Privacy Policy Privacy Policy

บทนำ

บริษัท โรงพยาบาลไทยจักษุ จำกัด (“โรงพยาบาล”, “เรา” หรือ “ของเรา”) ให้บริการทางการแพทย์ที่โรงพยาบาลไทยจักษุ พระราม 3 โรงพยาบาลตระหนักถึงความสำคัญของการคุ้มครองข้อมูลส่วนบุคคลของผู้ใช้บริการและมุ่งมั่นที่จะดำเนินการตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA) และกฎหมายที่เกี่ยวข้องทุกฉบับ นโยบายความเป็นส่วนตัวฉบับนี้อธิบายถึงวิธีการที่โรงพยาบาลเก็บรวบรวม ใช้ เปิดเผย และปกป้องข้อมูลส่วนบุคคลของท่านในฐานะผู้ป่วย ผู้ใช้บริการ หรือผู้เยี่ยมชมเว็บไซต์และช่องทางการติดต่อต่าง ๆ ของโรงพยาบาล นโยบายความเป็นส่วนตัวนี้ครอบคลุมการให้บริการต่าง ๆ ของโรงพยาบาล แก่ผู้ใช้งาน ท่านยอมรับว่า การที่ท่านใช้บริการของโรงพยาบาลผ่านทางช่องทางต่าง ๆ หรือการให้ข้อมูลกับโรงพยาบาล ถือว่าท่านได้ยอมรับวิธีปฏิบัติของโรงพยาบาลตามที่ระบุในนโยบายความเป็นส่วนตัวนี้แล้ว ทั้งนี้ โรงพยาบาล มีนโยบายในการพัฒนาและปรับปรุงการให้บริการให้มีความทันสมัย มีประสิทธิภาพและเป็นไปตามหลักธรรมาภิบาลและกฎหมายที่เกี่ยวข้องอยู่เสมอ โรงพยาบาล จึงอาจมีการปรับปรุงแก้ไขนโยบายความเป็นส่วนตัวนี้เป็นครั้งคราว จึงขอให้ท่านตรวจสอบนโยบายนี้เป็นระยะ ๆ เพื่อที่ท่านจะได้ทราบนโยบายความเป็นส่วนตัวล่าสุดของโรงพยาบาล

เพื่อความสะดวกของท่าน ท่านสามารถอ่านที่ชื่อของแต่ละหัวข้อเพื่ออ่านนโยบายความเป็นส่วนตัวนี้เป็นรายหัวข้อ ดังนี้

1. คำนิยาม

ภายในนโยบายฉบับนี้

  • “ผู้ควบคุมข้อมูล” หมายความว่า ผู้ให้บริการ ตามนโยบายฉบับนี้ อันได้แก่ บริษัท โรงพยาบาลไทยจักษุ จำกัด ตั้งอยู่ที่ 168 ถนนเจริญราษฎร์ แขวงบางโคล่ เขตบางคอแหลม กรุงเทพมหานคร 10120 ติดต่อ เจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (DPO) อีเมล [email protected] โทรศัพท์ (+66)2-689-8888
  • “ผู้ประมวลผลข้อมูล” หมายความว่า บุคคลภายนอกซึ่งประมวลข้อมูลเพื่อประโยชน์หรือในนามของผู้ควบคุมข้อมูล
  • “การประมวลผลข้อมูล” หมายความว่า การดำเนินการใด ๆ ซึ่งกระทำต่อข้อมูลส่วนบุคคลหรือชุดข้อมูลส่วนบุคคล ไม่ว่าจะโดยวิธีการอัตโนมัติหรือไม่ เช่น การเก็บ บันทึก จัดระบบ จัดโครงสร้างเก็บรักษา เปลี่ยนแปลงหรือปรับเปลี่ยน การรับ พิจารณา ใช้ เปิดเผยด้วยการส่งต่อ เผยแพร่ หรือการกระทำอื่นใดซึ่งทำให้เกิดความพร้อม ใช้งาน การจัดวางหรือผสมเข้าด้วยกัน การจำกัด การลบ หรือการทำลาย
  • “ข้อมูล” หมายความว่า ข้อมูลส่วนบุคคล ข้อมูลซึ่งไม่ใช่ข้อมูลส่วนบุคคล ข้อมูลระบบ
  • “ข้อมูลส่วนบุคคล” หมายความว่า ข้อมูลเกี่ยวกับบุคคลซึ่งทำให้สามารถระบุตัวบุคคลนั้นได้ไม่ว่าทางตรงหรือทางอ้อม
  • “ผู้ใช้งาน” หมายความว่า ท่าน ผู้เยี่ยมชม ผู้ใช้งาน ซึ่งเป็นเจ้าของข้อมูลส่วนบุคคลตามนโยบายฉบับนี้

2. แหล่งและวิธีที่ได้มาซึ่งข้อมูลส่วนบุคคลของท่าน

จากท่านโดยตรง เช่น ข้อมูลที่ท่านกรอกขณะลงทะเบียน หรือข้อมูลที่ผู้ใช้งานได้แก้ไขปรับปรุงในข้อมูลบัญชีของท่าน ทั้งนี้ เพื่อประโยชน์ในการปรับปรุงข้อมูลส่วนบุคคลของท่านเป็นปัจจุบัน และเพื่อปรับปรุงคุณภาพและประสิทธิภาพของผลิตภัณฑ์และการให้บริการของโรงพยาบาลให้ดียิ่งขึ้น

3. ข้อมูลที่โรงพยาบาลเก็บรวบรวม

– ข้อมูลส่วนบุคคลทั่วไป

  • ชื่อ-นามสกุล วันเดือนปีเกิด เพศ และสัญชาติ
  • หมายเลขบัตรประจำตัวประชาชน หรือหนังสือเดินทาง
  • ที่อยู่ หมายเลขโทรศัพท์ และอีเมล
  • ข้อมูลผู้ติดต่อฉุกเฉิน
  • ข้อมูลการชำระเงินและการประกันสุขภาพ

