What should a Managed Security Services Agreement include under Thai law?
The Managed Security Services Agreement on this site is an English-language document drafted for use under Thai law. Its 25 clauses cover Definitions and Interpretation; Services and Onboarding; Coverage, Severity Levels and Alerts; Escalation and Communication; Division of Response Responsibilities; Containment Actions; Access to Client Systems; Security Data and Logs; Personal Data; and 16 more. The notes below explain Before the Services go live and When something happens.
| Clauses in the template | 25 |
|---|---|
| Stamp duty | A managed security services agreement is a hire of work (Instrument 4 of the Stamp Duty Schedule). The Provider pays the duty (Clause 16.3): 1 THB for every 1,000 THB or part of 1,000 THB of the fees. On the Contract Value you entered, the duty on the original is the amount the system calculates from the figures entered, and each counterpart carries the amount the system calculates from the figures entered.Because the Fees are in …, convert the Contract Value to Thai Baht at the exchange rate on the date of signing and calculate the duty on the Baht amount. If the Contract Value is 1,000,000 THB or more, the duty must be paid in money to the Revenue Department. If the Agreement is signed electronically, pay through the e-Stamp Duty system within 15 days after signing. An unstamped agreement cannot be used as evidence in a Thai civil court until the duty and a surcharge are paid (Revenue Code section 118). Additional duty is due if the Agreement renews and more fees are received. |
| Tax | A Thai company paying service fees to a provider in Thailand normally withholds 3% and issues a certificate. If the Provider is abroad, different withholding rules and self-assessed VAT may apply, and a double tax treaty may reduce the rate. Ask an accountant before the first payment, especially because you ticked gross-up. |
| Language of the form | English |
| Price of the form on this site | 990 THB |
What the template covers
- Definitions and Interpretation
- Services and Onboarding
- Coverage, Severity Levels and Alerts
- Escalation and Communication
- Division of Response Responsibilities
- Containment Actions
- Access to Client Systems
- Security Data and Logs
- Personal Data
- Regulatory Notifications
- Automated Detection and AI Tools
- Reporting and Service Reviews
- Client's Responsibilities
- Service Levels and Service Credits
- Fees and Payment
- Taxes
- Intellectual Property
- Confidentiality
- Limitation of Liability
- Force Majeure
- Term and Termination
- Exit and Handover
- Notices
- Governing Law and Disputes
- General
Before the Services go live
- Schedule 1 is the heart of this Agreement. The Provider can only see systems that send it logs (Clause 2.3). Check the list of log sources against your real environment, and record anything deliberately excluded.
- Test the escalation list before the Service Commencement Date: ask the Provider to send a test Critical Alert at night and see who answers (Clause 4.1). An alert that nobody picks up protects nobody.
- Review the Playbook in Schedule 1 Part C with the people who own the affected systems. Every action listed there can be taken without waiting for your approval (Clause 6.1), so leave out anything that could stop a critical business process.- Every containment action needs your approval (Clause 6.1). Make sure the escalation contacts have authority to approve isolating a device or disabling an account at any hour, or the delay may let an attack spread.
- Keep your own emergency ("break-glass") administrator account that the Provider cannot use (Clause 7.3). Access to a computer system without permission can be a criminal offence under the Computer Crime Act (section 5), so the Provider's access should always be granted in writing and limited to what the Services need.
When something happens
- The Provider detects and advises; you decide and act (Clause 5). Patching, restoring from backups and all notifications to regulators, customers and the police remain your responsibility.
- If personal data may be affected, the law requires you, as data controller, to notify the Office of the Personal Data Protection Committee without delay and within 72 hours after becoming aware of the breach, unless the breach poses no risk to individuals' rights and freedoms, and to tell the affected individuals without delay if the risk to them is high (Personal Data Protection Act section 37(4)). The Provider must notify you within … hours (Clause 9.2(f)) and send a written summary within 24 hours of a Critical Alert (Clause 10.2), so you have time to assess and report.
