Privacy Information Collection Statement (“PICS”)
St Andrews International School Bangkok (“the School”) is committed to safeguarding Personal Data in accordance with Thailand's Personal Data Protection Act BE 2562 (2019) (“PDPA”). This PICS is addressed to past, prospective or visitors and third parties of the School which is owned by Nord Anglia Education. It explains how we collect and use your Personal Data.
This PICS is intended to explain our privacy practices and covers the following areas:
(1) What Personal Data do we process;
(2) How we use your Personal Data;
(3) Transmission, storage and security of Personal Data;
(4) Rights relating to Personal Data;
(5) Changes to our Privacy and Cookies Policy;
By providing your information (whether via our Website, in person, in writing or over the phone) to us, you acknowledge the processing set out in this PICS. Further notices highlighting certain uses we wish to make of your Personal Data together with the ability to opt in or out of selected uses may also be provided to you when we collect Personal Data from you.
School related processing activities set out in this PICS are undertaken by the School, and St Andrews International School Bangkok is the Data Controller. Other processing activities are undertaken by NAE, as the ultimate owner of NAE Schools.
Types of processing by the School include visitor and third party information for the purposes of either fulfilling our contractual obligations with one of the aforementioned parties or for legal requirements such as safeguarding. If the third parties, visitors and suppliers fail to comply and do not provide relevant details, the School may not be able to fulfil its contract with third parties, visitors and suppliers.
This PICS only relates to processing undertaken by or on behalf of the School. Whilst our Websites may contain links to other third party Websites, please note that we do not accept any responsibility or liability for their policies in relation to any Personal Data or their collecting processing of any Personal Data. Note that we will inform the data subject if we are storing information on them without their knowledge within 30 days from collecting the data.
1. What Personal Data do we process
We may collect and process the following Personal Data about visitors and third parties.
Biographical and identification information ► including name, date and place of birth, passport and national identity information;
Contact information ► including address(es), telephone number(s), email address(es), emergency contacts;
Payroll information ► including bank account and tax number
Website and communication usage ► details of visits to our Websites and information collected through cookies and other tracking technologies including, IP address and domain name, browser version and operating system, traffic data, location data, web logs and other communication data, and the resources that are accessed;
Information you have provided to us ► any additional information that you may provide to us, such as through completing enquiry or feedback forms.
Where we collect Personal Data from
We may obtain Personal Data from you directly, or from third parties such as other educational or sporting institutions, sanctions and politically exposed persons screening lists, our business partners and public registers.
2. How we use your Personal Data
Your Personal Data will only be processed where we have a specific purpose, and a lawful basis, for doing so. These purposes and bases are listed below. An explanation of the scope of the grounds available can be found at Lawful Bases.
(a)To onboard third party providers and to allow visitors access to the site ► to process all activities relating to an onsite visit at the School.
Lawful Bases: legitimate interests (to enable us to perform our obligations and provide our services).
(b) To provide a safe and healthy environment for visitors and third parties► this may in certain limited circumstances include Special Categories of Personal Data in the form of Health data, comprising information relating to any injury a visitor or third party may sustain at School or whilst undertaking any activities whilst on site; any disability; health conditions relevant to the purpose of an on site visit; and any health problems that the School needs to be aware of. Lawful Bases: contract and legal obligations.
