How Financial Organizations Can Attain PSD2 Compliance Standards Without Disruption

The EU’s updated Payment Services Directive has significantly changed how financial institutions function throughout the continent. Achieving PSD2 compliance demands strategic preparation, robust technical infrastructure, and a clear understanding of regulatory requirements. This guide explores practical strategies that enable banks and payment service providers to fulfill these requirements whilst preserving smooth functionality and protecting customer relationships throughout the implementation period.

Grasping PSD2 Compliance obligations in the UK financial organizations

The Revised Payment Services Directive sets out stringent requirements for financial institutions active in the United Kingdom and European Economic Area. These regulations mandate robust customer verification protocols, open banking application programming interfaces, and strengthened security protocols designed to protect consumers whilst fostering innovation in the financial services sector.

UK financial institutions and payment services must establish secure connection methods that allow external service providers to retrieve account information and initiate payments with direct customer authorization. This fundamental shift expects financial providers to align compliance requirements with business performance, ensuring technical systems comply with set standards without compromising service quality or customer satisfaction during deployment stages.

Financial organisations face particular difficulties including legacy system integration, regulatory mandates under GDPR, and preserving market position whilst opening infrastructure to qualified service providers. Recognising these complex requirements enables organisations to develop comprehensive strategies that tackle technical, operational, and commercial considerations vital for effective compliance achievement and sustainable business growth.

Establishing a Strong PSD2 Regulatory Framework

Financial institutions must establish a robust system that covers all legal standards whilst limiting operational disruption. This involves conducting thorough evaluations to identify areas requiring upgrades, developing detailed implementation roadmaps, and establishing cross-functional teams to supervise the transition process effectively.

A effective framework merges technical solutions with organisational change management, ensuring staff obtain sufficient instruction and customers understand new authentication procedures. Regular testing and system verification helps detect potential risks before they influence operational performance.

Enhanced Customer Verification (SCA) Deployment

Strong Customer Authentication serves as a foundation of the directive, requiring dual authentication factors from distinct groups: knowledge, possession, and inherence. Banks must implement solutions that confirm customer identity through methods such as biometrics, one-time passwords, or mobile app authentication whilst maintaining user-friendly experiences.

Well-designed SCA implementation harmonizes security with convenience by leveraging exemptions appropriately for lower-risk payments, established recipients, and regular transactions. Financial institutions must undertake comprehensive user testing to confirm authentication flows work seamlessly across various devices and channels.

API Development and Third-Party Access Management

Building secure and standardised APIs allows third-party organizations to access customer account information and initiate payments with appropriate authorization. These interfaces should comply with specification standards whilst integrating strong security protocols including mutual authentication, encryption, and detailed logging of all connection attempts.

Managing third-party access requires creating comprehensive onboarding procedures, monitoring API usage patterns, and keeping accurate registers of authorised providers. Financial institutions should implement rate limiting, anti-fraud systems, and crisis management procedures to defend against unauthorised access attempts or operational interruptions.

Data Security and Data Privacy Safeguards

Safeguarding customer data requires implementing comprehensive security controls including encryption at rest and in transit, secure key management, and regular vulnerability assessments. Banking organizations must ensure all platforms processing payment data adhere to industry standards whilst keeping comprehensive audit logs for regulatory oversight.

Privacy safeguarding extends beyond technical measures to encompass clear customer communications about information sharing, permission management frameworks, and procedures for handling data subject requests. Routine security reviews and penetration testing help identify vulnerabilities before they can be used by bad actors.

Putting into practice PSD2 Compliance As you Maintain Business Continuity

Financial institutions must adopt a phased implementation approach that emphasises key regulatory requirements whilst limiting service disruption. Begin by performing a thorough gap analysis to identify areas where current systems fall short of directive standards, then create a comprehensive roadmap with specific targets and accountability structures. This structured framework allows organisations to allocate resources effectively, address high-priority compliance areas first, and sustain key banking services throughout the transition period without compromising customer experience or security protocols.

