-----------------------------
Tokio Marine Life Insurance (Thailand) Public Company Limited, an affiliate/a company in Tokio Marine Group, (hereinafter referred to as the “Company”, “we”, “us”, or “our”) places significant importance on the protection of personal data and ensures that the personal data of relevant data subjects are processed in accordance with the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), together with applicable laws, regulations, and regulatory requirements prescribed by relevant supervisory authorities, including the Office of Insurance Commission (“OIC”).
We recognize that the products and services we provide as part of our total insurance solutions involve the collection, use, disclosure, and otherwise processing (“processing”) of personal data. Accordingly, the Company prepared this Privacy Notice in accordance with the PDPA to ensure the transparency and your rights under the PDPA.
This Privacy Notice (“Privacy Notice”) is intended to inform you of the Company’s practices in relation to the processing and protection of personal data, as well as the rights available to you as a data subject. It also provides information on how you may contact the Company for inquiries or to exercise such rights. You, therefore, are encouraged to read and understand this Privacy Notice.
This Privacy Notice applies to the following categories of individuals under the Company’s sales and distribution functions, regardless of whether their relationship with the Company is active or terminated. This includes insurance agent applicants; agents including agency leaders at all levels; participants in sales-related activities, training, or programs; and other individuals associated with the Company’s agency or distribution channels.
This section provides details on how the Company processes Personal Data relating to such individuals, including the processing and protection of Personal Data throughout the lifecycle of the agency relationship, from recruitment and onboarding to performance management and post-termination.
This Privacy Notice applies to the following categories of individuals within the Company’s personnel and workforce functions, regardless of whether their relationship with the Company is active or terminated. This includes job applicants and candidates; employees (including all employment types); temporary staff, interns, and outsourced personnel; directors and individual shareholders; and dependents, beneficiaries, emergency contacts, referees, guarantors, and other related individuals.
This section provides details on how the Company processes Personal Data relating to such individuals, including the processing and protection of Personal Data throughout the employment lifecycle, from recruitment and engagement to employment management and post-termination.
This Privacy Notice applies to the following categories of individuals and entities interacting with the Company, regardless of whether their relationship with the Company is active or terminated. This includes vendors, suppliers, and service providers; consultants, contractors, and outsourced personnel; business partners and counterparties; directors, employees, representatives, and authorized persons of such entities; and external contacts engaging or interacting with the Company, including through Human Resources, Procurement, Administration, or other business functions.
This section outlines how the Company processes Personal Data relating to such individuals, including the processing and protection of Personal Data throughout the business relationship lifecycle, from initial engagement and contractual arrangements to ongoing service delivery, operational interactions, and post‑relationship management.
This Privacy Notice applies to the following categories of individuals in connection with the Company’s insurance and related services, regardless of whether their relationship with the Company is active or terminated. This includes prospective customers applying for insurance products or services; policy owners, policyholders, insured persons, payors, beneficiaries, and group insurance members; former customers whose policies have lapsed or terminated; and any other individuals who interact with the Company in relation to insurance products or services.
This section describes how the Company processes and safeguards Personal Data relating to customers throughout the lifecycle of the customer relationship, from pre-contractual stage to post-termination.
The “Personal Data Protection Act. (“PDPA”)
means the Personal Data Protection Act. B.E. 2019, including subordinate legislation which is enacted by virtue of the Personal Data Protection Act, as amended from time to time, as well as any other applicable laws in respect to Personal Data protection, which are prescribed by the authorities in Thailand.
“Personal Data”
means any information relating to a Person, which enables the identification of such Person, whether directly or indirectly, but not including the information of deceased Persons in particular.
“Sensitive Personal Data”
means data which is specified in Article 26 of the PDPA, its amendments made from time to time; and relevant laws and regulation, including any Personal Data pertaining to racial, ethnic, origin, political opinions, cult, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data, or any data which may affect the data subject in the same manner.
“Data Controller”
means a person or juristic person having the power and duties to make decisions regarding the processing of Personal Data.
“Data Processor”
means a person or juristic person who Processes Personal Data on behalf of the Data Controller.
“Customers”
means insurance customers, including insured, policy owners, policyholders, beneficiaries, payors, group insurance members, and prospective customers who apply for an insurance policy or other persons who are interested in our insurance policies, regardless of whether insurance contract is still in-force or lapse.
