Data Collection and Consent
Company collects personal data lawfully with explicit consent from data subjects.
🌐 www.thairath.co.th
The policy covers collection, use, and sharing of personal data including sensitive data, but allows broad sharing with affiliates and third parties without specific consent for each case, and lacks detailed safeguards for sensitive data.
The policy references the Thai PDPA and lists data subject rights (access, deletion, objection, etc.), but does not clearly specify legal bases for processing or cross-border transfer safeguards, and the consent mechanism is vague.
The policy is heavily one-sided: it allows the company to change terms without explicit user consent, disclaims liability for third-party actions, and grants broad rights to use data for marketing without clear opt-out mechanisms.
The policy is lengthy and uses legalistic language; it is not written in plain language for a non-lawyer. Key risks (e.g., data sharing with affiliates, third-party cookies) are disclosed but buried in dense text.
- The policy is overly broad in its definition of personal data, including IP addresses, cookies, and ID Line, which may not clearly distinguish between sensitive and non-sensitive data.
- Section 3 allows the company to use and disclose personal data for marketing and advertising purposes without requiring prior consent before sharing with affiliates or business partners, relying on vague "benefit of you and the business" justifications.
- The policy lacks a clear opt-in mechanism for marketing communications and instead assumes consent through general use of services.
- Section 5 permits transfer of personal data to countries with potentially lower data protection standards, only promising "appropriate" measures without specifying what those are or guaranteeing equivalent protection.
- The policy states it may change over time and that continued use constitutes acceptance of those changes, which could undermine user rights and consent.
- The data retention period is described as "necessary to achieve the purpose" without providing specific timeframes, making it difficult for users to know how long their data is kept.
- Section 11 confuses the role of the Data Protection Officer with a title about "Changes to Privacy Policy," indicating potential drafting errors or lack of clarity.
- The policy disclaims responsibility for third-party data collection and external links, yet actively integrates those third-party services, potentially exposing users to risks outside their control.
- The section on financial data protection only promises non-disclosure except as stated in the policy, but the policy itself allows broad sharing with advertisers and business partners, reducing actual confidentiality.
- The system used for cookie settings and notifications is unclear, with insufficient guidance on how users can effectively manage or disable tracking technologies.
Company collects personal data lawfully with explicit consent from data subjects.
Data used for services, marketing, research, and legal obligations with consent.
Individuals can access, correct, delete, or object to data processing.
Company implements security to prevent unauthorized access or data breaches.
Data may be transferred abroad with safeguards or consent as required by law.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free