Trust, safety and responsible technology

Data, Privacy & Responsible AI

A child-centred policy for protecting personal data and using artificial intelligence with clear purpose, human judgment and accountability.

Document statusCurrent school policy

Effective

This policy governs personal data and responsible AI across School operations. The website and communications Privacy Policy gives the focused notice for the School website, online forms and communications. Read the Privacy Policy.

Our commitments

Child first

The best interests, safety, dignity and evolving capacity of each child guide every decision.

Use less data

Collect and retain only what is necessary for a stated, lawful school purpose.

Humans remain responsible

AI may assist people; it does not replace accountable professional judgment.

Explain and protect

Give clear notices, secure information and provide ways to ask questions or challenge outcomes.

1. Status, scope and governance Who and what this policy covers, and which rules take priority.
  • This policy covers personal data and AI used for school operations, learning, admissions, wellbeing, safeguarding, communications, websites and events, whether handled by governors, employees, students, volunteers, contractors or service providers.
  • Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) is the primary privacy law for the School’s Thai operations. The EU General Data Protection Regulation (GDPR) applies only where its Article 3 territorial scope or another binding legal rule makes it applicable; otherwise its child-protection and privacy-by-design provisions are used as a benchmark. A contract may separately require GDPR-aligned controls, but does not itself extend the GDPR’s statutory territorial scope.
  • ETDA, UNICEF, UNESCO, OECD and NIST materials guide responsible AI governance; this guidance is not law, certification or proof of compliance.
  • School administration is accountable for implementation. Privacy questions and rights requests use the School contact below; any requirement to appoint a Data Protection Officer is assessed under applicable law, and this policy does not claim that a DPO has been appointed.
2. Data, purposes and lawful bases What information may be used, why it is needed and the authority for doing so.
  • Data may include identity and contact details; family and emergency contacts; applications and enrolment; attendance and learning records; wellbeing, behaviour and safeguarding records; health, allergy and support information; photographs or recordings; accounts, devices and access logs; payments; and visitor, staff, contractor or supplier records.
  • Visitor pre-registration is limited to visitor category, full name, required email address, optional telephone number and organization, host or department, a broad purpose code, intended visit date and time, party size, an adult or responsible-adult declaration, and conduct and privacy acknowledgments. Visitors must not enter student names or sensitive data in free-text fields. The email address is retained to match the submission to its record and to respond to privacy questions or rights requests. The visitor-registration system does not automatically email the visitor.
  • AI-related records may include approved prompts, outputs, feedback, audit logs and tool-use metadata. Personal or sensitive student data must not be placed in unapproved AI tools.
  • Purposes include providing education and support, admissions, safety, communication, billing, staffing, site and account security, legal duties and service improvement. On a documented applicable lawful basis—which may include the School’s legitimate interests where appropriate—visitor records support pre-entry screening, campus access, safety, safeguarding and an auditable reception record. Form submission acknowledges the notices and is not consent for unrelated processing.
  • Each activity must have a documented lawful basis under applicable law—for example consent, contract or pre-contract steps, legal obligation, vital interests, or a legitimate interest that does not override individual rights. Sensitive data requires a specific PDPA basis, such as explicit consent or another lawful exception.
  • Consent must be specific, informed and freely given where relied on. Withdrawal affects future consent-based processing and does not invalidate lawful processing already completed.
3. Children and sensitive data Additional protection for children, health information and safeguarding records.
  • Children deserve specific protection. Notices and choices will be concise, age-appropriate and understandable, with parent or guardian involvement when applicable and meaningful attention to the child’s views and evolving capacity.
  • Consent for minors will be handled under the rules that apply to the particular activity. This policy does not adopt a blanket age threshold; Thailand’s PDPA rules and, when applicable, GDPR Article 8 for direct-to-child information-society services must be assessed in context.
  • Health, disability, biometric, safeguarding and other sensitive data will be limited to authorized people with a demonstrated need and a documented lawful basis.
  • Student data will not be used for behavioural advertising, sold, or used to build unrelated commercial profiles.
4. Transparency and individual rights Clear notices and a practical way to exercise privacy rights.
  • Privacy notices will explain the responsible organization, data categories, purposes, lawful bases, recipients, transfers, retention approach, required versus optional fields and available rights.
  • Subject to identity checks, legal conditions and exemptions, people may request access or a copy, correction, deletion, restriction or cessation, portability where applicable, withdrawal of consent, objection, or information about the source of data, and may complain to the competent authority.
  • The School will respond within applicable legal deadlines. Under the PDPA, an access request is ordinarily acted on without delay and no later than 30 days after receipt, unless a lawful ground permits refusal.
  • AI-supported outcomes that materially affect a person must be explainable enough to support meaningful human review, correction and challenge.
5. Retention, sharing and international transfers Keep data only as needed and control every disclosure.
