MITSUBISHI MOTORS (THAILAND) CO., LTD. AND MMTh ENGINE CO., LTD.

PRIVACY POLICY FOR EMPLOYEES AND OTHERS RELATED TO HUMAN RESOURCES MANAGEMENT

1. OUR PRIVACY STATEMENT

1.1 This privacy policy (“Privacy Policy”) describes how Mitsubishi Motors (Thailand) Co., Ltd. and MMTh Engine Co., Ltd. (hereinafter referred to as “MMTh/MEC”, “we”, “our” or “us”) collects, uses, stores, discloses and/or cross-border transfers Personal Data (as defined below) of the job applicants, employees, non-employee workers, contractors, former employees, retirees, expatriates, trainees, advisors and/or technical assistants (“you” or “your”), along with the information of any third party you have provided to us in order to protect the privacy of your Personal Data.

1.2 This Privacy Policy applies to any online or offline communication channels where we collect your Personal Data, whether face-to-face, our premises, job fairs/ events, phone, call center, online via emails or social media platforms (e.g., webpage, Facebook and Line), our website https://www.mitsubishi-motors.co.th/th and/or other websites (“Website”), other channels, and otherwise through the recruitment process during or after your employment/work contract with us, such as in relation to any employment agreement or work contract with you (correctively referred to as “Channel”).

1.3 For the purposes of this Privacy Policy, “Personal Data” means personal data or individually identifiable information as defined by the Applicable Laws, including sensitive data (as defined below).

1.4 MMTh/MEC is committed to ensure that your privacy is protected and to ensure that your Personal Data is processed in accordance with applicable laws and regulations (as amended or replaced from time to time) protecting the privacy of Personal Data in the jurisdictions in which we operate and target (“Applicable Laws”). MMTh/MEC will only collect, use, store, disclose and/or cross-border transfer your Personal Data in accordance to this Privacy Policy.

1.5 Please read the following carefully to understand MMTh/MEC’s views and practices regarding your Personal Data and how we will proceed it. Certain information about you is necessary or legally required in relation to our potential or existing employment agreement/work contract with you, including the continuation of such agreement/contract. If you do not agree to provide such information, we will not be able to perform our part of employment/ work contract's obligation to you.

1.6 Our work process are generally not aimed at minors, quasi-incompetents, or incompetent persons. Therefore, if you are under the age of 20 or the relevant age of majority in your territory of residence, quasi-incompetents, incompetent persons, as the case may be, unless otherwise permitted by law, and wishes engage in the employment/work contract relationship with us, you must obtain the consent of your parent or guardian prior to contact us or provide us with your Personal Data. We do not knowingly collect Personal Data of minors under the age of 20 without their parental consent when it is required, or from quasi-incompetent persons or incompetent persons without their legal guardian's consent.

1.7 This Privacy Policy was last updated on December 1st, 2020. MMTh/MEC reserves the right, in its sole discretion, to modify, revise, delete and update this Privacy Policy from time to time. MMTh/MEC will use reasonable endeavors to notify you and in appropriate manner of any significant modifications to the terms of this Privacy Policy (e.g. by emailing to you the revised policy with a new effective date or by publishing the information about such modification on our Channel).

2. PERSONAL DATA THAT WE COLLECT ABOUT YOU

We may collect or obtain the following types of information which may include your Personal Data directly or indirectly from you or other sources or through our parent company, parent company’s affiliates, parent company’s subsidiaries, affiliates and subsidiaries (“Group”), our authorized dealers, our service providers and/or business partners who are third parties, recruitment agencies, governmental agencies, other persons such as your former employers or referrals, or any other publically available source.

The context of your interaction, your field/position of work, and/or benefit received from us will determine the kind of Personal Data we collect about you and/or other individuals throughout the course of your employment agreement or work contract relationship with us.