Setting up a specialized multi-department compliance team proves essential for coordinating technical, legal, and operational aspects of the rollout effort. This team should comprise members from IT, risk management, legal departments, and customer service to make certain diverse viewpoints are included when establishing important guidelines. Consistent dialogue between stakeholders avoids compartmentalized thinking that could result in gaps, whilst guaranteeing that compliance initiatives match organizational goals and deployed technical solutions already implemented throughout the organisation.

Operating concurrent systems throughout the transition phase provides an effective approach for maintaining business continuity whilst evaluating updated compliance requirements. This approach allows institutions to validate API performance, robust authentication systems, and information exchange procedures in controlled environments before complete implementation. Comprehensive testing identifies potential issues early, minimizes the likelihood of service disruptions, and provides opportunities to refine processes based on practical situations without exposing customers to unnecessary complications or security vulnerabilities during the essential transition period.

Regular assessment and iterative improvements ensure that compliance measures remain effective as compliance standards evolve and technology advances. Establish robust reporting systems that track critical metrics, identify emerging compliance risks, and assess the effect of new processes on business performance. This forward-thinking strategy allows institutions to adapt quickly to regulatory updates, address technical challenges promptly, and show ongoing commitment to fulfilling regulatory obligations whilst maintaining the standard of support that customers expect from their financial providers.

Technology Solutions for Seamless PSD2 Adoption

Modern financial institutions demand sophisticated technology platforms that can handle the intricate demands of compliance standards whilst preserving system performance. Cloud computing platforms, automated testing environments, and continuous monitoring tools form the foundation of effective compliance deployment, enabling organisations to respond swiftly to changing regulations without interrupting current operations or undermining security measures.

Cloud-Based Compliance Solutions Systems

Cloud infrastructure delivers financial institutions the scalability and flexibility needed to deploy regulatory requirements efficiently. These platforms provide API frameworks that are pre-built, security protocols, and authentication mechanisms that comply with Strong Customer Authentication mandates, cutting development time and ensuring uniform implementation across all channels and touchpoints.

Leading cloud-based solutions connect smoothly with existing banking systems through microservices architecture, allowing institutions to roll out capabilities incrementally. This approach minimises disruption to core banking operations whilst providing real-time updates to maintain alignment with regulatory changes and technical standards released by the European Banking Authority.

Automated Inspection and Surveillance Tools

Extensive test systems enable financial institutions to verify API capabilities, security measures, and performance metrics prior to launch. Automated testing tools simulate third-party provider access scenarios, confirm authentication processes, and guarantee data protection measures meet regulatory standards, substantially lowering the likelihood of compliance breaches or security weaknesses.

Ongoing oversight solutions deliver real-time visibility into API performance, transaction patterns, and security events. These tools create comprehensive audit logs, measure service availability, and notify IT teams to emerging problems before they influence customer experience or regulatory reporting obligations, ensuring sustained compliance throughout operational lifecycles.

Ensuring Continuous PSD2 Compliance and Future-Proofing Your Institution

Adherence to regulations is not a one-off milestone but an evolving commitment that demands regular oversight and adaptation. Financial institutions must set up dedicated regulatory teams tasked with tracking regulatory updates from the European Banking Authority and domestic regulatory bodies. Regular internal audits, regular risk evaluations, and extensive record-keeping practices ensure your organisation remains aligned with current requirements whilst anticipating future amendments to the directive.

Technology infrastructure requires continuous investment to support evolving security standards and authentication methods. Implementing modular API architectures allows for seamless updates without disrupting core banking systems, whilst compliance monitoring systems can flag emerging problems before they escalate into regulatory breaches. Establishing collaborations with regtech firms gives institutions access to expert knowledge and cutting-edge solutions that adapt to changing requirements.

Building a framework for compliance consciousness throughout your company establishes sustainable compliance frameworks that withstand upcoming obstacles. Consistent training programs for staff, well-defined escalation pathways, and cross-departmental collaboration between compliance, technology, and operational groups ensure team members recognise their role in maintaining standards. Forward-thinking institutions also engage with industry working groups and regulatory sandboxes, positioning themselves to impact policy development whilst gaining early insights into upcoming changes that may affect their operations.

