This following document sets forth the Privacy Policy for the Australia Thailand Business Council website, https://www.aust-thai.org.au
The Australia Thailand Business Council is committed to providing you with the best possible customer service experience. The Australia Thailand Business Council is bound by the Privacy Act 1988 (Cth), which sets out a number of principles concerning the privacy of individuals.
The Australia Thailand Business Council (“ATBC”, “we”, “us”) is an incorporated association under the Associations Incorporation Act 1991 (ACT), constitution adopted 9 December 2004 and amended subsequently.
We connect professionals, companies and investors working across the Australia–Thailand economic corridor. Our members and contacts are located in both Australia and Thailand, and our systems operate across both countries. This policy is written to meet the requirements of both.
Contact for privacy matters: through our contact form — messages are routed to the Council's privacy contact.
Postal: [to be completed]
Australia — the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). ATBC has an annual turnover below the $3 million threshold at which the Privacy Act automatically applies. We nonetheless commit to complying with the Australian Privacy Principles in full, and will consider formally opting in via the Privacy Opt-in Register. Members entrust us with business contact information and expect it to be handled to a professional standard; a turnover threshold is not a reason to fall short of one.
Thailand — the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”). The PDPA applies to the personal data of individuals in Thailand, including where the data controller is outside Thailand but offers services to, or monitors the behaviour of, people in Thailand. ATBC is an Australian organisation, but it has Thai members, holds events in Thailand, and collects personal data from people in Thailand. The PDPA applies to us on that basis.
Where the two laws differ, we apply the higher standard. In practice that usually means the PDPA, which requires an identified lawful basis for every processing activity and grants broader individual rights than the APPs.
Members and prospective members — Name; job title; organisation; business email; business phone; postal address; country; sector; website; membership tier; membership start and renewal dates; payment records; event attendance; communication preferences; consent records; and any biography, photograph or company profile you provide for the members directory.
Event registrants (members and non-members) — Name; organisation; email; phone; dietary requirements where relevant to catering; accessibility requirements where you tell us; attendance records.
Newsletter subscribers — Name; email; and the source of subscription.
Board members, office holders and volunteers — The above, plus records necessary for governance — declared interests, appointment and resignation dates, and meeting attendance.
Website visitors — IP address, device and browser information, and pages visited, via analytics and necessary cookies.
We do not seek to collect sensitive information. Dietary and accessibility requirements may reveal health or religious information. We collect these only with your consent, use them only to make an event work for you, and delete them once the event has passed.
Directly from you — membership applications, event registrations, newsletter signups, correspondence, business cards exchanged at ATBC events, and forms on our website.
From third parties, where you would reasonably expect it — a colleague registering you for an event, or a member organisation nominating its representatives.
Publicly available sources, for corporate research relating to trade and investment activity.
If we receive information about you that we did not ask for and do not need, we destroy or de-identify it.
Every use of your personal data rests on one of the following. Under the PDPA we must identify a basis; under the APPs we must have a legitimate purpose.
What we do
Basis
Administer your membership, process payments, issue renewals
Contract — necessary to provide the membership you applied for
Publish your listing in the members directory
Consent
Send you ATBC newsletters and event invitations
Consent
Send you administrative notices about your membership
Contract — these are not marketing and you cannot opt out while a member
Include your details in a promotion sent on behalf of another member
Separate, express consent — see section 9
Share event registration details with an event sponsor
Separate, express consent given at registration — see section 10
Keep governance records, minutes and declared interests
Legal obligation under the Associations Incorporation Act 1991 (ACT)
Maintain financial records
Legal obligation — Australian tax and associations law
Improve our website and understand what content is useful
Legitimate interest, balanced against your privacy
You can withdraw consent at any time, and withdrawal is as easy as giving it. Withdrawing consent does not affect processing already carried out, and does not end your membership — but it may mean we can no longer deliver a particular benefit, such as your directory listing.
Consent is only meaningful if it is real. We therefore:
✦ Ask separately for separate things. Membership, directory listing, newsletter and third-party promotions are four distinct consents. Agreeing to one is not agreeing to the others.
✦ Never pre-tick boxes. Consent is an affirmative act.
