Skip to content
Official Document

Privacy Notice

Telemedicine and Telepharmacy Application
Ministry of Public Health (MOPH Meet)

1 Introduction

The Office of the Permanent Secretary of the Ministry of Public Health recognizes and prioritizes the protection of your personal data and other related information. This version has been converted to be fully compatible with WordPress HTML widgets without breaking the theme layout.

2 Definitions

  • Processing Any operation performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
  • Personal Data Any information relating to a person which enables the identification of such "Data Subject," whether directly or indirectly, including but not limited to name, surname, address, telephone number, national ID number, passport number, online identifiers, physical identity, mental, social, economic, or cultural identity (excluding data of the deceased).
  • Sensitive Personal Data Special categories of personal data under Section 26 of the PDPA, such as race, ethnic origin, political opinions, cults, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data, or any other data as determined by the Personal Data Protection Committee.
  • Data Subject A natural person who can be identified by such personal data, whether directly or indirectly.
  • Personal Data Processing Any action involving personal data, such as collecting, recording, copying, organizing, storing, updating, changing, using, retrieving, disclosing, forwarding, publishing, transferring, merging, deleting, or destroying.
  • Data Controller A person or legal entity with the power and duty to make decisions regarding the collection, use, or disclosure of personal data.
  • Data Processor A person or legal entity who operates in relation to the collection, use, or disclosure of personal data according to instructions or on behalf of the Data Controller.
  • OPS The Office of the Permanent Secretary, Ministry of Public Health.

3 Sources of Personal Data

The Office of the Permanent Secretary, Ministry of Public Health, collects or obtains various types of personal data from the following sources:

3.1 Direct Collection

The Office shall collect personal data directly from you through various service channels, such as filling out forms or providing information via telephone, websites, or various applications provided by the Office. The Office will collect personal data only to the extent necessary and use such data for the specified purposes, which are lawful purposes or actions taken according to legal requirements that mandate the Office to store such data.

3.2 Use of Websites or Applications

In the event that you contact or use services through the Office's websites or applications, the Office is required to comply with the law, which mandates the collection of your data from such usage, such as IP Address, etc. Furthermore, to facilitate the use of the websites or applications, the Office may use automated technologies to collect your usage data, which may include cookies, web beacons, pixel tags, and other similar tracking technologies, collectively referred to by the Office as "Cookies," for which you may read the details of cookie usage.

3.3 Personal Data Collected from Sources Other than the Data Subject

Where such sources have the authority, lawful reasons, or have already received consent from the data subject to disclose the data to the Office. Examples include the linking of digital services of government agencies to provide integrated public interest services to the data subject, or the receipt of personal data from other government agencies in the Office's capacity of having a mission-based duty to provide a central data exchange center to support the operations of government agencies in providing services to the public through digital systems, as well as from the necessity to provide services under a contract where personal data may be exchanged with contractual parties.

Additionally, this also includes cases where you provide personal data of third parties to the Office of the Attorney General. Therefore, you are responsible for informing such persons of the details according to this Notice or the notice of any other services, as the case may be, as well as obtaining consent from those persons if consent is required for the disclosure of information to the Office of the Attorney General.

3.4 Sensitive Data

The collection of such data must be conducted as prescribed by law, which includes the potential requirement of your consent. Therefore, the Office will collect sensitive data only in cases of necessity, and the Office will clearly inform you of the reasons and necessity, including potentially seeking your consent to collect such sensitive data in certain cases.

3.5 Personal Data of Minors, Quasi-incompetent Persons, and Incompetent Persons ("Persons with legally limited capacity to perform transactions")

The Office will process the personal data of persons with legally limited capacity to perform transactions only in necessary cases and in accordance with the guidelines prescribed by data protection laws. In the event that the Office needs to process the personal data of a person with legally limited capacity to perform transactions for any activity, the Office will also proceed to obtain consent from the parent or the person exercising parental power, guardian, or curator with the authority to act on behalf of such person (as the case may be). This excludes cases of seeking consent for the processing of personal data of a minor over 10 years of age, which is strictly personal or suitable to their station in life and necessary for their reasonable livelihood, for which such minor can provide consent independently.

4 Personal Data Collected by the Office

4.1 What Personal Data the Office Collects The Office may collect some or all of the following personal data:

First Name – Last Name Date of Birth Nationality Current Address Mobile Phone Number Username Password IP Address Address as stated in the Identification Card National Identification Number and information appearing on the Identification Card

4.2 Sensitive Data

Health Information Medical History Religion Race measurement data from IoT devices (e.g., blood pressure, heart rate, blood glucose levels) etc

5 Purposes of Collection and Processing of Personal Data

  • To be used for diagnosis, medical treatment, and medical consultation through digital systems.
  • To be used for recording medical history (Medical Record) to ensure continuity of care.
  • To be used for the reimbursement of medical expenses with relevant agencies (e.g., Social Security Office, NHSO).
  • To be used for monitoring service quality and the safety of both patients and personnel.
  • To maintain, store, and update information concerning you, including documents referencing you.
  • To carry out necessary actions for the legitimate interests of the Office, other individuals, or other legal entities related to the Office's operations.
  • To contact, inquire, and provide additional information regarding service provision.
  • To develop and improve the quality of service.
  • For the benefit of analysis and preparation of statistical data, whereby certain information, such as agency data, may be processed and displayed as aggregate data through anonymization methods that prevent individual identification.
  • To carry out any other actions that are similar or of a similar nature to the objectives specified above.

