Personal Data Protection Policy

Subject: Personal Data Protection Policy

TPI Polene Public Company Limited and its subsidiaries

Part 1: Intention

TPI Polene Public Company Limited and its subsidiaries (“the Company”) recognize the importance of personal data. To protect the personal data of individuals contacting the Company through its website and online media such as customers, suppliers, employees, job applicants, shareholders, bondholders, directors, and job contacts, etc., the Company complies with the Personal Data Protection Act. Therefore, the Company notifies individuals who contacts the Company via our website and online platforms that they must acknowledge and consent to the Company collecting, compiling, using, disclosing, editing, and destroying their personal data in accordance with this Personal Data Protection Policy.

The Company shalll collect and disclose data securely, using it solely for the purposes consented by the data subject and in compliance with applicable law. To comply with the Personal Data Protection Act, B.E. 2562 (2019), the Company has established this Personal Data Protection Policy to inform you about its intentions, the process of processing personal data, the exercise of rights, and security measures. The Company respects the privacy rights of customers, business partners, employees, job applicants, and job contacts. Personal data will be collected, compiled, used, disclosed, edited, and destroyed only as necessary or as required by law, in accordance with the details specified in this policy.

Part 2: Vocabulary and Explanation

  1. Personal Data: Information relating to an individual that enables identification, behavior analysis, or access to the data subject, either directly or indirectly.
  2. Sensitive Personal Data: Specific personal information, including genetic and biometric data, that may lead to unfair discrimination against the data subject based on race, ethnicity, political opinions, religious or philosophical beliefs, sexual orientation, criminal background, health and disability status, trade union membership, and other data as specified by the Personal Data Protection Commission.
  3. Data Subject: An individual to whom personal data pertains. The Company defines data subjects as the following types based on their legal relationships: job applicants, shareholders, bondholders, directors, and job contacts.
  4. Processing of Personal Data: Any action performed on personal data, including collection, use, disclosure, correction, and destruction.
  5. Data Controller: The individual with authority over the collection, use, and disclosure of personal data for the purpose of fulfilling their duties, who has the power to determine how and where such personal data is managed.
  6. Data Processor: An individual or entity that processes personal data, including its collection, use, and management, but does not act as a data controller.

 

 

Part 3: Purposes for Collecting, Using, or Disclosing Personal Data

  • The Company shall inform the data subject of the purposes for collecting, using, and disclosing personal data, as well as their rights, and will obtain consent at the initial stage. The Company shall collect and use the data subject's personal data to benefit business operations. This includes necessary actions for internal management, such as recruitment, procurement, entering into contracts for the purchase and sale of goods, financial transactions, insurance, conducting company activities, coordinating contacts, and improving work efficiency. Specific activities may include creating databases, analyzing and developing the Company’s processes, and other purposes that are not prohibited by law or that comply with regulations related to the Company’s operations. The Company shall collect and use such data solely for the period necessary to fulfill the purposes communicated to the data subject or as required by law.

The Company shalll not act against the stated purposes for data collection, except in the following circumstances:

  • The new purpose has been communicated to the data subject, and their consent has been obtained.
  • This ensures compliance with the Personal Data Protection Act and other relevant laws.

Part 4: Collection of Personal Data

  • Personal data is collected and disclosed for the benefit of the Company’s business operations, both directly and indirectly. The personal data provided to the Company may include details necessary for job applications, such as name, photograph, contact address, telephone number, ID card number, date of birth, educational qualifications, nationality, race, religion, and other relevant documents.
  • Personal data is collected to benefit the Company’s business operations, both directly and indirectly, including marketing and communication, purchasing, selling, special offers, sales promotions, discounts, privileges, and notifications about news and information related to the Company’s products, goods, and services.
  • The Company shall collect, use, and disclose information solely for its objectives related to the management of benefits, welfare, and marketing of the Company’s products, goods, and services, except when disclosure is required to comply with applicable laws, which the Company will strictly adhere to.
  • The Company shall collect personal data of directors and nominees directly from the data subjects, as well as from government and private agencies, publicly disclosed information, and official documents for identity verification purposes. This data may include name and surname, gender, ID card number, passport number, photograph, date of birth, nationality, place of birth, height, remuneration, training, activities, marital status, information on spouses/ on cohabitants, children, parents, siblings, blood type, bank account numbers, email, educational history, occupation, work history, directorships or positions in other companies or entities, attendance at meetings of the Board of Directors or subcommittees or shareholders, director remuneration, securities holdings, names of securities companies, performance of directors, and other information as specified by law or corporate governance principles.

