Abstract (Thai)
การท่องเที่ยวแห่งประเทศไทย (ททท.) เป็นหน่วยงานรัฐวิสาหกิจซึ่งมีหน้าที่ในการประชาสัมพันธ์และส่งเสริมการท่องเที่ยวไทย ททท. มีสำนักงานสาขาที่ตั้งอยู่ในเขตสหภาพยุโรป รวมทั้งมีสำนักงานใหญ่และสำนักงานภูมิภาคหลายสำนักงานที่ตั้งอยู่ในประเทศไทยและมีการเก็บรวบรวมข้อมูลส่วนบุคคลในเขตของสหภาพยุโรปและในประเทศไทย ดังนั้น ททท. จึงอยู่ภายใต้บังคับที่จะต้องปฏิบัติตามกฎหมายคุ้มครองข้อมูลส่วนบุคคลของสหภาพยุโรปและของไทย แต่อย่างไรก็ตาม ททท. มีการดำเนินกิจกรรมที่มีความหลากหลายที่เกี่ยวข้องกับการประมวลผลข้อมูลส่วนบุคคล จึงก่อให้เกิดปัญหาในการปฏิบัติตามภาระหน้าที่ตามกฎหมาย ยกตัวอย่างเช่น การบ่งชี้ว่า ททท. มีสถานะเป็นผู้ควบคุมข้อมูลหรือผู้ประมวลผลข้อมูล การบ่งชี้ฐานทางกฎหมายสำหรับการประมวลผลข้อมูลในแต่ละกิจกรรม งานวิจัยนี้จึงมุ่งศึกษาประเด็นปัญหาและอุปสรรคของ ททท. ในการปฏิบัติตามข้อบังคับทั่วไปเกี่ยวกับการคุ้มครองข้อมูล หรือที่เรียกกันว่า General Data Protection Regulation (GDPR) และพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 รวมทั้งมุ่งเสนอแนะวิธีการที่เหมาะสมในการบริหารจัดการปัญหาและอุปสรรคดังกล่าว เช่น การจัดทำคู่มือกำหนดแนวปฏิบัติขององค์กรในการปฏิบัติตามกฎหมาย ทั้งนี้ เพื่อเป็นการลดความเสี่ยงที่ ททท. จะมีความรับผิดที่เกิดขึ้นจากการไม่ปฏิบัติตามกฎหมาย อันจะส่งผลเสียต่อชื่อเสียงของ ททท. และประเทศไทยต่อไป
Abstract (English)
The Tourism Authority of Thailand (TAT) is a state-owner enterprise established for promoting Thailand Tourism. There are TAT’s branch offices located in the EU and TAT’s main offices and regional offices in Thailand which collect a range number of personal data from the data subjects in the EU and in Thailand, so that TAT is obliged to comply with the EU and Thai Personal Data Protection Law. Nevertheless, the fact that there are a wide range of activities of TAT involving the processing of personal data, has brought about some problems for TAT to comply with legal obligations. For instance, it can be difficult to determine whether TAT is a data controller or a data processor, as well as to identify the legal basis for processing personal data in each activity. This research explores the problems and obstacles of TAT to comply with the General Data Protection Regulation (GDPR) and the Personal Data Protection Act B.E. 2019 of Thailand (PDPA). Additionally, it aims to propose appropriate approaches for managing these problems and challenges, such as developing a manual for the organisation to comply with the laws. The goal is to reduce the risks for TAT to be liable for non-compliance with personal data protection laws, which could adversely affect both TAT’s reputation and Thailand as a whole.
Keywords (Thai)
การท่องเที่ยวแห่งประเทศไทย, ปัญหาและอุปสรรค, การปฏิบัติตามกฎหมาย, กฎหมายคุ้มครองข้อมูลส่วนบุคคล
Keywords (English)
The Tourism Authority of Thailand, Problems and Obstacles, Legal Compliance, Personal Data Protection Law
First Page
175
Last Page
217
Recommended Citation
Pibul, Auntika Na
(2025)
"ปัญหาและอุปสรรคในการปฏิบัติตามกฎหมายคุ้มครองข้อมูลส่วนบุคคลของสหภาพยุโรปและไทยในบริบทของการท่องเที่ยวแห่งประเทศไทย
(The Problems and Obstacles Regarding the Compliance on the EU Personal Data Protection Law and the Thai Personal Data Protection Law In the Context of the Tourism Authority of Thailand),"
Chulalongkorn University Law Journal: Vol. 43:
Iss.
1, Article 6.
Available at:
https://digital.car.chula.ac.th/culj/vol43/iss1/6