2026.10.01

บทเรียนค่าปรับ PDPA ที่ทุกธุรกิจควรศึกษา: เมื่อผู้ให้บริการทำลายข้อมูลทำข้อมูลรั่วไหล ทั้งคู่ต้องรับผิดชอบ

สคพ. ของไทยสั่งปรับโรงพยาบาลเอกชน 1.21 ล้านบาท หลังจากผู้รับจ้างทำลายข้อมูลทำเวชระเบียนกว่า 1,000 รายการรั่วไหล ความหมายของคดีนี้ต่อวิธีการกำจัดอุปกรณ์และข้อมูลของคุณ

อ่านภาษาไทย

คดีศึกษา: เวชระเบียนที่กลายสภาพเป็นถุงใส่ขนม

เมื่อวันที่ 1 สิงหาคม 2568 สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคพ.) ของประเทศไทย ได้ประกาศคำสั่งปรับทางปกครองในคดี PDPA จำนวน 5 คดี หนึ่งในนั้นคือเรื่องที่องค์กรที่กำจัดข้อมูลทุกแห่งต้องใส่ใจ

A large private hospital hired a small, family-run business to destroy patient medical records. The contractor did not follow the agreed process. Instead, it took the records back to a private home. More than 1,000 medical records leaked, and some were reused as paper bags for kanom Tokyo , a Thai street snack. Photos of the bags spread on social media.

ใครถูกปรับ และเพราะเหตุใด

  • The hospital: ฿1,210,000. The PDPC found it did not monitor, control or check the destruction process, and did not properly destroy the data within the required period. Health records are sensitive personal data under Section 26 of the PDPA.
  • The contractor: ฿16,940. It did not follow the agreed procedure and did not tell the hospital about the leak, which breached its duties as a data processor.

โดยรวมแล้ว คดีนี้มีมูลค่าค่าปรับรวม 1,226,940 บาท ยังไม่นับรวมความเสียหายต่อชื่อเสียงของโรงพยาบาล

บทเรียน: คุณไม่สามารถปัดความรับผิดชอบด้วยการว่าจ้างผู้อื่นได้

การว่าจ้างผู้อื่นให้ทำลายข้อมูลของคุณไม่ได้เป็นการโอนความรับผิดชอบไปให้พวกเขา โรงพยาบาลต้องจ่ายค่าปรับในจำนวนที่สูงกว่ามากเนื่องจากไม่ได้ควบคุมดูแลผู้ให้บริการของตน นอกจากนี้ สคพ. ยังพร้อมที่จะปรับผู้ประมวลผลข้อมูลโดยตรง ในอีกคดีหนึ่งที่มีการประกาศในวันเดียวกัน ร้านค้าปลีกของเล่นสะสมถูกปรับ 500,000 บาท ในขณะที่ผู้ประมวลผลข้อมูลถูกปรับ 3 ล้านบาท

สคพ. ระบุในเวลานั้นว่า ค่าปรับทางปกครองรวมนับตั้งแต่เริ่มบังคับใช้ PDPA ได้ทะยาน 21.5 ล้านบาทแล้ว และยังมีคดีความอยู่อีกจำนวนมากที่อยู่ระหว่างการพิจารณา

ความเสี่ยงรูปแบบเดียวกันนี้ยังใช้กับอุปกรณ์อิเล็กทรอนิกส์ด้วย

This case involved paper, but the pattern is identical for laptops, phones, hard drives and servers. A device handed to an informal recycler or a "we buy old computers" shop can leave your office with every file still recoverable. If something leaks later, you will have no record of what happened to it. That is why IT asset disposal needs the same paper trail as any other compliance process.

รายการตรวจสอบ: การเลือกผู้ให้บริการกำจัดข้อมูล

  1. ทำสัญญาเป็นลายลักษณ์อักษรที่กำหนดวิธีการทำลาย กรอบเวลา และหน้าที่ในการรายงานเหตุการณ์ที่เกิดขึ้น
  2. จัดทำบัญชีรายการหมายเลขซีเรียลของอุปกรณ์หรือกล่องเอกสารทุกชิ้นที่คุณส่งมอบ
  3. รับทราบว่าใครเป็นผู้รับสิ่งของเหล่านั้น นำไปที่ไหน และทำลายเมื่อใด
  4. กำหนดให้ต้องมีหนังสือรับรองการทำลายข้อมูลสำหรับอุปกรณ์แต่ละชิ้น โดยแสดงหมายเลขซีเรียล วิธีการ และวันที่
  5. ตรวจสอบให้แน่ใจว่าผู้ให้บริการต้องแจ้งให้คุณทราบทันทีหากมีสิ่งผิดปกติเกิดขึ้น ภายใต้กฎหมาย PDPA ในฐานะผู้ควบคุมข้อมูลโดยทั่วไปคุณมีเวลา 72 ชั่วโมงในการแจ้งเหตุการณ์ละเมิดต่อ สคพ.
  6. จัดเก็บหนังสือรับรองไว้กับเอกสารการปฏิบัติตามกฎระเบียบของคุณ

วิธีการทำงานของเรา

We handle laptop data destruction , hard drive and SSD destruction and server data destruction , as well as desktops and phones, and issue a Certificate of Data Destruction for every device with its serial number, method and date. We do not handle paper documents. If you use a shredding company for paper, hold them to the same checklist above.

Get an instant quote or call 082-797-3702.

Sources: PDPC announcement of 1 August 2025, as reported by Thai Post and summarised by Rajah & Tann Thailand . The hospital and contractor were not named.

บทความที่เกี่ยวข้อง

การกำจัดสินทรัพย์ไอที กรุงเทพฯ

การทำลายที่ได้รับการรับรอง ปฏิบัติตาม PDPA ในกรุงเทพฯ

Learn More