Bangkok Post

Lawyer urges action on data protection bill

- SUCHIT LEESA-NGUANSUK

The recent cases of data leakage by Facebook and True Move H are a wake-up call for the government to update and enforce data protection laws, says a legal expert.

Paiboon Amornpinyo­kiat, founder of P&P law, said the draft of the data protection bill passed a public hearing and has been pending for cabinet approval before proceeding to the National Legislativ­e Assembly (NLA).

But the bill may not come into effect, he said, as it is not considered as high a priority as the cybersecur­ity law, which is likely to be endorsed before the election.

“Thailand has planned to endorse the data protection law for almost 21 years, from when Chuan Leekpai was prime minister until the present government,” Mr Paiboon said.

The latest data protection draft was deemed outdated because it fails to address newer technologi­es like the Internet of Things (IoT), artificial intelligen­ce and big data.

Moreover, the draft lacks a penalty statement for service operators that leak data and makes no mention of requiring service providers to inform users in the event of a personal data breach.

The draft omits a mandate f or data processors and service providers t o include strong measures for data protection, particular­ly encryption, merely alluding to “proper measures”.

Mr Paiboon said European and US laws offer tax incentives to business operators who invest in technology for data protection in compliance with the law.

He said IoT and cloud computing have been incorporat­ed in the EU’s upcoming General Data Protection Regulation (GDPR), to take effect next month.

The GDPR also covers any organisati­on that has business with the EU and stores EU citizen data.

Mr Paiboon said the GDPR includes three major principles that the NLA might take into considerat­ion for Thailand’s data protection law.

The first is personal data minimisati­on, meaning that companies must limit personal data collection, storage and usage to data that is relevant, adequate and necessary for carrying out the purpose for which the data is processed.

The second is data anonymisat­ion for login, a type of informatio­n sanitisati­on for privacy protection through encrypting or removing personal identifica­tion informatio­n.

The third is privacy-friendly design, requiring online service providers to set the default to protecting user data first. For example, Facebook defaults to a public setting and lets users switch their setting to private later, but less-savvy users may not know how to turn off exposure of their data.

 ??  ?? Paiboon: Three ideas for NLA considerat­ion
Paiboon: Three ideas for NLA considerat­ion

Newspapers in English

Newspapers from Thailand