Navigation
  • SEARCH HERE
  • SOLUTIONS
    • Information Security Solutions
      • Enterprise Application Security Solutions in Asia
      • Network & Infrastructure Security Solutions
      • Zero Trust Security
      • Security Information and Event Management
      • Remote Monitoring & Management (RMM)
      • File Integrity Management
      • Systems Administration Tools
      • Data Loss Prevention
      • Data / Password Recovery
      • IT Management Solution Offering | Distributor in Asia
      • Identity and Access Management Solution Offering | Distributor in Asia
      • Employee Activity Monitoring (EAM)
      • Digital Forensic Investigation
    • Software Development Solutions
      • Integrated Development Environments
      • Development Components
        • UI Tools
        • Networking Components
        • Office Components
        • Barcode Components
        • Communication Components
      • Imaging Solutions
      • Software Localization
      • Release Automation & Management
      • eLearning Authoring Solutions
      • Charting Solutions
      • PDF Solutions
      • Reporting Solutions
      • Testing & QA
      • Text Retrieval / Enterprise Search
      • Database
  • Services
    • Live Solution Walkthroughs
    • Implementation Services
    • Best Practices Consulting
    • Pre-Sales and Post-Sales Services
  • What's New
    • Our Event
    • Our Blogs
    • Special Offers
  • About
    • About LOGON Software Asia
    • Our Partnership
  • Publishers - Join our network
  • Resellers - Expand your portfolio
  • Procurement Managers
Site logo
  • Solutions
    • Information Security Solutions
      • Identity and Access Management
        • Privileged Access Management (PAM)
        • Multi-Factor Authentication (MFA)
        • Identification Verification (IV)
        • Self-Service Password Reset (SSPR)
      • Network & Infrastructure Security
        • DDoS Mitigation and Protection
        • Digital Forensic Investigation
        • Malware Detection & Analysis
        • Network Monitoring Software
        • Email Security
        • Log Monitoring
      • Endpoint & Device Security
        • Patch Management
        • Remote Monitoring & Management (RMM)
        • Employee Activity Monitoring (EAM)
        • Mobile Device Management (MDM)
      • IT Management
        • IT Service Management
        • IT Asset Management
        • Software Asset Management
        • Hardware Asset Management
        • Software License Management
        • Systems Administration Tools
      • Application Security
        • Development Security | Shift Left AppSec | SAST, SCA, IAST
        • Runtime Protection Solutions | DAST, RASP, WAF, Container Security
        • Strategic Management Solutions | ASPM, MAST, VAPT
      • Data Security
        • Data Loss Prevention
        • File Integrity Management
        • Data / Password Recovery
        • Data Security Posture Management
      • Cloud Security
        • Cloud Security Posture Management
        • Cloud Work Protection
      • External Attack Surface Management
        • Cyber Threat Intelligence
        • Third Party Risk Management
      • Security Operations & Incident Management
        • Security Information and Event Management
        • Security Orchestration, Automation and Response (SOAR)
      • Zero Trust Security
    • Software Development Solutions
      • Integrated Development Environments
      • Imaging Solutions
      • UI Tools
      • Charting Solutions
      • Database
      • Networking Components
      • Office Components
      • Barcode Components
      • Release Automation & Management
      • Software Localization
      • Communication Components
      • Automated Testing
      • eLearning Authoring Solutions
      • Reporting Solutions
      • Text Retrieval / Enterprise Search
      • Testing & QA
  • Services
        • Live Walkthrough Sessions

          Experience the full feature of our key solutions through live platform

          View All Sessions >
        • Implementation Services
        • Pre-Sales and Post-Sales Services
        • Best Practices Consulting
  • Partners
    • Our Partners
    • Partner with LOGON Today!
      • Vendors - Join Our Network
      • Resellers - Expand Your Portfolio
      • Procurement Managers
  • Resources
        • ABOUT US

        • About Us
        • Our Locations
        • Careers@LOGON - We are hiring !
        • DISCOVER

        • Our BlogsNEW BLOGS
        • Our EventsJOIN UPCOMING EVENTS
        • LOGON to CyberSecurity PodcastNEW EPISODES
        • GET HELP

        • Contact Us
        • Help Desk
        • Request a Demo
        • Request a Quote
        • COMPLIANCE

        • 🇭🇰 Hong Kong PDPO
        • 🇮🇳 India DPDP Act
        • 🇸🇬 Singapore PDPA
        • 🇹🇭 Thailand PDPA
  • More results...