(c) To conduct extra-curricular programmes ► to organise, administer and operate extra-curricular expeditions and activities, including processing payment, which may include passing Personal Data to third parties for relevant insurance cover, medical assistance, supervision and execution of activities;
Lawful Bases: legitimate interests (to enable us to perform our obligations and provide our services)
(d) To provide newsletters and marketing materials ► to provide you with updates and offers relating to our products and services, where you have chosen to receive these. Where required by law, we obtain consent to conduct this marketing activity. We will provide an option to unsubscribe or opt-out of further communication on any electronic marketing communication sent to you or you may opt out by contacting us as set out using the details at the end of the Policy;
Lawful Bases: legitimate interests (to promote our services); consent
(e) To monitor certain activities ► to monitor communications to ensure compliance with our internal procedures and any legal requirements;
Lawful Bases: legal obligations; legal claims; legitimate interests (to ensure that the quality and legality of our services)
(g) To reorganise or make changes to our business ► - In the event that we are (i) subject to negotiations for the sale of our business or part thereof to a third party, (ii) is sold to a third party or (iii) undergo a re-organisation, we may need to transfer some or all of yourPersonal Data to the relevant third party (or its advisors) as part of any due diligence process or transferred to that re-organised entity or third party and used for the same purposes as set out in this PICS or for the purpose of analysing any proposed sale or re-organisation;
Lawful Bases: legitimate interests (in order to allow us to change and develop our business)
(h) In connection with legal or regulatory obligations ► We may process your personal Data to comply with our regulatory requirements or to engage in dialogue with our regulators. This may include disclosing that Personal Data to third parties, the court service and/or regulators or law enforcement agencies in connection with enquiries, proceedings or investigations by such parties anywhere in the world or where compelled to do so;
Lawful Bases: legal obligations; legal claims; legitimate interests (to cooperate with law enforcement and regulatory and public authorities). In the limited circumstances where we need to process Special Categories of Personal Data or Criminal Convictions Data we may also rely on explicit consent or legal claims.
(i) To manage our Websites ► We use cookies on our Websites. To find out more about how we use cookies, please see our Cookie Policy below.
Sharing Personal Data with other organisations.
In order to provide our education and Schooling services (including extra-curricular activities) effectively, we sometimes need to share information with other organisations. We share information with the following entities:
(a) NAE teams which undertake management functions for our Schools; and
(b) Our suppliers, who assist us in providing educational and extra-curricular services. A list of our suppliers can be provided upon request by contacting us on dpo@standrews.ac.th
Where these entities are outside of Thailand, we ensure that there are adequate safeguards in place to ensure the security of your Personal Data.
3. Transmission, storage and security of Personal Data
Security over the internet
No data transmission over the Internet or through a Website can be guaranteed to be secure from intrusion. However, we maintain commercially reasonable physical, electronic and procedural safeguards to protect your Personal Data, and that of any child you are responsible for, in accordance with data protection legislative requirements.
All information you, or any child you are responsible for, provide to us is stored on our or our suppliers’ secure servers and accessed and used subject to our security policies and standards. We ask that you, or any child you are responsible for:
(a) Refrain from sharing any password providing access to certain parts of our Websites, applications or systems with any other person; and
(b) Comply with any other security procedures that we may notify you of from time to time.
Export outside Thailand
Your Personal Data, may be transferred to, stored in or accessed by staff or suppliers in, a destination outside Thailand. Regardless of location, we will impose the same data protection safeguards that we deploy Thailand.
Please contact us at dpo@standrews.ac.th if you would like to see a copy of the specific safeguards applied to the export of Personal Data relating to you or any child you are responsible for.
Storage limits
We will retain your Personal Data for as long as is necessary for the processing purpose(s) for which they were collected and any other permitted linked purpose (for example certain transaction details and correspondence may be retained until the time limit for claims in respect of the transaction has expired or in order to comply with regulatory requirements regarding the retention of such data). So if Personal Data is used for two purposes we will retain it until the purpose with the latest period expires; but we will stop using it for the purpose with a shorter period one that period expires. We restrict access to Personal Data to those persons who need to use it for the relevant purpose(s).
Our retention periods are based on business needs and relevant laws. Records that are no longer needed are either irreversibly anonymised (and the anonymised information may be retained) or securely destroyed. Below is our retention periods.
Record Category I Description |
Retention Period - |
Accident reporting - Adults |
20 years |
Health and Safety Audits |
Length of building use |
Medical records - Paper records to be made electronic at the end of each academic year |
5 years |
Visitor information |
30 days |
Payroll records |
10 years |
4. Rights relating to Personal Data
Be aware of the rights that Data Subjects have in relation to their Personal Data
Data Subjects have a number of rights relating to how their Personal Data is used. Please be aware that certain exceptions apply to the exercise of these rights and so you will not be able to exercise them in all situations. If you wish to exercise any of these rights we will check your entitlement and respond within a reasonable timescale.