– ข้อมูลสุขภาพและการแพทย์ (ข้อมูลอ่อนไหว)

  • ประวัติทางการแพทย์ การวินิจฉัยโรค และผลการตรวจสุขภาพ
  • ข้อมูลการรักษา ยา และกระบวนการทางการแพทย์
  • ผลการตรวจทางห้องปฏิบัติการ ภาพถ่าย และผลการสแกน
  • บันทึกทางการพยาบาลและเวชระเบียน
  • ข้อมูลทางพันธุกรรม (หากเกี่ยวข้องกับการรักษา)

– ข้อมูลที่เก็บโดยอัตโนมัติ

  • ข้อมูลการเข้าใช้เว็บไซต์ (IP Address, คุกกี้, Log Files)
  • ข้อมูลอุปกรณ์และเบราว์เซอร์
  • ข้อมูลการนัดหมายผ่านระบบออนไลน์

4. วัตถุประสงค์ในการเก็บและใช้ข้อมูล

– ฐานทางกฎหมายในการประมวลผล

โรงพยาบาลประมวลผลข้อมูลส่วนบุคคลของท่านโดยอาศัยฐานทางกฎหมาย ดังนี้

  • การปฏิบัติตามสัญญา: เพื่อให้บริการทางการแพทย์ที่ท่านร้องขอ
  • ประโยชน์อันชอบด้วยกฎหมาย: เพื่อการบริหารงานโรงพยาบาลและการพัฒนาคุณภาพบริการ
  • การปฏิบัติตามกฎหมาย: เพื่อปฏิบัติตามข้อกำหนดทางกฎหมายด้านสาธารณสุขและวิชาชีพแพทย์
  • ความยินยอม: สำหรับข้อมูลอ่อนไหวและกิจกรรมที่เกินขอบเขตการรักษาโดยตรง เช่น การส่งข่าวสารการตลาด

– วัตถุประสงค์ในการใช้ข้อมูล

  • การให้บริการทางการแพทย์ การวินิจฉัย และการรักษา
  • การติดตามผลการรักษาและการนัดหมาย
  • การเรียกเก็บค่าบริการและการดำเนินการด้านประกันสุขภาพ
  • การพัฒนาคุณภาพและความปลอดภัยของบริการ
  • การวิจัยทางการแพทย์ (โดยได้รับความยินยอมและผ่านการทำให้ข้อมูลไม่สามารถระบุตัวตนได้)
  • การแจ้งเตือนด้านสุขภาพและข่าวสารที่เกี่ยวข้อง
  • การยืนยัน และ/หรือ ระบุตัวตนของเจ้าของข้อมูลส่วนบุคคลในการเข้าใช้บริการผ่านช่องทางต่าง ๆ หรือการติดต่อกับโรงพยาบาล
  • การติดต่อสื่อสาร แจ้ง และ/หรือ รับข้อมูลข่าวสารต่าง ๆ จากโรงพยาบาล หรือการเปลี่ยนแปลงต่าง ๆ ที่เกิดขึ้นของโรงพยาบาล
  • การดูแล การบำรุงรักษา และการดำเนินการ ที่เกี่ยวข้องกับการให้บริการ
  • การดำเนินการใด ๆ ที่จำเป็นและเหมาะสมในการตรวจสอบและป้องกันการกระทำที่ละเมิดหรืออาจจะละเมิดต่อกฎหมาย
  • การปฏิบัติตามกฎหมาย การสืบสวนของเจ้าพนักงาน หรือหน่วยงานกำกับดูแลหรือเพื่อให้เป็นไปตามกฎ ข้อบังคับ หรือข้อผูกพันที่กฎหมายหรือภาครัฐกำหนด

ทั้งนี้ สำหรับวัตถุประสงค์อื่น ๆ ที่ไม่ได้ระบุไว้ข้างต้น เจ้าของข้อมูลส่วนบุคคลจะได้รับการแจ้งเมื่อโรงพยาบาลมีการขอเก็บรวบรวมข้อมูลส่วนบุคคล อนึ่ง ในการได้ข้อมูลส่วนบุคคลของท่านมานั้น โรงพยาบาลจะเก็บรวบรวม ใช้ หรือเปิดเผยข้อมูลส่วนบุคคลของท่านภายใต้วัตถุประสงค์ตาม ข้อ 4. เฉพาะเมื่อเข้าเงื่อนไขดังต่อไปนี้:

  • ท่านจะอนุญาตและได้ให้ความยินยอมไว้กับโรงพยาบาลตามกฎหมาย
  • เป็นการจำเป็นเพื่อการปฏิบัติหน้าที่ในการดำเนินภารกิจเพื่อประโยชน์สาธารณะของโรงพยาบาล หรือปฏิบัติหน้าที่ในการใช้อำนาจที่รัฐได้มอบหมายให้แก่โรงพยาบาล
  • เป็นความจำเป็นเพื่อปฏิบัติตามกฎหมาย

5. การเปิดเผยข้อมูลแก่บุคคลภายนอก

โรงพยาบาลจะไม่ขาย ให้เช่า หรือเปิดเผยข้อมูลส่วนบุคคลของท่านแก่บุคคลภายนอกเพื่อวัตถุประสงค์ทางการค้า เว้นแต่กรณีดังต่อไปนี้

  • แพทย์ พยาบาล และบุคลากรทางการแพทย์ที่เกี่ยวข้องกับการรักษาของท่าน
  • โรงพยาบาลหรือสถานพยาบาลที่รับการส่งตัวผู้ป่วย
  • บริษัทประกันสุขภาพของท่าน (ตามที่ท่านให้ความยินยอม)
  • ผู้ให้บริการภายนอกที่ได้รับมอบหมาย เช่น ห้องปฏิบัติการ ผู้ให้บริการระบบสารสนเทศ
  • หน่วยงานรัฐ เช่น สำนักงานคณะกรรมการอาหารและยา กระทรวงสาธารณสุข ตามที่กฎหมายกำหนด
  • กรณีที่จำเป็นเพื่อป้องกันอันตรายต่อชีวิตหรือสุขภาพ

