นโยบายการคุ้มครองข้อมูลส่วนบุคคล

นิติบุคคลอาคารชุด หัวหิน บลูลากูน คอนโดมิเนียม (เหนือ)

แก้ไขครั้งที่

รายละเอียดการแก้ไข

ผู้แก้ไข

ต าแหน่ง

ผู้อนุมัติ

ต าแหน่ง

วันที่บังคับใช้

0

เริ่มประยุกต์ใช้ครั้งแรก

คุณกาญจนา

OM

คุณอณุรี

JM

1 ตุลาคม 2569

เอกสารควบคุมห้ามเผยแพร่หรือท าส าเนาโดยไม่ได้รับอนุญาตนโยบายการคุ้มครองข้อมูลส่วนบุคคล

นิติบุคคลอาคารชุด หัวหิน บลูลากูน คอนโดมิเนียม (เหนือ)

นิติบุคคลอาคารชุด หัวหิน บลูลากูน คอนโดมิเนียม (เหนือ) ตระหนักถึงความส าคัญของการคุ้มครองข้อมูลส่วน

บุคคลจึงได้จัดท านโยบายการคุ้มครองข้อมูลส่วนบุคคล (Personal Data Protection Policy) ขึ ้น โดยนโยบายนี ้ได้อธิบายถึง

วิธีการที่บริษัทปฏิบัติต่อข้อมูลส่วนบุคคล เช่น การเก็บรวบรวม การจัดเก็บรักษา การใช้การเปิดเผย รวมถึงสิทธิต่าง ๆ ของ

เจ้าของข้อมูลส่วนบุคคล เป็นต้น เพื่อให้เจ้าของข้อมูลได้รับทราบถึงนโยบายในการคุ้มครองข้อมูลส่วนบุคคลของบริษัท บริษัท

จึงประกาศนโยบายฯ ดังต่อไปนี ้

1. วัตถุประสงค์ :

นิติบุคคลอาคารชุด หัวหิน บลูลากูน คอนโดมิเนียม (เหนือ) จะท าการเก็บรวบรวม หรือใช้ข้อมูล เพื่อ

ประโยชน์ในการด าเนินงานของนิติบุคคลฯ เช่น การจัดจ้าง การท าสัญญา การท าธุรกรรมทางการเงิน การด าเนิน

กิจกรรมต่างๆของนิติบุคคลฯ การติดต่อประสานงานต่าง ๆ หรือเพื่อปรับปรุงคุณภาพการท างานให้มีประสิทธิภาพ

มากยิ่งขึ ้น เช่น การจัดท าฐานข้อมูล วิเคราะห์และพัฒนากระบวนการด าเนินงานของนิติบุคคลฯ แลเพื่อวัตถุประสงค์

อื่นใดที่ไม่ต้องห้ามตามกฎหมาย และ/หรือเพื่อปฏิบัติตามกฎหมายหรือกฎระเบียบที่เกี่ยวข้องต่อการด าเนินงานของ

นิติบุคคลฯ โดยนิติบุคคลฯจะจัดเก็บและใช้ข้อมูลดังกล่าวตามระยะเวลาเท่าที่จ าเป็ นตามวัตถุประสงค์ที่ได้ แจ้ง

เจ้าของข้อมูลหรือตามที่กฎหมายก าหนดไว้เท่านั ้น

นิติบุคคลฯจะไม่กระท าการใด ๆ แตกต่างจากที่ระบุในวัตถุประสงค์ของการเก็บรวบรวมข้อมูล เว้นแต่

1.1 ได้แจ้งวัตถุประสงค์ใหม่ให้แก่เจ้าของข้อมูลทราบและได้รับความยินยอมจากเจ้าของข้อมูล

1.2 เป็นการปฏิบัติตามพระราชบัญญัติข้อมูลส่วนบุคคล หรือกฎหมายอื่นที่เกี่ยวข้อง

2. ขอบเขต : การเก็บรวบรวมข้อมูลส่วนบุคคล นิติบุคคลฯจะท าการเก็บรวบรวมข้อมูลส่วนบุคคลโดยมี