- As a critical information infrastructure organisation, you may have separate duties to report cyber threats to your sector regulator and the national cybersecurity authority, with their own deadlines. Give the Provider those procedures in writing (Clause 10.3).
- The Provider will not negotiate with or pay an attacker (Clause 5.3). If you receive a ransom demand, take legal advice before any payment; payments may breach sanctions or other laws and do not guarantee recovery.
- Ask the Provider to export the relevant logs with their handling record as soon as a serious incident is confirmed (Clause 8.3). Logs are deleted after … days unless you ask for them to be preserved.
Personal data in the logs
- Logs contain personal data such as user names, IP addresses and email metadata, so the Provider acts as your data processor (Clause 9.2). The Personal Data Protection Act requires a written arrangement that controls the processor (section 40), and Clause 9 is designed to meet it. If your organisation uses its own standard form, you may sign a separate Data Processing Agreement instead, and state that it prevails.
- You chose to allow storage or access in …. That is a transfer of personal data abroad, which is lawful only if the destination has adequate protection or another condition in sections 28 and 29 of the Act is met, such as appropriate safeguards in a written agreement. Check this before the logs start flowing.- The logs must stay in Thailand (Clause 8.2). If the Provider later wants to use analysts or storage abroad, it needs your written consent and a lawful transfer mechanism.
- Tell your employees in your privacy notice that security monitoring takes place. Monitoring should be limited to what security requires.
Stamp duty
- A managed security services agreement is a hire of work (Instrument 4 of the Stamp Duty Schedule). The Provider pays the duty (Clause 16.3): 1 THB for every 1,000 THB or part of 1,000 THB of the fees. On the Contract Value you entered, the duty on the original is the amount the system calculates from the figures entered, and each counterpart carries the amount the system calculates from the figures entered.Because the Fees are in …, convert the Contract Value to Thai Baht at the exchange rate on the date of signing and calculate the duty on the Baht amount.
- If the Contract Value is 1,000,000 THB or more, the duty must be paid in money to the Revenue Department. If the Agreement is signed electronically, pay through the e-Stamp Duty system within 15 days after signing. An unstamped agreement cannot be used as evidence in a Thai civil court until the duty and a surcharge are paid (Revenue Code section 118). Additional duty is due if the Agreement renews and more fees are received.
VAT and withholding tax
- A Thai company paying service fees to a provider in Thailand normally withholds 3% and issues a certificate. If the Provider is abroad, different withholding rules and self-assessed VAT may apply, and a double tax treaty may reduce the rate. Ask an accountant before the first payment, especially because you ticked gross-up.
Service levels and liability
- Service credits of …% per late Critical or High Alert, capped at …% of the monthly fee, are deducted from the next invoice (Clause 14). Under Thai law they work like a penalty, which a court may reduce if excessive, and they do not stop you claiming a larger proven loss.- The alert times are targets without service credits (Clause 14). Keep the monthly reports; three consecutive months of missed targets is a breach you can act on.
- No provider can guarantee that every attack will be detected (Clause 19.1). The liability cap does not apply to misuse of access or data by the Provider's staff, fraud, gross negligence or personal injury (Clause 19.4). Consider cyber insurance for the losses that remain with you.
Ending the Agreement
- The Agreement renews every 12 months unless notice is given … days before the end of the current period (Clause 21.1). Diary the date.- The Agreement ends after the Initial Term. Arrange a new provider or a renewal in good time so that monitoring does not stop.
- During the Exit Period of … days, ask for the export of logs and custom detection rules (Clause 22.1). The Provider may not hold the logs back to press for payment (Clause 22.2). Remove the Provider's accounts and agents on the last day and ask for written confirmation of deletion.
Signing and disputes
- Each Party signs through its authorised director, as shown in its company affidavit or home registration documents. Clause 25.8 allows electronic signatures and signed PDF copies.
- A Thai court works in Thai, so a Party relying on this Agreement or on English logs and reports must file a certified Thai translation. If the other Party has no assets in Thailand, an arbitral award is usually easier to enforce abroad than a Thai judgment.
