the data for ten (10) years following our last interaction with you or as long as it is necessary to fulfil the purposes for which they were collected, for the legal purposes or as required or permitted by applicable laws.
23. We will cease to retain your Personal Data, or remove the means by which the data can be associated with you, as soon as it is reasonable to assume that such retention no longer serves the purposes for which the Personal Data were collected, and are no longer necessary for legal or business purposes.
PERSONAL DATA OVERSEAS TRANSFER
24. Your Personal Data may be transferred to and stored/processed in all countries where Roche group has established a legal presence. These locations may not have the same level of Personal Data protection. However, we will ensure that the overseas organization adheres to the procedure and guidance under the PDPA and ensure the Personal Data is adequately protected at the destination.
REVISION OF THE POLICY/NOTICE
25. This Notice applies in conjunction with any other policies, notices, contractual clauses and consent clauses that apply in relation to the collection, use and disclosure of your Personal Data by us.
26. We may revise this Notice from time to time without any prior notice. You may determine if any such revision has taken place by referring to the date on which this Notice was last updated. Your continued employment and participation in our recruitment process constitute your acknowledgement and acceptance of such changes.
If you have any questions on this Notice, your Personal Data protection or would like to exercise the entitled rights regarding the Personal Data, please contact us at:
Roche Diagnostics (Thailand) Company Limited
No. 555 Rasa Tower, 18th-19th Floor, Pahonyothin Road, Chatuchak Sub-district, Chatuchak District,
Data Protection Officer
DPO: Ruthaiwan Sinlapachan
Email: [email protected]
Effective date: 1 September 2021
Last updated: 1 September 2021