“Sales Representatives/Agents”
means an insurance agent and agency leaders of all levels, insurance agent trainees (if any), insurance broker, applicants, and any other persons who are interested in acting as our insurance intermediaries, regardless of whether such position is still effective or ineffective.
“Counterparty”
means any individual, juristic person, or authorized representative of such entity that enters into, or has entered into, a contractual or business relationship with the Company, whether or not such relationship remains in effect.
“Personnel”
means Our shareholders, directors, all types of employees, including candidates, trainees or interns, or regardless of whether such position is still effective or ineffective.
“Third Party” or “Service Provider”
means any person or entity other than the Company, the data subject, or a person acting under the direct authority of the Company, that receives or processes Personal Data for or on behalf of the Company, including vendors, outsourced service providers, and external partners engaged to perform services or functions related to the Company’s business operations, regardless of whether such relationship remains in effect or has been terminated.
“Others”
means other persons who are not Customers, Sales Representative, Business Partners or Our Personnel in accordance with the definitions specified in this Policy.
“Processing”
means any operation or set of operations which is performed on Personal Data, whether or not by automated means, including collection, use, disclosure, storage, retention, alteration, erasure, destruction, or otherwise processing.
“Artificial Intelligence (AI)”
means any Technology developed to enable computers to possess characteristics or behaviors similar to humans, such as learning, perception, responding to environments, reasoning, and problem-solving, based on human-defined objectives.
“Automated Decision-Making”
means any decision made solely by automated means, without human intervention, based on the processing of Personal Data, including the use of Artificial Intelligence (AI), algorithms, or system-based rules, without human intervention.
“Profiling”
means any form of automated processing of Personal Data consisting of the use of such data to evaluate certain personal aspects relating to an individual, in particular to analyze or predict aspects concerning that individual’s performance, preferences, behavior, location, or other characteristics.
“Cloud Services”
means third-party hosted infrastructure, platforms, or software solutions used for processing, storing, or transmitting Personal Data, which may be located within or outside Thailand.
COLLECTION OF PERSONAL DATA
When you contact us, use our services, or enter into a contract with us, we may collect and process your Personal Data as follows:
THE PROCESSING OF GENERAL PERSONAL DATA
This includes but is not limited to your name, surname, date of birth, age, occupation, gender, photographs or motion images, and contact details such as telephone number, address, email address, social media contact details, and emergency contact information. We may also collect any other information necessary for the purposes requested by you, or for purposes related to the Company’s operations, including offering products or services, delivering services, or entering into contractual arrangements.
THE PROCESSING OF SENSITIVE PERSONAL DATA
In certain circumstances, we may collect and process your Sensitive Personal Data, such as health information, criminal records, or biometric data (including photographs for identity verification, such as still images or liveness detection).
Where required by law, we will obtain your explicit consent prior to processing such Sensitive Personal Data, unless an exception under applicable laws permits us to do so without consent.
If consent is required and you do not provide such consent, we may be unable to enter into a contract with you or provide certain services, in whole or in part.
For further details on how we process your Personal Data based on specific communication methods, transactions, or purposes, please refer to the relevant sections below.
Where you do not provide, or are unable to provide, the Personal Data necessary for the purposes of entering into a contract with us and/or to perform our obligations under the contract with you, if you do not provide us with the required Personal Data under said circumstances, we may not be able to proceed with your such request, or we may not be able to provide our products or services to you, in whole or in part.
Moreover, there may be certain circumstances where your Personal Data is needed for the purpose of compliance with our legal obligations. If you do not provide your Personal Data under said circumstances, it may result in us and/or you being in violation of, or non-compliance with, the applicable law or regulation. In such case, we may need to suspend or terminate our provision of products or services to you, either in whole or in part.
The Company collects and processes Personal Data relating to sales representatives in connection with recruitment, onboarding, contract administration, regulatory compliance, training and development, performance management, and other operational activities.
Where you apply to join the Company’s sales force, enter into a sales agreement, request or receive services or benefits, or participate in recruitment, training, or sales-related activities, the Company may collect and process your Personal Data for purposes relevant to such activities.
The Company collects only Personal Data that is necessary, relevant, and proportionate to the specified purposes. In certain circumstances, the Company may also collect and process Sensitive Personal Data in accordance with applicable laws and regulatory requirements.
