Personal Data Protection
Policy Notice of
KASIKORNBANK PUBLIC
COMPANY LIMITED

Updated May 2022


KASIKORNBANK PUBLIC COMPANY LIMITED (“KBank”) operates its business in adherence with ethical standards and respect for your privacy. KBank has always placed importance on personal data protection and security to ensure that your personal data obtained by KBank will be used in accordance with the objectives and in compliance with law. KBank has formulated this personal data protection policy (this “Policy”) to inform you, as a data subject, of the objectives and details for collection, use and / or disclosure of personal data, including your legal rights.

  1. To whom will this Policy apply, and what are channels for personal data collection ?
    1. 1.1 To whom will this Policy apply ?

      This Policy shall apply to you if you are classified as one or several types of the following persons.

Type of person under the Policy Details and examples
  1. Individual customer of KBank
    ("Individual Customer")
KBank’s individual customer such as
  • person who is using or has used products and / or services
  • person who requests data on products and / or services
  • person who has knowledge of data on products and / or services via various channels
  • person who has been offered or persuaded by KBank to use or accept products and / or services
  1. Individual having involvement with a juristic person which is a customer of, or conducts transactions with, KBank
    ("Personnel of Juristic Person")
Individual having involvement with a juristic person which is a customer of, or conducts transactions with, KBank such as
  • shareholder
  • director
  • authorized person
  • agent or partner
  • employee, officer and / or assignee
  1. Individual having involvement with transactions of KBank or KBank’s customers
Individual having involvement with transactions of KBank or KBank’s customers such as
  • contact person
  • employee, staff, officer, personnel
  • person in the family, friend, neighbor
  • person recommended or referred by KBank’s customers
  • investor, guarantor, mortgager, security provider, ultimate beneficial owner
  • trade partner such as supplier, sponsor, dealer, seller, contractor, service provider, buyer, etc.
  • person who makes payment to or receives money from KBank’s customers
  • any other person of whom KBank may receive personal data from transaction conducted by customers (such as property assessment or loan provision)
  • person who visits KBank’s website or application, or online social media account or uses services at KBank’s branch or head office
  • professional advisor
  • any other individuals of similar nature
  1. General individual
General individual such as
  • person with whom KBank has a relationship, interaction, contact in other ways, or who has provided personal data to KBank, or of whom KBank has received personal data, either directly or indirectly, regardless of any channel
Click and scroll to view information.
  1. 1.2 Channel for collection of personal data

    KBank may collect your personal data via the following channels :