วัตถุประสงค์ ขอบเขต และใช้วิธีการที่ชอบด้วยกฎหมายและเป็นธรรม โดยในการเก็บรวบรวมนั ้นจะท าเพียงเท่าที่จ าเป็นแก่การ

ด าเนินงานภายใต้วัตถุประสงค์ของนิติบุคคลฯเท่านั ้น ทั ้งนี ้ นิติบุคคลฯ จะด าเนินการให้เจ้าของข้อมูล รับรู้ ให้ความยินยอมทาง

อิเล็กทรอนิกส์ หรือตามแบบวิธีการของนิติบุคคลฯ กรณีที่นิติบุคคลฯจัดเก็บข้อมูลส่วนบุคคลอ่อนไหวของเจ้าของข้อมูล นิติ

บุคคลฯจะขอความยินยอมจากเจ้าของข้อมูลโดยชัดแจ้งก่อนท าการเก็บรวบรวม เว้นแต่การเก็บข้อมูลส่วนบุคคลและข้อมูล

ส่วนบุคคลอ่อนไหวจะเข้าข้อยกเว้นตามที่พระรบัญญัติ คุ้มครองข้อมูลส่วนบุคคล พ.ศ.2562 หรือกฎหมายอื่นก าหนดไว้

3. ค านิยาม :

3.1 “ข้อมูลส่วนบุคคล” หมายถึง ข้อมูลเกี่ยวกับบุคคลซึ่งท าให้สามารถระบุตัวบุคคลนั ้นได้ไม่ว่าทางตรง

หรือทางอ้อม แต่ไม่รวมถึงข้อมูลผู้ถึงแก่กรรมโดยเฉพาะ ตัวอย่างเช่น ชื่อ นามสกุล หมายเลข

โทรศัพท์ ที่อยู่ อีเมลล์ หมายเลขบัตรประจ าตัวประชาชน เป็นต้น

เอกสารควบคุมห้ามเผยแพร่หรือท าส าเนาโดยไม่ได้รับอนุญาต3.2 “ข้อมูลส่วนบุคคลอ่อนไหว” หมายถึง ข้อมูลที่เป็นเรื่องส่วนบุคคลโดยแท้ของบุคคล แต่มีความ

ละเอียดอ่อนและอาจสุ่มเสี่ยงในการเลือกปฏิบัติอย่างไม่เป็นธรรม เช่น เชื ้อชาติ เผ่าพันธุ์ ความ

คิดเห็นทางการเมือง ความเชื่อในลัทธิ ศาสนาหรือปรัชญา พฤติกรรมทางเพศ ประวัติอาชญากรรม

ข้อมูลสุขภาพ ความพิการ ข้อมูลสหภาพแรงงาน ข้อมูลพันธุกรรม ข้อมูลชีวภาพ หรือข้อมูลอื่นใด

ซึ่งกระทบต่อเจ้าของข้อมูลส่วนบุคคลในท านองเดียวกันตามที่คณะกรรมการคุ้มครองข้อมูลส่วน

บุคคลประกาศก าหนด ซึ่งนิติบุคคลฯ ต้องด าเนินการด้วยความระมัดระวังเป็นพิเศษ โดยนิติบุคคล

ฯ จะเก็บรวบรวม ใช้ และ/หรือเปิดเผยข้อมูลส่วนบุคคลที่มีความอ่อนไหว ต่อเมื่อได้รับความ

ยินยอมโดยชัดแจ้งจากเจ้าของข้อมูลส่วนบุคคล หรือในกรณีที่นิติบุคคลฯ มีความจ าเป็นต้อง