Author and sources
Compiled from the notes that accompany the English contract templates on this site, published by Phuwara Krobtaku (ภูวรา ครอบตะคุ), Thai attorney-at-law, licence no. 477/2558. The short answer and summary at the top of this page are put together by the site from the template's clause headings and notes. Statutes are quoted only in the official Thai text: Thai is the only official language of Thai legislation, and an unofficial translation can mislead. Article registry OKC-C6A5DD. If you reuse this content, please credit the author and link to the original.
Frequently asked questions
Does a Managed Security Services Agreement need stamp duty in Thailand?
A managed security services agreement is a hire of work (Instrument 4 of the Stamp Duty Schedule). The Provider pays the duty (Clause 16.3): 1 THB for every 1,000 THB or part of 1,000 THB of the fees. On the Contract Value you entered, the duty on the original is the amount the system calculates from the figures entered, and each counterpart carries the amount the system calculates from the figures entered.Because the Fees are in …, convert the Contract Value to Thai Baht at the exchange rate on the date of signing and calculate the duty on the Baht amount. If the Contract Value is 1,000,000 THB or more, the duty must be paid in money to the Revenue Department. If the Agreement is signed electronically, pay through the e-Stamp Duty system within 15 days after signing. An unstamped agreement cannot be used as evidence in a Thai civil court until the duty and a surcharge are paid (Revenue Code section 118). Additional duty is due if the Agreement renews and more fees are received.
What tax applies to a Managed Security Services Agreement in Thailand?
A Thai company paying service fees to a provider in Thailand normally withholds 3% and issues a certificate. If the Provider is abroad, different withholding rules and self-assessed VAT may apply, and a double tax treaty may reduce the rate. Ask an accountant before the first payment, especially because you ticked gross-up.
How should a Managed Security Services Agreement be signed?
Each Party signs through its authorised director, as shown in its company affidavit or home registration documents. Clause 25.8 allows electronic signatures and signed PDF copies. A Thai court works in Thai, so a Party relying on this Agreement or on English logs and reports must file a certified Thai translation. If the other Party has no assets in Thailand, an arbitral award is usually easier to enforce abroad than a Thai judgment.
What personal data rules apply to a Managed Security Services Agreement?
Logs contain personal data such as user names, IP addresses and email metadata, so the Provider acts as your data processor (Clause 9.2). The Personal Data Protection Act requires a written arrangement that controls the processor (section 40), and Clause 9 is designed to meet it. If your organisation uses its own standard form, you may sign a separate Data Processing Agreement instead, and state that it prevails. You chose to allow storage or access in …. That is a transfer of personal data abroad, which is lawful only if the destination has adequate protection or another condition in sections 28 and 29 of the Act is met, such as appropriate safeguards in a written agreement. Check this before the logs start flowing.- The logs must stay in Thailand (Clause 8.2). If the Provider later wants to use analysts or storage abroad, it needs your written consent and a lawful transfer mechanism. Tell your employees in your privacy notice that security monitoring takes place. Monitoring should be limited to what security requires.
What happens if a Managed Security Services Agreement ends up in a dispute in Thailand?
Each Party signs through its authorised director, as shown in its company affidavit or home registration documents. Clause 25.8 allows electronic signatures and signed PDF copies. A Thai court works in Thai, so a Party relying on this Agreement or on English logs and reports must file a certified Thai translation. If the other Party has no assets in Thailand, an arbitral award is usually easier to enforce abroad than a Thai judgment.
What clauses does a Managed Security Services Agreement on this site include?
Definitions and Interpretation; Services and Onboarding; Coverage, Severity Levels and Alerts; Escalation and Communication; Division of Response Responsibilities; Containment Actions; Access to Client Systems; Security Data and Logs; Personal Data; Regulatory Notifications; Automated Detection and AI Tools; Reporting and Service Reviews; Client's Responsibilities; Service Levels and Service Credits; Fees and Payment; Taxes; Intellectual Property; Confidentiality; Limitation of Liability; Force Majeure; Term and Termination; Exit and Handover; Notices; Governing Law and Disputes; General
Thai law cited (official Thai text)
The 14 sections below are quoted from the official Thai text, the only official language of Thai legislation. No translation is given, because an unofficial translation can mislead; check the Royal Gazette before relying on them in court.