1. CATEGORIES OF GENERAL PERSONAL DATA
The Company may collect and process the following categories of Personal Data (including but not limited to):
2. SENSITIVE PERSONAL DATA
The Company may collect and process Sensitive Personal Data such as:
The Company collects and processes Personal Data relating to personnel in connection with recruitment, employment management, compensation and benefits administration, performance management, and compliance with applicable laws and regulations.
The types of Personal Data collected may vary depending on the nature of the employment relationship and stage of the employment lifecycle.
1. CATEGORIES OF GENERAL PERSONAL DATA
The Company may collect and process the following categories of Personal Data (including but not limited to):
2. SENSITIVE PERSONAL DATA
The Company may collect Sensitive Personal Data including:
1. CATEGORIES OF GENERAL PERSONAL DATA
The Company may collect and process the following categories of Personal Data (including but not limited to):
2. SENSITIVE PERSONAL DATA
The Company may process Sensitive Personal Data where necessary, including:
1. CATEGORIES OF GENERAL PERSONAL DATA
The Company may collect and process the following categories of Personal Data (including but not limited to):
2. SENSITIVE PERSONAL DATA
The Company may collect Sensitive Personal Data including:
In general, the Company collects Personal Data through various channels and methods, as follows:
2.1 AUTOMATIC COLLECTION OF PERSONAL DATA AND USE OF AUTOMATED TECHNOLOGIES
When you access or use our websites, applications, social media platforms, or services (including those provided through third-party platforms), the Company may collect and process certain Personal Data through systems hosted on cloud-based platforms, applications, and storage environments, including those operated by third-party service providers.
In this context, the Company may automatically collect certain technical and usage-related Personal Data through cookies, tracking technologies, or other automated means. Such data may include, but is not limited to:
This information may be collected and processed using automated systems, analytics tools, or Artificial Intelligence (AI) technologies for purposes such as system operation, cybersecurity monitoring, fraud detection, performance analysis, and service improvement.
The Company may also utilize AI and other advanced technologies to support data processing activities, including analytics, risk assessment, and operational efficiency.
Where such automated processing is applied, the Company ensures that appropriate safeguards, controls, and governance mechanisms are implemented, including human oversight where necessary, to ensure that processing is conducted in a lawful, fair, and transparent manner in accordance with applicable laws.
The Company does not rely solely on automated decision-making processes that produce legal or similarly significant effects on data subjects, unless permitted under applicable laws and supported by appropriate legal grounds.
Further details on the use of cookies and similar technologies are set out in our Cookie Policy. You are advised to review and understand the Cookie Policy prior to accessing or using our websites, applications, or social media platforms.
The Company ensures transparency in relation to such automated processing and facilitates the exercise of data subject rights in accordance with applicable laws.
2.2 DIRECT COLLECTION OF PERSONAL DATA
The Company may collect Personal Data directly from you when you interact with us, including where you:
2.3 COLLECTION OF PERSONAL DATA FROM THIRD PARTIES
The Company may also collect Personal Data from third parties, where permitted by applicable laws, including:
Where Personal Data is obtained from third parties, the Company ensures that such data is collected and processed in accordance with applicable laws and that appropriate measures are in place to verify its accuracy and legitimacy.
For further details on how the Company processes Personal Data in connection with specific communication channels, transactions, or purposes, please refer to the relevant sections of this Privacy Notice.
(A) DIRECT INTERACTIONS
When you communicate or interact with the Company through written, electronic, or verbal communications, regardless of who initiates the interaction, including when you access or interact with documents, systems, platforms, or links provided by the Company.
(B) THIRD-PARTY SOURCES
When Personal Data is obtained from third parties, including other sales representatives, business partners, service providers, industry associations, regulators (such as the OIC), publicly available sources, or other lawful commercial sources. Such collection may be carried out for purposes including contractual performance, regulatory compliance, supervision, or the Company’s legitimate interests.
(C) SECURITY AND PREMISES ACCESS
When you enter, exit, or remain within Company premises, where Personal Data may be collected through access control systems (e.g. access cards, passcodes, biometric systems) and CCTV recordings.
(D) RECRUITMENT AND ONBOARDING
When you apply to join or are engaged as part of the sales force, including during application, recruitment, onboarding, and contractual processes.