สำหรับบุคคลที่อาจเป็นลูกค้า ลูกค้าปัจจุบัน และบุคคลที่เกี่ยวข้อง

 

1.วัตถุประสงค์และขอบเขต บริษัท มีที่ มีเงิน จำกัด (“บริษัทฯ”) ยึดมั่นในการปฏิบัติหน้าที่ตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (“พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล”) โดยประกาศความเป็นส่วนตัวฉบับนี้ช่วยให้ท่านเข้าใจแนวปฏิบัติของบริษัทฯ ในการคุ้มครองข้อมูลส่วนบุคคลของท่าน (ตามที่นิยามไว้ด้านล่างนี้) รวมทั้งอธิบายเหตุผลและวิธีการของบริษัทฯ ในการเก็บรวบรวม ใช้ เปิดเผย โอนไปยังต่างประเทศ และ/หรือ ดำเนินการด้วยวิธีอื่นใด (รวมเรียกว่า “ประมวลผล”) ซึ่งข้อมูลส่วนบุคคลของท่าน และอธิบายสิทธิที่ท่านมีเกี่ยวกับข้อมูลส่วนบุคคลของท่าน รวมถึงสิทธิในการปกป้องข้อมูลส่วนบุคคลดังกล่าว ประกาศความเป็นส่วนตัวฉบับนี้ใช้บังคับกับการประมวลผลข้อมูลส่วนบุคคลของบุคคลที่อาจเป็นลูกค้า ลูกค้าปัจจุบัน และบุคคลที่เกี่ยวข้อง โดยบรรดาบุคคลที่เกี่ยวข้องทุกฝ่ายควรอ่านและทำความเข้าใจ รวมถึงทบทวนประกาศความเป็นส่วนตัวฉบับนี้อย่างสม่ำเสมอเพื่อที่จะได้มีความเข้าใจเกี่ยวกับการประมวลผลข้อมูลส่วนบุคคลของท่านอย่างถ่องแท้ ในประกาศความเป็นส่วนตัวฉบับนี้ “ข้อมูลส่วนบุคคล” หมายถึง ข้อมูลใด ๆ เกี่ยวกับบุคคลธรรมดาที่ยังมีชีวิตอยู่ ซึ่งสามารถทำให้ระบุตัวบุคคลนั้นได้ด้วยข้อมูลนั้นเอง หรือเมื่อนำข้อมูลนั้นไปรวมกับข้อมูลอื่นก็ตาม และ“ข้อมูลส่วนบุคคลที่อ่อนไหว” หมายถึง ข้อมูลส่วนบุคคลใด ๆ เกี่ยวกับเชื้อชาติ เผ่าพันธุ์ ความคิดเห็นทางการเมือง ลัทธิ ความเชื่อในลัทธิศาสนาหรือปรัชญา พฤติกรรมทางเพศ ประวัติอาชญากรรม ข้อมูลสุขภาพ ความพิการ ข้อมูลสหภาพแรงงาน ข้อมูลพันธุกรรม และข้อมูลชีวภาพของบุคคล ประกาศความเป็นส่วนตัวฉบับนี้ใช้บังคับกับบุคคลธรรมดาซึ่งเป็นลูกค้าของบริษัทฯ ทั้งบุคคลที่อาจเป็นลูกค้า ลูกค้าปัจจุบัน และบุคคลที่เกี่ยวข้อง (รวมถึง ผู้รับผลประโยชน์ ผู้ขับขี่ พยาน ผู้ค้ำประกัน คู่สมรสของลูกค้า/ผู้กู้ร่วม ผู้ชนะการประมูล ผู้รับมอบ บุคคลที่สามารถติดต่อสอบถามหรือทวงถามหนี้ได้ และบุคคลที่ติดต่อเข้ามา) ซึ่งในประกาศความเป็นส่วนตัวฉบับนี้จะเรียกโดยรวมว่า “ท่าน” หากท่านมีคำถามหรือข้อเสนอแนะประการใดเกี่ยวกับแนวปฏิบัติของบริษัทฯ ในการคุ้มครองข้อมูลส่วนบุคคลของท่าน หรือหากท่านต้องการใช้สิทธิของท่านตาม พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล ท่านสามารถติดต่อบริษัทฯ ผ่านช่องทางต่อไปนี้ บริษัท มีที่ มีเงิน จำกัด 63/2 อาคารบริษัท ทิพยประกันภัย จำกัด(มหาชน) ถนนพระราม 9 แขวงห้วยขวาง เขตห้วยขวาง กรุงเทพมหานคร เบอร์โทรศัพท์ 02-025-6999 เจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล Email : MKT@meetee.co.th หมายเลขโทรศัพท์ 02-025-6999

