We, Lufthansa Services Thailand, located at;

999 Moo 1 A4-091A Concourse Building
Bangna Trad Hwy. KM 15
Road Rachathewa Subdistrict Bangpli District, Samutprakarn 10540,
Thailand;

issue below Privacy Notice in the light of the enactment of EU General Data Protection Regulation (GDPR). Although GDPR is an EU regulation it is relevant for us and potentially for you: LST is a company of the Lufthansa Group, and the GDPR imposes high standards of personal data protection with extra-territorial reach.

One of our responsibilities as a data controller is to be transparent in our processing of your personal data and to tell you about the different ways in which we collect and use your personal data. Please consult the privacy notice that best fits your relationship with us and note that in addition to these notices you may on occasion be provided with additional privacy information where we need to tell you about something not covered by one of these notices.

999 Moo 1 A4-091A Concourse Building Bangna Trad Hwy. KM 15 Road Rachathewa Subdistrict Bangpli District, Samutprakarn 10540, Thailand;

issue below Privacy Notice in the light of the enactment of EU General Data Protection Regulation (GDPR). Although GDPR is an EU regulation it is relevant for us and potentially for you: LST is a company of the Lufthansa Group, and the GDPR imposes high standards of personal data protection with extra-territorial reach.

One of our responsibilities as a data controller is to be transparent in our processing of your personal data and to tell you about the different ways in which we collect and use your personal data. Please consult the privacy notice that best fits your relationship with us and note that in addition to these notices you may on occasion be provided with additional privacy information where we need to tell you about something not covered by one of these notices.

This notice applies to individuals at clients or potential clients, suppliers or potential suppliers, and partners and potential partners of ours in respect of whom we hold personal data. This notice does not form part of a contract to provide services or any other contract. We may update this notice at any time. With the following information, we would like to give you an overview of how we will process your data and of your rights according to data privacy laws. The details on what data will
be processed and which method will be used depend significantly on the services applied for or agreed upon.

This notice applies to individuals at clients or potential clients, suppliers or potential suppliers, and partners and potential partners of ours in respect of whom we hold personal data. This notice does not form part of a contract to provide services or any other contract. We may update this notice at any time. With the following information, we would like to give you an overview of how we will process your data and of your rights according to data privacy laws. The details on what data will be processed and which method will be used depend significantly on the services applied for or agreed upon.

We are Lufthansa Services (Thailand) Ltd
You can reach our company data protection officer at dpc@lst-thai.com

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you:

  • Personal and Contact Details such as Name, Title, Addresses, Telephone Numbers, and Email addresses
  • Passport and Personal ID Card
  • Date of birth
  • Gender
  • Nationality
  • Language
  • Flight Number, Flight Date, Routing
  • Boarding Information
  • Dietary
  • Accessibility
  • Complaints, Compliments, General Questions
  • National Insurance number
  • Billing and Payment Details including Credit Card Details

We may also collect, store and use the following “special categories” of more sensitive personal information:

  • PNR Special services Health indications due to booking of special services e.g. DPNA, wheelchairs (WCHC, WCHR, WCHS), Oxygen, Medical equipment, Deaf or Blind Airlines Passengers, Passenger Traveling with Emotional Dogs etc.
  • Religious Indications due to Special Meals (e.g. KSML)
  • Information about criminal convictions and offences

We process personal data that we obtain from our Airlines Clients in the context of our business relationship. We may also collect information about you – insofar as necessary to provide our service – in a number of different ways. This includes reservation systems, personal, telephonic or e-mail contact or other means. We may sometimes collect information from third parties e.g. travel authorities, travel agencies etc.

We process personal data in accordance with the provisions of the European General Data Protection Regulation (GDPR):

1. For fulfillment of Contractual Obligations (Art. 6 para. 1b of the GDPR)

Data is processed in order to provide services in the context of carrying out our contracts with our Airlines clients. The purposes of data processing are primarily in compliance with the specific product, e.g. Passenger Services, Baggage Services, Airlines Crew Services, Aircraft Operations Services, Cargo Services, Call Center Services for Reservations, Bookings and Ticketing, Station Support Services for voluntary and involuntary change of travel.

2. In the context of balancing interests (Art. 6 para. 1f of the GDPR)

Where required, we process your data beyond the actual fulfillment of the contract for the purposes of the legitimate interests pursued by us or a third party. Examples:

  • Business management and planning, including accounting and auditing
  • Measures for further development of services and products
  • To contact you about your service requirements
  • To contact you with information about our services
  • Education, training and development requirements

3. Due to statutory provisions (Art. 6 para. 1c of the GDPR)

Furthermore, we process your data subject to various legal obligations,meaning statutory requirements (e.g. Immigration Act, B.E. 2522, Thailand Tax Law). Purpose of processing include fulfilling airport, customs and immigration requirements as well as reporting obligations under fiscal laws.

 

Within the company, every unit that requires your data to fulfill our contractual services, a legitimate interest or legal obligations will have access to it. Service providers and vicarious agents appointed by us can also receive access to data for the purposes given, if they maintain data confidentiality. These are companies in the categories of IT services, logistics, telecommunications etc.

With regard to transferring data, we may pass on information about you to recipients outside the company only to fulfill business support to our Airlines Clients or if legal provisions demand it.
Under these requirements, recipients of personal data can be, for example:

  • Service providers and public entities upon contractual obligation (e.g. Logistic Company, Luggage Delivery Company, Hotels, Lounges, Auditing Companies etc.
  • Legal Institutions (e.g. Airport Authorities, Immigration, Custom, Thai Revenue Department etc.)

For How Long will Your Data be stored?

We will only retain your personal information for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

In some circumstances we may anonymize your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.

Once your data is no longer required in order to fulfill contractual or statutory obligations, we will retain and securely destroy your data in accordance with applicable laws and regulations.

We will only retain your personal information for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

In some circumstances we may anonymize your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.

Once your data is no longer required in order to fulfill contractual or statutory obligations, we will retain and securely destroy your data in accordance with applicable laws and regulations.

We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They may only process your personal information on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.

In establishing and carrying out a business relationship, we generally do not use any automated decision-making pursuant to Article 22 of the GDPR. If we use this procedure in individual cases, we will inform you of this separately, as long as this is a legal requirement.

Every data subject has the right to access according to Article 15 of the GDPR, the right to rectification Article 16 of the GDPR, the right to erasure according to Article 17 of the GDPR, the right to restrict processing according to Article 18 of the GDPR, the right of object according to Article 21 of the GDPR, and if applicable – the right to data portability according to Article 20 of the GDPR.

Furthermore, if applicable on you, there is also a right to lodge a complaint with an appropriate data privacy regulatory authority

In case you would like to find out what data, if any, we are holding or are processing that related to you, you can contact us at:

In case you would like to find out what data, if any, we are holding or are processing that related to you, you can contact us at:

 

You may complete the SUBJECT ACCESS REQUEST FORM and send to us or simply send your request to via channels mentioned above. Please note that you will also need to provide prove of your identity. Your request will be processed within 30 calendar days upon receipt of your request.

25.05.2018
Lufthansa Services Thailand