Australia Thailand Business Council

Australia Thailand Business Council (ATBC)

Privacy and Consent Policy

Draft for board consideration — not yet adopted. Version 0.1, 28 July 2026. This policy takes effect once adopted by the ATBC board.
English source text. Where the Thai and English versions differ, the English version governs until the board resolves otherwise.

Prepared by: Simon Henry, Director (Technology and Memberships portfolios)

Review cycle: annually, or on any material change to systems or law

1. Who we are

The Australia Thailand Business Council (“ATBC”, “we”, “us”) is an incorporated association under the Associations Incorporation Act 1991 (ACT), constitution adopted 9 December 2004 and amended subsequently.

We connect professionals, companies and investors working across the Australia–Thailand economic corridor. Our members and contacts are located in both Australia and Thailand, and our systems operate across both countries. This policy is written to meet the requirements of both.

Contact for privacy matters: through our contact form — messages are routed to the Council's privacy contact.

Postal: [to be completed]

2. Why two laws apply to us

Australia — the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). ATBC has an annual turnover below the $3 million threshold at which the Privacy Act automatically applies. We nonetheless commit to complying with the Australian Privacy Principles in full, and will consider formally opting in via the Privacy Opt-in Register. Members entrust us with business contact information and expect it to be handled to a professional standard; a turnover threshold is not a reason to fall short of one.

Thailand — the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”). The PDPA applies to the personal data of individuals in Thailand, including where the data controller is outside Thailand but offers services to, or monitors the behaviour of, people in Thailand. ATBC is an Australian organisation, but it has Thai members, holds events in Thailand, and collects personal data from people in Thailand. The PDPA applies to us on that basis.

Where the two laws differ, we apply the higher standard. In practice that usually means the PDPA, which requires an identified lawful basis for every processing activity and grants broader individual rights than the APPs.

3. What personal information we collect

Members and prospective members — Name; job title; organisation; business email; business phone; postal address; country; sector; website; membership tier; membership start and renewal dates; payment records; event attendance; communication preferences; consent records; and any biography, photograph or company profile you provide for the members directory.

Event registrants (members and non-members) — Name; organisation; email; phone; dietary requirements where relevant to catering; accessibility requirements where you tell us; attendance records.

Newsletter subscribers — Name; email; and the source of subscription.

Board members, office holders and volunteers — The above, plus records necessary for governance — declared interests, appointment and resignation dates, and meeting attendance.

Website visitors — IP address, device and browser information, and pages visited, via analytics and necessary cookies.

We do not seek to collect sensitive information. Dietary and accessibility requirements may reveal health or religious information. We collect these only with your consent, use them only to make an event work for you, and delete them once the event has passed.

4. How we collect it

Directly from you — membership applications, event registrations, newsletter signups, correspondence, business cards exchanged at ATBC events, and forms on our website.

From third parties, where you would reasonably expect it — a colleague registering you for an event, or a member organisation nominating its representatives.

Publicly available sources, for corporate research relating to trade and investment activity.

If we receive information about you that we did not ask for and do not need, we destroy or de-identify it.

5. Our lawful bases

Every use of your personal data rests on one of the following. Under the PDPA we must identify a basis; under the APPs we must have a legitimate purpose.

What we doBasis
Administer your membership, process payments, issue renewalsContract — necessary to provide the membership you applied for
Publish your listing in the members directoryConsent
Send you ATBC newsletters and event invitationsConsent
Send you administrative notices about your membershipContract — these are not marketing and you cannot opt out while a member
Include your details in a promotion sent on behalf of another memberSeparate, express consent — see section 9
Share event registration details with an event sponsorSeparate, express consent given at registration — see section 10
Keep governance records, minutes and declared interestsLegal obligation under the Associations Incorporation Act 1991 (ACT)
Maintain financial recordsLegal obligation — Australian tax and associations law
Improve our website and understand what content is usefulLegitimate interest, balanced against your privacy

You can withdraw consent at any time, and withdrawal is as easy as giving it. Withdrawing consent does not affect processing already carried out, and does not end your membership — but it may mean we can no longer deliver a particular benefit, such as your directory listing.