 

2.บุคคลที่มีสิทธิในการประมวลผลข้อมูลส่วนบุคคลของท่าน เนื่องจากบริษัทฯ มีบทบาทและหน้าที่ในการกำหนดวัตถุประสงค์และวิธีการในการประมวลผลข้อมูลส่วนบุคคลของท่านให้เป็นไปตาม พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล บริษัทฯ จึงทำหน้าที่เป็นผู้ควบคุมข้อมูลส่วนบุคคลของท่าน

 

3.ข้อมูลส่วนบุคคลที่บริษัทฯ เก็บรวบรวม ข้อมูลส่วนบุคคลทั่วไป กรณีของบุคคลที่อาจเป็นลูกค้า บริษัทฯ เก็บรวบรวมข้อมูลส่วนบุคคลของบุคคลที่อาจเป็นลูกค้า ซึ่งรวมถึงแต่ไม่จำกัดเพียงประเภทข้อมูลดังต่อไปนี้ ข้อมูลที่สามารถระบุตัวตนได้ เช่น ชื่อ นามสกุล ชื่อเล่น เลขบัตรประจำตัวประชาชน ข้อมูลประวัติ เช่น เพศ ข้อมูลการติดต่อ เช่น เบอร์โทรศัพท์ ที่อยู่ อีเมล Facebook LINE ID ข้อมูลระบุทรัพย์สินของบุคคล เช่น ประเภททรัพย์สินที่มี ทะเบียนรถยนต์ ยี่ห้อรถยนต์ เลขที่โฉนด ความเป็นเจ้าของ ข้อมูลเกี่ยวกับการจ้างงาน เช่น อาชีพ รายได้ และ ข้อมูลอื่น ๆ เช่น บัญชี Facebook วงเงินสินเชื่อที่สนใจ ผลิตภัณฑ์ที่สนใจ กรณีของลูกค้าปัจจุบันและบุคคลที่เกี่ยวข้อง (รวมถึง ผู้รับผลประโยชน์ ผู้ขับขี่ พยาน ผู้จัดการมรดก ผู้ค้ำประกัน ผู้กู้ร่วม คู่สมรสของลูกค้า/ผู้กู้ร่วม บุคคลที่สามารถติดต่อสอบถามหรือทวงถามหนี้ได้ และบุคคลที่ติดต่อเข้ามา) บริษัทฯ เก็บรวบรวมข้อมูลส่วนบุคคลของลูกค้าปัจจุบันและบุคคลที่เกี่ยวข้อง (รวมถึง ผู้รับผลประโยชน์ ผู้ขับขี่ พยาน ผู้จัดการมรดก ผู้ค้ำประกัน ผู้กู้ร่วม คู่สมรสของลูกค้า/ผู้กู้ร่วม บุคคลที่สามารถติดต่อสอบถามหรือทวงถามหนี้ได้ และบุคคลที่ติดต่อเข้ามา) ซึ่งรวมถึงแต่ไม่จำกัดเพียงประเภทข้อมูลดังต่อไปนี้ ข้อมูลที่สามารถระบุตัวตนได้ เช่น ชื่อ นามสกุล ชื่อเล่น ลายมือชื่อ สำเนาทะเบียนบ้าน สำเนาบัตรประจำตัวประชาชน เลขบัตรประจำตัวประชาชน สำเนาใบอนุญาตขับขี่ ลายมือชื่อ รหัสลูกค้า รูปภาพ ข้อมูลประวัติ เช่น เพศ สัญชาติ อายุ ความสัมพันธ์กับลูกค้า เพศ วันเกิด สถานภาพการสมรส จำนวนบุตร ส่วนสูง น้ำหนัก ข้อมูลการติดต่อ เช่น ที่อยู่ เบอร์โทรศัพท์ อีเมล บัญชี LINE บัญชี Facebook แผนที่บ้าน ข้อมูลการเงิน เช่น เลขที่บัญชีธนาคาร สำเนาบัญชีธนาคาร แหล่งที่มาของรายได้ จำนวนหนี้และอัตราดอกเบี้ย ยอดหนี้ค้างชำระ ยอดหนี้ครบกำหนดชำระ ข้อมูลระบุทรัพย์สินของบุคคล เช่น รายละเอียดหลักประกัน วงเงิน สำเนาโฉนดที่ดิน สำเนาทะเบียนรถยนต์ รูปและรายละเอียดของหลักทรัพย์ กรรมสิทธิ์ในที่อยู่ ข้อมูลเกี่ยวกับการจ้างงาน เช่น อาชีพ ตำแหน่ง รายได้ หนังสือรับรองเงินเดือน อายุงาน สถานที่ทำงาน ข้อมูลอื่น ๆ เช่น เลขที่สัญญา วันที่ทำสัญญา รายละเอียดการขอเอาประกันภัย บันทึกเสียง รายละเอียดการชำระค่างวด เรื่องที่ต้องการร้องเรียน ข้อมูลส่วนบุคคลที่อ่อนไหว นอกเหนือจากข้อมูลส่วนบุคคลที่ระบุไว้ข้างต้น บริษัทฯ อาจประมวลผลข้อมูลส่วนบุคคลที่อ่อนไหวของลูกค้าปัจจุบันและบุคคลที่เกี่ยวข้อง (รวมถึง ผู้รับผลประโยชน์ ผู้ขับขื่ พยาน ผู้จัดการมรดก ผู้ค้ำประกัน ผู้กู้ร่วม คู่สมรสของลูกค้า/ผู้กู้ร่วม บุคคลที่สามารถติดต่อสอบถามหรือทวงถามหนี้ได้ และบุคคลที่ติดต่อเข้ามา) ดังต่อไปนี้ ข้อมูลสุขภาพ ข้อมูลความพิการ ข้อมูลศาสนา ข้อมูลเชื้อชาติ

