Data Privacy & PDPA Compliance

Thailand: Personal Data Protection Act B.E. 2562 (PDPA)

Select country

Review how this page describes privacy-law coverage for your school jurisdiction.

Last reviewed: March 2026

Our Commitment

River SIS processes personal data for school management operations including student administration, staff records, and school activities. For Thailand coverage, this page is intended to summarise how our operational controls map to the Thai Personal Data Protection Act B.E. 2562 (PDPA), including transparency, lawful processing, security safeguards, retention controls, and support for data-subject rights such as access, correction, deletion, portability, objection, and restriction where applicable.


Data Classification
ClassificationDescriptionExamples
PIIPersonally identifiable informationDatabase records, user profile images
ConfidentialSensitive operational dataApp configuration, environment secrets
AuditAccess and activity recordsDatabase audit logs, admin activity
InternalNon-personal operational dataApplication logs, container images

Security Measures
Encryption at Rest
  • DocumentDB: KMS encryption at cluster level
  • S3 buckets: AWS KMS server-side encryption
  • CloudWatch Log Groups: KMS encryption
  • Container registry (ECR): KMS encryption
Encryption in Transit
  • HTTPS only; TLS 1.2 minimum, TLS 1.3 preferred
  • Application to database: TLS enforced, plaintext rejected

Data Retention
Data CategoryStorageRetentionDeletion
Customer images (current)S3IndefiniteManual on request
Customer images (superseded)S330 daysAutomatic (S3 Lifecycle)
Database backupsDocumentDB30 daysAutomatic
Application logsCloudWatch7 daysAutomatic
Database audit logsCloudWatch90 daysAutomatic

Your Data Rights
Access Requests

Thailand's PDPA gives data subjects a right to request access to personal data and related processing information. We support verified access requests through customer administrators, records review, and available audit history.

Deletion and Withdrawal

Thailand's PDPA includes rights to request deletion, anonymisation, or destruction in certain circumstances and to withdraw consent where consent is the lawful basis. We assess these requests against customer instructions, legal obligations, and security-retention needs.

Correction and Accuracy

Data subjects may request correction of inaccurate or incomplete personal data. Administrative workflows, role-based controls, and traceable updates help us support verified correction requests.

Data Portability

Thailand's PDPA includes a data portability right in applicable circumstances. Where technically feasible and legally appropriate, we support structured exports or customer-mediated delivery of relevant data.

Objection and Restriction

Thailand's PDPA also recognises objection and restriction-related rights in certain contexts. We review such requests in light of the processing purpose, legal basis, customer role, and any overriding legal or operational obligations.


Governance Schedule
Monthly

Review data classification, retention settings, access permissions, and operational changes that may affect privacy risk.

Quarterly

Conduct least-privilege access reviews, verify key security controls, and document material changes to processing activities or vendor arrangements.

Annually

Perform a fuller review of data inventories, test data-rights handling and deletion workflows, review incident-response readiness, and update this document.


Exercise Your Data Rights

To exercise any of your data rights or for privacy-related enquiries, please contact SchoolHero.io OÜ at info@riversis.com or by post at Harju maakond, Kuusalu vald, Pudisoo küla, Männimäe, 74626, Estonia.