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 224
หนี้เงินนั้น ให้คิดดอกเบี้ยในระหว่างเวลาผิดนัดในอัตราที่กำหนดตามมาตรา 7 บวกด้วยอัตราเพิ่มร้อยละสองต่อปี ถ้าเจ้าหนี้อาจจะเรียกดอกเบี้ยได้สูงกว่านั้นโดยอาศัยเหตุอย่างอื่นอันชอบด้วยกฎหมาย ก็ให้คงส่งดอกเบี้ยต่อไปตามนั้น
ส่วนที่ 1 การไม่ชำระหนี้
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 373
ความตกลงทำไว้ล่วงหน้าเป็นข้อความยกเว้นมิให้ลูกหนี้ต้องรับผิดเพื่อกลฉ้อฉล หรือความประมาทเลินเล่ออย่างร้ายแรงของตนนั้น ท่านว่าเป็นโมฆะ
หมวด 2 ผลแห่งสัญญา
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 383
ถ้าเบี้ยปรับที่ริบนั้นสูงเกินส่วน ศาลจะลดลงเป็นจำนวนพอสมควรก็ได้ ในการที่จะวินิจฉัยว่าสมควรเพียงใดนั้น ท่านให้พิเคราะห์ถึงทางได้เสียของเจ้าหนี้ทุกอย่างอันชอบด้วยกฎหมาย ไม่ใช่แต่เพียงทางได้เสียในเชิงทรัพย์สิน เมื่อได้ใช้เงินตามเบี้ยปรับแล้ว สิทธิเรียกร้องขอลดก็เป็นอันขาดไป
หมวด 3 มัดจำและกำหนดเบี้ยปรับ
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 386
ถ้าคู่สัญญาฝ่ายหนึ่งมีสิทธิเลิกสัญญาโดยข้อสัญญาหรือโดยบทบัญญัติแห่งกฎหมาย การเลิกสัญญาเช่นนั้นย่อมทำด้วยแสดงเจตนาแก่อีกฝ่ายหนึ่ง
หมวด 4 เลิกสัญญา
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 387
ถ้าคู่สัญญาฝ่ายหนึ่งไม่ชำระหนี้ อีกฝ่ายหนึ่งจะกำหนดระยะเวลาพอสมควร แล้วบอกกล่าวให้ฝ่ายนั้นชำระหนี้ภายในระยะเวลานั้นก็ได้ ถ้าและฝ่ายนั้นไม่ชำระหนี้ภายในระยะเวลาที่กำหนดให้ไซร้ อีกฝ่ายหนึ่งจะเลิกสัญญาเสียก็ได้
หมวด 4 เลิกสัญญา
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 391
เมื่อคู่สัญญาฝ่ายหนึ่งได้ใช้สิทธิเลิกสัญญาแล้ว คู่สัญญาแต่ละฝ่ายจำต้องให้อีกฝ่ายหนึ่งได้กลับคืนสู่ฐานะดังที่เป็นอยู่เดิม แต่ทั้งนี้จะให้เป็นที่เสื่อมเสียแก่สิทธิของบุคคลภายนอกหาได้ไม่
หมวด 4 เลิกสัญญา
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 587
อันว่าจ้างทำของนั้น คือสัญญาซึ่งบุคคลคนหนึ่ง เรียกว่าผู้รับจ้าง ตกลงจะทำการงานสิ่งใดสิ่งหนึ่งจนสำเร็จให้แก่บุคคลอีกคนหนึ่ง เรียกว่าผู้ว่าจ้าง และผู้ว่าจ้างตกลงจะให้สินจ้างเพื่อผลสำเร็จแห่งการที่ทำนั้น
ลักษณะ 7 จ้างทำของ
พ.ร.บ.ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540 มาตรา 4