(E) DURING THE CONTRACTUAL LIFECYCLE
When Personal Data is collected or generated during the course of the contractual relationship to perform contractual obligations, comply with applicable laws, and provide services, benefits, or operational support.
(F) COMPENSATION AND FINANCIAL ADMINISTRATION
When Personal Data is processed to calculate commissions, compensation, benefits, and to comply with tax and legal obligations.
(G) OPERATIONAL AND BUSINESS INTERACTIONS
When you interact with the Company’s personnel or business partners, including through meetings, communications, or the use of systems and platforms.
(H) PERFORMANCE AND EVALUATION
When Personal Data is collected or generated for performance evaluation, including behavioral data, disciplinary records, and performance assessments.
(I) TRAINING AND DEVELOPMENT
When Personal Data is processed in connection with training programs, professional development, and licensing or certification requirements.
(J) BENEFITS AND BUSINESS ACTIVITIES
When Personal Data is processed for benefits administration, participation in campaigns, incentive programs, and other business or sales-related activities.
AUTOMATED PROCESSING
In certain circumstances, Personal Data collected through the above channels may be processed using automated systems, analytics tools, or Artificial Intelligence (AI) throughout the AI lifecycle, including for purposes such as performance analysis, fraud detection, system security, risk assessment, AI model development and training and operational efficiency.
The Company ensures that such processing is conducted in a lawful, fair, and transparent manner, with appropriate safeguards and human oversight, in accordance with applicable laws and regulatory requirements.
(A) DIRECT INTERACTIONS
When Personal Data is provided directly by you during recruitment, onboarding, employment, or other interactions with the Company, including applications, agreements, and communications.
(B) INTERNAL SYSTEMS AND TECHNOLOGIES
When Personal Data is generated through your use of the Company’s information technology systems, applications, networks, devices, and communication tools.
(C) AUTOMATED AND TECHNICAL COLLECTION
When Personal Data is automatically collected through digital platforms and security systems, including:
(D) THIRD-PARTY SOURCES
When Personal Data is obtained from third parties, including recruitment agencies, referees, regulators, business partners, and publicly available sources.
(E) DURING THE EMPLOYMENT LIFECYCLE
When Personal Data is collected and generated throughout the employment lifecycle, including:
(A) DIRECT INTERACTIONS
When Personal Data is collected during contract negotiation, vendor onboarding, due diligence processes, and business communications or meetings.
(B) AUTOMATED AND TECHNICAL COLLECTION
When Personal Data is collected through the use of Company systems and facilities, including:
(C) THIRD-PARTY SOURCES
When Personal Data is obtained from third parties, including recruitment agencies, references, regulators, business partners, group companies, and publicly available or commercial sources.
(D) DURING THE CONTRACTUAL LIFECYCLE
When Personal Data is collected and generated in connection with contractual relationships and service arrangements, including:
(A) DIRECT INTERACTIONS
When you communicate or interact with the Company through written, electronic, verbal, or face-to-face channels, including when you complete application forms, submit declarations, request quotes, purchase insurance, update policy details, submit claims, make payments, or contact customer service.
(B) THROUGH AGENTS, BROKERS, AND INTERMEDIARIES
When Personal Data is provided to the Company through insurance agents, brokers, bancassurance partners, distribution channels, intermediaries, or other persons acting in connection with the offering or servicing of insurance products.
(C) THIRD-PARTY SOURCES
When Personal Data is obtained from third parties, including regulators, government authorities, healthcare providers, hospitals, clinics, reinsurers, business partners, service providers, publicly available sources, and other lawful commercial or industry sources, for purposes such as underwriting, claims assessment, fraud detection, regulatory compliance, or contractual performance.
(D) DIGITAL PLATFORMS AND AUTOMATED TECHNOLOGIES
When you access or use the Company’s websites, applications, online services, social media platforms, or services provided through third-party platforms, where Personal Data may be automatically collected through cookies, tracking technologies, logs, analytics tools, or other automated means.
(E) DURING THE POLICY AND SERVICE LIFECYCLE
When Personal Data is collected or generated during the customer relationship, including during underwriting, policy issuance, premium collection, policy servicing, renewals, endorsements, claims handling, investigations, complaint handling, and post-termination administration.
(F) SECURITY AND PREMISES ACCESS
When you enter, exit, or remain within Company premises, where Personal Data may be collected through access control systems and CCTV recordings for security and safety purposes.