7. Cross-border data transfers — read this section

This is the most significant privacy consideration for ATBC, because we collect personal data in two countries and store it in a third.

The shape of it

ATBC is an Australian not-for-profit and is the data controller. We decide what is collected and why, and we remain responsible for it wherever it is stored.

We collect personal data from people in Australia and in Thailand. That data is stored in our membership platform, which is hosted offshore from both countries.

So there are two distinct transfers, and neither is “Australia to Thailand”:

TransferGoverned by
Australia → hosting jurisdictionAustralian Privacy Principle 8
Thailand → hosting jurisdictionThai PDPA, sections 28–29

Where your data is stored

SystemProviderData stored inWhat it holds
Scalify (CRM, website, events, communications)Simple Scalable SolutionsOffshore — understood to be Singapore. To be confirmed in writing with the provider before go-live.Member and contact records, event registrations, communications
StripeStripeAustralia / United StatesPayment processing. We do not store your card details
Microsoft 365MicrosoftAustralia and other Microsoft regionsEmail and documents

A note on the platform provider. Simple Scalable Solutions is a Thailand-based company. Where a company is based and where it stores data are different questions, and it is the storage location that determines which transfer rules apply. We will state the confirmed hosting jurisdiction here once the provider has given it to us in writing.

If you are in Australia

Your personal information is disclosed to an overseas recipient when it is stored in our platform. Under APP 8, ATBC takes reasonable steps to ensure that recipient handles your information consistently with the Australian Privacy Principles, and ATBC remains accountable to you for what happens to it. If an overseas recipient mishandles your information, that is treated as a breach by us — not as somebody else's problem.

We do this through contractual data protection obligations covering purpose limitation, security, subprocessors, breach notification, and deletion on termination.

APP 8 does not work from a list of approved countries. It asks whether we took reasonable steps, and holds us accountable either way.

If you are in Thailand

Where your personal data is transferred out of Thailand to our hosting jurisdiction, the PDPA's cross-border rules apply.

Thailand's framework does not yet operate from a published list of approved countries. The governing notifications took effect on 24 March 2024 and set out the available mechanisms — adequacy, specific exemptions, Binding Corporate Rules, and appropriate safeguards such as standard contractual clauses. The adequacy determination itself depends on a list the Personal Data Protection Committee has not yet issued, and the restriction is generally understood to take full effect when it does.

We are not waiting for that. ATBC relies on:

  • appropriate safeguards — standard contractual clauses in our agreement with the platform provider; and
  • your informed consent where a transfer is not covered by a safeguard, given after we have told you where your data is going and that the destination may not offer the same protections as Thailand.

When the Committee publishes its list, we will reassess and tell you if anything changes.

8. The members directory

If you consent, your organisation's listing appears in the members directory on our website. Gold, Silver, Bronze and Platinum members receive a listing; Gold, Silver and Platinum members may publish a detailed profile.

A public website listing is a publication, not a private record. It can be indexed by search engines and copied by others. We therefore:

  • publish only what you provide for that purpose;
  • ask for business contact details, never personal ones;
  • let you review your listing before it goes live;
  • remove it within 5 business days of your request; and
  • remove it when your membership lapses, without you having to ask.

Individual members are listed only with express consent, and may be listed by name only.

9. Member access to the ATBC mailing list

Gold and Platinum members are entitled to six promotional communications a year, and Silver members three, under the approved membership structure.

This benefit is delivered by ATBC sending the communication on the member's behalf. The mailing list itself is never disclosed to any member.

We say this explicitly because the alternative — handing a member the list — would be a disclosure of every other member's contact details to a third party for direct marketing, which we will not do and which neither Australian nor Thai law would permit without each recipient's individual consent.

Recipients may opt out of third-party promotional messages while remaining subscribed to ATBC's own communications. Opting out of one does not opt you out of the other.

10. Event sponsors

Sponsors of ATBC events may receive attendee information only where the attendee has expressly consented at the point of registration, through a clearly labelled, unticked option naming the sponsor.