The Company shall collect personal data from shareholders, bondholders, their attorneys or proxies, and subscribers of shares and bonds directly from individuals, as well as through securities brokers, securities registrars, and relevant government and private agencies. This data may include name, surname, address, telephone number, email, contact information, nationality, occupation, date of birth, taxpayer identification number, identification number, juristic person registration number, bank account details, number of shares, etc.

The Company may need to collect and process special types of personal data as required by the Personal Data Protection Act, such as health information, food allergies, and drug allergies, in order to facilitate participation in meetings or other activities.

The Company will obtain explicit consent from such data subject and will make every effort to implement adequate security measures to protect this sensitive personal data. The data will be stored, used, and disclosed solely for the benefit of the Company’s business operations in accordance with the law.

  • The Company has a stringent, appropriate, sufficient, and secure system for collecting, using, and disclosing personal data.
  • The Company has designated a data controller, data processor, and personal data protection officer to ensure that personal data is used according to its intended purpose, remains within the scope of consent, and does not cause harm to the data subject.
  • When it is necessary to collect, use, or disclose sensitive personal data—such as information regarding ethnicity, political opinions, religious beliefs, health data, criminal records, or disabilities—the Company shall obtain explicit consent from the data subject and handle this information with care and confidentiality.

Part 5: Rights of Personal Data Subjects

  • Data subjects have the right to easily access, review, and withdraw their consent regarding their data at any time during its storage, including non-Thais foreign data subjects. Their data will be stored and managed in the same manner as that of Thai data subjects.
  • Right to Access
  • Data Portability Right
  • Right to Object
  • Erasure Right
  • Right to Restrict Processing
  • Right to Rectification
  • Right to Lodge a Complaint
  • Right to Withdraw Consent
  • The withdrawal of consent will not affect any processing of personal data that occurred prior to the withdrawal. However, withdrawing consent may result in reduced access to certain services, such as product updates, discounts, and other benefits.

 

Part 6: Personal Data Protection Measures

The Company, as the personal data controller and processor, has established security measures to ensure the confidentiality, accuracy, completeness, and availability of personal data used in processing by:

  1. Implementing a system for ROPA (Record of Processing Activities) to control access to personal data and assess the risks associated with potential breaches, particularly in critical areas such as the processing of sensitive personal data.
  2. The Company has implemented management and technical measures to prevent unauthorized access, use, alteration, modification, or disclosure of personal data, as well as to prevent data loss.
  3. The Company has implemented measures to maintain the security of personal data and conducts training to enhance data protection awareness among employees, ensuring strict compliance with the established measures.

Part 7: Disclosure of Personal Data and Use of Personal Data

  • The Company may disclose personal data to its subsidiaries and to government or state agencies as required by law, court orders, or directives from authorized officials. Personal data will be kept confidential in both document and electronic forms throughout all stages of data transmission. When sending personal data to external agencies or abroad, the Company will establish agreements with these entities or destination countries to ensure appropriate and adequate protection, in compliance with legal requirements.

Part 8: Guidelines for Implementing Personal Data Protection Measures

  • The Company treats the personal data collected as if it were its own property. No one is permitted to violate, disclose, access, exploit, or destroy this data without the consent of the data controller. Violators will face the maximum penalties, and prosecution will be pursued to the fullest extent of the law, including full compensation for damages as stipulated by law.

Part 9: Review and Amendment of Personal Data Protection Policy Information

  • The Company may amend this Personal Data Protection Policy periodically to comply with legal requirements and updates in the Company's Personal Data Protection Policy. When such changes are made, the Company will issue a formal announcement. If additional consent is required, the Company will seek it from you.