AUTOMATED PROCESSING
In certain circumstances, Personal Data collected through the above channels may be processed using automated systems, analytics tools, or Artificial Intelligence (AI) throughout the AI lifecycle, including data preparation, model development, training, testing, and ongoing monitoring for purposes such as insurance operations, underwriting support, fraud detection, risk assessment, system security, service improvement, operational efficiency.
The Company ensures that such processing is conducted in a lawful, fair, and transparent manner, with appropriate safeguards and human oversight, in accordance with applicable laws and regulatory requirements.
Where you provide Personal Data of other individuals or third parties to the Company (including, but not limited to, applicants, employees, customers, beneficiaries, business partners, family members, or any other related persons), you represent and warrant that:
The provision of Personal Data relating to beneficiaries or other associated individuals shall be in accordance with applicable laws and relevant requirements.
To the fullest extent permitted by law, you agree to indemnify and hold the Company harmless from and against any losses, damages, liabilities, costs, expenses, or sanctions (including legal or litigation costs, fines, penalties, interest, or surcharges imposed by any competent authority) arising from or in connection with your provision of Personal Data in breach of applicable laws or this Privacy Notice, including any act or omission by you or your employees, representatives, agents, or advisors.
The Company reserves the right to refuse, suspend, or limit services where the above requirements are not complied with.
The Company processes Personal Data for the purposes set out in this Privacy Notice, and in accordance with the lawful bases permitted under the PDPA.
4.1 REGULATORY AND SUPERVISORY PURPOSES
The Company may collect, use, and disclose Personal Data as necessary for the supervision and promotion of insurance business by relevant regulatory authorities, including the OIC, in accordance with applicable laws such as the Insurance Commission Act, the Life Insurance Act, and/or the Non-Life Insurance Act, as well as the data protection policies of the OIC.
Further details of the OIC’s policies may be found at: https://www.oic.or.th
4.2 LEGAL BASIS FOR PROCESSING PERSONAL DATA
The Company may process Personal Data for one or more of the following purposes, based on the corresponding legal basis:
1. GENERAL PERSONAL DATA
(A) CONTRACTUAL NECESSITY
For the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract.
(B) LEGAL OBLIGATIONS
For compliance with applicable laws, regulations, or regulatory requirements.
(C) LEGITIMATE INTERESTS
For the legitimate interests of the Company or third parties, provided that such interests are not overridden by your fundamental rights and freedoms.
(D) PUBLIC INTEREST AND OFFICIAL AUTHORITY
For the performance of tasks carried out in the public interest or in the exercise of official authority vested in the Company.
(E) VITAL INTERESTS
To prevent or suppress danger to a person’s life, body, or health.
(F) RESEARCH, STATISTICS, AND ARCHIVAL PURPOSES
For purposes relating to research, statistics, or the preparation of historical documents or archives in the public interest, subject to appropriate safeguards.
(G) SUBSTANTIAL PUBLIC INTEREST
For compliance with laws for purposes relating to substantial public interest, with appropriate measures to protect the rights and interests of the data subject.
(H) LEGAL CLAIMS
For the establishment, exercise, or defense of legal claims.
(I) CONSENT
Where required by applicable laws, and where no other legal basis applies, the Company will process Personal Data based on your explicit consent.
2. SENSITIVE PERSONAL DATA
Sensitive Personal Data will be processed only where necessary and permitted under applicable laws, based on:
4.3 PROCESSING FOR ADDITIONAL OR NEW PURPOSES
Unless otherwise permitted by applicable laws, where the Company intends to process Personal Data for purposes other than those specified in this Privacy Notice, or for purposes not directly related to the original purpose of collection, the Company will notify you of such purposes and, where required, obtain your consent prior to such processing.
4.4 FURTHER INFORMATION
For further details on how the Company processes Personal Data in connection with specific communication channels, transactions, or purposes, please refer to the relevant sections of this Privacy Notice.
USE OF AUTOMATED PROCESSING AND AI
In certain circumstances, the Company may utilize automated systems, analytics tools, or Artificial Intelligence (AI) to support its operations throughout the AI lifecycle, including data preparation, model development and training, testing, deployment, ongoing monitoring, and decommissioning. Such AI-supported activities such as fraud detection, risk monitoring, performance analysis, system security, and operational efficiency.
