Privacy & Data Handling Guideline

Department

HR

Summary

How Kiluth employees must handle documents with personal or sensitive information (pay slips, contracts, ID scans, financial records). Store in secure cloud storage (e.g., Google Drive) with restricted access; share links in Kiluth Tasks, not direct uploads. Aligns with PDPA/GDPR.

Table of Contents


Purpose

This guideline defines how Kiluth employees must handle documents containing personal or sensitive information (e.g., pay slips, contracts, identification documents, financial records) when using shared platforms.

The objective is to protect employee privacy, ensure data security, and maintain compliance with data protection standards (e.g., PDPA, GDPR).

Outcome
Employee privacy is protected, data is secure, and handling stays compliant with data protection standards.

Prerequisites

Before proceeding with this document, please review the following documents:

#DocumentPurpose
1Onboarding GuidelineUnderstand how Kiluth uses Google Workspace, Kiluth Tasks, and other core tools

Scope

This policy applies to all Kiluth employees, contractors, and interns who access or manage sensitive files while using:

Tool
1Task and project management tools (Kiluth Tasks)
2Cloud storage platforms (Google Drive)

Definitions

SubjectDefinition
Sensitive InformationDocuments containing personal identifiers such as a person’s full name, address, salary, ID/passport number, or financial details.
Organizational identifierData that identifies a company or a piece of work rather than a person: client company name, project code (e.g. PROJ-0030), quotation or invoice number. Not personal data.
Secure Storage PlatformAuthorized cloud or internal storage system with access control, version history, and audit logs.
Shared WorkspaceA place where multiple employees access the same tasks or projects, such as Kiluth Tasks.
Private WorkspaceStorage or folders with restricted access, available only to authorized employees or departments.

Guidelines

Uploading Sensitive Documents

Uploading Sensitive Documents
✓ CorrectUpload sensitive files (e.g., pay slips, contracts, ID scans) only to a secure cloud storage platform with access control, version history, and audit logs. At Kiluth that is Google Drive.
✓ CorrectYou may store the file in any folder you manage, provided that access is restricted to only those who need it.
✕ IncorrectDo not upload sensitive files directly to Kiluth Tasks or any other task tracker.
Sharing Links in Project Tools
1Store the file in a secure folder with appropriate access control.
2Generate a share link that allows only authorized personnel (e.g., project manager, HR, finance, or relevant stakeholders).
3Paste the link in the task description instead of uploading the file.
4Add a note such as: “Sensitive file stored in a secure location. Access restricted to authorized users only.”

PII in Task and Project Management Tools

The rules above cover files. This one covers text — what you type into a task title or description. Kiluth Tasks is shared: everyone with access can read every task, and tasks are searched, published to the web view, and processed by automation.

Typing in Kiluth Tasks
✓ CorrectUse organizational identifiers freely: client company name, project code, quotation or invoice number. Task templates depend on these.
✓ CorrectLink to the secure record (CRM lead, Drive file, ERPNext document) and add a short redacted summary when context is needed.
✓ CorrectPut Kiluth colleagues in assignee and requester as full @kiluth.com emails. The restriction is on typing out someone’s personal contact details, not on naming who a task is for.
✕ IncorrectDo not type a person’s full name, personal email, phone number, or ID number into a task title or description.
✕ IncorrectDo not paste the contents of a document holding personal data, even as plain text.

A person’s name is personal data. A company’s name is not.

Access Control

Access Control
1Follow the principle of least privilege (only HR/Finance or necessary managers should have access).
2Avoid using “Anyone with the link can view.” Instead, prefer:
• Specific people only
• Anyone in the Kiluth domain with the link (if broader access is required but still controlled)
3Review permissions regularly and remove unnecessary access.

Temporary Files

Temporary Files
1If a sensitive file must be temporarily uploaded for workflow reasons:
• Use restricted access only.
• Delete the file immediately after use.
• Confirm deletion and note it in the task.

Employee Responsibility

Employee Responsibility
1Always double-check before sharing: “Does this file contain personal or sensitive data?“
2If yes → Use a secure storage platform and share a controlled link, not a direct upload.
3If uploaded incorrectly → Delete immediately and notify HR.

Enforcement

Enforcement
1Any breach of this guideline may result in disciplinary action depending on severity.
2HR and IT will conduct regular audits of shared folders and project tools to ensure compliance.

Example Scenarios

Example Scenarios
✕ IncorrectUploading “Pay slip – Khun Somchai.pdf” directly into a task.
✓ CorrectUploading the file to your secure Google Drive folder (restricted access) and pasting the link in Kiluth Tasks.
✕ IncorrectSharing a sensitive file link set to “Anyone with the link.”
✓ CorrectSharing a link restricted to specific authorized users only.
✓ Correcttask titled Draft/review contract set – Wandee Co. – Website Revamp, with a link to the CRM record.
✕ Incorrecttask titled Call Khun Somchai 08x-xxx-xxxx about the Wandee quote.

Remember: Privacy is everyone’s job. Following these principles protects both Kiluth and our clients — and maintains the trust that defines our brand.