Trust, safety and responsible technology

Data, Privacy & Responsible AI

A child-centred policy for protecting personal data and using artificial intelligence with clear purpose, human judgment and accountability.

Document statusCurrent school policy

Effective

This policy governs personal data and responsible AI across School operations. The website and communications Privacy Policy gives the focused notice for the School website, online forms and communications. Read the Privacy Policy.

Our commitments

Child first

The best interests, safety, dignity and evolving capacity of each child guide every decision.

Use less data

Collect and retain only what is necessary for a stated, lawful school purpose.

Humans remain responsible

AI may assist people; it does not replace accountable professional judgment.

Explain and protect

Give clear notices, secure information and provide ways to ask questions or challenge outcomes.

1. Status, scope and governance Who and what this policy covers, and which rules take priority.
  • This policy covers personal data and AI used for school operations, learning, admissions, wellbeing, safeguarding, communications, websites and events, whether handled by governors, employees, students, volunteers, contractors or service providers.
  • Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) is the primary privacy law for the School’s Thai operations. The EU General Data Protection Regulation (GDPR) applies only where its Article 3 territorial scope or another binding legal rule makes it applicable; otherwise its child-protection and privacy-by-design provisions are used as a benchmark. A contract may separately require GDPR-aligned controls, but does not itself extend the GDPR’s statutory territorial scope.
  • ETDA, UNICEF, UNESCO, OECD and NIST materials guide responsible AI governance; this guidance is not law, certification or proof of compliance.
  • School administration is accountable for implementation. Privacy questions and rights requests use the School contact below; any requirement to appoint a Data Protection Officer is assessed under applicable law, and this policy does not claim that a DPO has been appointed.
2. Data, purposes and lawful bases What information may be used, why it is needed and the authority for doing so.
  • Data may include identity and contact details; family and emergency contacts; applications and enrolment; attendance and learning records; wellbeing, behaviour and safeguarding records; health, allergy and support information; photographs or recordings; accounts, devices and access logs; payments; and visitor, staff, contractor or supplier records.
  • Visitor pre-registration is limited to visitor category, full name, required email address, optional telephone number and organization, host or department, a broad purpose code, intended visit date and time, party size, an adult or responsible-adult declaration, and conduct and privacy acknowledgments. Visitors must not enter student names or sensitive data in free-text fields. The email address is retained to match the submission to its record and to respond to privacy questions or rights requests. The visitor-registration system does not automatically email the visitor.
  • AI-related records may include approved prompts, outputs, feedback, audit logs and tool-use metadata. Personal or sensitive student data must not be placed in unapproved AI tools.
  • Purposes include providing education and support, admissions, safety, communication, billing, staffing, site and account security, legal duties and service improvement. On a documented applicable lawful basis—which may include the School’s legitimate interests where appropriate—visitor records support pre-entry screening, campus access, safety, safeguarding and an auditable reception record. Form submission acknowledges the notices and is not consent for unrelated processing.
  • Each activity must have a documented lawful basis under applicable law—for example consent, contract or pre-contract steps, legal obligation, vital interests, or a legitimate interest that does not override individual rights. Sensitive data requires a specific PDPA basis, such as explicit consent or another lawful exception.
  • Consent must be specific, informed and freely given where relied on. Withdrawal affects future consent-based processing and does not invalidate lawful processing already completed.
3. Children and sensitive data Additional protection for children, health information and safeguarding records.
  • Children deserve specific protection. Notices and choices will be concise, age-appropriate and understandable, with parent or guardian involvement when applicable and meaningful attention to the child’s views and evolving capacity.
  • Consent for minors will be handled under the rules that apply to the particular activity. This policy does not adopt a blanket age threshold; Thailand’s PDPA rules and, when applicable, GDPR Article 8 for direct-to-child information-society services must be assessed in context.
  • Health, disability, biometric, safeguarding and other sensitive data will be limited to authorized people with a demonstrated need and a documented lawful basis.
  • Student data will not be used for behavioural advertising, sold, or used to build unrelated commercial profiles.