2.1 Your personal information: This includes information about you that you give us by communicating with us through our Channel or by filling in forms. Such information may include, but is not limited to:

(a) Identification Information, such as your title, first name, family name, nickname, gender, age, date of birth, nationality, marital status, numbers of children, details and/or copies of your national identification card, driving license, passport, visa, work permit, house registration, vehicle registration, tax identification number, social security number, and/or other similarly identifiable documents, blood type, photographs, stills and moving footage, images, voice records from CCTV footage or telephone call records with MMTh/MEC or other Channel, signature, education and qualification details (e.g. resume or curriculum vitae (CV)), letter of recommendation or reference letter, professional licenses, language proficiency and other skills, past employment experiences (e.g., job title, employment status, employment background, employer name, employer address, nature of business designation, and length of current service), and any information that you choose to share with us which may be considered Personal Data;

(b) Contact Information, such as your phone number, mobile number, fax number, address (both current and permanent address), postcode, social media contact (e.g., Facebook and Line ID, Instagram) and email address;

(c) Work Related Information, such as your date of commencement, probation end date, job position, rank, business contact details, employee identification number, job description, behavior, performance at work, grade results, service history, a copy of your employment agreement, employee salary file and salary deduction report, attendance data, absences, resignation date, training record, training certificate, other certificates, and information obtained during your exit interview including reasons for leaving;

(d) Financial Information, such as your bank account details, tax details, saving/loan/investment amount and information, loan account number, and insurance premium;

(e) Remunerations and Benefits related Information, such as your salary, pay and benefits information, pay slip, salary package, tax deduction information, reimbursement related information (e.g., hospital used, or type of sickness for medical reimbursement), start and end date of provident fund contribution, provident fund rate and option, new year lucky draw present value, and insurance policy information;

(f) Technical Information, that MMTh/MEC collects through your use of our email system such as, your email communication content, and date and time of your email correspondence;

(g) Geolocation information, such as geolocation of vehicles and/or devices and/or electronic devices (including longitude/latitude data, city and street location);

(h) Driving Behaviour, such as speed using in driving and/or break using behavior;

(i) Other Information, such as your comments, questions, inquiries and enquiries, complaints, survey responds, preferences, interests or hobbies; and

(j) Sensitive Data, such as your

  • Religion as contained within national identification card;
  • Ethnicity;
  • Health information (e.g. pregnancy status, hospital service used, type of sickness, medical certificate and receipt, alcohol test result, and urine drug test result);
  • Disability information;
  • Biometric information (e.g. fingerprints);
  • Criminal records;
  • Labour union information; and
  • Genetic information.

2.2 Personal information of other persons, such as your spouses, child, adopted child, dependencies, parents, siblings, relatives, beneficiaries, emergency contacts, referrals, or any individuals which includes name, date of birth, contact details, relationship with you, education information, bank account information, government identification documents (e.g., national identification card), and/or other information relating to such individual which you have provided to us in any forms.

By providing other person’s Personal Data to us, you represent and warrant that you have the authority to do so and to permit us to use such Personal Data in accordance to this Privacy Policy. You are also responsible to provide this Privacy Policy for their acknowledgement and/or obtain consent where applicable or necessary.

Even if certain information under 2. are not Personal Data, however, when combining with other information or the related Personal Data, it could be used to identify you and deemed Personal Data as well. Therefore, we will treat this information with the same standard as the Personal Data. However, when we process anonymized data or in aggregated form which can no longer identify you, this Privacy Policy would not be applicable.

3. WHY WE COLLECT, USE, STORE, DISCLOSE AND/OR CROSS-BORDER TRANSFER YOUR PERSONAL DATA AND ON WHAT LEGAL GROUNDS

MMTh/MEC, Group and third party who may be acting on our behalf may collect, use, store, disclose, and/or cross-border transfer your Personal Data described above based on (1) your consent; (2) contractual basis, for our initiation or fulfilment of agreement/contract with you; (3) legitimate interest, for the purpose of our legitimate interests and the legitimate interests of third parties, to be balanced with your own interest and fundamental rights and freedoms in relation to the protection of your Personal Data; (4) our legal obligations to which we are subject; (5) vital interest, preventing or suppressing a danger to a person’s life, body or health; and (6) the reason for an establishment and defences of legal claims in the future, for the following purposes:

3.1 The purpose of which your consent would be required:

(a) Activities related to Sensitive Data

To collect, use, store, disclose, and/or cross-border transfer your Sensitive Data for the purpose where consent is required by law, which is the following:

  • Religion (contained in the national identification card): such as to authenticate and verify identity of a person; to provide employee/worker welfare, including diet and activities facilitation; and to approve religious leave request;
  • Ethnicity to be collected as evidence for recruitment process;
  • Health information for occupational health and decision making in regards to the fitness for work; to provide group insurance and medical reimbursement, and to conduct alcohol test result and/or urine drug test result;
  • Disability status to accompanied hiring decision making;
  • Biometric Information to grant building and area access and to access electronic devices;
  • Criminal Records to perform background check;
  • Labour union information to conduct any activities and transactions related to labour union; and
  • Genetic information to for occupational health and decision making in regards to the fitness for work; to provide group insurance, and medical reimbursement.