Where an attendee has not consented, ATBC may send a communication to attendees on the sponsor's behalf instead. Attendee lists are not provided to sponsors by default.

Sponsors receiving attendee data must agree in writing to use it only for the stated purpose, not to transfer it onward, and to delete it within 90 days of the event.

11. Direct marketing

We send marketing only with consent, and every marketing message contains a working unsubscribe mechanism that we action promptly and at no cost, consistent with the Spam Act 2003 (Cth) and the PDPA.

Administrative messages about your membership — renewal notices, receipts, AGM notices, constitutional notices — are not marketing and continue while you are a member.

If you ask us to stop marketing to you, we will also tell you where we obtained your information if you ask.

12. Security

We protect personal information through role-based access limited to those who need it; encryption in transit and at rest; multi-factor authentication on administrative accounts; contractual security obligations on providers; and prompt removal of access when a person leaves a role.

Individual credentials, never shared ones. Shared account passwords are prohibited.

No system is perfectly secure. If something goes wrong, section 13 applies.

13. Data breaches

Australia. Where a data breach is likely to result in serious harm, we notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, under the Notifiable Data Breaches scheme.

Thailand. Where personal data of individuals in Thailand is affected, we notify the Personal Data Protection Committee (PDPC) without undue delay and within 72 hours of becoming aware, unless the breach is unlikely to result in risk to rights and freedoms. Where there is a high risk, we also notify the affected individuals.

In practice we will meet the 72-hour standard for any breach, rather than assessing which jurisdiction's clock applies while it runs.

We maintain an internal breach register recording every incident, whether or not it is notifiable.

14. Retention

We keep personal information only as long as we need it:

RecordRetention
Current member recordsDuration of membership
Lapsed member records2 years after lapse, then deleted or de-identified — retained so a returning member need not start again
Financial and payment records7 years, as required by Australian law
Governance records (minutes, resolutions, declared interests)Permanently, as the association's record
Event registration data12 months after the event
Dietary and accessibility requirementsDeleted immediately after the event
Newsletter subscribersUntil unsubscribe, then contact details deleted
Unsuccessful enquiries12 months

15. Your rights

Both Australia and Thailand give you the right to:

  • access the personal information we hold about you;
  • correct information that is inaccurate, out of date or incomplete;
  • complain if you believe we have mishandled your information.

Thailand's PDPA additionally gives you the right to:

  • withdraw consent at any time;
  • erasure — have your data deleted where we no longer have a basis to hold it;
  • restrict processing while a dispute is resolved;
  • data portability — receive your data in a machine-readable form, or have it sent to another controller;
  • object to processing based on legitimate interest, and to direct marketing at any time.

We extend the PDPA rights to every member and contact regardless of where you are located. It is simpler, fairer, and avoids us treating an Australian member worse than a Thai one for no reason other than geography.

How to exercise them: send your request through our contact form. We respond within 30 days. We do not charge. If we refuse a request we tell you why in writing and how to complain.

16. Complaints

Contact us first — send the details through our contact form. We acknowledge within 5 business days and respond substantively within 30 days.

If you are not satisfied:

  • Australia — Office of the Australian Information Commissioner (OAIC), oaic.gov.au, 1300 363 992
  • Thailand — Personal Data Protection Committee (PDPC), pdpc.or.th
  • ACT — matters relating to our conduct as an incorporated association may also be raised with Access Canberra

17. Website and cookies

Our website uses cookies that are strictly necessary for it to function, and analytics cookies to understand which content is useful.

Analytics and marketing cookies are set only with your consent, obtained through a banner that makes refusing as easy as accepting. Necessary cookies do not require consent. You can change your preferences at any time.

18. Children

ATBC's activities are directed at business professionals. We do not knowingly collect personal information from anyone under 20 — the PDPA's threshold, and the higher of the two applicable standards. If we learn we have, we delete it.

19. Changes

We review this policy annually and whenever we materially change our systems. Material changes are notified to members by email before taking effect. The current version is always available at aust-thai.org.au.