Privacy Policy & Data Protection (PDPA)
Compliance with Personal Data Protection Act B.E. 2562 | Security | Confidentiality
How does NYC protect my personal data under the PDPA?
Our Standard:
NYC Translation & Notary Services Co., Ltd. is fully compliant with the Personal Data Protection Act B.E. 2562 (2019). We act as a Data Controller for the information you provide (Passports, ID Cards, Contracts). We employ strict security measures: (1) Encryption of digital files in transit and storage, (2) Physical Security for original documents in locked archives, (3) Limited Access restricted to authorized attorneys and staff only. We only collect data necessary for legal processing and share it only with mandated government bodies (MFA, Embassies) with your consent.
- Purpose: Legal services & government submission only.
- Retention: 10 years for legal records (Anti-Money Laundering requirement).
- Rights: You can request access or correction of your data.
- Security: Enterprise-grade firewalls and physical safes.
Unshakeable Authority: Confidentiality Guaranteed
Attorney-Client Privilege
Beyond the PDPA, our clients benefit from Attorney-Client Privilege. As a registered law firm (Reg No: 0435567000061) staffed by licensed attorneys, the information you share with us for legal advice is protected by professional secrecy laws. This level of protection is NOT available when using freelance agents or general translation shops. Whether it's a sensitive criminal background check or a corporate merger document, your secrets are safe with NYC.
Meet Our Data Protection Team
Our lawyers oversee compliance to ensure your information is handled ethically.
Data Protection Officer (DPO)
Our Senior Counsel serves as the DPO. He ensures all operational processes align with PDPA regulations and handles any data subject requests.
Family Privacy Guardian
Specializes in protecting sensitive family data (Divorce decrees, Child custody) from unauthorized disclosure during the legalization process.
Visa Data Security
Manages the secure transmission of passport copies and financial statements to Embassies, ensuring no leaks occur during third-party handling.
Asset Protection
Ensures that Title Deeds and financial transaction records relating to property purchases are kept strictly confidential to prevent fraud.
Legal Records Keeper
Oversees the physical archive. He manages the secure logging and eventual destruction of expired legal documents according to statutory timelines.
Corporate Secrets
Protects trade secrets and intellectual property contained in commercial contracts submitted for notarization and translation.
Legal Knowledge Hub: Understanding PDPA
What the law says and how we apply it to protect you.
1. What is Personal Data?
Under the PDPA, "Personal Data" is any information that can identify a living person, directly or indirectly. This includes your name, address, phone number, email, passport number, and biometric data. "Sensitive Personal Data" (Section 26) includes criminal records, health data, and religion. We treat ALL client data with the highest level of care, but apply extra encryption to Sensitive Data.
2. Lawful Basis for Collection
We collect your data based on "Contractual Basis" (to fulfill the service you hired us for) and "Legal Obligation" (we are required by law to keep records of notarial acts). We do not need your consent to collect data necessary for the contract, but we will always inform you of the purpose. We will never use your data for marketing without your explicit consent.
3. Data Retention Policy
We do not keep data forever.
- General Inquiries: Deleted after 90 days if no service is booked.
- Translation Files: Kept for 3 years to allow for re-prints/amendments, then deleted.
- Notarial Register: Kept for 10 years as required by the Lawyers Council regulations for audit and verification purposes.
4. Sharing Data with Third Parties
We only share your data when necessary to complete your job. This typically means sharing with:
- The Ministry of Foreign Affairs (for legalization).
- Embassies/Consulates (for visa/authentication).
- Courier Services (Thai Post/Kerry) for delivery.
We have Data Processing Agreements with our partners to ensure they also comply with PDPA standards.
5. Your Rights as a Data Subject
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to fix inaccurate data.
- Deletion: Request data erasure (if no legal retention obligation exists).
- Complaint: File a complaint with the PDPC if you believe your rights were violated.
6. Cybersecurity Measures
We utilize enterprise-grade security. Our internal case management system is cloud-based with 256-bit encryption. Access is protected by Multi-Factor Authentication (MFA). Physical documents pending processing are stored in fire-proof, locked cabinets in a CCTV-monitored office. We conduct regular IT security audits.