4. Transparency and individual rights Clear notices and a practical way to exercise privacy rights.
  • Privacy notices will explain the responsible organization, data categories, purposes, lawful bases, recipients, transfers, retention approach, required versus optional fields and available rights.
  • Subject to identity checks, legal conditions and exemptions, people may request access or a copy, correction, deletion, restriction or cessation, portability where applicable, withdrawal of consent, objection, or information about the source of data, and may complain to the competent authority.
  • The School will respond within applicable legal deadlines. Under the PDPA, an access request is ordinarily acted on without delay and no later than 30 days after receipt, unless a lawful ground permits refusal.
  • AI-supported outcomes that materially affect a person must be explainable enough to support meaningful human review, correction and challenge.
5. Retention, sharing and international transfers Keep data only as needed and control every disclosure.
  • A documented retention schedule sets periods by record type, purpose and legal duty. Data is then securely deleted, anonymized or archived where law requires preservation.
  • Visitor pre-registration records are retained for 90 days by default; an authorized administrator may configure 30 to 365 days. A documented legal, safeguarding or incident hold may extend that period only while the need continues.
  • A complete copy of each submitted visitor record is encrypted at rest using a site-specific key that the visitor system creates and manages automatically. Limited linked operational metadata—including date, time, category, purpose, party size, status, notification state and retention timestamps—may also remain in access-controlled columns of the private table so authorized administrators can operate and audit the service.
  • When a visitor submits a registration, privacy-minimized TIS-branded HTML notifications are sent separately only to the School administrator recipients configured in the website backend. They contain only the reference, intended visit date and time, visitor category, broad purpose, party size, and a manager-only link to the protected record; they exclude the visitor’s name, contact route, organization and host. No automatic submission email is sent to the visitor. Website hosting, mail, SMTP, mail-delivery or mail-log providers may process or retain the notification and message or delivery metadata under the School’s configuration and applicable provider terms. Acceptance by the website mail system is not confirmation of inbox delivery.
  • The workflow does not generate a QR code or expose a public check-in bearer token. The printable or savable confirmation is evidence that the form was submitted, not permission to enter. Normal reception identity, safeguarding and entry checks still apply.
  • Access and sharing will be limited to authorized school teams, service providers, professional advisers, emergency services or public authorities when necessary and lawful. The School will not sell personal data.
  • Processors must be selected through due diligence and bound by written instructions, confidentiality, security, deletion/return, incident support and subprocessor controls.
  • International transfers must be recorded and use a lawful PDPA or, where applicable, GDPR transfer mechanism, with supplementary safeguards where risk requires them.
6. Security and personal-data breaches Proportionate controls, prompt escalation and legally required notification.
  • The School will use proportionate administrative, technical and physical safeguards such as role-based access, strong authentication, secure configuration, encryption where appropriate, backups, patching, logging, supplier controls, staff training and tested response procedures.
  • Suspected loss, unauthorized access, disclosure, alteration or destruction must be reported immediately through the School’s incident route; staff and students must not investigate by accessing more data or conceal an incident.
  • Where PDPA notification duties apply, the School will notify the Personal Data Protection Committee Office without delay and, where feasible, within 72 hours after becoming aware, unless the breach is unlikely to result in risk. When the breach is likely to result in high risk, affected people will also be notified without delay, as applicable.
  • Incidents will be contained, documented, assessed, remediated and reviewed for lessons learned, while preserving evidence and safeguarding affected children.
7. Website, cookies and communications Transparent online services without unnecessary tracking.
  • Essential cookies may support security, language preferences and core functions. After a visitor-form submission, an encrypted, HttpOnly first-party confirmation cookie is retained for up to 30 minutes solely to display, translate, print or save a non-identifying submission confirmation. It contains only the reference, submission time, intended visit date and time, and confirmation status; it is not used for advertising or analytics. For abuse prevention, the form derives a keyed pseudonymous rate identifier from the connection address and does not keep the raw address in its rate table. The identifier stops affecting decisions at the next hourly boundary; expired buckets are removed by scheduled cleanup. Hosting or CDN security logs are governed separately. Other non-essential analytics, advertising or similar storage will be used only with the notice and choice required by applicable law.