6 Legal Basis for the Collection or Use of Personal Data

The Office is permitted to collect or use your personal data based on the following:

  • To prevent or suppress a danger to a person's life, body, or health.
  • It is necessary for the performance of a task carried out in the public interest by the Data Controller, or in the exercise of official authority vested in the Data Controller.
  • You have provided consent to the Office (Consent) (in cases where the Office collects and uses information outside of these operations).

The Office is permitted to collect or use your sensitive personal data based on the following grounds:

  • For the purposes of preventive medicine or occupational medicine, the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care, medical treatment, the management of health or social care systems and services. In cases where this is not mandated by law, and such personal data is under the responsibility of an occupational or professional person or a person obligated to maintain the confidentiality of such personal data by law, it must be in accordance with a contract between the Data Subject and a medical professional.
  • Public interest in public health, such as health protection from communicable diseases, dangers, or epidemics that may contact or spread into the Kingdom, or the control of standards or quality of medicines, medical supplies, or medical devices, for which appropriate and specific measures have been provided to protect the rights and freedoms of the Data Subject, particularly the confidentiality of personal data according to professional duties or ethics.
  • Labor protection, social security, national health security, medical benefits for legally entitled persons, protection for motor vehicle accident victims, or social protection, where the collection of personal data is necessary for compliance with the rights or duties of the Data Controller or the Data Subject, by providing appropriate measures to protect the fundamental rights and interests of the Data Subject.
  • You have provided consent to the Office (Consent) (in cases where the Office collects and uses information outside of these operations).

7 Sharing or Disclosure of Your Personal Data

7.1 Consent Required

The Office will not disclose personal data collected through the use of MOPH Meet services to other persons without your consent. Such disclosure will be conducted solely for the purposes of providing services on the Health ID and Provider ID systems. By agreeing to this Privacy Policy, you or your guardian (in cases where you are under 20 years of age) acknowledge that you have read and understood this Privacy Policy and agree to all terms herein. In particular, you agree and consent to the Office collecting, using, disclosing, storing, or processing your personal data for the provision of services by the Office to you according to this Privacy Policy.

7.2 Disclosure Without Consent (Good Faith)

The Office may disclose your personal data without consent in certain cases if the Office believes in good faith that such action is necessary to comply with legal obligations under applicable laws or to respond to lawful legal processes, such as search warrants, court orders, or subpoenas. This includes cases where the Office believes in good faith it is necessary for legitimate interests regarding national security, law enforcement, litigation, criminal investigation, protection of any person's safety, or to prevent imminent death or bodily harm, provided the Office deems such legitimate interests outweigh your legal interests or fundamental rights and freedoms regarding personal data protection.

7.3 Healthcare Recipients and/or Providers

For Healthcare Recipients and/or Providers: You acknowledge and agree that the Office may disclose your personal data and employment information to affiliate service units that are connected and have data-sharing agreements.

7.4 Service Units

For Service Units: You acknowledge and agree that the Office may disclose contact information specified in the Provider ID system or other information provided through various channels, which may include the personal data of employees, staff, internal personnel, or persons related to the service unit, alongside their affiliated job positions, for the benefit of provider registration. If there are names, images, or personal data of employees, staff, internal personnel, or related persons of the organization, in whole or in part, the organization certifies and confirms that consent has been obtained from the data owners and has the right to use such data for provider registration.

7.5 Third-Party Links

The Office wishes to inform you that the MOPH Meet application will contain links to third-party websites which may have privacy policies different from the Office’s. You should study the privacy policies of those websites to understand personal data protection details and to decide on disclosing personal data to third-party websites. The Office shall not be responsible for any loss or damage arising from the actions of third-party websites in any case.

8 Data Retention Period

The OPS will store your personal data for the duration necessary to achieve the objectives specified in this Privacy Policy or as required by law (such as Public Health laws or the Computer Crimes Act). Upon the expiration of such period, the Office will cease using your data. When the Office's document and data destruction cycle is reached, the Office will delete, destroy, or render the personal data unidentifiable.

However, the Office may need to store your personal data beyond the specified period if there is a reason the Office is notified or believes in good faith that there may be a breach of the Office's service agreement, a violation of the law, or a dispute, necessitating investigation and collection of evidence for legal proceedings. The Office will store your personal data for as long as necessary until the process is completed or for the duration specified by the relevant laws.

9 International Transfer of Personal Data

— None —

10 Security and Confidentiality

The Office recognizes the trust you place in providing important information. Personal data protection law requires the Office, as a Data Controller, to have security measures and management to ensure that data is protected and available for the data subject to access and inspect.