 

4.บริษัทฯ เก็บรวบรวมข้อมูลส่วนบุคคลของท่านอย่างไร โดยทั่วไปแล้ว บริษัทฯ จะเก็บรวบรวมข้อมูลส่วนบุคคลของบุคคลที่อาจเป็นลูกค้า ลูกค้าปัจจุบัน และบุคคลที่เกี่ยวข้อง (รวมถึง ผู้รับผลประโยชน์ ผู้ขับขี่ พยาน ผู้จัดการมรดก ผู้ค้ำประกัน ผู้กู้ร่วม คู่สมรสของลูกค้า/ผู้กู้ร่วม บุคคลที่สามารถติดต่อสอบถามหรือทวงถามหนี้ได้ และบุคคลที่ติดต่อเข้ามา) โดยตรง อย่างไรก็ตาม ในบางกรณี บริษัทฯ อาจเก็บรวบรวมข้อมูลส่วนบุคคลโดยอ้อมจากบุคคลที่สาม

 

5.บริษัทฯ นำข้อมูลส่วนบุคคลของท่านไปใช้อย่างไร กรณีของบุคคลที่อาจเป็นลูกค้า บริษัทฯ ใช้ข้อมูลส่วนบุคคลของบุคคลที่อาจเป็นลูกค้า เพื่อดำเนินการต่าง ๆ ตามขอบเขตและวัตถุประสงค์ในดำเนินกิจกรรมต่าง ๆ ซึ่งรวมถึงแต่ไม่จำกัดเพียง การติดต่อ การทำการตลาด กรณีของลูกค้าปัจจุบันและบุคคลที่เกี่ยวข้อง (รวมถึง ผู้รับผลประโยชน์ ผู้ขับขี่ พยาน ผู้จัดการมรดก ผู้ค้ำประกัน ผู้กู้ร่วม คู่สมรสของลูกค้า/ผู้กู้ร่วม บุคคลที่สามารถติดต่อสอบถามหรือทวงถามหนี้ได้ และบุคคลที่ติดต่อเข้ามา) บริษัทฯ ใช้ข้อมูลส่วนบุคคลของลูกค้าปัจจุบันและบุคคลที่เกี่ยวข้อง เพื่อดำเนินการต่าง ๆ ตามขอบเขตและวัตถุประสงค์ในดำเนินกิจกรรมต่าง ๆ ซึ่งรวมถึงแต่ไม่จำกัดเพียง การทำการตลาด การจัดกิจกรรมที่เกี่ยวข้องกับวัตถุประสงค์ทางการตลาด การติดต่อ การยืนยันตัวตน การขายประกันภัยทางโทรศัพท์ การวิเคราะห์ความเสี่ยงในการให้สินเชื่อ การพิจารณาอนุมัติสินเชื่อ การติดตามทวงหนี้ และการสืบทรัพย์ การตรวจสอบยืนยันการปิดหนี้ การยึดหลักทรัพย์ และทำรายงาน การประมูลหลักทรัพย์ที่ยึดมา การดำเนินคดี การดำเนินการที่เกี่ยวข้องกับการสมัครประกันภัย การตรวจสอบการทำธุรกรรมรายการต้องสงสัยตามข้อกำหนดสำนักงานป้องกันและปราบปรามการฟอกเงิน การตรวจสอบลงพื้นที่ การจดหลักประกันทางธุรกิจ การเก็บข้อมูลในฐานข้อมูล การรับเรื่องติดต่อผ่านช่องทาง Call Center การรับเรื่องร้องเรียน การตอบคำถามผ่านช่องทางออนไลน์ การคืนเงินเยียวยา การจัดส่งสินค้า การทำเอกสารทางการเงิน เช่น