Part 10: Contact Channels

For any inquiries or concerns regarding personal data protection, data collection, use or disclosure, the exercise of rights, or any complaints, please contact us through the following channels:

 

  1. TPI Polene Public Company Limited and its subsidiaries

Head Office: 26/56 TPI Tower, Chan Tat Mai Road, Thungmahamek, Sathorn, Bangkok 10120

Tel. Number: +66 (0) 2213-1039-49, 285-5090-9

Fax Number: +66 (0) 2213-1035, 213-1038

Website : https://www.tpipolene.co.th/en/

Email    : This email address is being protected from spambots. You need JavaScript enabled to view it. (This email address is being protected from spambots. You need JavaScript enabled to view it.)

Facebook : TPI Polene (Public) Co., LTD

Line         : @tpipl

  1. Personal Data Protection Officer (DPO)

Telephone : 02-213-1039, 02-285-5090

Email        : This email address is being protected from spambots. You need JavaScript enabled to view it. (mailto:This email address is being protected from spambots. You need JavaScript enabled to view it.)

 

Summary of performance appraisal of directors and top executives (CEO) (Year 2023) 

 

          TPI Polene Public Company Limited arranges for the Board of Directors, subcommittees, and top executives (CEO) of the Company to conduct self-evaluations at least once a year in order to adhere to the principles of good corporate governance. This is done by including the factors that affect the Company’s sustainability performance as part of the performance assessment indicators for the Board of Directors and executives, and concentrating on the assessment results that can be used to make improvements (CEO). The assessment form includes

  1. Performance assessment form of the Board of Directors as a whole (Assessment as a whole)
  2. Performance assessment form for the committee as a group
  3. 3. Performance assessment form of the Board of Directors individually (for the Board of Directors/Sub-Committees)
  4. 4. Performance assessment form of Chief Executive Officer (CEO)

The assessment criteria are determined by the percentage of the full score for each item as follows:

More than 90% score = Excellent

More than 80% Score = Very Good

More than 70% Score = Good

More than 60% score = Fair

Below 60% = Need Improvement

  1. Performance assessment form of the Board of Directors as a whole (Assessment as a whole)

Consists of 6 topics, namely structure and qualifications of the committee, roles, duties and responsibilities of the committee, meetings of the committee, performance of duties of directors, relationship with management, self-development of directors, and development of executives. The assessment results have an average score of 92.5% (Excellent).

  1. Performance assessment form for the committee as a group

Consists of 3 topics: structure and qualifications of directors, meetings of sub-committees, roles, duties and responsibilities of sub-committees.

 Audit Committee The assessment results have an average score of 92% (Excellent).

 Nomination and Remuneration Committee The assessment results have an average score of 90% (Very Good).

  1. 3. Performance assessment form of the Board of Directors individually (for the Board of Directors/Sub-Committees)

Consists of 3 topics: structure and qualifications of the committee/sub-committee, meetings of the committee/sub-committee, roles, duties and responsibilities of the committee/sub-committee.

The assessment results have an average score of 93% (Excellent).

  1. 4. Performance assessment form of Chief Executive Officer (CEO or equivalent)

It is an assessment that takes into account the elements that determine the Company’s sustainability performance as part of the KPI. To assess the performance of Chief Executive Officer (CEO), including financial performance (e.g. revenue, company sales, Economic Value Add (EVA), other financial performance) and environmental, social and/or governance (ESG) performance, such as employee/supplier/community satisfaction, especially with the aim of reducing greenhouse gas emissions, reducing the use of company resources, etc. These are part of the performance assessment indicators of Chief Executive Officer (CEO or equivalent) that consists of 10 topics:

  1. Leadership
  2. Strategies
  3. Strategy Implementation
  4. Financial Planning and Performance
  5. Relationship with the Board of Directors
  6. External Relations
  7. Management and Relations with Personnel
  8. Succession
  9. Knowledge of Products and Services
  10. Personal Attributes

 

The assessment results have an average score of 95% (Excellent).

 

Recruiting CEO and Presidents to replace vacant positions with the consideration of the Nomination Committee based on the following criteria:

  1. Being a director of the Company according to the Articles of Association
  2. Having the knowledge and ability to run a business, including skills, experience, professionalism, and specific qualifications in various areas that are extremely necessary and beneficial to the business of the Company.
  3. Possessing skills and experience necessary for the business operations of the Company Group.
  4. Possessing leadership qualities and a robust sense of responsibility.
  5. Received recognition from business organizations within the Company's industry.
  6. Obtaining approval from the Board of Directors
  7. Considering conflict of interest

 

Sustainable Development Committee

No.