The Company ensures that such processing is conducted in a lawful, fair, and transparent manner, with appropriate safeguards and human oversight, in accordance with applicable laws.
(A) CORE BUSINESS AND CONTRACTUAL PURPOSES
(B) TRAINING AND DEVELOPMENT
(C) MARKETING AND ENGAGEMENT
(D) BUSINESS OPERATIONS
(E) LEGAL, RISK, AND COMPLIANCE
(F) INFORMATION TECHNOLOGY, SECURITY AND AI
(A) HUMAN RESOURCE MANAGEMENT
(B) WORKPLACE AND OPERATIONAL MANAGEMENT
(C) LEGAL, RISK, AND COMPLIANCE
(D) INFORMATION TECHNOLOGY, SECURITY AND AI
(A) VENDOR AND CONTRACT MANAGEMENT
(B) PROCUREMENT AND BUSINESS OPERATIONS
(C) ADMINISTRATION AND SUPPORT
(D) LEGAL, RISK, AND COMPLIANCE
(E) INFORMATION TECHNOLOGY, SECURITY AND AI
(A) INSURANCE AND CONTRACTUAL PURPOSES
for customer onboarding, pre-contractual assessment, underwriting, policy issuance, contract administration, premium collection, policy servicing, renewals, endorsements, claims handling, benefit payment, and performance of contractual obligations.
(B) CUSTOMER SERVICE AND RELATIONSHIP MANAGEMENT
for responding to inquiries, handling complaints, providing support services, managing customer relationships, facilitating communications, and improving service quality and customer experience.
(C) MEDICAL UNDERWRITING AND CLAIMS ASSESSMENT
for reviewing medical and non-medical underwriting factors, assessing insurability, verifying eligibility, processing claims, investigating claim circumstances, coordinating with healthcare providers, and administering insurance benefits.
(D) MARKETING AND BUSINESS ENGAGEMENT
for marketing communications, product offers, promotional activities, customer segmentation, customer satisfaction surveys, analytics, and customer engagement activities, subject to applicable legal requirements and consent requirements where relevant.
(E) BUSINESS OPERATIONS AND ANALYTICS
for internal reporting, product development, business analysis, service improvement, data analytics, operational planning, quality assurance, and internal business management.
(F) LEGAL, REGULATORY, RISK, AND COMPLIANCE PURPOSES
for complying with applicable laws, regulations, and supervisory requirements, including those prescribed by the Office of Insurance Commission (“OIC”), Anti-Money Laundering laws, fraud prevention requirements, tax obligations, dispute handling, investigations, audits, risk monitoring, and the establishment, exercise, or defense of legal claims.
(G) INFORMATION TECHNOLOGY, SECURITY AND AI
for system access control, authentication, cybersecurity monitoring, fraud detection, incident prevention, IT administration, business continuity, and the operation and improvement of the Company’s systems and infrastructure, including AI systems used in support of insurance operations. This may encompass the use of Personal Data for AI model development, training, testing, calibration, and ongoing monitoring to enhance the accuracy, reliability, and fairness of AI-supported services, subject to appropriate data minimization and safeguards.
The Company is committed to safeguarding your Personal Data and maintaining its confidentiality. Personal Data will only be disclosed where permitted or required by applicable laws, or where necessary for the purposes described in this Privacy Notice.
The Company ensures that any disclosure of Personal Data is carried out subject to appropriate safeguards and in accordance with applicable data protection laws, including the PDPA.
In this regard, the Company may disclose your Personal Data to the following categories of recipients:
INTERNAL PARTIES
Personnel within the Company, including employees, directors, management, and authorized staff, on a need-to-know basis for the performance of their duties
SERVICE PROVIDERS (DATA PROCESSORS)
Third parties engaged by the Company to perform services on its behalf, including but not limited to information technology providers, cloud hosting providers, cloud infrastructure providers, data storage providers, data processing providers, call centers, payment service providers, marketing agencies, AI providers, and other outsourced service providers.