ข้อตกลงในสัญญาระหว่างผู้บริโภคกับผู้ประกอบธุรกิจการค้า หรือวิชาชีพ หรือในสัญญาสำเร็จรูป หรือในสัญญาขายฝากที่ทำให้ผู้ประกอบธุรกิจการค้า หรือวิชาชีพ หรือผู้กำหนดสัญญาสำเร็จรูป หรือผู้ซื้อฝากได้เปรียบคู่สัญญาอีกฝ่ายหนึ่งเกินสมควร เป็นข้อสัญญาที่ไม่เป็นธรรม และให้มีผลบังคับได้เพียงเท่าที่เป็นธรรมและพอสมควรแก่กรณีเท่านั้น
พระราชบัญญัติ ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540
พ.ร.บ.ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540 มาตรา 8
ข้อตกลง ประกาศ หรือคำแจ้งความที่ได้ทำไว้ล่วงหน้า เพื่อยกเว้นหรือจำกัดความรับผิดเพื่อละเมิดหรือผิดสัญญาในความเสียหายต่อชีวิต ร่างกาย หรืออนามัยของผู้อื่น อันเกิดจากการกระทำโดยจงใจหรือประมาทเลินเล่อของผู้ตกลง ผู้ประกาศ ผู้แจ้งความ หรือของบุคคลอื่นซึ่งผู้ตกลง ผู้ประกาศ หรือผู้แจ้งความต้องรับผิดด้วย จะนำมาอ้างเป็นข้อยกเว้นหรือจำกัดความรับผิดไม่ได้
พระราชบัญญัติ ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540
พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 มาตรา 28
ในกรณีที่ผู้ควบคุมข้อมูลส่วนบุคคลส่งหรือโอนข้อมูลส่วนบุคคลไปยังต่างประเทศ ประเทศปลายทางหรือองค์การระหว่างประเทศที่รับข้อมูลส่วนบุคคลต้องมีมาตรฐานการคุ้มครองข้อมูล ส่วนบุคคลที่เพียงพอ ทั้งนี้ ต้องเป็นไปตามหลักเกณฑ์การให้ความคุ้มครองข้อมูลส่วนบุคคลตามที่ คณะกรรมการประกาศกำหนดตามมาตรา 16 (5) เว้นแต่ (1) เป็นการปฏิบัติตามกฎหมาย (2) ได้รับความยินยอมจากเจ้าของข้อมูลส่วนบุคคลโดยได้แจ้งให้เจ้าของข้อมูลส่วนบุคคลทราบถึง มาตรฐานการคุ้มครองข้อมูลส่วนบุคคลที่ไม่เพียงพอของประเทศปลายทางหรือองค์การระหว่างประเทศ ที่รับข้อมูลส่วนบุคคลแล้ว (3) เป็นการจำเป็นเพื่อการปฏิบัติตามสัญญาซึ่งเจ้าของข้อมูลส่วนบุคคลเป็นคู่สัญญาหรือ เพื่อใช้ในการดำเนินการตามคำขอของเจ้าของข้อมูลส่วนบุคคลก่อนเข้าทำสัญญานั้น (4) เป็นการกระทำตามสัญญาระหว่างผู้ควบคุมข้อมูลส่วนบุคคลกับบุคคลหรือนิติบุคคลอื่น เพื่อประโยชน์ของเจ้าของข้อมูลส่วนบุคคล (5) เพื่อป้องกันหรือระงับอันตรายต่อชีวิต ร่างกาย หรือสุขภาพของเจ้าของข้อมูลส่วนบุคคล หรือบุคคลอื่น เมื่อเจ้าของข้อมูลส่วนบุคคลไม่สามารถให้ความยินยอมในขณะนั้นได้ (6) เป็นการจำเป็นเพื่อการดำเนินภารกิจเพื่อประโยชน์สาธารณะที่สำคัญ ในกรณีที่มีปัญหาเกี่ยวกับมาตรฐานการคุ้มครองข้อมูลส่วนบุคคลที่เพียงพอของประเทศปลายทาง หรือองค์การระหว่างประเทศที่รับข้อมูลส่วนบุคคล ให้เสนอต่อคณะกรรมการเป็นผู้วินิจฉัย ทั้งนี้ คำวินิจฉัยของคณะกรรมการอาจขอให้ทบทวนได้เมื่อมีหลักฐานใหม่ทำให้เชื่อได้ว่าประเทศปลายทางหรือ องค์การระหว่างประเทศที่รับข้อมูลส่วนบุคคลมีการพัฒนาจนมีมาตรฐานการคุ้มครองข้อมูลส่วนบุคคล ที่เพียงพอ
พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (เฉพาะส่วนที่ใช้ร่างสัญญา)
พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 มาตรา 29
ในกรณีที่ผู้ควบคุมข้อมูลส่วนบุคคลหรือผู้ประมวลผลข้อมูลส่วนบุคคลซึ่งอยู่ ในราชอาณาจักรได้กำหนดนโยบายในการคุ้มครองข้อมูลส่วนบุคคลเพื่อการส่งหรือโอนข้อมูลส่วนบุคคล ไปยังผู้ควบคุมข้อมูลส่วนบุคคลหรือผู้ประมวลผลข้อมูลส่วนบุคคลซึ่งอยู่ต่างประเทศและอยู่ในเครือกิจการ หรือเครือธุรกิจเดียวกันเพื่อการประกอบกิจการหรือธุรกิจร่วมกัน หากนโยบายในการคุ้มครองข้อมูล ส่วนบุคคลดังกล่าวได้รับการตรวจสอบและรับรองจากสำนักงาน การส่งหรือโอนข้อมูลส่วนบุคคลไปยัง ต่างประเทศที่เป็นไปตามนโยบายในการคุ้มครองข้อมูลส่วนบุคคลที่ได้รับการตรวจสอบและรับรองดังกล่าว ให้สามารถกระทำได้โดยได้รับยกเว้นไม่ต้องปฏิบัติตามมาตรา 28 นโยบายในการคุ้มครองข้อมูลส่วนบุคคล ลักษณะของเครือกิจการหรือเครือธุรกิจเดียวกัน เพื่อการประกอบกิจการหรือธุรกิจร่วมกัน และหลักเกณฑ์และวิธีการตรวจสอบและรับรองตามวรรคหนึ่ง ให้เป็นไปตามที่คณะกรรมการประกาศกำหนด ในกรณีที่ยังไม่มีคำวินิจฉัยของคณะกรรมการตามมาตรา 28 หรือยังไม่มีนโยบายในการคุ้มครอง ข้อมูลส่วนบุคคลตามวรรคหนึ่ง ผู้ควบคุมข้อมูลส่วนบุคคลหรือผู้ประมวลผลข้อมูลส่วนบุคคลอาจส่ง หรือโอนข้อมูลส่วนบุคคลไปยังต่างประเทศได้โดยได้รับยกเว้นไม่ต้องปฏิบัติตามมาตรา 28 เมื่อผู้ควบคุม ข้อมูลส่วนบุคคลหรือผู้ประมวลผลข้อมูลส่วนบุคคลได้จัดให้มีมาตรการคุ้มครองที่เหมาะสมสามารถบังคับ ตามสิทธิของเจ้าของข้อมูลส่วนบุคคลได้ รวมทั้งมีมาตรการเยียวยาทางกฎหมายที่มีประสิทธิภาพ ตามหลักเกณฑ์และวิธีการที่คณะกรรมการประกาศกำหนด
พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (เฉพาะส่วนที่ใช้ร่างสัญญา)
พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 มาตรา 37