       Name

        Position

    Attendance *

1

Mr. Prachai Leophairatana

Chairman of the Sustainability Committee

1/1

2

Sustainable Development Committee (Head Office team)

List of committees according to organization structure

1/1

3

Sustainable Development Committee (Saraburi Plant team)

List of committees according to organization structure

1/1

4

Sustainable Development Committee (CRT/FCB plants team)

List of committees according to organization structure

1/1

5

Sustainable Development Committee (Rayong Plant team)

List of committees according to organization structure

1/1

         

 

Functions and Responsibilities of the Sustainability Development Committees

  1. 1. Determine policies, strategies, operational frameworks, strategic approaches, and consider and select issues that promote sustainable development of the organization, including setting sustainable development goals that are in line with business operations in economic, social, and environmental aspects propose to the Chief Executive Officer for approval.
  2. 2. Supervise, review, monitor the progress of implementation, and evaluate the effectiveness of the implementation of the sustainability development policy.
  3. 3. Encourage relevant organizations both inside and outside the organization to practice and create involvement in the implementation of various projects under the umbrella of sustainable development.
  4. 4. Consult, promote, support the appropriate resources and personnel to ensure that the sustainability strategy is implemented throughout the organization and aligned in the same direction.
  5. 5. The Chairman of the Committee has the power to appoint sub-committees or working groups to be responsible for each aspect of sustainable development operations to cover and be consistent with the organization’s key issues.
  6. Report on the performance of the preparation of sustainability reports to senior executives.
  7. Supervise the implementation of climate change strategies.

The Risk Management Committee

 

No.

       Name

        Position

 

1

Mr. Khantachai Vichakkhana

Chairman and Independent Director

2

Mr. Prachai Leophairatana

Director

3

Mr. Prateep Leopairut

Director

4

Dr. Pramuan Leophairatana   

Director

5

Mr. Prayad Liewphairatana

Director

6

Mrs. Orapin Leophairatana    

Director

7

Mr. Tayuth Sriyuksiri

Director

8

Miss Malinee Leophairatana

Director

9

Mr. Supoj Singsanei

Chairman of the Audit Committee and Independent Director

10

Mr. Pises Iamsakulrat

Audit Committee and Independent Director

11

Mr. Thavich Taychanavakul

Audit Committee and Independent Director

12

Mr. Pakorn Leopairut

Director

13

Mr. Pornpol Suwanamas

Audit Committee and Independent Director

14

Miss Thanyarat Iamsopana

Director

15

Mr. Virat Chatdarong

Director

         

 

Functions and Responsibilities of the Risk Management Committee

  1. Review and propose the policy and risk management framework to the Board of Directors for approval.
  2. Review and approve the risk appetite (Risk Appetite) and present to the Board of Directors for acknowledgment.
  3. Overseeing the development and implementation of risk management policies and frameworks on an ongoing basis to ensure that the Group has an effective enterprise-wide risk management system and consistent compliance.
  4. Review risk management reports to monitor material risks and take action to ensure that the organization has adequate and appropriate risk management.
  5. Coordinate with the audit committee to identify significant risks, and have the internal audit department conduct a review to make sure the Company has the necessary internal controls in place to manage those risks. This includes putting the right risk management systems in place and ensuring that everyone is following the rules throughout the Company.
  6. Regularly report to the Board of Directors on key risks and risk management.
  7. Provide advice and consultation to the Sub-Risk-Management Committee (SRM) and/or the departments and/or working groups related to risk management, including considering appropriate ways to correct various information about developing a risk management system.
  8. Consider appointing sub-committees and/or additional or replacement personnel in the risk management sub-committee and/or units and/or working groups related to risk management as appropriate, including determining roles and responsibilities for the benefit of carrying out the objectives
  9. Any other operations related to risk management assigned by the Board of Directors.
  10. Assess organizational risks, including climate change opportunities risks.

             In this regard, the management and/or the risk management subcommittee and/or the unit and/or the working group related to risk management and/or the internal auditor and/or the auditor must report or present the information and related documents to the Risk Management Committee to support the work of Risk Management Committee to achieve the assignedduties.