BUSINESS PARTNERS AND COUNTERPARTIES
Persons or entities with whom the Company enters into contractual or business relationships, including distributors, intermediaries, business partners, and other counterparties
INSURANCE RELATED PARTIES
Other insurers, reinsurers, brokers, industry associations, or relevant organizations within the insurance sector
REGULATORY AUTHORITIES AND GOVERNMENT AGENCIES
Competent authorities, including the OIC, Securities and Exchange Commission (“SEC”), law enforcement agencies, courts, or other governmental bodies, where disclosure is required or permitted by law
PROFESSIONAL ADVISORS
Auditors, legal advisors, consultants, and other professional service providers acting on behalf of the Company
AFFILIATES AND GROUP COMPANIES
Companies within the same corporate group, both within Thailand and overseas, for purposes consistent with this Privacy Notice
OTHER THIRD PARTIES
Any other person or entity to whom disclosure is necessary to comply with legal obligations, exercise legal rights, or with your consent
(A) INTERNAL DISCLOSURES
Personal Data may be accessed or disclosed to authorized personnel within the Company on a need-to-know basis, in accordance with the Company’s organizational structure, including:
(B) EXTERNAL DISCLOSURES
The Company may disclose Personal Data to external parties, including:
(A) INTERNAL DISCLOSURES
Personal Data may be disclosed within the Company on a need-to-know basis, including :
(B) EXTERNAL DISCLOSURES
The Company may disclose Personal Data to external parties, including:
(A) INTERNAL DISCLOSURES
Personal Data may be disclosed within the Company on a need-to-know basis, including to relevant departments responsible for procurement, operations, IT, finance, legal, compliance, risk management, and internal audit.
(B) EXTERNAL DISCLOSURES
Personal Data may be disclosed to external parties, including:
(A) INTERNAL DISCLOSURES
Personal Data may be accessed or disclosed to authorized personnel within the Company on a need-to-know basis, including personnel responsible for underwriting, claims, customer service, operations, finance, actuarial, product management, information technology, legal, compliance, risk management, internal audit, and management functions.
(B) EXTERNAL DISCLOSURES
The Company may disclose Personal Data to external parties, including:
The Company may transfer, store, or otherwise process your Personal Data both within and outside the Kingdom of Thailand as part of its normal business operations. This may include the use of cloud-based services, shared servers, centralized systems, outsourcing arrangements, or other cloud infrastructure solutions (including overseas data centers), where Personal Data is handled by affiliated companies, service providers, or third parties located in various jurisdictions.
Such transfers may occur where Personal Data is hosted in cloud environments, processed through regional or global systems, shared within the Company’s group for operational or analytical purposes, or processed by external service providers on the Company’s behalf.
The Company utilizes cloud hosting and cloud infrastructure providers for data storage and processing, which may involve cross-border transfers, subject to appropriate safeguards under applicable laws.
Where Personal Data is transferred to another country, the Company will ensure that such transfer is carried out in compliance with the PDPA, and applicable laws. Appropriate safeguards will be implemented to ensure that Personal Data remains adequately protected, including contractual arrangements, data protection obligations imposed on recipients, and technical and organizational security measures.
The Company establishes and maintains a comprehensive data protection and security framework to ensure that Personal Data is processed in a lawful, secure, and controlled manner throughout its lifecycle, in accordance with the PDPA and applicable regulatory requirements.
7.1 SAFEGUARDING PRINCIPLES
The Company ensures that Personal Data is protected against unauthorized or unlawful access, use, disclosure, alteration, or destruction by implementing appropriate safeguards across all processing activities. Such safeguards include:
7.2 SECURITY MEASURES AND OPERATIONAL CONTROLS
To support the safeguarding of Personal Data, the Company implements appropriate technical and organizational controls, including but not limited to:
7.3 DATA RISK MANAGEMENT
The Company adopts a risk-based approach to managing risks associated with the processing of Personal Data, including those arising from modern technologies and outsourcing arrangements.
Key risk areas may include:
To mitigate such risks, the Company implements appropriate controls, including:
7.4 GOVERNANCE AND CONTINUOUS IMPROVEMENT
The Company maintains an information security and privacy management framework aligned with internationally recognized standards, including ISO/IEC 27001 (Information Security Management) and ISO/IEC 27701 (Privacy Information Management).
The Company ensures that:
These controls apply to both on-premises and cloud-based environments, ensuring a consistent level of protection regardless of where Personal Data is processed.
The Company is committed to retaining Personal Data strictly in accordance with the purposes set out in this Privacy Notice and in compliance with applicable laws and regulatory requirements. Personal Data will be retained only for as long as necessary to fulfill such purposes and will not be kept longer than is reasonably required.
Throughout the retention period, the Company ensures that Personal Data is maintained securely at all times, subject to appropriate technical and organizational safeguards, and strictly limited to access by authorized personnel on a need-to-know basis.
The Company regularly and systematically reviews retained Personal Data to ensure that it remains necessary, relevant, and not excessive in relation to the purposes for which it is processed.
Upon expiry of the applicable retention period, Personal Data will be securely deleted, destroyed, or anonymized in a timely and controlled manner, in accordance with established internal policies, regulatory requirements, and recognized security standards. In general, such disposal will be carried out within a period not exceeding two (2) years from the expiry of the retention period, based on defined and monitored deletion cycles, except there is an unexpected event preventing us in doing so.
The Company ensures that appropriate governance, oversight, and controls are in place throughout the data lifecycle to safeguard Personal Data and to ensure full compliance with applicable data protection laws.
The applicable retention periods are as follows:
The applicable retention periods are as follows:
The applicable retention periods are as follows:
In general, Personal Data relating to policy owners, policyholders, insured persons, beneficiaries, payors, and other persons connected with an insurance relationship will be retained for the duration of the contractual or insurance relationship and for up to ten (10) years following termination, lapse, expiry, closure of claim, or last interaction with the Company, unless a longer retention period is required or permitted by law, including for regulatory compliance or legal claims.
Operational data such as CCTV footage, access logs, call records, and certain technical logs will generally be retained for a shorter period, typically ranging from thirty (30) to ninety (90) days, depending on the nature and purpose of such data.
You are entitled to exercise your rights as a data subject in accordance with the PDPA and applicable laws.
You may submit a request to exercise your rights at: https://www.tokiomarinelife.co.th/pdpa/en
The Company may prescribe appropriate forms, procedures, and conditions for the exercise of each type of right as required by applicable law.
In the event that any law, notification, regulation, guideline, or requirement issued by a relevant regulatory authority provides additional rights to data subjects, or if there are any subsequent amendments to the details regarding the exercise of such rights, the Company will comply with the applicable legal requirements and may revise the relevant details concerning the exercise of rights, including the forms, procedures, and channels for submitting requests, as appropriate.
For the latest information regarding data subject rights, the procedures for exercising such rights, and the channels for submitting requests, please visit https://www.tokiomarinelife.co.th/pdpa/en. The Company uses this channel as its primary means of communicating information relating to data subject rights, including any updates, amendments, or revisions from time to time.
The Company will process your request in accordance with applicable legal requirements.
The Company reserves the right to take reasonable steps to verify your identity prior to processing any request. The Company may refuse to act on your request or may limit the scope of its response where permitted under applicable laws.
Unless otherwise provided by law, you may exercise the following rights:
The exercise of these rights may be subject to conditions, limitations, or exemptions as prescribed under applicable laws.
If you have any questions regarding this Privacy Notice, or wish to exercise your data subject rights, you may contact the Company through the following channels:
DATA PROTECTION OFFICER (DPO)
Email: dpo@tokiomarinelife.co.th
GENERAL CONTACT DETAILS AND CHANNELS FOR SUBMISSION OF REQUESTS UNDER THIS NOTICE
The Company will handle all inquiries and requests in accordance with applicable laws and will take appropriate steps to verify your identity before proceeding.
If you are not satisfied with the Company’s response, you have the right to lodge a complaint with the relevant supervisory authority, i.e., the Personal Data Protection Committee (“PDPC”).
The Company reserves the right to amend, revise, or update this Privacy Notice from time to time, as appropriate and as permitted under applicable laws.
Where any material changes are made, the Company will take reasonable steps to notify you of such changes through appropriate channels. Where required by applicable laws, the Company will obtain your consent prior to implementing such changes.
This Privacy Notice has been updated from the previous Privacy Policy in accordance with OIC regulations and shall take effect on 3 August 2026.
Choose your country or region
Visit HQ Pages
Visit Country Pages
Select your location and language
You are currently on a site outside of your country Switch to external site?
Visit your local page. If you change your mind, you can use the dropdown at the top navigation to visit other Tokio Marine country pages.
You are currently on a site outside of your country. Switch to local site?
Visit your local page. If you change your mind, you can use the dropdown at the top navigation to visit other Tokio Marine country pages.