(b) Cross-border transfer of your Personal Data

To cross-border transfer your Personal Data to the country which may not have an adequate level of data protection and where the consent is required by law.

(c) Marketing and Communications

To provide marketing, re-marketing, communications, sales, special offers, promotions, notices, news, and information about other products and services, from MMTh and/or Group where we cannot rely on other legal grounds.

Where legal basis is consent, you have the right to withdraw consent pursuant to the conditions provided under this Privacy Policy and applicable laws. The withdrawal of consent will not affect the lawfulness of the collection, use and/or disclosure of your Personal Data based on your consent before it was withdrawn.

3.2 The purpose that we may rely on other grounds for processing your Personal Data:

(a) If you are a job applicant, we rely on the legal grounds above for the following purposes of collection, use, store, disclose, and/or cross-border transfer of your Personal Data, including but not limited to:

  • to process your application for internship, part-time job, or employment;
  • to accept and determine your application;
  • to identify and verify your identity;
  • to conduct related exam or interview;
  • to evaluate your test results and your performance;
  • to make any decision in relation to your application;
  • to perform background check;
  • to contact your former or current employers or referrals for reference;
  • to contact with you in relation to the job/work applied for;
  • to communicate with your designated contacts in case of emergency;
  • to determine your appropriate salary and other compensation; and
  • to submit report to other third parties upon your request (e.g. internship report to your academic institution).

(b) If you are a/an employees, non-employee workers, contractors, former employees, retirees, expatriates, trainees, advisors and/or technician assistants, we rely on the legal grounds above for the following purposes of collection, use, and/or disclosure of your Personal Data, including but not limited to:

  • Employment/Work related: such as to perform our obligation or exercise our rights in connection with your employment agreement/work contract with us; to perform background check, including by way of contacting your former employers or referrals; to proceed with on boarding process; to provide tools and equipment necessary to carry out your duties; to grant building access; to issue employee identification card; to provide necessary training; to keep training record, training certificates or other certificates; to conduct performance evaluation; to perform alcohol test; to perform urine drug test; and to assist in the request for parking card granted;
  • Communication with you: such as to enable adequate communication with you for the performance of work; and to contact your dependencies, family or emergency contact in connection with an emergency;
  • Compensation and benefits: such as to proceed with payroll process; to provide bonus payment; to provide entitled benefits; to create payment code; to reimburse (e.g. medical, gasoline, toll fee and other fees entitled to reimbursement); to provide retirement reward; to pay severance pay and compensation pay; to provide insurance; to provide provident fund; to provide business trip and facilitate in its management; and to benchmark employee salaries and benefits with similar organizations;
  • Business Operation: such as to record and maintain our employee/worker data; to process your Personal Data related to your use of our email system in order to enable the effective operation of the email system; to comply with the functions in relation to the regional or global HR decisions; to ensure that the use of our system is in accordance with our policies and procedures; to perform our contractual obligation with any third-parties; to allow us to effectively and efficiently administer and manage the operation of our business; to ensure a consistent approach to the management of our employees and the employees of our Group worldwide; to maintain internal policies and procedure compliance; to conduct survey; to issue an invitation letter to expat employee; to assist expat employee during the immigration process; to assist employee in going to work abroad; and to proceed with disciplinary and compliant procedure;
  • Marketing communication: to provide marketing, re-marketing, communications, sales, special offers, promotions, program, notices, news, updates, and information about other products and services, from MMTh and/or our Group; to generate personalized marketing strategy and advertisement and to circulate events promotions and news;
  • Compliance of legal obligation: such as to process your Personal Data in accordance to the legal obligation, right or duty under the applicable law, including laws outside your country of residence; to assess compliance with applicable laws, rules, regulations, and internal policies and procedures; and to comply with investigational purposes, as requested by governmental officials;
  • Protection of our rights and our interest: to protect our rights, property, safety or operations or those of any of our Group, you or others; to allow us to pursue available remedies or limit the damages that we may sustain; to enforce or apply our agreement or to investigate potential breaches of such agreements; to establish, exercise, or defend our legal rights or for the purposes of legal proceeding; and in the event of sale, transfer, merger, reorganization, or similar event we may transfer your information to third parties as part of that transaction;
  • Fraud detection: such as to authenticate and verify your identity; and to prevent and detect crime or fraud; and
  • Life: to prevent or suppress a danger to a person's life, body, or health.

