How Kiluth employees must handle documents with personal or sensitive information (pay slips, contracts, ID scans, financial records). Store in secure cloud storage (e.g., Google Drive) with restricted access; share links in Kiluth Tasks, not direct uploads. Aligns with PDPA/GDPR.
This guideline defines how Kiluth employees must handle documents containing personal or sensitive information (e.g., pay slips, contracts, identification documents, financial records) when using shared platforms.
The objective is to protect employee privacy, ensure data security, and maintain compliance with data protection standards (e.g., PDPA, GDPR).
Outcome
Employee privacy is protected, data is secure, and handling stays compliant with data protection standards.
Prerequisites
Before proceeding with this document, please review the following documents:
Understand how Kiluth uses Google Workspace, Kiluth Tasks, and other core tools
Scope
This policy applies to all Kiluth employees, contractors, and interns who access or manage sensitive files while using:
Tool
1
Task and project management tools (Kiluth Tasks)
2
Cloud storage platforms (Google Drive)
Definitions
Subject
Definition
Sensitive Information
Documents containing personal identifiers such as a person’s full name, address, salary, ID/passport number, or financial details.
Organizational identifier
Data that identifies a company or a piece of work rather than a person: client company name, project code (e.g. PROJ-0030), quotation or invoice number. Not personal data.
Secure Storage Platform
Authorized cloud or internal storage system with access control, version history, and audit logs.
Shared Workspace
A place where multiple employees access the same tasks or projects, such as Kiluth Tasks.
Private Workspace
Storage or folders with restricted access, available only to authorized employees or departments.
Guidelines
Uploading Sensitive Documents
Uploading Sensitive Documents
✓ Correct
Upload sensitive files (e.g., pay slips, contracts, ID scans) only to a secure cloud storage platform with access control, version history, and audit logs. At Kiluth that is Google Drive.
✓ Correct
You may store the file in any folder you manage, provided that access is restricted to only those who need it.
✕ Incorrect
Do not upload sensitive files directly to Kiluth Tasks or any other task tracker.
Sharing Links in Project Tools
Sharing Links in Project Tools
1
Store the file in a secure folder with appropriate access control.
2
Generate a share link that allows only authorized personnel (e.g., project manager, HR, finance, or relevant stakeholders).
3
Paste the link in the task description instead of uploading the file.
4
Add a note such as: “Sensitive file stored in a secure location. Access restricted to authorized users only.”
PII in Task and Project Management Tools
The rules above cover files. This one covers text — what you type into a task title or description. Kiluth Tasks is shared: everyone with access can read every task, and tasks are searched, published to the web view, and processed by automation.
Typing in Kiluth Tasks
✓ Correct
Use organizational identifiers freely: client company name, project code, quotation or invoice number. Task templates depend on these.
✓ Correct
Link to the secure record (CRM lead, Drive file, ERPNext document) and add a short redacted summary when context is needed.
✓ Correct
Put Kiluth colleagues in assignee and requester as full @kiluth.com emails. The restriction is on typing out someone’s personal contact details, not on naming who a task is for.
✕ Incorrect
Do not type a person’s full name, personal email, phone number, or ID number into a task title or description.
✕ Incorrect
Do not paste the contents of a document holding personal data, even as plain text.
A person’s name is personal data. A company’s name is not.
Access Control
Access Control
1
Follow the principle of least privilege (only HR/Finance or necessary managers should have access).
2
Avoid using “Anyone with the link can view.” Instead, prefer:
• Specific people only
• Anyone in the Kiluth domain with the link (if broader access is required but still controlled)
3
Review permissions regularly and remove unnecessary access.
Temporary Files
Temporary Files
1
If a sensitive file must be temporarily uploaded for workflow reasons:
• Use restricted access only.
• Delete the file immediately after use.
• Confirm deletion and note it in the task.
Employee Responsibility
Employee Responsibility
1
Always double-check before sharing: “Does this file contain personal or sensitive data?“
2
If yes → Use a secure storage platform and share a controlled link, not a direct upload.
3
If uploaded incorrectly → Delete immediately and notify HR.
Enforcement
Enforcement
1
Any breach of this guideline may result in disciplinary action depending on severity.
2
HR and IT will conduct regular audits of shared folders and project tools to ensure compliance.
Example Scenarios
Example Scenarios
✕ Incorrect
Uploading “Pay slip – Khun Somchai.pdf” directly into a task.
✓ Correct
Uploading the file to your secure Google Drive folder (restricted access) and pasting the link in Kiluth Tasks.
✕ Incorrect
Sharing a sensitive file link set to “Anyone with the link.”
✓ Correct
Sharing a link restricted to specific authorized users only.
✓ Correct
task titled Draft/review contract set – Wandee Co. – Website Revamp, with a link to the CRM record.
✕ Incorrect
task titled Call Khun Somchai 08x-xxx-xxxx about the Wandee quote.
Remember: Privacy is everyone’s job. Following these principles protects both Kiluth and our clients — and maintains the trust that defines our brand.