การออกใบเสร็จตรวจสอบเงินเกิน การทำบัญชีลูกหนี้ การทำบัญชีเจ้าหนี้ การออกใบกำกับภาษี การออกเอกสารรับชำระค่างวด บริษัทฯ อาศัยฐานทางกฎหมายและเงื่อนไขพิเศษบางประการดังต่อไปนี้ในการประมวลผลข้อมูลส่วนบุคคลของท่าน อนึ่ง ฐานทางกฎหมายและเงื่อนไขพิเศษบางประการที่ระบุด้านล่างนี้ มิได้ใช้กับการประมวลผลข้อมูลส่วนบุคคลของท่านทั้งหมด โดยการประมวลผลข้อมูลส่วนบุคคลอาจอาศัยฐานทางกฎหมายเพียงฐานใดฐานหนึ่งหรือหลายฐานรวมกันก็ได้ ฐานสัญญา บริษัทฯ มีหน้าที่ในการประมวลผลข้อมูลส่วนบุคคลของท่านเพื่อปฏิบัติหน้าที่ตามสัญญากู้ โดยข้อมูลส่วนบุคคลที่ต้องใช้ในการประมวลผลตามฐานนี้ เป็นข้อมูลส่วนใหญ่ซึ่งปรากฏในข้อ 3. ในกรณีที่ท่านไม่ให้ข้อมูลส่วนบุคคลใดแก่บริษัทฯ เพื่อวัตถุประสงค์ที่กำหนดไว้ บริษัทฯ อาจไม่สามารถติดต่อหรือเข้าทำสัญญากับท่านได้ ฐานประโยชน์อันชอบธรรม เฉพาะในบางกรณี บริษัทฯ จำเป็นต้องใช้ข้อมูลส่วนบุคคลของท่านเพื่อประโยชน์อันชอบธรรมของบริษัทฯ หรือของบุคคลที่สาม ทั้งนี้ ประโยชน์อันชอบธรรมดังกล่าวจะต้องไม่มีความสำคัญเหนือไปกว่าประโยชน์และสิทธิและเสรีภาพขั้นพื้นฐานของท่าน ฐานความยินยอม ในบางกรณี บริษัทฯ จำเป็นต้องได้รับความยินยอมโดยชัดแจ้งจากบุบุคคลที่อาจเป็นลูกค้า ลูกค้าปัจจุบัน และบุคคลที่เกี่ยวข้องในการประมวลผลข้อมูลส่วนบุคคลของบุคคลที่อาจเป็นลูกค้า ลูกค้าปัจจุบัน และบุคคลที่เกี่ยวข้องสำหรับการติดต่อรวมถึงการทำการตลาด ฐานหน้าที่ตามกฎหมาย บริษัทฯ มีหน้าที่ในการประมวลผลข้อมูลส่วนบุคคลของท่านตามหน้าที่ตามกฎหมาย คำสั่งศาล หรือคำพิพากษาใด ๆ ที่เกี่ยวข้องกับการดำเนินการของบริษัทฯ ในกรณีที่ท่านไม่ให้ข้อมูลส่วนบุคคลใดแก่บริษัทฯ เพื่อวัตถุประสงค์ที่กำหนดไว้ อาจมีผลที่ตามมาตามกฎหมายที่เกี่ยวข้อง การปฏิบัติตามกฎหมายเพื่อให้บรรลุวัตถุประสงค์เกี่ยวกับฐานประโยชน์สาธารณะที่สำคัญ บริษัทฯ มีความจำเป็นในการปฏิบัติตามกฎหมายเพื่อให้บรรลุวัตถุประสงค์เกี่ยวกับประโยชน์สาธารณะที่สำคัญสำหรับการเก็บข้อมูลสุขภาพของลูกค้าที่ต้องการสมัครประกันภัยวินาศหรือประกันภัยชีวิต