ด าเนินการตามที่กฎหมายอนุญาต

3.3 “เจ้าของข้อมูลส่วนบุคคล” หมายถึง บุคคลธรรมดาซึ่งเป็นเจ้าของข้อมูลส่วนบุคคลที่ข้อมูลส่วนบุคคล

สามารถระบุตัวตนของบุคคลนั ้นได้ ไม่ว่าทางตรงหรือทางอ้อม

3.4 “การประมวลผล” หมายถึง การด าเนินการเกี่ยวกับการเก็บรวบรวม ใช้ เปิดเผย การลบ หรือการท าลาย

ข้อมูลส่วนบุคคล

3.5 “ผู้ควบคุมข้อมูลส่วนบุคคล” หมายถึง บุคคลหรือนิติบุคคลซึ่งมีอ านาจหน้าที่ตัดสินใจเกี่ยวกับการเก็บ

รวบรวม ใช้ หรือเปิดเผยข้อมูลส่วนบุคคล

3.6 “ผู้ประมวลผลข้อมูลส่วนบุคคล” หมายถึง บุคคลหรือนิติบุคคลซึ่งด าเนินการเกี่ยวกับการเก็บรวบรวม

ใช้ หรือเปิดเผยข้อมูลส่วนบุคคลตามค าสั่งหรือในนามของบริษัท ทั ้งนี ้ บุคคลหรือนิติบุคคล ซึ่ง

ด าเนินการดังกล่าวไม่เป็นผู้ควบคุมข้อมูลส่วนบุคคล

3.7 “คณะกรรมการคุ้มครองข้อมูลส่วนบุคคล” หมายถึง คณะกรรมการที่ได้รับการแต่งตั ้ งขึ ้น โดยมีหน้าที่

และอ านาจก ากับดูแล ออกหลักเกณฑ์ มาตรการ หรือข้อปฏิบัติอื่นใดที่เกี่ยวข้องกับการคุ้มครอง

ข้อมูลส่วนบุคคลตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ.2562

4. การเปิ ดเผยข้อมูลส่วนบุคคล :

นิติบุคคลฯจะไม่เปิดเผยข้อมูลส่วนบุคคลของเจ้าของข้อมูลไปให้บุคคลใดโดยปราศจากความยินยอม และ

จะเปิดเผยตามวัตถุประสงค์ที่ได้มีการแจ้งไว้ อย่างไรก็ดี เพื่อให้เป็นประโยชน์ต่อการด าเนินงานของนิติบุคคลฯ และการ

ให้บริการแก่เจ้าของข้อมูล นิติบุคคลฯอาจมีความจ าเป็นในการเปิดเผยข้อมูลส่วนบุคคลของเจ้าของข้อมูล ให้แก่

คณะกรรมการบริหารนิติบุคคลฯ ผู้จัดการนิติบุคคลฯ ฝ่ายบริหารจัดการอาคาร หรือผู้ให้บริการต่าง ๆ ที่ต้องด าเนินงานที่

เกี่ยวข้องกับข้อมูลส่วนบุคคล โดยในการเปิดเผยข้อมูลส่วนบุคคลให้แก่บุคคลดังกล่าว นิติบุคคลฯจะด าเนินการให้บุคคล

เหล่านั ้นเก็บรักษาข้อมูลส่วนบุคคลไว้เป็นความลับ และไม่น าไปใช้เพื่อวัตถุประสงค์อื่นนอกเหนือจากขอบเขตที่นิติบุคคลฯได้

ก าหนดไว้

เอกสารควบคุมห้ามเผยแพร่หรือท าส าเนาโดยไม่ได้รับอนุญาต5. การจัดเก็บข้อมูลส่วนบุคคล :

นิติบุคคลฯจะเก็บรักษาข้อมูลส่วนบุคคลของท่านไว้ตามระยะเวลาที่จ าเป็นในระหว่างที่ท่านมีความสัมพันธ์

