Association of Thai Businesses in the UK (ATBUK)
Last updated: 6th December 2025


1. Introduction
ATBUK is committed to safeguarding the privacy and security of personal data. This Privacy Policy outlines how ATBUK collects, processes, stores, and protects personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
ATBUK acts as the Data Controller for information provided by members, partners, event participants, and website users.


2. Legal Basis for Processing
ATBUK processes personal data under the following lawful bases:
– Consent: when individuals voluntarily provide information for membership or communication.
– Contractual necessity: when processing is required to manage memberships or deliver member services.
– Legitimate interests: for the effective administration of ATBUK activities, events, and communications.
– Legal obligation: where required for financial reporting or compliance with statutory authorities.

3. Categories of Personal Data Collected
ATBUK may collect the following categories of information:
– Identification data: name, title, business information.
– Contact data: email address, telephone number, postal address.
– Membership data: membership status, history, payment records.
– Event participation data: attendance records, dietary requirements if voluntarily disclosed.
– Technical data: IP address, browser type, cookies, and website usage information. ATBUK does not intentionally collect special category data unless voluntarily provided and necessary for event safety or accessibility.

4. Purpose of Data Processing
Personal data is processed for the following purposes:
– Administration of ATBUK membership.
– Issuing membership documentation, receipts, and communications.
– Management of events, including registration and logistics.
– Circulation of updates, newsletters, and organisational announcements.
– Maintenance of accurate financial and administrative records.
– Compliance with regulatory or legal obligations.


5. Data Sharing and Third-Party Disclosure
ATBUK does not sell personal data. Information may be shared only when necessary, with:
– Event venues or partners for logistical requirements.
– Payment processors for membership fees or event bookings.
– Professional advisors such as accountants to meet statutory obligations.
All third parties must demonstrate compliance with UK GDPR.
6. International Data Transfers
ATBUK may use cloud-based services that store data outside the UK. In such cases, ATBUK ensures appropriate safeguards, such as Standard Contractual Clauses, to maintain protection equivalent to UK GDPR standards.

7. Data Retention Policy
ATBUK retains personal data only for as long as is necessary for the purposes for which it was collected:
– Membership records: retained for up to 3 years after membership ends.
– Financial and accounting records: retained for 6 years in accordance with HMRC requirements.
– Event attendance information: retained for up to 2 years.
Data no longer required will be securely deleted or anonymised.

8. Data Security Measures
ATBUK employs appropriate organisational and technical safeguards to ensure the confidentiality, integrity, and availability of personal data, including:
– Password-protected data systems.
– Access restricted to authorised committee members only.
– Secure cloud storage and encrypted communication channels.
– Regular review of data-handling practices.

9. Individual Rights
Under the UK GDPR, individuals have the following rights:
– The right to access their personal data.
– The right to request rectification of inaccurate information.
– The right to request erasure (“right to be forgotten”).
– The right to restrict or object to processing.
– The right to data portability.
– The right to withdraw consent at any time.
Requests may be submitted by email to [email protected]


10. Cookies and Tracking Technologies
ATBUK’s website may use cookies or similar tools to analyse website usage and improve user experience. Users may disable cookies at any time through their browser settings. Continued use of the website signifies consent to cookie usage.

11. Data Breach Procedure
In the event of a suspected data breach, ATBUK will:
– Assess the severity and scope of the breach.
– Notify affected individuals if risks to rights and freedoms are identified.
– Report the breach to the Information Commissioner’s Office within 72 hours where legally required.

12. Complaints
Individuals who wish to raise concerns may contact ATBUK directly. If unresolved, complaints may
be submitted to the Information Commissioner’s Office at https://ico.org.uk.

13. Policy Review
This Privacy Policy will be reviewed bi-annually or sooner if legislative changes require updates.

GDPR Statement for Membership Forms
By completing this form, you provide consent for ATBUK to collect and process your personal data for the purposes of membership administration, communication, and event management. Your data will be stored securely and will not be shared for marketing purposes. You may withdraw consent or
request deletion at any time.

Email Footer – Data Protection Notice
ATBUK processes all personal data in accordance with UK GDPR. If you wish to update your details or request removal from our communications, please contact us at [email protected]
Cookie Notice
ATBUK uses cookies to enhance website performance and analyse visitor behaviour. Users may
disable cookies via their browser settings. Continued website use indicates acceptance of cookie
usage.

The Data Use and Access Act 2025 (DUAA) introduces major reforms to UK data protection law, updating the UK GDPR and the Data Protection Act 2018. The Act simplifies compliance, promotes responsible innovation, and clarifies rules for data access, international transfers, and recognised legitimate interests. ATBUK will monitor phased implementation (2025–2026) and align governance and data-handling processes with forthcoming statutory guidance from the ICO.