  • The cookie notice must identify actual tools, purposes, providers and durations; generic wording will not replace a verified cookie inventory.
  • External links and services operate under their own notices. School communications will use appropriate recipients, access controls and opt-out choices where relevant.
8. Permitted AI uses Approved, proportionate assistance with a clear educational or operational purpose.
  • Approved AI may support lesson planning, translation, accessibility, brainstorming, practice, formative feedback, drafting, summarization, coding assistance and routine administration when a responsible person checks the result.
  • Use must match the user’s role, the tool’s approved age range and terms, the learning objective and the minimum-data rule. A safer non-AI method should be used where it achieves the purpose with less risk.
  • Users must verify facts, calculations, citations, tone, cultural context, copyright, bias and accessibility before relying on or sharing an output.
  • AI-generated or materially AI-assisted work must be disclosed when required by the teacher, assessment rules or professional context.
9. Prohibited AI uses Uses that the School will not authorize because they create unacceptable risk.
  • Do not enter identifiable, confidential, safeguarding, health, financial or other sensitive school information into an unapproved AI service, personal account or public chatbot.
  • Do not make admissions, grading, promotion, discipline, safeguarding, special-support, employment or medical decisions solely through automated processing or AI.
  • Do not use biometric identification, emotion recognition, covert surveillance or manipulative profiling through AI in school activities.
  • Do not create impersonations, deceptive deepfakes, non-consensual intimate material, harassment, discriminatory content, malware, dangerous instructions or content that exploits a child.
  • Do not use AI to cheat, fabricate evidence or citations, bypass assessment rules, conceal authorship, violate copyright or obtain unauthorized access.
10. People, human review and academic integrity Clear duties for leaders, staff, students, families and contractors.
  • Leaders approve systems and risk decisions; staff set age-appropriate boundaries and remain accountable for professional judgments; students follow teacher directions and assessment rules; contractors follow the same controls as school personnel.
  • Staff must not treat plausible AI output as fact. A qualified person must review high-impact advice, and safeguarding, health, legal and learning-support concerns must follow established human-led procedures.
  • Students will be taught how AI works and fails, how to protect privacy, verify sources, cite assistance, recognize bias and seek help. Access must respect provider age limits and any required parent or guardian authorization.
  • No one will be penalized merely for raising an AI or privacy concern in good faith. Reasonable non-AI alternatives will be available where access, disability, language or family choice requires them.
11. Procurement, impact assessment, fairness and accessibility Check a system before data or people are exposed to it.
  • Before approval, the School will examine purpose, necessity, age suitability, data flows and locations, retention, model-training terms, subprocessors, transfers, security, incident notice, deletion, intellectual property, accessibility, bias, explainability and exit arrangements.
  • A privacy impact assessment—and a formal data-protection impact assessment where legally required—will precede processing likely to create high risk. AI assessments will also consider accuracy, safety, discrimination, child development, academic integrity, human oversight and affected-group input.
  • Contracts should prohibit provider use of school data to train or improve general models unless specifically assessed, transparently authorized and supported by an applicable lawful basis.
  • Systems will be tested in context and monitored for unequal performance or exclusion. Material problems require restriction, correction, suspension or retirement rather than reliance on a vendor claim.
12. Records, concerns, review and contact Keep evidence of decisions and give the community a clear route to help.
  • The School will maintain appropriate records of processing, lawful bases, consent where used, notices, vendors, assessments, approved AI tools, significant human reviews, rights requests, incidents and decisions to restrict or retire systems.
  • Privacy, safety, unfairness, inaccurate outputs or suspected misuse should be reported promptly. Urgent child-safeguarding concerns must also follow the School’s safeguarding route and must not wait for a privacy review.
  • This policy will be reviewed at least annually and after a material legal, system, vendor or incident change. Updated notices and renewed consent will be provided where required.
  • Questions and rights requests: info@thaiinternationalschool.ac.th or 063 838 9900. The School assesses and meets any DPO-related duty under applicable law; this general School contact is not represented as a DPO contact.