อยู่กับนิติบุคคลหรือตลอดระยะเวลาที่จ าเป็นเพื่อให้บรรลุวัตถุประสงค์ที่เกี่ยวข้องในนโยบายฉบับนี ้ ซึ่งอาจมีความจ าเป็นต้อง

เก็บรักษาไว้ต่อไปภายหลังจากนั ้นหากมีกฎหมายก าหนดหรืออนุญาตไว้ เช่น จัดเก็บไว้เพื่อวัตถุประสงค์ในการพิสูจน์

ตรวจสอบกรณีอาจเกิดข้อพิพาทภายในอายุความตามที่กฎหมายก าหนดเป็นระยะเวลาไม่เกิน 10 ปี เป็นต้น

ทั ้งนี ้ นิติบุคคลฯ จะลบหรือท าลายข้อมูลส่วนบุคคล หรือท าให้เป็นข้อมูลที่ไม่สามารถระบุถึงตัวตนของท่าน

ได้เมื่อหมดความจ าเป็นหรือสิ ้นสุดระยะเวลาดังกล่าว

6. แนวทางในการด าเนินการคุ้มครองข้อมูลส่วนบุคคล :

นิติบุคคลฯ จะก ำหนดและจัดให้มีมำตรกำรรักษำควำมมั่นคงปลอดภัยของข้อมูลส่วนบุคคลทั ้งในด้ำน

กำยภำพ (Physical Security) และด้ำนเทคนิค (Technical Security) ที่เหมำะสมและสอดคล้องกับลักษณะของข้อมูลส่วน

บุคคลและควำมเสี่ยงที่อำจเกิดขึ ้น เช่น กำรก ำหนดสิทธิและควบคุมกำรเข้ำถึงระบบกล้องวงจรปิด (CCTV) ระบบฐำนข้อมูล

ของเจ้ำของร่วม และ/หรือข้อมูลส่วนบุคคลของเจ้ำของข้อมูล รวมถึงกำรก ำหนดมำตรกำรควบคุมกำรเข้ำถึง กำรจัดเก็บ กำรใช้

กำรส่งต่อ และกำรเปิดเผยข้อมูลส่วนบุคคลอย่ำงเหมำะสม

นิติบุคคลฯ จะจัดให้มีมำตรกำรรักษำควำมมั่นคงปลอดภัยของข้อมูลส่วนบุคคลที่สอดคล้องกับกฎหมำย

ระเบียบ หลักเกณฑ์ และแนวปฏิบัติที่เกี่ยวข้องกับกำรคุ้มครองข้อมูลส่วนบุคคล ตลอดจนก ำหนดแนวทำงและขั ้นตอนกำร

ปฏิบัติงำนที่เกี่ยวข้องให้แก่พนักงำนของนิติบุคคลฯ และบุคคลอื่นที่เกี่ยวข้อง เพื่อให้กำรด ำเนินกำรเกี่ยวกับข้อมูลส่วนบุคคล

เป็นไปอย่ำงถูกต้อง เหมำะสม และมีประสิทธิภำพ

นอกจำกนี ้ นิติบุคคลฯ จะสนับสนุนและส่งเสริมให้พนักงำนมีควำมรู้ ควำมเข้ำใจ และควำมตระหนักถึง

หน้ำที่และควำมรับผิดชอบในกำรเก็บรวบรวม กำรจัดเก็บรักษำ กำรใช้ และกำรเปิดเผยข้อมูลส่วนบุคคลของเจ้ำของข้อมูล

รวมถึงตระหนักถึงควำมส ำคัญของกำรรักษำควำมมั่นคงปลอดภัยและกำรรักษำควำมลับของข้อมูลส่วนบุคคล

พนักงำนของนิติบุคคลฯ และบุคคลที่เกี่ยวข้องจะต้องปฏิบัติตำมนโยบำย มำตรกำร และแนวปฏิบัติด้ำนกำรคุ้มครองข้อมูล