    1. (1) The personal data that you give directly to or through KBank, or held by KBank by your use of products and / or services, contact, visit, joining activities, search via service channels and / or KBank’s contact channels such as branch, head office, website, application, online social media account of KBank, email, ATM, K - CDM (Cash Deposit Machine) or other financial service machines, banking agent, K CHECK ID, cheque direct service, customer data service center, international trade service center, telephone, facsimile, postal mail, short message service (SMS), questionnaire, name card, meeting, training, seminar, event, recreation, marketing promotion activity, contact or any other channel;
    2. (2) The personal data received or accessed by KBank from other sources, such as government agencies, other companies within KBank Financial Conglomerate, other banks or financial institutions, financial service providers and other service providers of KBank, business partners and service providers of business partners, companies that jointly issue products and / or services with KBank, the National Credit Bureau, information service providers, KBank’s customers, individuals or juristic persons conducting a transaction with KBank (as you having involvement with such transactions as mentioned above), registrar, securities issuer, Thailand Securities Depository Co., Ltd. (TSD), online social media, online platform of third party, public data sources (such as Government Gazette), a person having legal authority or legal right, any other person or agency with which KBank has a legal relationship, etc.
  1. Which personal data does KBank collect, use, and / or disclose ?
    1. 2.1 Personal data is the data that can directly or indirectly identify you, i.e.
    2. 2.1.1 Individual means Individual Customer, individual having involvement with transactions of KBank or KBank’s customers and general individual.
Type of data Examples of data that KBank collects, uses and / or discloses
Personal information
  • Title, first name, middle name, last name, alias (if any)
  • Gender, date of birth, age
  • Marital status, family status, number of family members and children
  • Data of relationships (such as between the principal and joint borrower, principal and supplementary cardholder, you and beneficiary)
  • Nationality, country of residence
  • Signature
  • Data on the document issued by government agencies (such as copy of national ID card, copy of passport, copy of visa, copy of certificate of alien, copy of work permit, copy of government / state enterprise official, copy of house registration, copy of birth certificate, copy of name change, copy of marriage certificate, copy of divorce certificate, copy of death certificate, copy of driving license or documents used for identifying and confirming identity of the same characteristic), other KYC and CDD data, etc.
Contact information
  • Address per important document, home address and address in the country of your nationality, workplace
  • Telephone number, mobile phone number, facsimile, email
  • Name or user name for contact via electronic communication or online social media (such as LINE ID)
  • Evidence for having residence in Thailand (for foreign national)
Education and work information
  • Data on a copy of student ID card, the highest education level
  • Career and professional field
  • Position, current years of work
  • Work detail, type of business
Proprietorship data
  • Shareholding ratio and / or data on other documents for confirming business operation (such as commercial lease agreement)
Financial data and transaction
  • Deposit account number, deposit amount, interest
  • Credit / debit card number
  • Income data, source of income and expenses
  • Information on salary certificate, salary slip / bonus or evidence showing other income, other banks’ account statement, appraised value of property
  • Tax ID number and data on personal tax payment
  • Data on application for channel, product and / or service
  • Type of account, deposit period, conditions for payment, type of card, account statement
  • Credit score, credit card limit, accumulated points, approved credit limit, borrowing data, debt amount, collateral data and documents showing ownership of collateral details and payment history
  • Investment data (such as details of securities subscription or reservation), invest risk level, data per risk profile assessment form, client suitability data, trading securities data, value of securities, investment value, investment period)
  • Transaction history, transaction details and objectives for transaction, data in transaction memo, transaction reference number, transaction channel
  • Application user name and password
  • Insurance data (such as documents related to insurance application, type of insurance, insurance application, details of insurance policy, starting and ending date of coverage, details of insured property, insurance premium, the sum insured and details on insurance claims)
  • Other information to support the use of products / services (such as customer code / customer information system (CIS), cheque data, bill of exchange data, credit line, interest rate, related currency, information to support loan application, trade data, purchase order, purchase and sale agreement and / or other agreements, details on guarantee, Form for Declaration of Status as U.S. Person or Non - U.S. Person (FATCA)
Technical data, devices or equipment
  • Data of application usage
  • IP address or MAC address
  • Cookies ID
  • Web beacon, Pixel Tag or Software Development Kit (SDK)
  • Device ID
  • Series and type of devices, network, connection data
  • Data on access, data on single sign - on (SSO)
  • Log
  • Data on login, access period, usage and usage period of application and website, search history, browsing data
  • Time zone and location data
  • Type and version of plug - in browser, operating system and platform including other technologies on your device used for accessing platform
  • Other technical data from usage on platform and operating system
Other information
  • Record of communication or correspondence between you and KBank, details on complaints or comments, request for exercising rights, survey results, audio record, photos, video, audio clips, communication record via log / chat bot, photos or video from CCTV, data on court order / Government Gazette related to transactions of KBank’s customers or related to KBank’s compliance with laws (such as receivership order, order for appointment of administrator of an estate, order effecting a person to be incompetent or quasi - competent person, order for submission of documentary evidence or physical evidence) and any other data deemed personal data under the personal data protection law.
  • Data on registration for joining KBank’s activities
Click and scroll to view information.
  1. 2.1.2 Personnel of Juristic Person means individual having involvement with a juristic person which is a customer of, or conducts transactions with, KBank.
Type of data Examples of data that KBank collects, uses and / or discloses
Personal information
  • Title, first name, middle name, last name, alias (if any)
  • Gender, date / month / year of birth, age
  • Marital status, signature,
  • Data on documents issued by government agencies (such as copy of national ID card, copy of passport, copy of visa, copy of alien certificate, copy of work permit, copy of house registration or documents used for verifying and confirming identity of the same characteristics), other KYC and CDD data, etc.
Contact information
  • Address per important document, current home address and address in the country of nationality, workplace
  • Telephone number, mobile phone number, facsimile number, email
Work information
  • Career and professional field
  • Position, current years of work
  • Work detail, type of business
Information in documents supporting transaction
  • Company certificate
  • List of shareholders
  • Power of Attorney
  • Commercial registration certificate
Other information
  • Information which has been collected, used and / or disclosed relating to relationship with KBank such as information given by a juristic person to KBank in a contract, details about complaints or comments, survey results., information on registration for joining KBank’s activities
Click and scroll to view information.
  1. 2.2 Sensitive Personal Data