6. ระยะเวลาการเก็บรักษาข้อมูล

โรงพยาบาลจะเก็บรักษาข้อมูลส่วนบุคคลของท่านตามระยะเวลาดังนี้

  • เวชระเบียนและข้อมูลทางการแพทย์: อย่างน้อย 10 ปีนับจากวันที่รักษาครั้งสุดท้าย หรือตามที่กฎหมายกำหนด
  • ข้อมูลการเงินและการชำระเงิน: 5-10 ปี ตามกฎหมายบัญชีและภาษีอากร
  • ข้อมูลเว็บไซต์และคุกกี้: ตามที่ระบุในข้อ 13. คุกกี้และเทคโนโลยีติดตาม

โดยคำนึงถึงวัตถุประสงค์และความจำเป็นที่โรงพยาบาลจะต้องดำเนินการจัดเก็บรวบรวมและประมวลผล เว้นแต่กรณีที่กฎหมายกำหนดหรืออนุญาตให้เก็บรักษาข้อมูลไว้นานกว่า ซึ่งอาจมีกำหนดประมาณ 5 – 10 ปี หรือเกินกว่านั้นเท่าที่จำเป็น เช่น ตามอายุความที่กฎหมายกำหนดสำหรับเรื่องที่เกี่ยวข้อง เพื่อการดำเนินคดี หรือเพื่อการตรวจสอบของหน่วยงานที่กำกับดูแล โดยโรงพยาบาลจะจัดเก็บไว้ในสถานที่จัดเก็บที่เหมาะสมตามประเภทของข้อมูลส่วนบุคคล ทั้งนี้โรงพยาบาลจำเป็นต้องเก็บข้อมูลส่วนบุคคลต่อไปแม้จะพ้นกำหนดอายุความตามกฎหมายแล้วก็ตาม เช่น กรณีอยู่ระหว่างการดำเนินคดีหรือพิจารณาคดีตามกฎหมาย เป็นต้น

ทั้งนี้ โรงพยาบาลจะเก็บรักษาข้อมูลส่วนบุคคลของท่านไว้เป็นอย่างดีตามมาตราการป้องกันด้านการบริหารจัดการ (administrative safeguard) มาตรการป้องกันด้านเทคนิค (technical safeguard) และมาตรการป้องกันทางกายภาพ (physical safeguard) เพื่อรักษาความมั่นคงปลอดภัยในการประมวลผลข้อมูลส่วนบุคคลที่เหมาะสม หมายความว่า มีการธำรงไว้ซึ่งความลับ (confidentiality) ความถูกต้องครบถ้วน (integrity) และให้ข้อมูลอยู่ในลักษณะที่พร้อมใช้งาน (availability) และเพื่อป้องกันการละเมิดข้อมูลส่วนบุคคล โดยโรงพยาบาล ได้กำหนดนโยบาย ระเบียบ และหลักเกณฑ์ในการคุ้มครองข้อมูลส่วนบุคคล เช่น มาตรฐานความปลอดภัยของระบบเทคโนโลยีสารสนเทศ และมาตรการเพื่อป้องกันไม่ให้ผู้รับข้อมูลไปจากโรงพยาบาล ใช้หรือเปิดเผยข้อมูลนอกวัตถุประสงค์ หรือโดยไม่มีอำนาจหรือโดยไม่ชอบ และโรงพยาบาล ได้มีการปรับปรุงนโยบาย ระเบียบ และหลักเกณฑ์ดังกล่าวเป็นระยะ ๆ ตามความจำเป็นและเหมาะสม

นอกจากนี้ โรงพยาบาล ยังได้กำหนดให้พนักงาน บุคลากร และผู้รับข้อมูลจากโรงพยาบาล มีหน้าที่รักษาข้อมูลส่วนบุคคลของท่านไว้เป็นความลับและมีความปลอดภัยตามมาตรการที่โรงพยาบาลกำหนด เมื่อต้องมีการดำเนินการใด ๆ กับข้อมูลส่วนบุคคลของท่าน

7. การโอน ถ่าย และ/หรือ ส่งข้อมูลส่วนบุคคลไปยังต่างประเทศ

ในกรณีที่โรงพยาบาลมีการโอน ถ่าย และ/หรือ ส่งข้อมูลไปยังต่างประเทศ โรงพยาบาลจะกำหนดมาตรฐานในการทำข้อตกลง และ/หรือ สัญญาร่วมธุรกิจกับโรงพยาบาล องค์กรที่จะได้รับข้อมูลส่วนบุคคลนั้น มีมาตรฐานการคุ้มครองข้อมูลส่วนบุคคลที่เป็นที่ยอมรับ และสอดคล้องกับกฎหมายที่เกี่ยวข้อง เพื่อให้มั่นใจว่าข้อมูลส่วนบุคคลนั้น จะได้รับการคุ้มครองอย่างปลอดภัย อาทิเช่น

  • กรณีที่โรงพยาบาลมีความจำเป็นในการจัดเก็บ และ/หรือ โอน ถ่าย ข้อมูลส่วนบุคคล เพื่อการจัดเก็บ
  • การประมวลผลในระบบคลาวด์ (Cloud) โรงพยาบาลจะพิจารณาองค์กรที่มีมาตรฐานความมั่นคงปลอดภัยในระดับสากล และจะจัดเก็บข้อมูลส่วนบุคคลในรูปแบบการเข้ารหัส หรือวิธีการอื่น ๆ ที่ไม่สามารถระบุตัวตนของเจ้าของข้อมูลส่วนบุคคลได้ เป็นต้น