ส่วนบุคคลที่นิติบุคคลฯ ก ำหนดไว้อย่ำงเคร่งครัด เพื่อให้นิติบุคคลฯ สำมำรถด ำเนินกำรเกี่ยวกับข้อมูลส่วนบุคคลได้อย่ำง

ถูกต้อง เหมำะสม โปร่งใส และมีประสิทธิภำพ รวมทั ้งสำมำรถปฏิบัติตำมกฎหมำยและหลักเกณฑ์ด้ำนกำรคุ้มครองข้อมูลส่วน

บุคคลที่เกี่ยวข้องได้อย่ำงครบถ้วน

7. สิทธิของเจ้าของข้อมูลส่วนบุคคล :

เจ้าของข้อมูลส่วนบุคคมีสิทธิในการด าเนินการดังต่อไปนี ้

7.1 สิทธิในการเพิกถอนความยินยอมในการประมวลผลข้อมูลส่วนบุคคลที่ได้ให้ความยินยิมไว้ ทั ้งนี ้การเพิก

ถอนความยินยอมย่อมไม่ส่งผลกระทบต่อการเก็บรวบรวม ใช้ หรือเปิดเผยข้อมูลส่วนบุคคลที่ได้ให้ความยินยอมไว้แล้ว

7.2 สิทธิในการเข้าถึงข้อมูลส่วนบุคคลและขอท าส าเนาข้อมูลส่วนบุคคล รวมถึงการขอให้เปิดเผยการได้ซึ่ง

ข้อมูลส่วนบุคคลที่ไม่ได้ให้ความยินยอม

7.3 สิทธิในการแก้ไขข้อมูลส่วนบุคคลให้ถูกต้อง

เอกสารควบคุมห้ามเผยแพร่หรือท าส าเนาโดยไม่ได้รับอนุญาต7.4 สิทธิในการลบข้อมูลส่วนบุคคล

7.5 สิทธิในการระงับการใช้ข้อมูลส่วนบุคคล

7.6 สิทธิในการให้โอนย้ายข้อมูลส่วนบุคคล

7.7 สิทธิในการคัดค้านการประมวลผลข้อมูลส่วนบุคคล

เจ้าของข้อมูลสามารถขอใช้สิทธิดังกล่าวข้างต้นได้ โดยยื่นค าร้องขอใช้สิทธิต่อนิติบุคคลฯเป็นลายลักษณ์

อักษรหรือผ่านทางจดหมายอิเล็กทรอนิกส์ตามแบบฟอร์มที่นิติบุคคลฯก าหนด ผ่าน “ช่องทางการติดต่อของนิติบุคคลฯ”

ด้านล่าง โดยนิติบุคคลฯจะพิจารณาและแจ้งผลการพิจารณาตามค าร้องฯ ของเจ้าของข้อมูล ภายใน 30 วัน นับแต่วันที่ได้

รับค าร้องฯดังกล่าว ทั ้งนี ้ นิติบุคคลฯอาจปฏิเสธสิทธิของเจ้าของข้อมูลได้ในกรณีที่มีกฎหมายก าหนดไว้

8. ช่องทางการติดต่อ :

หากมีข้อสงสัยเกี่ยวกับนโยบายความเป็นส่วนตัว สามารถติดต่อสอบถามได้ที่ ส านักงานนิติบุคคล อาคาร

ชุด หัวหิน บลูลากูน คอนโดมิเนียม (เหนือ) โทร.098 3577 7347 หรือ E mail : hhbl.north@hotmail.com หรือ

Line ID : hhbl.north หรือบุคคลส าคัญด้านล่างนี ้

4.1 4.2 4.3 คณะกรรมการบริหารงานนิติบุคคลอาคารชุด หัวหิน บลูลากูน คอนโดมิเนียม (เหนือ)

ผู้จัดการนิติบุคคลอาคารชุด หัวหิน บลูลากูน คอนโดมิเนียม (เหนือ)

ฝ่ายบริหารจัดการอาคาร นิติบุคคลอาคารชุด หัวหิน บลูลากูน คอนโดมิเนียม (เหนือ)