7. Handling Data Breaches
In the unlikely event of a data breach (e.g., a hack or accidental leak), we have a response protocol. We will notify the Office of the Personal Data Protection Committee (PDPC) within 72 hours and inform affected clients immediately, providing guidance on how to mitigate risks.
8. Cookies and Website Data
Our website uses necessary cookies for functionality. We use analytical cookies (like Google Analytics) to improve user experience, but this data is anonymized. We do not use tracking pixels to sell your browsing history to advertisers.
9. International Data Transfer
If we need to send your data abroad (e.g., emailing a scanned document to a foreign lawyer at your request), we ensure the destination country has adequate data protection standards or obtain your specific consent for the transfer as per Section 28 of the PDPA.
10. Staff Training
Human error is the biggest risk. All NYC employees undergo mandatory PDPA training upon hiring and annually thereafter. They sign strict Non-Disclosure Agreements (NDAs). A breach of client confidentiality is grounds for immediate dismissal.
WARNING: The Danger of "Freelance" Agents
Your identity is valuable. Don't hand it to just anyone.
- Identity Theft: Unregistered agents often sell passport copies or use them for illegal activities (like opening mule bank accounts). They have no office and no accountability.
- Public Clouds: Many agents use free, unsecured email (Gmail/Hotmail) or public cloud storage to share your sensitive documents. This makes your data vulnerable to hacks. NYC uses secure, business-domain email servers.
- Lack of NDA: Freelancers rarely sign NDAs. If they leak your business secrets or private family details, you have little legal recourse. NYC is bound by professional legal ethics.
Protect your privacy. Choose a regulated law firm.
Success Stories: Privacy in Practice
How we handle sensitive situations.
Case 1: High-Profile Divorce
Client: Celebrity couple.
Challenge: Needed certified translation of divorce papers without leaks to the press.
Solution: We assigned a single Senior Attorney to handle the file end-to-end. Physical documents were kept in a separate safe. Digital files were password-protected.
Outcome: Documents processed with zero leaks.
Case 2: Corporate Merger
Client: Multinational Tech Firm.
Challenge: Translating confidential financial audits before a public announcement.
Solution: All translators signed specific project NDAs. We used a secure file transfer protocol (SFTP) instead of email. Data was deleted immediately after delivery.
Outcome: Merger successful, trade secrets protected.
Case 3: Victim of Stalking
Client: Expat escaping an abusive partner.
Challenge: Needed visa help but terrified of address being revealed.
Solution: We restricted access to her contact details in our CRM. We used our office address for correspondence where legally permitted to shield her location.
Outcome: Client visa secured safely.
Case 4: Medical Records
Client: Applicant for insurance claim.
Challenge: Highly sensitive medical history translation.
Solution: Handled by our specialist medical translator under strict HIPAA-compliant protocols (adopted voluntarily).
Outcome: Claim processed privately.
Case 5: Recovering Lost Data
Client: Returning client lost their legalized degree scan.
Challenge: Needed a copy urgently 2 years later.
Solution: After rigorous ID verification to prove it was the original client, we retrieved the scan from our secure archives.
Outcome: Client saved time and money.
Frequently Asked Questions (FAQ)
Do you sell my email address?
Never. We despise spam as much as you do. Your contact details are used strictly for communicating about your job and sending legal updates if you opted in.
Is your Line account secure?
Yes. We use a Line Official Account (@NYCLI) which has enterprise security features. Chat logs are accessible only to authorized customer service managers.
Can I delete my data after the job?
You can request deletion of marketing data or non-essential files. However, we must keep the "Notarial Register" record for 10 years by law. This protects you if verification is needed later.
How do you destroy physical documents?
We use cross-cut shredders for all draft papers. Official documents that are not collected by clients after 1 year are shredded and disposed of securely via a certified waste management partner.
Who is your DPO?
Our Data Protection Officer can be reached directly at [email protected] for any privacy concerns or subject access requests.
Service Area Coverage: All of Thailand
Secure document handling available nationwide. Send your documents to our HQ with confidence.