บริษัท เอเชียน มารีน เซอร์วิสส์ จำกัด (มหาชน)
ASIAN MARINE SERVICES PUBLIC COMPANY LIMITED
Announcement No. EXC A67061
Subject: Measures to Maintain Personal Data Security
Asian Marine Services Public Company Limited respects the privacy rights of personal data and complies with the Notification of the Personal Data Protection Committee on Security Measures for Personal Data Controllers B.E. 2565 (2022), referred to as the “Law.” This Law requires personal data controllers to establish and maintain security measures to protect the privacy rights of data subjects and their control over their personal data. Maintaining the security of personal data is a legal obligation for both personal data controllers and data processors, who must implement safeguards to prevent data loss, unauthorized access, use, alteration, modification or disclosure of personal data that could result in a personal data breach.
The Company has implemented personal data security measures covering the collection, use, and disclosure of personal data in accordance with the Law, encompassing administrative, technical, and physical safeguards, and are implemented as follows:
1. Administrative Safeguard Measures
1. The Company has implemented measures to safeguard personal data in accordance with these policies, applying to the Board of Directors, executives, all levels of employees, and all types of Company personnel, as well as business partners, business alliances, and/or stakeholders. This includes promoting awareness of the importance of personal data protection to ensure that such persons strictly comply with the designated measures.
2. The Company maintains risk prevention standards, monitors and surveils threats, and responds to personal data breach incidents in accordance with its Information Security Policies. Roles and responsibilities are defined for Company representatives to take action in the event of a breach, and to maintain and restore data following threats and personal data breach incidents, as follows:
2.1. Appoint a personal data protection custodian and establish operational procedures in the event of personal data breaches.
2.2. Require Company’s representatives to notify the Office of Personal Data Protection Committee of any personal data breach within 72 hours of becoming aware of the incident.
2.3. Reporting of violations may be waived if there is no risk to the rights and freedoms of individuals. In the event of a personal data breach, the Company will review its security measures each time.
3. The Company establishes permissions and determines rights regarding access to personal data, such as the rights to view, edit, supplement, disclose, and publish it, verify data quality, and delete or destroy it.
4. The Company limits access to users’ personal information to authorized personnel only.
5. The Company shall provide a method for tracking back access to, changes to, deletion of, copying of, and transfers of personal data in a consistent and appropriate manner.
6. In the event of a violation of these security measures due to the Company’s negligence, resulting in a breach or leakage of personal data, the Company will promptly inform the data subject of the incident details and the plan for remedying the damage caused by the breach or leakage. However, the Company will not be liable for any damages arising from the use or disclosure of the data, including negligence, by the data subject or any other person authorized by the data subject.
7. Deletion of Personal Data: When personal data is no longer in use or no longer necessary to retain, the Company will delete it from the system or render it anonymized, except where retention is required by law or permitted by a legal exception.
8. The Company has reviewed and assessed the effectiveness of the personal data protection system through relevant agencies.
2. Technical Safeguard Measures
1. The Company manages user access rights appropriately, including granting, revoking, reviewing, and modifying those rights.
2. The Company has a data backup and recovery system to ensure the continued operation of its systems and/or services, in accordance with the Company’s information management policies and procedures.
3. Physical Safeguard Measures
1. The Company controls access to personal data, storage devices, and equipment used to process personal data, with a focus on the security of personal data.
2. The Company designates authorized personnel to access devices used for the storage or processing of personal data based on their roles and responsibilities. This is to prevent unauthorized access to, disclosure of, or awareness of personal data, as well as the unauthorized copying of personal data, theft of storage devices or personal data processing equipment, and to implement appropriate safeguards against personal data leakage or data breaches.
3. In the event personal data must be provided to other individuals or legal entities, the Company will require those recipients to implement security measures equivalent to or exceeding those outlined in these policies. These measures are to prevent the unauthorized or unlawful loss, access, use, alteration, modification, or disclosure of personal data, and recipients must notify the Company of any data breach. The stringency of these measures should be proportionate to the level of risk or potential damage resulting from the unlawful leakage, alteration, copying, or destruction of personal data.
4. In the event that the Company’s security measures are breached, resulting in a personal data breach or the unauthorized disclosure of personal data to the public, the Company will promptly notify the affected data subjects and provide information regarding the appropriate remedial measures.
4. Review of Measures
The Company will review security measures as appropriate and when necessary to align with evolving circumstances or changes in the law.
5. Disclaimer
The Company will not be liable for any damages resulting from the use or disclosure of third-party personal information, including negligence, omission, or failure to log out of databases or other systems, whether by the data subject or by any other person authorized by the data subject.
6. Contact Channels
Asian Marine Services Public Company Limited, 128 Moo 3, Laem Fha Pha, Phra Samut Chedi District, Samut Prakan 10290, Telephone: 02 8152060, Website: www.asimar.com, Email: dpo@asimar.com
Therefore, this announcement is made for all employees’ acknowledgment.
Announced on December 23, 2024
-Signature -
(Mr. Suradej Tanpaibul)
Chief Executive Officer