9. การทบทวนและเปลี่ยนแปลงนโยบายการคุ้มครองข้อมูลส่วนบุคคล

นิติบุคคลฯ อาจท าการปรับปรุงหรือแก้ไขนโยบายนี ้เป็นครั้งคราวเพื่อให้สอดคล้องกับข้อก าหนดตาม

กฎหมาย การเปลี่ยนแปลงการด าเนินงานของบริษัท รวมถึงข้อเสนอแนะและความคิดเห็นจากหน่วยงานต่าง ๆ โดยนิติบุคคลฯ

จะประกาศแจ้งการเปลี่ยนแปลงให้ทราบอย่างชัดเจน ก่อนจะเริ่มด าเนินการเปลี่ยนแปลง

พิจารณาทบทวนและประกาศใช้ ณ 1 ตุลาคม 2569

............................................ .........................................

( Mr.Mark Kreitzman ) ( นางสาวอณุรี ไชยฮะ)

ประธานคณะกรรมการบริหาร ผู้จัดการนิติบุคคลอาคารชุด

นิติบุคคลอาคารชุด หัวหิน บลูลากูน คอนโดมิเนียม (เหนือ) นิติบุคคลอาคารชุด หัวหิน บลูลากูน คอนโดมิเนียม (เหนือ)

เอกสารควบคุมห้ามเผยแพร่หรือท าส าเนาโดยไม่ได้รับอนุญาตPERSONAL DATA PROTECTION POLICY

HUA HIN BLUE LAGOON CONDOMINIUM (NORTH) JURISTIC PERSON

Revision

No. Details of Revision Prepared/Amended

by Position by Approved

Position Effective

Date

0 Initial

implementation Ms. Kanjana OM Ms. Anuree JM 1 October

2026

เอกสารควบคุมห้ามเผยแพร่หรือท าส าเนาโดยไม่ได้รับอนุญาตPERSONAL DATA PROTECTION POLICY

HUA HIN BLUE LAGOON CONDOMINIUM (NORTH) JURISTIC PERSON

Hua Hin Blue Lagoon Condominium (North) Juristic Person recognizes the importance of personal data

protection and has therefore established this Personal Data Protection Policy.

This Policy explains how the Juristic Person handles personal data, including the collection, storage,

use, disclosure, and protection of personal data, as well as the rights of data subjects.

In order to ensure that data subjects are informed of the Juristic Person’s personal data protection

practices, the Juristic Person hereby announces this Personal Data Protection Policy as follows:

1. Purpose

Hua Hin Blue Lagoon Condominium (North) Juristic Person may collect, use, or process personal data

for purposes related to the operations of the Juristic Person, including recruitment and employment,

entering into agreements and contracts, financial transactions, activities of the Juristic Person,

communication and coordination, and improving the efficiency and quality of its operations.

This may include establishing databases, analyzing and developing operational processes, and other

purposes that are not prohibited by law, as well as complying with applicable laws, regulations, rules,

and requirements relating to the operations of the Juristic Person.

The Juristic Person shall retain and use such personal data only for as long as necessary to fulfill the

purposes notified to the data subject or for the period required by applicable law.

The Juristic Person shall not process personal data for purposes that are different from those stated at

the time of collection, except where:

1.1 The new purpose has been notified to the data subject and the data subject’s consent has been

obtained, where consent is legally required; or

เอกสารควบคุมห้ามเผยแพร่หรือท าส าเนาโดยไม่ได้รับอนุญาต1.2 Such processing is necessary to comply with the Personal Data Protection Act or other applicable

laws.

2. Scope

In collecting personal data, the Juristic Person shall collect personal data in a lawful and fair manner,

with a specified purpose and within an appropriate scope.

The Juristic Person shall collect only personal data that is necessary for its operations and the purposes

for which such data is processed.