Thailand PDPA Compliance: A Guide for Businesses


LOGON Software Asia offers comprehensive cybersecurity and data protection solutions to help organizations in Thailand and across Asia safeguard their data and systems.

Contact us today for your PDPA consultation

This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form

Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) is the country’s first consolidated data protection law, marking a significant milestone in Thailand’s digital transformation journey. Published in the Royal Thai Government Gazette in May 2019, the PDPA came into full force on June 1, 2022, following multiple extensions to allow organizations time to prepare.

The PDPA is Thailand’s comprehensive response to the growing need for robust data protection in an increasingly digital economy. Heavily influenced by the European Union’s General Data Protection Regulation (GDPR) , the PDPA establishes a framework that protects the personal data of individuals in Thailand while providing clear guidelines for organizations that collect, use, or disclose personal data.

For businesses operating in Thailand or offering goods and services to individuals in Thailand, understanding and complying with the PDPA is essential to avoid significant penalties and maintain customer trust.


Overview of the Thailand PDPA

The Personal Data Protection Act B.E. 2562 (2019) is Thailand’s primary data protection legislation. It regulates the collection, use, and disclosure of personal data by data controllers and data processors, whether in the public or private sector. The law applies to both electronic and non-electronic data processing activities.

 

Key Developments
  • May 2019: PDPA published in the Royal Thai Government Gazette

  • January 2022: Personal Data Protection Committee (PDPC) established

  • June 1, 2022: PDPA came into full force

  • April 2024: Master Plan for Enhancement and Protection of Personal Data (2024-2027) launched

  • August 2024: First major administrative fine (THB 7 million) imposed on a company for PDPA violations

  • 2025-2026: Ongoing issuance of subordinate regulations and guidelines

 

Who Must Comply?

The PDPA applies to:

  • Data Controllers: Persons or juristic persons with authority to make decisions on collection, use, or disclosure of personal data

  • Data Processors: Persons processing personal data on behalf of or in compliance with orders from a data controller

  • Extraterritorial Application: Organizations outside Thailand that offer goods or services to individuals in Thailand or monitor their behavior

 

Exemptions

The PDPA does not apply to:

  • Persons conducting personal or household activities

  • Public authorities maintaining state security (financial/public safety)

  • Mass media, fine arts, and literature activities in accordance with professional ethics

  • The House of Representatives, Senate, or Parliament

  • Trial and adjudication courts

  • Credit bureau companies (specific operations)


Key Definitions Under the PDPA

Term Definition
Personal Data Any information relating to a person which enables the identification of such person, whether directly or indirectly, but not including information of deceased persons.
General Personal Data (GPD) Information that allows identification of an individual, including names, addresses, contact details, customer ID, age, gender, usernames, passwords, and IP addresses.
Sensitive Personal Data (SPD) Information requiring explicit consent, including race, ethnicity, political opinions, religious beliefs, philosophical beliefs, sexual orientation, criminal records, health data, disabilities, trade union information, genetic data, and biometric data.
Data Controller A person or juristic person with the authority and duty to make decisions regarding the collection, use, or disclosure of personal data.
Data Processor A person or juristic person who collects, uses, or discloses personal data in compliance with orders from a data controller or on behalf of a data controller.
Data Subject The individual to whom the personal data relates.
Personal Data Protection Committee (PDPC) The regulatory authority responsible for enforcing the PDPA, issuing subordinate regulations, and prescribing guidelines.