    Sensitive Personal Data” means personal data which is specifically determined by law. KBank has no intention to collect Sensitive Personal Data from you.

    In certain cases, however, KBank may need to collect Sensitive Personal Data from you for providing services or products to you, for example, religion (displayed on a copy of national ID card) or race (displayed on a copy of passport of some countries), biometric data (such as facial recognition data, fingerprint recognition data, electronic signature data which uses technology extracting specific behavior of such signing for identification and authentication of the person who writes such signature), data on criminal record, health data, data on disability, sexual behavior, etc. KBank shall collect, use and / or disclose the Sensitive Personal Data provided that KBank has been given explicit consent by you or permitted by law. This shall be undertaken on a case - by - case basis when KBank is required to collect Sensitive Personal Data from you.

    (Unless specifically stated otherwise, personal data and Sensitive Personal Data as earlier mentioned shall hereinafter be collectively referred to as “Personal Data”.)

  1. 2.3 Personal Data of minors, incompetent or quasi - incompetent persons

    KBank has no intention to collect, use and / or disclose Personal Data of minors, the incompetent or quasi - incompetent persons, unless KBank obtains consent from the guardian, the appointed guardian the appointed curator or any act which minors may give consent by itself pursuant to law (as the case may be) and / or has any lawful basis. If KBank discovers that the collection, use and / or disclosure of Personal Data of minors, the incompetent or quasi - incompetent persons is undertaken without (i) consent from the guardian, the appointed guardian, the appointed curator or minors who may give consent by itself pursuant to law (as the case may be) and (ii) any lawful basis, KBank shall delete or destroy such Personal Data.

  1. 2.4 Personal Data of any other third party

    If you provide Personal Data of any other third party who is a Personnel of Juristic Person and / or who has involvement with you to KBank such as shareholders, directors, authorized persons, family members, reference persons, trade partners, guarantors, mortgagers, providers of collateral, beneficiaries, administrator of an estate, emergency contact persons and / or any other person per document of your transaction, etc., please inform those persons of the details under this Policy and request their consent, if necessary, or apply other lawful bases to ensure that KBank can collect, use and / or disclose Personal Data of the aforementioned third party.

  1. What are the objectives of collection, use and / or disclosure of your Personal Data ?

    KBank will collect, use and / or disclose your Personal Data only as necessary under KBank’s legitimate objectives which include the collection, use and / or disclosure of Personal Data for compliance with the contract in which you are a contract party, for performance of duties as required by law, for legitimate interest, for operations according to your consent and / or for operations under other lawful bases. Objectives for collection, use and / or disclosure of Personal Data under this Policy are as follows.

    Some of the following objectives may or may not apply to you. Please consider the objectives in accordance with your relationship with KBank on a case - by - case basis.

    1. 3.1 Objectives requiring consent

      KBank shall collect, use and / or disclose your Personal Data based on consent for the following objectives.