✦ Never bundle consent into the terms of membership. Under the PDPA, consent that is a condition of receiving a service is not freely given.
✦ Tell you what you are agreeing to before you agree, in plain language, including who will receive your data and whether it will leave your country.
✦ Record what you consented to, when, and how — and keep that record for as long as we rely on it.
✦ Make withdrawal easy — an unsubscribe link in every marketing message, and a single request to our privacy contact for anything else.
This is the most significant privacy consideration for ATBC, because we collect personal data in two countries and store it in a third.
The shape of it
ATBC is an Australian not-for-profit and is the data controller. We decide what is collected and why, and we remain responsible for it wherever it is stored.
We collect personal data from people in Australia and in Thailand. That data is stored in our membership platform, which is hosted offshore from both countries.
So there are two distinct transfers, and neither is “Australia to Thailand”:
Governed by
Australia → Hosting Jurisdiction
Australian Privacy Principle 8
Thailand → Hosting Jurisdiction
Thai PDPA, Sections 28–29
Where your data is stored
System
Provider
Data stored in
What it holds
Scalify (CRM, website, events, communications)
Simple
Scalable
Solutions
Offshore — understood to be Singapore. To be confirmed in writing with the provider before go-live.
Member and contact records, event registrations, communications
Stripe
Stripe
Australia / United States
Payment processing. We do not store your card details
Microsoft 365
Microsoft
Australia and other Microsoft regions
Email and documents
A note on the platform provider. Simple Scalable Solutions is a Thailand-based company. Where a company is based and where it stores data are different questions, and it is the storage location that determines which transfer rules apply. We will state the confirmed hosting jurisdiction here once the provider has given it to us in writing.
If you are in Australia
Your personal information is disclosed to an overseas recipient when it is stored in our platform. Under APP 8, ATBC takes reasonable steps to ensure that recipient handles your information consistently with the Australian Privacy Principles, and ATBC remains accountable to you for what happens to it. If an overseas recipient mishandles your information, that is treated as a breach by us — not as somebody else's problem.
We do this through contractual data protection obligations covering purpose limitation, security, subprocessors, breach notification, and deletion on termination.
APP 8 does not work from a list of approved countries. It asks whether we took reasonable steps, and holds us accountable either way
If you are in Thailand
Where your personal data is transferred out of Thailand to our hosting jurisdiction, the PDPA's cross-border rules apply.
Thailand's framework does not yet operate from a published list of approved countries. The governing notifications took effect on 24 March 2024 and set out the available mechanisms — adequacy, specific exemptions, Binding Corporate Rules, and appropriate safeguards such as standard contractual clauses. The adequacy determination itself depends on a list the Personal Data Protection Committee has not yet issued, and the restriction is generally understood to take full effect when it does.
We are not waiting for that. ATBC relies on:
✦ Appropriate safeguards — standard contractual clauses in our agreement with the platform provider; and
✦ Your informed consent where a transfer is not covered by a safeguard, given after we have told you where your data is going and that the destination may not offer the same protections as Thailand.
When the Committee publishes its list, we will reassess and tell you if anything changes.
If you consent, your organisation's listing appears in the members directory on our website. Gold, Silver, Bronze and Platinum members receive a listing; Gold, Silver and Platinum members may publish a detailed profile.
A public website listing is a publication, not a private record. It can be indexed by search engines and copied by others. We therefore:
✦ publish only what you provide for that purpose;
✦ ask for business contact details, never personal ones;
✦ let you review your listing before it goes live;
✦ remove it within 5 business days of your request; and
✦ remove it when your membership lapses, without you having to ask.
Individual members are listed only with express consent, and may be listed by name only.
Gold and Platinum members are entitled to six promotional communications a year, and Silver members three, under the approved membership structure.
This benefit is delivered by ATBC sending the communication on the member's behalf. The mailing list itself is never disclosed to any member.
We say this explicitly because the alternative — handing a member the list — would be a disclosure of every other member's contact details to a third party for direct marketing, which we will not do and which neither Australian nor Thai law would permit without each recipient's individual consent.
Recipients may opt out of third-party promotional messages while remaining subscribed to ATBC's own communications. Opting out of one does not opt you out of the other.