 

6.บริษัทฯ เปิดเผยหรือโอนข้อมูลส่วนบุคคลของท่านให้กับบุคคลใดบ้าง บริษัทฯ อาจจำเป็นต้องเปิดเผยหรือโอนข้อมูลส่วนบุคคลของท่านให้แก่บุคคลภายนอกเพื่อประมวลข้อมูลส่วนบุคคลของท่าน โดยบุคคลดังกล่าวอาจรวมถึงบุคคลดังต่อไปนี้ บริษัทในเครือที่เกี่ยวข้อง ผู้ให้บริการคลาวด์ Outsourced Agency ที่ทำการติดตามทวงหนี้ บริษัทประมูล หน่วยงานของรัฐที่เกี่ยวข้อง บริษัทประกัน พนักงานภายนอก บริษัทตรวจสอบบัญชี บริษัทที่ทำการจัดเก็บเอกสาร บริษัทขนส่ง

 

7.การโอนข้อมูลส่วนบุคคลไปยังต่างประเทศ เพื่อวัตถุประสงค์ที่ระบุไว้ในประกาศความเป็นส่วนตัวฉบับนี้ บริษัทฯ อาจเปิดเผยหรือโอนข้อมูลส่วนบุคคลของท่านให้แก่บุคคลภายนอกหรือเซิร์ฟเวอร์ที่อยู่ในต่างประเทศซึ่งอาจมีมาตรฐานการคุ้มครองข้อมูลส่วนบุคคลเช่นเดียวกับประเทศไทยหรือไม่ก็ได้ นอกจากนี้ บริษัทฯ ได้ดำเนินมาตรการเพื่อให้มั่นใจว่าข้อมูลส่วนบุคคลของท่านถูกโอนไปอย่างปลอดภัยและผู้รับข้อมูลส่วนบุคคลมีการใช้มาตรฐานการคุ้มครองข้อมูลส่วนบุคคลที่เหมาะสม และการโอนข้อมูลส่วนบุคคลนั้นเป็นไปตาม พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล

 

8.มาตรการรักษาความปลอดภัยเพื่อการคุ้มครองข้อมูลส่วนบุคคล บริษัทฯ ได้จัดให้มีมาตรการเชิงเทคนิคและมาตรการเชิงบริหารจัดการเพื่อป้องกันการสูญหายของข้อมูลส่วนบุคคล การใช้ข้อมูลส่วนบุคคลในทางที่ผิด รวมทั้งการเข้าถึง การเปิดเผย และการเปลี่ยนแปลงข้อมูลส่วนบุคคลของท่านโดยไม่ได้รับอนุญาต และบุคคลภายนอก