Where applicable, you will have the following rights relating to your Personal Data or the Personal Data of a dependant.
Subject Access: Be provided access to any data held about you by the School. This information will generally be provided within one month of us confirming your identity and understanding the scope of your request.
Rectification: Require inaccurate Personal Data amended.
Erasure: Require us to erase Personal Data in certain circumstances. If the Personal Data has been made public, reasonable steps will be taken to inform other controllers that are processing the data that you have requested the erasure of any links to, copies or replication of it.
Withdrawal of consent: Withdraw any consents to processing that you have given us and prevent further processing, if there is no other ground under which we can rely to process your Personal Data.
Restriction: Require certain Personal Data to be marked as restricted in some circumstances, for example, whilst we resolve any complaint we may have received. Restriction means that whilst we still store the data, we will not process it until such time as the restriction may be lifted.
Portability: Have a copy of any Personal Data you have provided to us returned to you, or transmitted to another controller in a commonly used, machine readable format.
Prevent processing: Require the School to stop any processing based on the legitimate interests ground unless the School reasons for undertaking that processing outweigh any prejudice to your data protection right.
Marketing: Require the School to prevent processing of your Personal Data for direct marketing purposes.
Raise a complaint: Complain to your local Data Protection Authority about our processing of your Personal Data.
If you have any queries relating to your rights or exercise of your rights, please contact us at dpo@standrews.ac.th
5. Changes to our Privacy and Cookies Policy
Our PICS and our Cookie Policy may change from time to time in the future. We therefore encourage you to review them when you visit the Website from time to time to stay informed of how we are using Personal Data.
This PICS was last updated on 22/04/2022
Use of Personal Data under Thai data protection laws must be justified under one of a number of Lawful Bases and we are required to set out the Lawful Bases in respect of each use in this policy. We note the Lawful Bases we use to justify each use of your information next to the use in the “How we use your Personal Data".
These are the principal Lawful Bases that justify our use of your Personal Data:
Consent: You have given your consent to the processing of those Personal Data for one or more specified purposes. You are free to withdraw your consent by contacting dpo@standrews.ac.th |
Contract performance: where your information is necessary to enter into or perform our contract with you. |
Legal obligation: where we need to use your information to comply with our legal obligations. |
Legitimate interests: where we use your information to achieve a legitimate interest and our reasons for using it outweigh any prejudice to your data protection rights. |
Legal claims: where your information is necessary for us to defend, prosecute or make a claim against you, us or a third party. |
These are the principal Lawful bases that justify our use of Special Categories of your Personal Data, in the limited circumstances where it is necessary to do so:
Explicit consent: You have given your explicit consent to the processing of those Personal Data for one or more specified purposes. You are free to withdraw your consent by contacting dpo@standrews.ac.th. Where you do so, we may be unable to provide a service that requires the use of such data. |
Protection of vital interests of you or another person, where you are unable to consent: Processing is necessary to protect the vital interests of you or of another natural person where you are physically or legally incapable of giving consent. |
For legal claims: Processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity. |
In the substantial public interest: Processing is necessary for reasons of substantial public interest, on the basis of Thai law. |
The following terms are used in this PICS:
Data Controller: this is the person which alone or jointly with others determines the purpose and means of the processing of Personal Data.
Data Protection Authority: The Office of Personal Data Protection Committee can be contacted on pdpc@mdes.go.th
Data Subject: for the purpose of this policy this includes all living individuals about whom we hold Personal Data, including visitors and third parties. A Data Subject need not be a national or resident of the country the concerned NAE business is based in. Within Thailand, all Data Subjects have legal rights in relation to their Personal Data.
Data Processor: this is the person which processes Personal Data on behalf of the Data Controller (not including employees of the Data Controller). NAE’s suppliers and agencies that handle Personal Data on our behalf will be Data Processors.