ผู้ควบคุมข้อมูลอาจส่งหรือโอนข้อมูลส่วนบุคคลของผู้ใช้งานไปยังต่างประเทศได้ในกรณีดังต่อไปนี้

  • ประเทศปลายทางหรือองค์การระหว่างประเทศที่รับข้อมูลส่วนบุคคลนั้นมีมาตรฐานการคุ้มครองข้อมูลส่วนบุคคลที่เพียงพอตามที่กฎหมาย กฎ ระเบียบ ข้อบังคับเกี่ยวกับการคุ้มครองข้อมูลส่วนบุคคล
  • ได้รับความยินยอมจากเจ้าของข้อมูลส่วนบุคคล โดยที่ผู้ใช้งานเจ้าของข้อมูลส่วนบุคคลได้รับแจ้งและรับทราบถึงมาตรฐานการคุ้มครองข้อมูลส่วนบุคคลที่ไม่เพียงพอของประเทศปลายทางหรือองค์การระหว่างประเทศที่รับข้อมูลนั้นแล้ว
  • เป็นการปฏิบัติตามกฎหมาย
  • เป็นการจำเป็นเพื่อการปฏิบัติตามสัญญาซึ่งผู้ใช้งานเจ้าของข้อมูลส่วนบุคคลเป็นคู่สัญญานั้นหรือเพื่อใช้ในการดำเนินการตามคำขอของผู้ใช้งานเจ้าของข้อมูลส่วนบุคคลก่อนการเข้าทำสัญญานั้น
  • เป็นการกระทำการตามสัญญาระหว่างผู้ควบคุมข้อมูลกับบุคคลอื่นโดยเป็นไปเพื่อประโยชน์ของผู้ใช้งานเจ้าของข้อมูลส่วนบุคคลนั้น
  • เพื่อป้องกันหรือระงับอันตรายต่อชีวิต ร่างกาย หรือสุขภาพของผู้ใช้งานเจ้าของข้อมูลส่วนบุคคลนั้นหรือบุคคลใด ๆ เมื่อเจ้าของข้อมูลส่วนบุคคลไม่สามารถให้ความยินยอมในขณะนั้นได้
  • เป็นการจำเป็นเพื่อการดำเนินภารกิจเพื่อประโยชน์สาธารณะที่สำคัญ

อนึ่งเจ้าของข้อมูลส่วนบุคคลสามารถตรวจสอบรายชื่อบุคคลภายนอกที่โรงพยาบาลจะทำการเปิดเผยข้อมูลส่วนบุคคลได้จาก รายชื่อพันธมิตรทางธุรกิจ โดยสามารถขอรับรายชื่อดังกล่าวได้จากเจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (DPO) ตามช่องทางการติดต่อในข้อ 14. ทั้งนี้ รายชื่อบุคคลภายนอกที่โรงพยาบาลจะทำการเปิดเผยข้อมูลส่วนบุคคลนั้น อาจมีการเปลี่ยนแปลง เพิ่มขึ้น หรือลดลงได้ ซึ่งโรงพยาบาลจะทำข้อมูลให้เป็นปัจจุบันเสมอ

8. สิทธิของเจ้าของข้อมูลส่วนบุคคล

ท่านมีสิทธิในฐานะเจ้าของข้อมูลส่วนบุคคลตามกฎหมายคุ้มครองข้อมูลส่วนบุคคลอันรวมถึงแต่ไม่จำกัดเพียงสิทธิของผู้ใช้งาน ดังต่อไปนี้

  • สิทธิในการเข้าถึงข้อมูล: ขอรับสำเนาข้อมูลส่วนบุคคลที่โรงพยาบาลเก็บไว้
  • สิทธิในการแก้ไขข้อมูล: ขอแก้ไขข้อมูลที่ไม่ถูกต้องหรือไม่สมบูรณ์
  • สิทธิในการลบข้อมูล: ขอให้ลบหรือทำลายข้อมูล เมื่อพ้นความจำเป็นหรือถอนความยินยอม
  • สิทธิในการระงับการใช้ข้อมูล: ขอให้ระงับการประมวลผลข้อมูลชั่วคราว
  • สิทธิในการโอนย้ายข้อมูล: ขอรับข้อมูลในรูปแบบที่อ่านได้ด้วยเครื่อง
  • สิทธิในการคัดค้าน: คัดค้านการประมวลผลข้อมูลที่อาศัยฐานประโยชน์อันชอบด้วยกฎหมาย
  • สิทธิในการถอนความยินยอม: ถอนความยินยอมที่ให้ไว้ได้ทุกเมื่อ
  • สิทธิในการร้องเรียน: ร้องเรียนต่อโรงพยาบาล หากท่านเชื่อว่าการเก็บรวบรวม ใช้ และเปิดเผยข้อมูลส่วนบุคคลของท่านเป็นการกระทำในลักษณะที่ฝ่าฝืนหรือไม่ปฏิบัติตามกฎหมายที่เกี่ยวข้อง โปรดดูข้อ 14.