Sponsors of ATBC events may receive attendee information only where the attendee has expressly consented at the point of registration, through a clearly labelled, unticked option naming the sponsor.
Where an attendee has not consented, ATBC may send a communication to attendees on the sponsor's behalf instead. Attendee lists are not provided to sponsors by default.
Sponsors receiving attendee data must agree in writing to use it only for the stated purpose, not to transfer it onward, and to delete it within 90 days of the event.
We send marketing only with consent, and every marketing message contains a working unsubscribe mechanism that we action promptly and at no cost, consistent with the Spam Act 2003 (Cth) and the PDPA.
Administrative messages about your membership — renewal notices, receipts, AGM notices, constitutional notices — are not marketing and continue while you are a member.
If you ask us to stop marketing to you, we will also tell you where we obtained your information if you ask.
We protect personal information through role-based access limited to those who need it; encryption in transit and at rest; multi-factor authentication on administrative accounts; contractual security obligations on providers; and prompt removal of access when a person leaves a role.
Individual credentials, never shared ones. Shared account passwords are prohibited.
No system is perfectly secure. If something goes wrong, section 13 applies.
Australia. Where a data breach is likely to result in serious harm, we notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, under the Notifiable Data Breaches scheme.
Thailand. Where personal data of individuals in Thailand is affected, we notify the Personal Data Protection Committee (PDPC) without undue delay and within 72 hours of becoming aware, unless the breach is unlikely to result in risk to rights and freedoms. Where there is a high risk, we also notify the affected individuals.
In practice we will meet the 72-hour standard for any breach, rather than assessing which jurisdiction's clock applies while it runs.
We maintain an internal breach register recording every incident, whether or not it is notifiable.
We keep personal information only as long as we need it:
Record
Retention
Current member records
Duration of membership
Lapsed member records
2 years after lapse, then deleted or de-identified — retained so a returning member need not start again
Financial and payment records
7 years, as required by Australian law
Governance records (minutes, resolutions, declared interests)
Permanently, as the association's record
Event registration data
12 months after the event
Dietary and accessibility requirements
Deleted immediately after the event
Newsletter subscribers
Until unsubscribe, then contact details deleted
Unsuccessful enquiries
12 months
Both Australia and Thailand give you the right to:
✦ Access the personal information we hold about you;
✦ Correct information that is inaccurate, out of date or incomplete;
✦ Complain if you believe we have mishandled your information.
Thailand's PDPA additionally gives you the right to:
✦ Withdraw Consent at any time;
✦ Erasure — have your data deleted where we no longer have a basis to hold it;
✦ Restrict processing while a dispute is resolved;
✦ Data Portability — receive your data in a machine-readable form, or have it sent to another controller;
✦ Object to processing based on legitimate interest, and to direct marketing at any time.
We extend the PDPA rights to every member and contact regardless of where you are located.
It is simpler, fairer, and avoids us treating an Australian member worse than a Thai one for no reason other than geography.
How to exercise them: send your request through our contact form. We respond within 30 days. We do not charge. If we refuse a request we tell you why in writing and how to complain.
Contact us first — send the details through our contact form. We acknowledge within 5 business days and respond substantively within 30 days.
If you are not satisfied:
✦ Australia — Office of the Australian Information Commissioner (OAIC), oaic.gov.au, 1300 363 992
✦ Thailand — Personal Data Protection Committee (PDPC), pdpc.or.th
✦ ACT — matters relating to our conduct as an incorporated association may also be raised with Access Canberra
Our website uses cookies that are strictly necessary for it to function, and analytics cookies to understand which content is useful.
Analytics and marketing cookies are set only with your consent, obtained through a banner that makes refusing as easy as accepting. Necessary cookies do not require consent. You can change your preferences at any time.
ATBC's activities are directed at business professionals. We do not knowingly collect personal information from anyone under 20 — the PDPA's threshold, and the higher of the two applicable standards. If we learn we have, we delete it.
We review this policy annually and whenever we materially change our systems. Material changes are notified to members by email before taking effect. The current version is always available at aust-thai.org.au.

Promoting trade and investment between Australia and Thailand.
© 2026 Australia Thailand Business Council. All rights reserved.