  • A documented retention schedule sets periods by record type, purpose and legal duty. Data is then securely deleted, anonymized or archived where law requires preservation.
  • Visitor pre-registration records are retained for 90 days by default; an authorized administrator may configure 30 to 365 days, and the configured ordinary period cannot exceed 365 days after the scheduled visit. A documented legal, safeguarding or incident hold may preserve a record in the restricted backend only while the need continues.
  • A complete copy of each submitted visitor record is encrypted at rest using a site-specific key that the visitor system creates and manages automatically. Limited linked operational metadata—including date, time, category, purpose, party size, status, notification state and retention timestamps—may also remain in access-controlled columns of the private table so authorized administrators can operate and audit the service.
  • When a visitor submits a registration, a separate TIS-branded HTML notification is sent only to each School administrator recipient configured in the website backend. It contains the complete submitted registration, including the reference, visitor name and contact details, organization when provided, visitor category, purpose, host or department, intended visit date and time, party size, form language, required acknowledgments, accepted notice version and submission time. It also contains that recipient’s private link to a read-only summary of all records still within their recorded retention period. No automatic submission email is sent to the visitor. A complete current link can start a 12-hour browser viewing session, so it must be kept confidential and must not be forwarded. Removing a recipient or replacing the private summary links revokes that recipient’s previous link and viewing sessions. Website hosting, mail, SMTP, mail-delivery or mail-log providers may process or retain the notification, access credential, personal data, and message or delivery metadata under the School’s configuration and applicable provider terms. Acceptance by the website mail system is not confirmation of inbox delivery.
  • The email-linked staff summary reads retained records live and is not a separate archive. A record no longer appears there after an authorized backend deletion or once its recorded retention deadline is reached, and the summary never displays a record beyond 365 days after the scheduled visit. A formal hold may preserve a due record for authorized WordPress managers, but it does not extend visibility in the email-linked summary.
  • The workflow does not generate a QR code or expose a public check-in bearer token. The printable or savable confirmation is evidence that the form was submitted, not permission to enter. Normal reception identity, safeguarding and entry checks still apply.
  • Access and sharing will be limited to authorized school teams, service providers, professional advisers, emergency services or public authorities when necessary and lawful. The School will not sell personal data.
  • Processors must be selected through due diligence and bound by written instructions, confidentiality, security, deletion/return, incident support and subprocessor controls.
  • International transfers must be recorded and use a lawful PDPA or, where applicable, GDPR transfer mechanism, with supplementary safeguards where risk requires them.
6. Security and personal-data breaches Proportionate controls, prompt escalation and legally required notification.
  • The School will use proportionate administrative, technical and physical safeguards such as role-based access, strong authentication, secure configuration, encryption where appropriate, backups, patching, logging, supplier controls, staff training and tested response procedures.
  • Suspected loss, unauthorized access, disclosure, alteration or destruction must be reported immediately through the School’s incident route; staff and students must not investigate by accessing more data or conceal an incident.
  • Where PDPA notification duties apply, the School will notify the Personal Data Protection Committee Office without delay and, where feasible, within 72 hours after becoming aware, unless the breach is unlikely to result in risk. When the breach is likely to result in high risk, affected people will also be notified without delay, as applicable.
  • Incidents will be contained, documented, assessed, remediated and reviewed for lessons learned, while preserving evidence and safeguarding affected children.
7. Website, cookies and communications Transparent online services without unnecessary tracking.
  • Essential cookies may support security, language preferences and core functions. After a visitor-form submission, an encrypted, HttpOnly first-party confirmation cookie is retained for up to 30 minutes solely to display, translate, print or save a non-identifying submission confirmation. It contains only the reference, submission time, intended visit date and time, and confirmation status; it is not used for advertising or analytics. For abuse prevention, the form derives a keyed pseudonymous rate identifier from the connection address and does not keep the raw address in its rate table. The identifier stops affecting decisions at the next hourly boundary; expired buckets are removed by scheduled cleanup. Hosting or CDN security logs are governed separately. Other non-essential analytics, advertising or similar storage will be used only with the notice and choice required by applicable law.
  • The cookie notice must identify actual tools, purposes, providers and durations; generic wording will not replace a verified cookie inventory.
  • External links and services operate under their own notices. School communications will use appropriate recipients, access controls and opt-out choices where relevant.
8. Permitted AI uses Approved, proportionate assistance with a clear educational or operational purpose.
  • Approved AI may support lesson planning, translation, accessibility, brainstorming, practice, formative feedback, drafting, summarization, coding assistance and routine administration when a responsible person checks the result.
  • Use must match the user’s role, the tool’s approved age range and terms, the learning objective and the minimum-data rule. A safer non-AI method should be used where it achieves the purpose with less risk.