ท่านสามารถใช้สิทธิดังกล่าวได้โดยติดต่อเจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (DPO) ของโรงพยาบาลตามช่องทางที่ระบุในข้อ 14. โรงพยาบาลจะดำเนินการตามคำขอภายใน 30 วันนับแต่วันที่ได้รับคำขอ และมีบางกรณีที่มีเหตุจำเป็นที่โรงพยาบาล อาจปฏิเสธหรือไม่สามารถดำเนินการตามคำขอใช้สิทธิข้างต้นของท่านได้ เช่น ต้องปฏิบัติตามกฎหมายหรือคำสั่งศาล เพื่อประโยชน์สาธารณะ การใช้สิทธิอาจละเมิดสิทธิหรือเสรีภาพของบุคคลอื่น เป็นต้น โดยหากโรงพยาบาลปฏิเสธคำขอข้างต้น โรงพยาบาล จะแจ้งเหตุผลของการปฏิเสธให้ท่านทราบด้วย

9. มาตรการรักษาความปลอดภัยของข้อมูล

โรงพยาบาลใช้มาตรการทางเทคนิคและการบริหารจัดการที่เหมาะสมเพื่อปกป้องข้อมูลส่วนบุคคลของท่านจากการเข้าถึง การใช้ การเปิดเผย การแก้ไข หรือการทำลายโดยไม่ได้รับอนุญาต ซึ่งรวมถึง

  • การเข้ารหัสข้อมูล (Encryption) ในระบบจัดเก็บและการส่งผ่านข้อมูล
  • การควบคุมการเข้าถึงระบบตามบทบาทหน้าที่ (Role-Based Access Control)
  • การฝึกอบรมบุคลากรด้านการคุ้มครองข้อมูลส่วนบุคคลเป็นประจำ
  • การตรวจสอบและประเมินความเสี่ยงด้านความปลอดภัยของระบบอย่างสม่ำเสมอ
  • นโยบายการจัดการข้อมูลสำรองและการกู้คืนระบบ

10.การเก็บรวบรวมใช้และ/หรือเปิดเผยข้อมูลส่วนบุคคลตามกฎหมายคุ้มครองข้อมูลส่วนบุคคล

ผู้ใช้งานรับทราบและตกลงว่าผู้ควบคุมข้อมูลอาจเก็บรวบรวม ใช้ และ/หรือเปิดเผยข้อมูลของผู้ใช้งานได้โดยไม่ต้องได้รับความยินยอมจากผู้ใช้งานก่อนล่วงหน้า ทั้งนี้เท่าที่จำเป็นและตราบเท่าที่เป็นไปตามวัตถุประสงค์และในกรณีดังต่อไปนี้เท่านั้น

  • เพื่อให้บรรลุวัตถุประสงค์ที่เกี่ยวกับการจัดทำเอกสารประวัติศาสตร์หรือจดหมายเหตุเพื่อประโยชน์สาธารณะ หรือเกี่ยวกับการศึกษาวิจัยหรือสถิติซึ่งได้จัดให้มีมาตรการปกป้องที่เหมาะสมเพื่อคุ้มครองสิทธิและเสรีภาพของข้อมูลส่วนบุคคลของผู้ใช้งาน
  • เพื่อป้องกันหรือระงับอันตรายต่อชีวิต ร่างกาย หรือสุขภาพของบุคคลใด ๆ
  • เป็นการจำเป็นเพื่อการปฏิบัติตามสัญญาซึ่งผู้ใช้งานเจ้าของข้อมูลส่วนบุคคลนั้นเป็นคู่สัญญาหรือเพื่อใช้ในการดำเนินการตามคำขอของผู้ใช้งานเจ้าของข้อมูลส่วนบุคคลก่อนเข้าทำสัญญาดังกล่าวนั้น
  • เป็นการจำเป็นเพื่อการปฏิบัติหน้าที่ในการดำเนินการเพื่อประโยชน์สาธารณะของผู้ควบคุมข้อมูลหรือปฏิบัติหน้าที่ในการใช้อำนาจรัฐที่ได้มอบให้แก่ผู้ควบคุมข้อมูลนั้น
  • เป็นการจำเป็นเพื่อประโยชน์โดยชอบด้วยกฎหมายของผู้ควบคุมข้อมูลหรือของบุคคลอื่นซึ่งประโยชน์ดังกล่าวมีความสำคัญมากกว่าสิทธิขั้นพื้นฐานในข้อมูลส่วนบุคคลของผู้ใช้งานนั้น
  • เป็นการปฏิบัติตามกฎหมายของผู้ควบคุมข้อมูล

ทั้งนี้ ผู้ควบคุมข้อมูลจะบันทึกการเก็บรวบรวม ใช้ หรือเปิดเผยข้อมูลส่วนบุคคลของผู้ใช้งานตามวรรคก่อนหน้าไว้เป็นสำคัญ

11. การใช้งานของบุคคลซึ่งอยู่ในความปกครอง อนุบาล หรือพิทักษ์ของผู้ใช้งาน

ผู้ใช้งานรับรองว่าตนจะไม่เป็นและจะไม่ยินยอมให้บุคคลซึ่งเป็นบุคคลบกพร่องความสามารถตามกฎหมายดังต่อไปนี้ เยี่ยมชม ใช้งาน หรือเป็นสมาชิกของเว็บไซต์และแอปพลิเคชัน

  1. คนไร้ความสามารถซึ่งอยู่ในความอนุบาลของผู้ใช้งาน
  2. คนเสมือนไร้ความสามารถซึ่งอยู่ในความพิทักษ์ของผู้ใช้งาน

ในกรณีที่ผู้ใช้งานยินยอมให้บุคคลดังกล่าวข้างต้นเยี่ยมชม หรือใช้งาน ผู้ใช้งานตกลงให้ถือว่าผู้ใช้งานได้ใช้อำนาจปกครอง อนุบาล หรือพิทักษ์ของบุคคลดังกล่าว แล้วแต่กรณี ในการตกลงและให้ความยินยอมตามนโยบายฉบับนี้ทั้งสิ้นเพื่อและในนามของบุคคลดังกล่าวด้วย

12. การแจ้งเตือนเหตุการละเมิดข้อมูลส่วนบุคคล

ในกรณีที่ผู้ควบคุมข้อมูลทราบถึงการละเมิดข้อมูลส่วนบุคคลไม่ว่าจะมีการละเมิดโดยบุคคลใด ผู้ควบคุมข้อมูลจะดำเนินการดังต่อไปนี้