4. DISCLOSURE OF YOUR PERSONAL DATA TO THIRD PARTIES

4.1 We may share your Personal Data within the MMTh/MEC network for the purposes described above. We will take steps to ensure that access to Personal Data is restricted on a need-to-know basis.

4.2 We may also share your Personal Data outside of MMTh/MEC network with the following parties, for the purposes set out in this Privacy Policy:

(a) Group: Parent companies, subsidiary companies, affiliates. As MMTh/MEC is a part of a Group which collaborate and partially share human resources service and systems including website-related services and systems, we may need to transfer your Personal Data to, or otherwise allow access to such Personal Data by other companies within our Group for the purposes set out in this Privacy Policy. This will allow other companies within our Group to rely on consent obtained by MMTh/MEC;

(b) Business partners. To conduct business and services related to our business’ (e.g. recruitment agency, insurance company, financial institution, leasing company, financial service provider, cooperative, asset management company, and funeral association).

(c) Authorized dealers and sale representative agencies. From time to time, MMTh/MEC will share your Personal Data to our authorized dealers in relation to our employment/ work relationship with you;

(d) Service providers/ Suppliers/ Sub-contractors. We may use other companies, agents or contractors to perform services on our behalf or to assist with the employment/ work relationship with you. We may share your Personal Data to our service providers or third-party suppliers including, but not limited to (1) IT system service providers and IT support company; (2) analytics and research service providers.; (3) payroll service providers; (4) data storage or cloud service providers; (5) outsourced training institute; (6) medical/hospitality service provider; (7) companies who provide statistical analysis services; (8) survey agencies; (9) event organizers; and (10) similar third-party vendors and other outsourced service providers that assist us in carrying out business activities.

(e) External advisors. This includes lawyers, technicians, tax consultants and auditors who assist in running our business, or defending or bringing any legal claims;

(f) Third parties required by law. In certain circumstances, we may be required to disclose or share your Personal Data in order to comply with a legal or regulatory obligations. This includes any law enforcement agency (e.g., Royal Thai Police, Social Security Office, Revenue Department, Department of Employment, Immigration Bureau, Department of Skills and Development, Ministry of Labour, the Board of Investment of Thailand, District Office, Embassy, and/or any other relevant government or public authorities), court, regulator, government authority or other third party where we believe it is necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights, the rights of any third party or individuals’ personal safety, or to detect, prevent, or otherwise address fraud, security or safety issues;

(g) Hospitals and emergency rescue. Your Personal Data may be disclosed in case of emergency for the protection of your own interest;

(h) Assignee of rights and/or obligations. Third parties as our assignee, in the event of any reorganization, merger, business transfer, whether in whole or in part, sale, purchase, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets, or stock or similar transactions; will comply with this Privacy Policy to respect your Personal Data;

(i) Other publicly available sources, such as website, advertisement and/or social media platforms; and

4.3 To the fullest extent permitted by law, MMTh/MEC excludes all liability arising from the use of your information by third parties. So, please view the privacy notices of these third parties to understand how they will use your Personal Data.

4.4 Except as set out in this Privacy Policy, we will not disclose, sell, distribute, rent or lease your Personal Data to third parties unless we have your permission or to complete a transaction for you.

5. INTERNATIONAL TRANSFER OF PERSONAL DATA

5.1 MMTh/MEC operates a global business and may transfer the Personal Data collected from you to our oversea related entities, Group, and franchisees in order to comply or perform purposes set out above. It may also be necessary for us to disclose your Personal Data to a third parties located overseas in connection with the purposes set out in this Privacy Policy. The countries to where we may transfer your Personal Data include but not limited to US, Japan and Singapore. Such disclosure or transfer may only be done by obtaining your consent, unless there are any other compelling legitimate grounds (e.g. to perform the contract terms between us and other persons for your benefit) or other cross-border mechanism as permitted by applicable laws for us to conduct without obtaining your consent.

5.2 Please be aware that those overseas countries, that form the standpoint of the data protection supervisory authority in Thailand, may not have an ‘adequate standard of protection’ as specified by the data protection supervisory authority in Thailand, although our collection, storage, disclosure and use of your Personal Data will continue to be governed by this Privacy Policy. If your Personal Data is transferred to destination countries where the standard of protection available is not sufficient under the Applicable Laws, we will take steps necessary to protect the Personal Data transferred to other persons internationally to reach the same level of protection as we provide with respect to your Personal Data, and in compliance with the Applicable Laws which is in effect at that time.

