1. Scope
This policy covers the website, electronic service systems and related databases of เทศบาลตำบลบ้านริมธาร. Its purpose is to preserve the confidentiality, integrity and availability of information in line with the Cybersecurity Act B.E. 2562 (2019).
2. Security measures
- Access control — user permissions are granted according to job responsibilities and reviewed at least once a year.
- Authentication — administrators must use strong passwords together with two-step verification.
- Event logging — access logs are retained for no less than 90 days as required by law.
- Threat protection — firewalls and intrusion detection are in place and software is kept up to date.
- Assessment — systems are checked for vulnerabilities at least once a year and fixed according to risk level.
3. Data transmission
The website encrypts data between your browser and the server using HTTPS (TLS) on every page, in particular pages where personal data is entered, such as the contact form and the complaint form.
4. Backups
The agency backs up its systems and databases daily, stores the backups separately from the live system, and tests restoration at least twice a year so that services can continue even if a failure occurs.
5. Responding to a security breach
In the event of a personal data breach, the agency will contain the incident, assess the damage and notify the Office of the Personal Data Protection Committee within 72 hours of becoming aware of it, and notify affected data subjects without undue delay.
6. Advice for users
- Check that the address begins with
https://before entering any personal data. - Never disclose your password or OTP to anyone. Our officers will never ask for them by telephone or email.
- Keep your browser and operating system up to date.
- Log out and close the browser whenever you use a public computer.
7. Reporting a vulnerability
If you find a vulnerability or suspicious behaviour, please report it directly to the administrator at info@banrimthan.go.th or on 0-2000-0000. We ask that you do not publish vulnerability details before they have been fixed.
The agency never sends email or SMS asking for your ID card number, bank account number or password. If you receive such a message, do not reply and please inform us immediately.