NAE, Our, Us, We: Nord Anglia Education (which includes each of the companies and Schools listed on our Website). For the avoidance of doubt this includes the School.
Personal Data: this is defined as any information relating to an identified or identifiable natural person. An identifiable person is one who can be identified (either directly or indirectly) by reference to an 'identifier'. These include names, ID numbers, location data, online identifiers or one or more factors specific to the physical, psychological, genetic, mental, economic, cultural or social identity of that person.
Special Categories of Personal Data: this type of data is, in Thailand and some other countries, subject to more stringent processing conditions than other Personal Data and in Thailand includes Personal Data which reveals racial or ethnic origin, political opinion, religious or philosophical beliefs, trade-union membership, and the processing of genetic data, biometric data in order to uniquely identify a person or data concerning health, sex life and sexual orientation. Data concerning health covers Personal Data relating to the physical or mental health of an individual which reveals information about the individual's health status. In Thailand, Personal Data relating to criminal convictions or offences or related security measures may only be processed when authorised by Thai law. In other countries the term Special Categories of Personal Data may include other categories of information such as financial information and passwords. If in doubt, please contact the Data Protection Officer on dpo@standrews.ac.th.
8. Contact Us
St Andrews International School
Primary School
9 Pridi Banomyong 20/1, Sukhumvit 71
Watthana
Bangkok
10110
THAILAND
High School
1020 Sukhumvit Rd, Khlong Toei,
Phra Khanong
Bangkok
10110
THAILAND
Primary School +66 2 381 2387
High School +66 2 056 9555
Email: dpo@standrews.ac.th
Cookie Policy
Consent
By using this Website (the Website) of St Andrews International School Bangkok, a School within the NAE group, you consent to the use of cookies in accordance with this Cookies Policy. You will have seen a pop up to this effect on your first visit to this Website; and although it will not usually appear on subsequent visits you may withdraw your consent at any time by following the instructions below.
What are cookies?
Cookies are text files containing small amounts of information which are downloaded to your device when you visit a Website. Cookies are then sent back to the originating web domain on your subsequent visits to that domain. Most web pages contain elements from multiple web domains so when you visit the Website, your browser may receive cookies from several sources.
We use the cookies on this Website to help you navigate our Website efficiently, perform certain functions and to collect site statistics. These cookies do not store any personal information that would, on its own, allow us to identify individual users of this service without your permission. Please be aware that restricting cookies may impact on the functionality of the Website and could mean that key features do not work properly. We strongly recommend allowing cookies from this Website so that we can provide you with a full service.
What type of cookies do we use?
We use a number of suppliers (3rd Party) who also set cookies on our Website on our behalf in order to deliver the services that they are providing. If you would like more information about the cookies used by these suppliers, as well as information on how to opt-out, please see the information in the tables provided below.
To help you make an informed decision, we have categorised the cookies used on this site into two categories;
-
Necessary cookies – these cookies are fundamental to ensure the site works correctly.
-
Optional cookies – These cookies could help us track how you use the Website so that we can improve the information and experience provided to you. They may also provide additional features by 3rd party providers to allow you to socially share content or comment on this Website.
How to control and delete cookies
We will not use cookies to collect personally identifiable information about you unless you willing provide it. However, if you wish to restrict or block the cookies which are set by this Website, or indeed any other Website, you can do this through your browser settings. The Help function within your browser should tell you how.
Alternatively, you may wish to visit www.aboutcookies.org which contains comprehensive information on how to do this on a wide variety of browsers. You will also find details on how to delete cookies from your computer as well as more general information about cookies. For information on how to do this on the browser of your mobile phone you will need to refer to your handset manual.
We do not use ’spyware’, that is web bugs or hidden identifiers or other similar devices to gain access to information, store hidden information or to trace your activities.
Traffic data
We keep a record of traffic data which is logged automatically by the server. This includes your IP address, the Website address you visited before ours, the Website address you visit after leaving our site and which pages you visit on our site. We do not store or analyse this traffic data in a way that identifies any individual. We also use Google Analytics for site statistics – see 'Cookies’ above for details of how this works