ผู้ควบคุมข้อมูลส่วนบุคคลมีหน้าที่ ดังต่อไปนี้ (1) จัดให้มีมาตรการรักษาความมั่นคงปลอดภัยที่เหมาะสม เพื่อป้องกันการสูญหาย เข้าถึง ใช้ เปลี่ยนแปลง แก้ไข หรือเปิดเผยข้อมูลส่วนบุคคลโดยปราศจากอำนาจหรือโดยมิชอบ และต้องทบทวน มาตรการดังกล่าวเมื่อมีความจำเป็นหรือเมื่อเทคโนโลยีเปลี่ยนแปลงไปเพื่อให้มีประสิทธิภาพในการรักษา ความมั่นคงปลอดภัยที่เหมาะสม ทั้งนี้ ให้เป็นไปตามมาตรฐานขั้นต่ำที่คณะกรรมการประกาศกำหนด (2) ในกรณีที่ต้องให้ข้อมูลส่วนบุคคลแก่บุคคลหรือนิติบุคคลอื่นที่ไม่ใช่ผู้ควบคุมข้อมูลส่วนบุคคล ต้องดำเนินการเพื่อป้องกันมิให้ผู้นั้นใช้หรือเปิดเผยข้อมูลส่วนบุคคลโดยปราศจากอำนาจหรือโดยมิชอบ (3) จัดให้มีระบบการตรวจสอบเพื่อดำเนินการลบหรือทำลายข้อมูลส่วนบุคคลเมื่อพ้นกำหนด ระยะเวลาการเก็บรักษา หรือที่ไม่เกี่ยวข้องหรือเกินความจำเป็นตามวัตถุประสงค์ในการเก็บรวบรวม ข้อมูลส่วนบุคคลนั้น หรือตามที่เจ้าของข้อมูลส่วนบุคคลร้องขอ หรือที่เจ้าของข้อมูลส่วนบุคคล ได้ถอนความยินยอม เว้นแต่เก็บรักษาไว้เพื่อวัตถุประสงค์ในการใช้เสรีภาพในการแสดงความคิดเห็น การเก็บรักษาไว้เพื่อวัตถุประสงค์ตามมาตรา 24 (1) หรือ (4) หรือมาตรา 26 (5) (ก) หรือ (ข) การใช้เพื่อการก่อตั้งสิทธิเรียกร้องตามกฎหมาย การปฏิบัติตามหรือการใช้สิทธิเรียกร้องตามกฎหมาย หรือการยกขึ้นต่อสู้สิทธิเรียกร้องตามกฎหมาย หรือเพื่อการปฏิบัติตามกฎหมาย ทั้งนี้ ให้นำความใน
พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (เฉพาะส่วนที่ใช้ร่างสัญญา)
พ.ร.บ.ว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. 2550 มาตรา 5
ผู้ใดเข้าถึงโดยมิชอบซึ่งระบบคอมพิวเตอร์ที่มีมาตรการป้องกันการเข้าถึงโดยเฉพาะและมาตรการนั้นมิได้มีไว้สำหรับตน ต้องระวางโทษจำคุกไม่เกินหกเดือน หรือปรับไม่เกินหนึ่งหมื่นบาท หรือทั้งจำทั้งปรับ
พระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. 2550 (เฉพาะมาตราที่ใช้ร่างสัญญา)
ประมวลรัษฎากร มาตรา 118
ตราสารใดไม่ปิดแสตมป์บริบูรณ์ จะใช้ต้นฉบับ คู่ฉบับ คู่ฉีก หรือสำเนาตราสารนั้นเป็นพยานหลักฐานในคดีแพ่งไม่ได้ จนกว่าจะได้เสียอากรโดยปิดแสตมป์ครบจำนวนตามอัตราในบัญชีท้ายหมวดนี้ และขีดฆ่าแล้ว แต่ทั้งนี้ ไม่เป็นการเสื่อมสิทธิที่จะเรียกเงินเพิ่มอากรตามมาตรา 113 และมาตรา 114
บทบัญญัติ (ถ้อยคำตามเว็บกรมสรรพากร)