6. HOW LONG DO WE KEEP YOUR PERSONAL DATA

MMTh/MEC will only retain your Personal Data for as long as reasonably necessary to fulfil our duties to achieve the purposes prescribed in this Privacy Policy. If a judicial or disciplinary action is initiated, your Personal Data may be stored until the end of such action, including any potential period for appeal, and will then be deleted or archived as permitted by Applicable Laws.

7. SECURITY

MMTh/MEC has in place security measures to store all Personal Data collected and received securely. We use appropriate technical, organizational, administrative and physical security measures to protect your Personal Data contained in our systems against the unauthorized or unlawful loss, access to, use, alteration, correction, accidental damage, and deletion of Personal Data. We will also review such measures when it is necessary, or when the technology has changed in order to efficiently maintain the appropriate security and safety. Once MMTh/MEC has received your Personal Data, we will use strict procedure and security features to try to prevent unauthorized access.

8. YOUR RIGHTS AS A DATA SUBJECT

Under some circumstances, we may require you to prove your identity before complying with data subject exercise of rights, for your own privacy and security.

Subject to Applicable Laws and exceptions thereof, you may have the following rights to:

(a) Access: You may have the right to access or request a copy of the Personal Data we are collecting, using and disclosing about you. For your own privacy and security, we may require you to prove your identity before providing the requested information to you.

(b) Rectification: You may have the right to request for rectification of the incomplete, inaccurate, misleading, or not up-to-date Personal Data that we collect, use, store, disclose and/or cross-border transfer.

(c) Data Portability: You may have the right to obtain Personal Data we hold about you, in a structured, electronic format, and to send or transfer such data to another data controller, where this is (a) Personal Data which you have provided to us, and (b) if we are processing such data on the basis of your consent or to perform a contract with you.

(d) Objection: You may have the right to object to certain collection, use and disclosure of your Personal Data.

(e) Restriction: You may have the right to restrict the use of your Personal Data in certain circumstances.

(f) Withdraw Consent: For the purposes that you have consented to our collecting, using and disclosing of your Personal Data, you have the right to withdraw your consent.

(g) Deletion: You may have the right to request that we delete or de-identity Personal Data that we collect, use and disclose about you, except we are not obligated to do so if we need to retain such data in order to comply with a legal obligation or to establish, exercise, or defend legal claims.

(h) Lodge a complaint: You may have the right to lodge a complaint to the competent authority where you believe our collection, use and disclosure of your Personal Data is unlawful or noncompliant with Applicable Laws.

9. CHANNELS AND PERIOD FOR EXERCISING RIGHTS OF DATA SUBJECT

Rights

Channels for data subject to exercise its rights

Period for fulfilling data subject's right request

Access

Office of Human Resources Strategy

30 days

Rectification

Office of Human Resources Strategy

7 days

Data Portability

Office of Human Resources Strategy

30 days

Objection

Office of Human Resources Strategy

30 days

Restriction

Office of Human Resources Strategy

30 days

Withdraw Consent

Office of Human Resources Strategy

7 days

Deletion

Office of Human Resources Strategy

30 days

10. OUR CONTACT DETAILS

If you wish to exercise your rights above, or if you have any queries, comments and/or questions about your Personal Data under this Privacy Policy, please contact us at:

10.1 Office of Human Resources Strategy for MMTh/MEC

  • Address

Ø Head Office: FYI Center Tower 1, 9th Floor, 2525 Rama IV Road, Klong Toei, Klong Toei, Bangkok 10110 Thailand

Ø Laem Chabang: Laem Chabang Industrial Estate 199 Moo 3, Thung Sukhla, Si Racha, Chon Buri 20230 Thailand

  • Contact details

Ø Phone number: Head Office Tel. 0-2079-9064, 0-2079-9108

Laem Chabang Tel. 0-3849-8260

Ø E-mail address: Head Office yada.promploy@th.mitsubishi-motors.com

wilailuk.bongkochpreechapanich@th.mitsubishi-motors.com

Laem Chabang uraiwan.jamduang@th.mitsubishi-motors.com

10.2 Data Protection Officer (DPO)

  • Contact details

Ø Address: FYI Center Tower 1, 9th Floor, 2525 Rama IV Road, Klong Toei, Klong Toei, Bangkok 10110 Thailand

Ø E-mail address: dpo.mmth@th.mitsubishi-motors.com