  • Users must verify facts, calculations, citations, tone, cultural context, copyright, bias and accessibility before relying on or sharing an output.
  • AI-generated or materially AI-assisted work must be disclosed when required by the teacher, assessment rules or professional context.
9. Prohibited AI uses Uses that the School will not authorize because they create unacceptable risk.
  • Do not enter identifiable, confidential, safeguarding, health, financial or other sensitive school information into an unapproved AI service, personal account or public chatbot.
  • Do not make admissions, grading, promotion, discipline, safeguarding, special-support, employment or medical decisions solely through automated processing or AI.
  • Do not use biometric identification, emotion recognition, covert surveillance or manipulative profiling through AI in school activities.
  • Do not create impersonations, deceptive deepfakes, non-consensual intimate material, harassment, discriminatory content, malware, dangerous instructions or content that exploits a child.
  • Do not use AI to cheat, fabricate evidence or citations, bypass assessment rules, conceal authorship, violate copyright or obtain unauthorized access.
10. People, human review and academic integrity Clear duties for leaders, staff, students, families and contractors.
  • Leaders approve systems and risk decisions; staff set age-appropriate boundaries and remain accountable for professional judgments; students follow teacher directions and assessment rules; contractors follow the same controls as school personnel.
  • Staff must not treat plausible AI output as fact. A qualified person must review high-impact advice, and safeguarding, health, legal and learning-support concerns must follow established human-led procedures.
  • Students will be taught how AI works and fails, how to protect privacy, verify sources, cite assistance, recognize bias and seek help. Access must respect provider age limits and any required parent or guardian authorization.
  • No one will be penalized merely for raising an AI or privacy concern in good faith. Reasonable non-AI alternatives will be available where access, disability, language or family choice requires them.
11. Procurement, impact assessment, fairness and accessibility Check a system before data or people are exposed to it.
  • Before approval, the School will examine purpose, necessity, age suitability, data flows and locations, retention, model-training terms, subprocessors, transfers, security, incident notice, deletion, intellectual property, accessibility, bias, explainability and exit arrangements.
  • A privacy impact assessment—and a formal data-protection impact assessment where legally required—will precede processing likely to create high risk. AI assessments will also consider accuracy, safety, discrimination, child development, academic integrity, human oversight and affected-group input.
  • Contracts should prohibit provider use of school data to train or improve general models unless specifically assessed, transparently authorized and supported by an applicable lawful basis.
  • Systems will be tested in context and monitored for unequal performance or exclusion. Material problems require restriction, correction, suspension or retirement rather than reliance on a vendor claim.
12. Records, concerns, review and contact Keep evidence of decisions and give the community a clear route to help.
  • The School will maintain appropriate records of processing, lawful bases, consent where used, notices, vendors, assessments, approved AI tools, significant human reviews, rights requests, incidents and decisions to restrict or retire systems.
  • Privacy, safety, unfairness, inaccurate outputs or suspected misuse should be reported promptly. Urgent child-safeguarding concerns must also follow the School’s safeguarding route and must not wait for a privacy review.
  • This policy will be reviewed at least annually and after a material legal, system, vendor or incident change. Updated notices and renewed consent will be provided where required.
  • Questions and rights requests: info@thaiinternationalschool.ac.th or 063 838 9900. The School assesses and meets any DPO-related duty under applicable law; this general School contact is not represented as a DPO contact.
School visits & Sit-In Program This visitor form adjusts to the selected visit type. General visits collect contact details, purpose or event details and dates. Family and event groups provide group counts and the ages, enrolment status, current school and grade of attending children. No child details are collected for groups with no children. Contractors and vendors provide only contact details, purpose, host department and date, with policy acknowledgments. Trial and sit-in applications additionally collect the enabled student, guardian, support, document and fee-choice fields.
  • Health, allergy and learning or attention-support information, diagnosed or not, is requested to assess and prepare appropriate support. The form asks separately for authorization to use this information. Families may contact the school about assistance or future consent withdrawal.
  • TIS uses your contact, group and visit details to arrange your visit and manage reception. These basic details are sent to the school’s configured notification recipients and are available through their private visitor-summary links. Student identity documents, health and learning-support information remain restricted to authorized school accounts and are not included in these emails or private summaries. Hosting and email providers support this service. Email copies follow the school’s mailbox retention policy and are not removed when website records expire.
  • Registration records and uploads are scheduled for deletion 180 days after the visit date or last requested student day, or after submission if dates are not supplied. Separate school enrolment or accounting records follow the school’s retention policies. Contact info@thaiinternationalschool.ac.th to ask about access, correction, deletion, or health-information consent. Required and optional fields are identified on this form; contact the school if you need help providing required information.