FFFaith Forge LabsThailand delivery deskPlan a project

Privacy and data

Follow the Thailand data from collection to deletion.

Thailand's PDPA requires current review of roles, lawful basis, consent, notices, sensitive data, processors, transfers, rights, retention, security, DPO, and incidents.

01

Collect

State the purpose, minimum fields, audience, notice, choice, and sensitive-data boundaries.

02

Use

Name ownership, access roles, processors, AI use, automated decisions, and data-quality checks.

03

Move

List hosting locations, vendors, transfers, subprocessors, backups, and remote access.

04

Keep

Set retention, deletion, account closure, legal holds, audit evidence, and recovery.

05

Respond

Assign rights requests, security events, breach decisions, escalation, and communications.

Analytics follows the same consent analysis.

The Thailand microsite has its own GA4 property. That separation improves reporting; it does not remove any notice or consent duty that applies to the visitor. Advertising or profiling tags require a separate decision.

Next step

Turn the Thailand context into a workable brief.

The clearest scope starts with the actual Thailand operation: people, access, content, transactions, deadlines, support, and acceptance.

Use the project briefEmail Faith Forge Labs