    2. 3.1.1 Collection, use and / or disclosure of Sensitive Personal Data for which KBank cannot apply other lawful bases but must request explicit consent. Such objectives shall be :
      1. (1) Data on religion and race (such data collected from a copy of national ID card or passport of some countries which KBank needs to use as evidence of identification and authentication only.)
      2. (2) Biometric data for signing, identification and authentication, electronic know your customer service of KBank and for support of KBank’s business partners
      3. (3) Health record data, disability data, criminal record, and sexual behavior which KBank shall collect, use and / or disclose only when necessary for the use of certain products and / or services of KBank only. Criminal record shall be used for examination and confiscation of related property
    3. 3.1.2 Analyses, research and / or conducting statistical data including those for development, improvement of products and / or services of KBank, other companies within KBank Financial Conglomerate, business partners and / or other juristic persons that require your consent in accordance with law.
    4. 3.1.3 Marketing operations, submission of offers for products and / or services, privileges for attending activities held by KBank, other companies within KBank Financial Conglomerate, business partners and / or other juristic persons including news, useful advice and appropriately selected promotions and launch of marketing strategies that require your consent in accordance with law.
    5. KBank may request your consent directly or via other companies within KBank Financial Conglomerate, business partners and / or other juristic persons on a case - by - case basis.

  1. 3.2 Objectives requiring other lawful bases other than consent

    KBank will collect, use and / or disclose your Personal Data based on other lawful bases as necessary under KBank’s legitimate objectives, such as, for compliance with the contract in which you are a contract party or your request, for performance of duties as required by law , for the legitimate interest and / or for operations under other lawful bases for the following objectives :