Examples of security measures and management for protecting personal data used by the Office include:

  • Establishing physical prevention measures and limiting access to personal data only to Office employees with a Need to Know basis.
  • Establishing measures to prevent access to systems and data, such as using passwords to access service systems, to prevent unauthorized persons from accessing your personal data.
  • Utilizing Data Encryption with confidentiality layers so that data cannot be read by unauthorized persons.
  • Establishing work processes for personal data protection and responding to suspicious problems or incidents of personal data breach. In such events, the Office will promptly notify you and inform relevant government officials as required by law.
  • Conducting employee training to create awareness and understanding of operational procedures for personal data protection and handling suspicious personal data breach incidents.
  • Reviewing personal data protection work processes at specified intervals to ensure that processes are appropriate and consistent with current situations.
  • Auditing and testing systems that store or process personal data to ensure the security of the systems or technology used, and ensuring the latest security management software is updated and installed (Update Patches).
However, please be aware that sending data through public networks, using public computers, or even using personal computers or communication devices infected with malware carries risks. The Office cannot guarantee the security of your data, which may be clandestinely accessed, disclosed, or transferred, potentially causing you damage. For more information regarding information system security, you may study the "Information Security Policy and Guidelines" of the Office.

11 Your Rights Regarding Personal Data

Data subjects have rights under personal data protection law, and the Office places great importance on facilitating you as a data subject in exercising those rights as follows:

Right to be Informed

The Office will provide a "Privacy Notice" with clear details regarding the objectives of collection, use, and disclosure.

Right to Withdraw Consent

You may request to withdraw consent previously given to the Office at any time.

Right to Access

You may request access to your personal data and a copy of the personal data, as well as request the Office to disclose the acquisition of such data.

Right to Rectification

You may request to update or correct inaccurate personal data so that the information is accurate, current, and not misleading.

Right to Erasure

You may request the Office to delete, destroy, or render the personal data unidentifiable to the data subject.

Right to Data Portability

In cases where the Office's data system supports general reading or usage by automated tools or devices and can use or disclose personal data by automated means, you may request a copy of your personal data, including requesting the automated transfer of such data to another data controller and receiving the personal data so sent or transferred.

Right to Restrict Processing

You may request the Office to suspend the use of personal data.

Right to Object

You may request to object to the processing of personal data.

The exercise of your rights must be under the terms, notices, and regulations specified by the OPS, which will follow the criteria of personal data protection law, the Office’s personal data protection policy, and other criteria specified by the OPS. To exercise the above rights, you must submit a written request to the OPS Data Protection Officer. The consideration of such requests is at the sole discretion of the OPS, and the decision of the OPS regarding your request shall be final. In some cases, the Office may refuse the request if there are legitimate legal grounds, or if it is an action for purposes required by law or court order, or if it may affect and cause damage to the rights or freedoms of the data subject or other persons.

12 Withdrawal of Consent

If you no longer wish for the Office to collect, use, process, or disclose your personal data, you may withdraw your consent by submitting a request to the OPS Data Protection Officer. Such withdrawal must be under the conditions, terms, notices, or regulations specified in personal data protection law, the OPS personal data protection policy, and other criteria specified by the Office.

Note: Withdrawal of consent may cause limitations for the Office in performing transactions or providing services to you.

13 Links to Third-Party Services

Some of the Office’s services may link to websites, applications, or other services belonging to third parties, provided solely for your convenience. If you use such links, you will leave the Office’s services. The Office is not involved in, and cannot verify or control the accuracy and reliability of, those websites, applications, or services. This Notice applies only to the Office’s services.

If you use such links to access third-party services outside the scope of this Notice, the Office recommends you read and understand the privacy policies or notices of those services before use.

14 Use of Cookies

Cookies are a process that helps service users use the website more conveniently. Cookies are useful for allowing web servers to retrieve that information later. Cookies will be installed while you browse the website. After you quit the browser program, some cookies will be stored on your computer as files, or they may expire or not be stored. You may adjust your browser settings to support or disable the operation of cookies.

15 Review and Improvement of the Notice

The Office may update this Notice from time to time to ensure the content is appropriate, current, and consistent with personal data protection law and related laws. If the Office updates this Notice, the latest version will be displayed on the MOPH Meet application, and you may be notified through appropriate channels. The Office recommends you regularly read and check this Notice, especially before submitting personal data through the Office's services. Continued use of the Office’s services after this Notice has been updated and displayed here constitutes your approval and acceptance of the revised Notice.

16 Data Protection Officer

The Office of the Permanent Secretary of the Ministry of Public Health has appointed a Data Protection Officer (DPO) to coordinate the protection of the interests of data subjects and the OPS, assisting in efficient and effective risk management and personal data management. In cases where the data subject wishes to exercise rights or has questions regarding their rights or consent provided, they may contact the following:

Contact the Data Protection Officer

📍 Information and Communication Technology Center, Office of the Permanent Secretary,
Ministry of Public Health, Building 2, Floor 1, No. 88/20 Moo 4, Tiwanon Road, Talat Khwan Sub-district, Mueang District, Nonthaburi Province 11000
✉️ Email: dpo@moph.go.th
📞 Telephone: 0 2590 2180 ext. 112, 316 or 0 2590 1213
🌐 Website: https://pdpa.moph.go.th