  • ในกรณีมีความเสี่ยงที่จะมีผลกระทบต่อสิทธิหรือเสรีภาพของบุคคลใด ๆ ผู้ควบคุมข้อมูลจะแจ้งเหตุการละเมิดข้อมูลส่วนบุคคลดังกล่าวต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล โดยไม่ชักช้าเท่าที่จะสามารถกระทำได้ภายใน 72 (เจ็ดสิบสอง) ชั่วโมงนับตั้งแต่ทราบเหตุ
  • ในกรณีมีความเสี่ยงที่จะมีผลกระทบอย่างสูงต่อสิทธิหรือเสรีภาพของบุคคลใด ๆ ผู้ควบคุมข้อมูลจะแจ้งเหตุการละเมิดข้อมูลส่วนบุคคลดังกล่าวและแนวทางการเยียวยาต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคลและต่อผู้ใช้งานเจ้าของข้อมูลส่วนบุคคลนั้น โดยไม่ชักช้าเท่าที่จะสามารถกระทำได้ภายใน 72 (เจ็ดสิบสอง) ชั่วโมงนับแต่ทราบเหตุ

13. คุกกี้และเทคโนโลยีติดตาม

เว็บไซต์ของโรงพยาบาลใช้คุกกี้และเทคโนโลยีติดตามที่คล้ายคลึงกันเพื่อปรับปรุงประสบการณ์การใช้งาน ท่านสามารถตั้งค่าการยอมรับคุกกี้ผ่านเบราว์เซอร์ของท่าน อย่างไรก็ตาม การปฏิเสธคุกกี้บางประเภทอาจส่งผลต่อการทำงานของเว็บไซต์

  • คุกกี้ที่จำเป็น: สำหรับการทำงานพื้นฐานของเว็บไซต์
  • คุกกี้เพื่อวิเคราะห์: เพื่อวิเคราะห์พฤติกรรมการใช้งาน (ต้องได้รับความยินยอม)
  • คุกกี้ทางการตลาด: สำหรับการแสดงโฆษณาที่เกี่ยวข้อง (ต้องได้รับความยินยอม)

14. ช่องทางการติดต่อ

หากท่านมีข้อสงสัย ต้องการใช้สิทธิ หรือต้องการแจ้งข้อร้องเรียนเกี่ยวกับการคุ้มครองข้อมูลส่วนบุคคล กรุณาติดต่อ

Thai Eye Center

ที่อยู่: 168 ถนนเจริญราษฎร์ แขวงบางโคล่ เขตบางคอแหลม กรุงเทพมหานคร 10120

Tel: (+66)2-689-8888

อีเมล: [email protected]

ท่านมีสิทธิร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.) หากพบว่าโรงพยาบาลไม่ปฏิบัติตาม PDPA

15. การเปลี่ยนแปลงนโยบาย

โรงพยาบาลขอสงวนสิทธิ์ในการแก้ไขหรือปรับปรุงนโยบายความเป็นส่วนตัวนี้เป็นครั้งคราวเพื่อให้สอดคล้องกับการเปลี่ยนแปลงทางกฎหมาย ระเบียบปฏิบัติ หรือแนวทางปฏิบัติของโรงพยาบาล โรงพยาบาลจะแจ้งให้ท่านทราบเมื่อมีการเปลี่ยนแปลงสาระสำคัญผ่านทางเว็บไซต์หรือช่องทางการติดต่ออื่น ๆ ที่เหมาะสม

16. กฎหมายที่ใช้บังคับ

นโยบายฉบับนี้ให้อยู่ภายใต้บังคับกฎหมายของประเทศไทย

17. การระงับข้อพิพาท

หากมีข้อโต้เถียง ข้อขัดแย้งใด ๆ เกิดขึ้นอันเนื่องมาจากนโยบายฉบับนี้ หากคู่สัญญาไม่สามารถตกลงกันได้ คู่สัญญาตกลงจะนำข้อพิพาทดังกล่าวขึ้นฟ้องต่อศาลในประเทศไทย

ประกาศความเป็นส่วนตัวมีผลใช้บังคับตั้งแต่วันที่ 12 มิถุนายน 2569

Introduction

Thai Eye Hospital Co., Ltd. (the “Hospital,” “we,” or “our”) provides medical services at Thai Eye Hospital. The Hospital recognizes the importance of protecting the personal data of its service users and is committed to complying with the Personal Data Protection Act B.E. 2562 (2019) (PDPA) and all related laws.

This Privacy Policy explains how the Hospital collects, uses, discloses, and protects your personal data in your capacity as a patient, service user, or visitor to the Hospital’s websites and various contact channels.

This Privacy Policy covers the various services provided by the Hospital to the User. You agree that your use of the Hospital’s services through various channels or your provision of information to the Hospital constitutes your acceptance of the Hospital’s practices as specified in this Privacy Policy. Furthermore, the Hospital maintains a policy of continuously developing and improving its services to be modern, efficient, and consistently compliant with good corporate governance principles and relevant laws. Therefore, the Hospital may amend this Privacy Policy from time to time. You are encouraged to periodically review this policy to stay informed of the Hospital’s latest privacy practices.

For your convenience, you may click on the title of each section to read this Privacy Policy section by section, as follows:

1. Definitions

Within this Policy:

  • (a) “Data Controller” means the service provider under this policy, namely Thai Eye Hospital Co., Ltd., located at 168 Charoen Rat Road, Bang Khlo, Bang Kho Laem, Bangkok 10120, Contact: Data Protection Officer (DPO), Email: [email protected], Tel. (+66)2-689-8888.
  • (b) “Data Processor” means a third party who processes data for the benefit of, or on behalf of, the Data Controller.
  • (c) “Data Processing” means any operation performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
  • (d) “Data” means personal data, non-personal data, and system data.
  • (e) “Personal Data” means any information relating to a person, which enables the identification of such person, whether directly or indirectly.
  • (f) “User” means you, a visitor, or a user, who is the data subject under this policy.