Where consent is required by law, the Juristic Person shall obtain consent from the data subject,

including through electronic means or other methods prescribed by the Juristic Person.

In cases where the Juristic Person collects sensitive personal data, the Juristic Person shall obtain

explicit consent from the data subject prior to such collection, unless such collection falls within an

exception permitted under the Personal Data Protection Act B.E. 2562 (2019) or other applicable laws.

3. Definitions

3.1 “Personal Data” means any information relating to a person that enables the identification of such

person, whether directly or indirectly, but does not include information of a deceased person in

particular. Examples include name, surname, telephone number, address, email address, identification

card number, etc.

3.2 “Sensitive Personal Data” means personal data that is particularly sensitive and may create a risk

of unfair discrimination, such as racial or ethnic origin, political opinions, religious or philosophical

beliefs, sexual behavior, criminal records, health information, disability, trade union information,

genetic data, biometric data, or any other information prescribed by the Personal Data Protection

Committee as having a similar effect on the data subject.

The Juristic Person shall exercise particular care when collecting, using, and/or disclosing sensitive

personal data and shall do so only where explicit consent has been obtained from the data subject or

where such processing is permitted by law.

3.3 “Data Subject” means a natural person who is the owner of personal data and who can be

identified, directly or indirectly, from such personal data.

3.4 “Processing” means any operation performed on personal data, including collection, use,

disclosure, deletion, or destruction.

3.5 “Data Controller” means a person or juristic person who has the authority and responsibility to

make decisions regarding the collection, use, or disclosure of personal data.

เอกสารควบคุมห้ามเผยแพร่หรือท าส าเนาโดยไม่ได้รับอนุญาต3.6 “Data Processor” means a person or juristic person who carries out activities relating to the

collection, use, or disclosure of personal data in accordance with the instructions or on behalf of the

Data Controller, and who is not the Data Controller.

3.7 “Personal Data Protection Committee” means the committee appointed under the Personal Data

Protection Act B.E. 2562 (2019), having duties and powers to supervise, issue rules, measures, or other

practices relating to personal data protection.

4. Disclosure of Personal Data

The Juristic Person shall not disclose the personal data of a data subject to any person without consent

where consent is required by law and shall disclose personal data only for the purposes that have been

notified to the data subject.

However, for the purposes of the operations of the Juristic Person and the provision of services to data

subjects, it may be necessary for the Juristic Person to disclose personal data to the Juristic Person’s

Board of Directors, Juristic Person Manager, building management team, or service providers who are

required to process personal data in connection with their duties.

When disclosing personal data to such persons, the Juristic Person shall take appropriate measures to

ensure that they maintain the confidentiality and security of personal data and do not use such personal

data for purposes beyond the scope specified by the Juristic Person.

5. Retention of Personal Data

The Juristic Person shall retain personal data for as long as necessary while the data subject maintains a

relationship with the Juristic Person, or for as long as necessary to fulfill the relevant purposes specified

in this Policy.

The Juristic Person may retain personal data after such relationship has ended where retention is

required or permitted by law, for example, for the purposes of evidence, verification, or potential

disputes, within the applicable statutory limitation period, which may be for a period of up to 10 years

where legally applicable.

The Juristic Person shall delete or destroy personal data, or anonymize such data so that the data subject

can no longer be identified, when the data is no longer necessary or when the applicable retention

period has expired.

6. Personal Data Protection Measures

The Juristic Person shall establish and implement appropriate physical and technical security

measures to protect Personal Data against unauthorized access, collection, use, disclosure, alteration,

loss, destruction, or other unlawful or unauthorized processing. Such measures shall be appropriate to

the nature of the Personal Data and the risks associated with the processing of such Personal Data.

เอกสารควบคุมห้ามเผยแพร่หรือท าส าเนาโดยไม่ได้รับอนุญาตSuch security measures may include, but are not limited to, restricting and controlling access to Closed-

Circuit Television (CCTV) systems, databases containing information of Co-owners, and/or Personal

Data of Data Subjects, as well as implementing appropriate measures for the access, storage, use,

transfer, disclosure, and other processing of Personal Data.

