The university strengthens its cyber security standards to prevent data leaks and ensure strict compliance with the Personal Data Protection Act.
On 13 July 2026, Khon Kaen University organised a briefing session to enhance the understanding of Khon Kaen University Directive No. 1039/2026 regarding the Personal Data Retention and Destruction Policy. The meeting was attended by Mrs. Natsamol Tanakulrungsarit, Vice President for Legal and Corporate Communications, and Dr. Kitt Tientanopajai, the Data Protection Officer (DPO) of Khon Kaen University, along with representatives from various university sectors. The participants gathered to exchange knowledge and establish a unified standard for personal data management at Sirikunakorn Room 3, Sirikunakorn Building, Khon Kaen University.

The primary objective of this meeting was to inform personnel responsible for data management across all sectors about how data security measures are implemented in practice. The directive covers both physical documents and digital formats in alignment with international cyber security standards. This initiative aims to build trust among data subjects and prepare the university for future external audits.

Mrs. Tanakulrungsarit discussed the origin of the initiative, noting that personal data leaks leading to scams by fraudulent call centres is an issue the university takes very seriously. Consequently, all departments must understand the appropriate boundaries of data retention to mitigate risks and strictly comply with the Personal Data Protection Act B.E. 2562 (PDPA).
“As a juristic person and an autonomous state agency, Khon Kaen University recognises its crucial responsibility in processing vast amounts of personal data,” the Vice President stated. “This is particularly critical for large faculties and sectors that handle sensitive information, such as medical records. Without stringent control measures, we face the risk of data leaking to scammers or call centre gangs targeting our students and staff. The university has therefore issued Directive No. 1039/2026 on the Personal Data Retention and Destruction Policy to support operations in full compliance with the PDPA. This policy serves as a vital tool to empower operational staff to manage data securely—ranging from initial collection and defining necessary retention periods to proper destruction methods that meet cyber security standards. This will minimise the risks and burdens of keeping unnecessary data, build confidence among data subjects, and ensure our readiness for external quality audits.”

Dr. Tientanopajai, the Data Protection Officer of Khon Kaen University, explained the core substance of the policy, highlighting that its key focus is defining appropriate data destruction methods and clear retention timelines. This approach ensures that storing data that is no longer required does not become a logistical burden. He emphasised the importance of frontline staff participating in evaluating whether the specified retention conditions are practical in daily operations.
“We want to know if the established guidelines pose any practical challenges to actual work,” the DPO remarked. “For instance, we need to assess whether a 10-year retention period is excessive. If it can be reduced, we will adjust the directive to better fit the operational context, ensuring that data utilization and destruction are perfectly synchronised.”
The event also featured a collaborative workshop among coordinators responsible for maintaining the Record of Processing Activities (RoPA) within each department. This session allowed teams to monitor operational progress and resolve challenges arising from practical execution, enabling the university to manage personal data efficiently and sustainably.