2. Sources and Methods of Acquiring Your Personal Data

Directly from you, such as information you provide during registration, or information the User amends or updates in your account profile. This is for the purpose of keeping your personal data up to date and to improve the quality and efficiency of the Hospital’s products and services.

3. Data Collected by the Hospital

– General Personal Data:

  • First name, last name, date of birth, gender, and nationality
  • Identification card number or passport number
  • Address, telephone number, and email address
  • Emergency contact information
  • Payment and health insurance information

– Health and Medical Data (Sensitive Data):

  • Medical history, diagnosis, and health examination results
  • Treatment information, medications, and medical procedures
  • Laboratory test results, imaging, and scan results
  • Nursing notes and medical records
  • Genetic data (if relevant to treatment)

– Automatically Collected Data:

  • Website usage data (IP Address, Cookies, Log Files)
  • Device and browser information
  • Online appointment system data

4. Purposes of Data Collection and Use

– Legal Bases for Processing: The Hospital processes your personal data relying on the following legal bases:

  • Contractual Obligation: To provide the medical services you requested.
  • Legitimate Interest: For hospital administration and service quality improvement.
  • Legal Obligation: To comply with legal requirements concerning public health and the medical profession.
  • Consent: For sensitive data and activities outside the direct scope of medical treatment, such as sending marketing communications.

– Purposes of Data Use:

  • To provide medical services, diagnosis, and treatment.
  • To follow up on treatment and manage appointments.
  • To collect service fees and process health insurance claims.
  • To improve the quality and safety of services.
  • For medical research (with consent and after the data has been anonymized).
  • To send health alerts and related news.
  • To verify and/or authenticate the identity of the data subject when accessing services through various channels or contacting the Hospital.
  • To communicate, notify, and/or receive news and information from the Company, or regarding any changes occurring at the Hospital.
  • To oversee, maintain, and carry out operations related to the provision of services.
  • To take any necessary and appropriate actions to investigate and prevent acts that violate or may violate the law.
  • To comply with the law, investigations by competent authorities, or regulatory bodies, or to adhere to rules, regulations, or obligations prescribed by law or the government.

For any other purposes not specified above, the data subject will be notified when the Company requests to collect such personal data. Furthermore, in acquiring your personal data, the Company will collect, use, or disclose your personal data for the purposes under Clause 4 only when the following conditions are met:

(a) You have authorized and given consent to the Company in accordance with the law; (b) It is necessary for the performance of a task carried out in the public interest by the Company, or for the exercising of official authority vested in the Company. (c) It is necessary for compliance with a law.

5. Disclosure of Data to Third Parties

The Hospital will not sell, rent, or disclose your personal data to third parties for commercial purposes, except in the following circumstances:

  • Doctors, nurses, and medical personnel involved in your treatment.
  • Hospitals or medical facilities receiving patient referrals.
  • Your health insurance company (as consented to by you).
  • Assigned third-party service providers, such as laboratories and IT system providers.
  • Government agencies, such as the Food and Drug Administration (FDA) and the Ministry of Public Health, as required by law.
  • Cases where it is necessary to prevent danger to life or health.

6. Data Retention Period

The Hospital will retain your personal data for the following periods:

  • Medical records and medical data: At least 10 years from the date of the last treatment, or as prescribed by law.
  • Financial and payment data: 5-10 years, in accordance with accounting and tax laws.
  • Website and cookie data: As specified in Clause 13 (Cookies and Tracking Technologies).

Retention is based on the purposes and necessities for which the Company must collect and process the data, unless the law prescribes or permits a longer retention period, which may be approximately 5–10 years or longer as necessary, such as the statutory limitation period for relevant matters, for litigation, or for inspection by regulatory bodies. The Hospital will store the data in appropriate storage facilities according to the type of personal data. The Company may need to retain personal data even after the statutory limitation period has expired, such as in cases of ongoing litigation or legal proceedings.

The Hospital will securely maintain your personal data using appropriate administrative safeguards, technical safeguards, and physical safeguards to ensure the security of personal data processing. This means maintaining confidentiality, integrity, and availability, and preventing personal data breaches. The Hospital has established policies, regulations, and criteria for personal data protection, such as IT security standards and measures to prevent recipients of data from the Hospital from using or disclosing data outside the intended purposes, without authority, or unlawfully. The Company periodically updates such policies, regulations, and criteria as necessary and appropriate.

Additionally, the Hospital requires its employees, personnel, and data recipients to maintain the confidentiality and security of your personal data in accordance with the measures prescribed by the Company whenever they handle your personal data.

7. Cross-Border Transfer of Personal Data

In the event that the Hospital transfers, transmits, and/or sends data overseas, the Hospital will establish standards for agreements and/or business joint venture contracts ensuring that the receiving organization has adequate personal data protection standards recognized and consistent with relevant laws. This is to ensure your personal data will be safely protected, for example:

  • In cases where the Hospital needs to store and/or transfer personal data for storage purposes.
  • For Cloud processing, the Company will select organizations with international security standards and will store personal data in an encrypted format or through other methods that render the data subject unidentifiable.

The Data Controller may send or transfer the User’s personal data overseas in the following cases:

(a) The destination country or international organization receiving the personal data has adequate data protection standards as prescribed by data protection laws, rules, or regulations.

(b) Consent has been obtained from the data subject, provided that the User (data subject) has been informed of the inadequate personal data protection standards of the destination country or international organization.

(c) It is necessary for compliance with a law.

(d) It is necessary for the performance of a contract to which the User (data subject) is a party, or in order to take steps at the request of the User prior to entering into a contract.

(e) It is necessary for the conclusion or performance of a contract between the Data Controller and a third party in the interest of the User.

(f) To prevent or suppress a danger to the life, body, or health of the User or any other person, when the data subject is incapable of giving consent at that time.