The Juristic Person, in its capacity as the Data Controller, shall establish and maintain appropriate

Personal Data security measures in compliance with applicable laws, regulations, rules, criteria, and

guidelines relating to Personal Data protection. The Juristic Person shall also establish policies,

procedures, and operational guidelines concerning Personal Data protection for its employees and other

relevant persons involved in the processing of Personal Data, in order to ensure that Personal Data is

processed lawfully, fairly, appropriately, and effectively.

Furthermore, the Juristic Person shall support and promote employees’ knowledge, understanding, and

awareness of their duties and responsibilities regarding the collection, recording, storage, use,

disclosure, and other processing of Personal Data of Data Subjects. Employees shall also be made

aware of the importance of maintaining the confidentiality, integrity, and security of Personal Data.

All employees of the Juristic Person and other relevant persons involved in the processing of Personal

Data shall strictly comply with the Personal Data protection policies, security measures, procedures, and

guidelines prescribed by the Juristic Person. This is to ensure that the Juristic Person processes Personal

Data in a lawful, appropriate, transparent, and effective manner and in compliance with the Personal

Data Protection Act B.E. 2562 (2019) and other applicable laws and regulations concerning Personal

Data protection.

7. Rights of Data Subjects

Data subjects have the following rights, subject to the conditions and exceptions provided by applicable

law:

7.1 The right to withdraw consent previously given for the processing of personal data. Withdrawal of

consent shall not affect the processing of personal data that was lawfully carried out before the

withdrawal.

7.2 The right to access personal data and request a copy of such personal data, including the right to

request information regarding the source of personal data obtained without consent, where applicable.

7.3 The right to request correction of inaccurate or incomplete personal data.

7.4 The right to request deletion or destruction of personal data.

7.5 The right to request restriction of the use of personal data.

7.6 The right to data portability, where applicable.

7.7 The right to object to the processing of personal data, where applicable.

Data subjects may exercise the above rights by submitting a written request or by email using the form

prescribed by the Juristic Person through the contact channels specified below.

เอกสารควบคุมห้ามเผยแพร่หรือท าส าเนาโดยไม่ได้รับอนุญาตThe Juristic Person shall consider each request and notify the data subject of the outcome within the

period prescribed by applicable law. The Juristic Person may refuse a request where such refusal is

permitted or required by law.

8. Contact Channels

If you have any questions or concerns regarding this Personal Data Protection Policy, you may contact:

Hua Hin Blue Lagoon Condominium (North) Juristic Person Office

Telephone: 098-357-7734

Email: hhbl.north@hotmail.com

LINE ID: hhbl.north

You may also contact:

8.1 The Board of Directors of Hua Hin Blue Lagoon Condominium (North) Juristic Person

8.2 The Juristic Person Manager of Hua Hin Blue Lagoon Condominium (North)

8.3 The Building Management Team of Hua Hin Blue Lagoon Condominium (North) Juristic Person

9. Review and Amendment of the Personal Data Protection Policy

The Juristic Person may review, update, or amend this Policy from time to time to ensure compliance

with applicable legal requirements, changes in the operations of the Juristic Person, and

recommendations or comments from relevant authorities or other parties.

The Juristic Person shall clearly announce any significant changes to this Policy before such changes

become effective.

Reviewed and effective as of 1 October 2026.

....................................................

(Mr.Mark Kreitzman)

Chairman of the Board of Directors

Hua Hin Blue Lagoon Condominium (North) Juristic Person

....................................................

(Ms. Anuree Chaiha)

Juristic Person Manager

Hua Hin Blue Lagoon Condominium (North) Juristic Person

เอกสารควบคุมห้ามเผยแพร่หรือท าส าเนาโดยไม่ได้รับอนุญาต