  2. 3.2.1 Operations before entering into a contract with KBank such as giving consultation, advice and / or any other data related to products and / or services, analysis and assessment of customer demand, verification of qualification, verification of juristic person customer’s status, check of data or document accuracy, identification and authentication, including know - your - customer (KYC) and customer due diligence (CDD) procedure, property assessment, credit data examination and / or request for credit data correction, examination of Sanction List of competent authorities and / or government agencies which are generally disclosed as required by law, examination of receivership or insolvency, customer risk classification, and pre - filling of customer’s personal information / contact information for facilitation in applying for products and / or services of KBank.
  3. 3.2.2 Any operation related to consideration of products and / or service provision such as communication, receipt / delivery of documents or parcels, processing of request and operation per the request approval procedure (including but not limited to customer’s property assessment, property examination and valuation, property price review), establishment of card / loan limit, entering into a contract, agreement and / or any other related juristic act, registration for use of products, services and / or for participation in KBank’s activities.
  4. 3.2.3 Delivery of products and / or services under the contract you have entered into with KBank such as
    • Disbursement of loan, investment, purchase of insurance, deposit, withdrawal, transfer, exchange
    • Any operation related to the provision of products and / or services (such as opening of account, change in data, establishment of, use of or change in credit line or account update, payment of dividend and interest, return of principal, acceptance of payments, amendment to deposit contract and interest rates as earlier agreed, account suspension, card suspension, account balance check, conducting transaction report, operation related to relationship between credit line and securities, operation related to securities, purchase of property insurance, credit card point accumulation and redeeming accumulated points, reconciliation, change or increase in card limit, check of accumulated points, card activation, preparation of customer data documents used for customer’s transaction (such as document certification))
    • Examination, confirmation and improvement of transactions (including transaction conducted via K - CDM, ATM, K CHECK ID, website and / or KBank’s application
    • Provision of benefits and operation in accordance with customers’ benefits
    • Customer relationship management, after - sale transaction operation, customer facilitation and / or management of complimentary gifts for customers
    • Provision of advice or risk management guidelines
    • Complaint management, solving problem, operation per customer request
    • Acceptance of payment or any asset
    • Monitoring compliance with conditions for use of products and / or services, termination of services.
  5. 3.2.4 Marketing operation which does not require your consent under the law such as
    • Consideration of customer groups for sending them invitation to join activities or sales promotion as appropriate
    • Submission of the offering of products and / or services, privileges for attending activities, events or meeting held by KBank, including facilitation for joining activities (such as registration for event)
    • Offering of products, services and / or privileges that you have requested or notification of your benefits
    • Offering of products and / or services of the same type / close to those of KBank or other companies within KBank Financial Conglomerate which you are using
    • Contact in case where you have dropped off the application for products and / or services to facilitate you in case you wish to reapply for the products and / or services of the same type with KBank, or offering other products and / or services that you may have an interest in
    • Organization of sales promotional activities (such as provision of benefits and gifts).
  6. 3.2.5 Analysis, research and / or conducting statistical data which does not require your consent under the law for development, improvement of products and / or services within KBank such as
    • Analysis, research, marketing research, conducting statistical data analysis of your financial data and / or conducting report for KBank’s internal use
    • Analysis, conducting model (such as credit scoring)
    • Studying, analyzing and monitoring the proportion of credit portfolio.
  7. 3.2.6 Other operations of KBank such as
    • Management, risk management, internal audit within KBank
    • Maintain legitimate benefits
    • Conducting customer database or recording data in the system or database
    • Consideration and review of customer credit quality
    • Notification of debt payment or renewal of products and / or services
    • Debt collection
    • Satisfaction survey and assessment after use of products and / or services
    • Litigation or other legal processes
    • Participation, coordination and / or assignment of work to another person to perform on behalf of or in collaboration with KBank (such as for design of products or services, design of customer service experience, design of process or support of the delivery of products and / or services)
    • Assignment of rights and / or duties, management of operations of KBank and other companies within KBank Financial Conglomerate
    • Use of CCTV, control of entry / exit of KBank’s premises
    • Management of complaints or management of illegal incidents or suspicious incidents (such as fraud, money laundering, terrorism and mass destruction weapon proliferation, crime, intellectual property infringement including management planning, examination, surveillance, evidence collection, reporting, and / or detection)
    • Prevention and assessment of risk, which may be incurred from granting financial accommodations, of financial institution system
    • Conducting database on business risk to KBank
    • IT operation, communication system management and prevention, response and mitigation of IT risk and cyber threats
  8. 3.2.7 Compliance with the order of competent authorities and / or compliance with laws such as
    • Compliance with the order of court, the government agencies, banking supervisory agencies, competent officers under the personal data protection law, financial institution business law, securities and stock exchange law, life insurance law, non - life insurance law, insurance commission law, payment system law, exchange control law, deposit protection agency law, taxation law, anti - money laundering law, counter - terrorism and proliferation of weapons of mass destruction financing law, computer crime law, bankruptcy law and other laws with which KBank is required to comply, either in Thailand or other countries, including regulations and rules issued under these laws, which are now being enforced, to be amended or to be enforced in the future.
  9. 3.2.8 Prevention or cessation of danger to a person’s life, body or health
  10. 3.2.9 Conducting historical documents or annals for public benefit or related to study, research or statistics
  11. 3.2.10 KBank’s operation of public benefit or performance of duties in using the government’s authority granted to KBank
  12. If KBank needs to collect, use and / or disclose your Personal Data for execution of or compliance with a contract that you have entered into with KBank and / or for KBank’s performance of duties under the law and you, upon request, do not provide such necessary Personal Data to KBank or you have chosen to delete your user account from the application of KBank, KBank may not be able to approve or deliver / provide products and / or services, either partly or wholly, for you and it may impact on KBank’s performance of duties under the law or your relationship with KBank.

  1. To whom will your Personal Data be disclosed ?

    Under your consent or criteria permitted by law, KBank may disclose your Personal Data to a third party. Persons or agencies receiving such Personal Data will collect, use and / or disclose your Personal Data within the scope for which you have given consent, or within the scope related to this Policy. In certain cases, you may be under the personal data protection policy of such recipient of your Personal Data. The recipient of your Personal Data may be in Thailand or other countries.

    KBank may disclose your Personal Data to persons or agencies based on your relationship and transaction as follows :