(g) It is necessary for the performance of a task carried out for significant public interest.

The data subject may review the list of third parties to whom the Hospital may disclose personal data from the list of business partners, which may be requested from the Data Protection Officer (DPO) via the contact channels in Clause 14. The list of third parties to whom the Hospital may disclose personal data may change, increase, or decrease, and the Hospital will keep this information continually updated.

8. Rights of the Data Subject

You are fully entitled to your rights as a data subject under the personal data protection laws, which include but are not limited to the following rights of the User:

  • Right of Access: To request a copy of the personal data held by the Hospital.
  • Right to Rectification: To request the correction of inaccurate or incomplete data.
  • Right to Erasure: To request the deletion or destruction of data when it is no longer necessary or upon withdrawal of consent.
  • Right to Restriction of Processing: To request a temporary suspension of data processing.
  • Right to Data Portability: To receive data in a machine-readable format.
  • Right to Object: To object to data processing that relies on legitimate interests.
  • Right to Withdraw Consent: To withdraw the consent previously provided at any time.
  • Right to Lodge a Complaint: To file a complaint against the Hospital if you believe the collection, use, and disclosure of your personal data violates or fails to comply with relevant laws. Please see Clause 14.

You may exercise these rights by contacting the Hospital’s Data Protection Officer (DPO) via the channels specified in Clause 14. The Hospital will process your request within 30 days of receipt. However, there may be necessary circumstances where the Hospital may reject or be unable to comply with your request, such as to comply with legal obligations or court orders, for public interest, or if the exercise of rights may violate the rights or freedoms of others. If the Company rejects your request, the Hospital will notify you of the reasons for the refusal.

9. Data Security Measures

The Hospital implements appropriate technical and administrative measures to protect your personal data from unauthorized access, use, disclosure, alteration, or destruction, which include:

  • Data encryption in storage systems and during transmission.
  • Role-Based Access Control (RBAC).
  • Regular personal data protection training for personnel.
  • Regular security audits and risk assessments of systems.
  • Data backup and disaster recovery policies.

10. Collection, Use, and/or Disclosure of Personal Data under the Personal Data Protection Law

The User acknowledges and agrees that the Data Controller may collect, use, and/or disclose the User’s data without obtaining prior consent, strictly to the extent necessary, in accordance with the stated purposes, and only in the following cases:

(a) To achieve purposes relating to the preparation of historical documents or archives for public interest, or for research or statistical purposes, provided that appropriate safeguards are implemented to protect the rights and freedoms of the User’s personal data.

(b) To prevent or suppress a danger to a person’s life, body, or health.

(c) It is necessary for the performance of a contract to which the User is a party, or to take steps at the User’s request prior to entering into such a contract.

(d) It is necessary for the performance of a task carried out in the public interest by the Data Controller, or for the exercising of official authority vested in the Data Controller.

(e) It is necessary for the legitimate interests of the Data Controller or any other person, provided that such interests are not overridden by the fundamental rights of the User’s personal data.

(f) It is necessary to comply with the laws applicable to the Data Controller.

The Data Controller shall strictly record the collection, use, or disclosure of the User’s personal data in accordance with the preceding paragraph.

11. Use by Persons under Guardianship or Custodianship

The User warrants that they are not, and will not permit, persons with defective legal capacity as listed below to visit, use, or become members of the website and application: (a) Incompetent persons under the User’s guardianship. (b) Quasi-incompetent persons under the User’s custodianship.

In the event the User permits the aforementioned persons to visit or use the services, it is deemed that the User has exercised their power of parental control, guardianship, or custodianship over such persons, as the case may be, to agree to and provide consent under this policy for and on behalf of such persons in all respects.

12. Personal Data Breach Notification

In the event the Data Controller becomes aware of a personal data breach, regardless of who caused the breach, the Data Controller shall proceed as follows:

(a) In the event the breach poses a risk to the rights or freedoms of any individual, the Data Controller shall notify the Office of the Personal Data Protection Committee of the breach without undue delay, and where feasible, within 72 (seventy-two) hours of becoming aware of it.

(b) In the event the breach poses a high risk to the rights or freedoms of any individual, the Data Controller shall notify the Office of the Personal Data Protection Committee and the affected Users (data subjects) of the breach and the remedial measures without undue delay, and where feasible, within 72 (seventy-two) hours of becoming aware of it.

13. Cookies and Tracking Technologies

The Hospital’s website uses cookies and similar tracking technologies to improve the user experience. You can set your cookie acceptance preferences through your browser; however, rejecting certain types of cookies may affect website functionality.

  • Necessary Cookies: For basic website functionality.
  • Analytics Cookies: To analyze user behavior (consent required).
  • Marketing Cookies: To display relevant advertisements (consent required).

14. Contact Channels

If you have any questions, wish to exercise your rights, or wish to file a complaint regarding personal data protection, please contact:

Thai Eye Hospital

168 Charoenraj Road, Bang Khlo, Bang Kho Laem, Bangkok 10120

Telephone: (+66)2-689-8888

Email: [email protected]

You have the right to lodge a complaint with the Office of the Personal Data Protection Committee (PDPC) if you find that the Hospital fails to comply with the PDPA.

15. Policy Changes

The Hospital reserves the right to amend or update this Privacy Policy from time to time to reflect changes in the law, regulations, or the Hospital’s practices. The Hospital will notify you of any material changes via the website or other appropriate communication channels.

16. Governing Law

This Policy shall be governed by and construed in accordance with the laws of Thailand.

17. Dispute Resolution

Should any dispute or controversy arise in connection with this Policy, and the parties are unable to reach an amicable settlement, the parties agree to submit such dispute to the jurisdiction of the competent courts in Thailand.

This Privacy Notice is effective from 12 June 2026.

ส่งข้อมูลสำเร็จ