The Personal Data Protection Committee (PDPC)

The Personal Data Protection Committee (PDPC) is the official regulator of the PDPA in Thailand, established in January 2022. The committee consists of:

  • A Chairperson

  • Vice-Chairperson

  • Five Commission Members

  • Nine Honorary Commission Members

 

Key Functions of the PDPC:
  1. Establishing a master plan for the promotion and protection of personal data

  2. Prescribing measures, criteria, and guidelines for business operators

  3. Issuing subordinate regulations and rules under the PDPA

  4. Enforcing compliance and imposing penalties

  5. Regulating cross-border data transfers

  6. Providing guidance on data protection standards

 

Recent Initiatives:
  • April 2024: Launched a master plan for enhancement and protection of personal data (2024-2027)

  • March 2024: Released additional sub-regulations on cross-border data transfers and Binding Corporate Rules (BCRs)

  • Ongoing: Issuing subordinate regulations to clarify specific compliance requirements


Extraterritorial Application

The PDPA has extraterritorial scope, meaning organizations outside Thailand may be subject to the law if they:

  1. Offer goods or services to data subjects in Thailand (regardless of whether payment is made)

  2. Monitor the behavior of data subjects in Thailand (e.g., using cookies, Google Analytics, or search panels)

 

Representative Requirement

Data controllers or data processors located outside Thailand and subject to the PDPA must:

  • Appoint a representative in Thailand (individual or legal person) in writing

  • The representative acts on behalf of the data controller without limitation of liability

 

Exemption from Representative Requirement

Organizations that:

  • Are public authorities as prescribed by the PDPC

  • Do not process Sensitive Personal Data

  • Do not have a large amount of personal data requiring regular monitoring

 

Compliance Obligations for Foreign Entities:
  • Must comply with all PDPA requirements

  • Must appoint a DPO if applicable

  • Must implement Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs) for cross-border transfers

  • Must designate a representative in Thailand for regulatory communication


Key Compliance Requirements

1. Consent Requirements

General Consent

  • Specific consent is required from the data subject prior to or at the time of collection, use, or disclosure

  • Consent must be in writing or via electronic means

  • Data subjects may withdraw consent at any time

  • Consent withdrawal must be as easy as giving consent

 

Consent for Sensitive Personal Data

  • Explicit consent is required for Sensitive Personal Data

  • Exceptions apply where:

    • Preventing or suppressing danger to life, body, or health

    • The data subject is incapable of giving consent

 

Consent for Direct Marketing

  • Separate, explicit consent required for direct marketing activities

  • Data subjects have the right to object to direct marketing at any time

  • Organizations must provide an easy opt-out mechanism

 

Consent Withdrawal Method

  • Data controllers must publicize a consent withdrawal method

  • Data subjects must be notified of their right to withdraw consent

  • This applies to personal data collected before June 1, 2022

2. Collection of Personal Data

Lawful Purpose

  • Collection must be for a lawful purpose

  • Must be directly relevant and necessary for the activities of the data controller

 

Notification Requirements

Data controllers must inform data subjects prior to or at the time of collection of:

  1. The purpose of collection, use, or disclosure

  2. Whether data supply is mandatory or voluntary (and consequences if not provided)

  3. The personal data to be collected

  4. The retention period (or criteria for determining it)

  5. Categories of persons/entities to whom data may be disclosed

  6. Contact details of the data controller and DPO (if applicable)

  7. The rights of the data subject under the PDPA

 

Direct Collection

  • Personal data must typically be collected directly from the data subject

  • Exceptions apply under limited circumstances

 

Sensitive Personal Data

  • Collection is prohibited without explicit consent

  • Exceptions are strictly limited (e.g., life-saving situations)

3. Rights of Data Subjects

The PDPA grants data subjects comprehensive rights:

Right Description
Right to Withdraw Consent Withdraw consent at any time, as easily as it was given
Right to Access Access and obtain a copy of personal data
Right to Data Portability Receive data in machine-readable format and request transfer to another controller
Right to Object Object to collection, use, or disclosure in specified circumstances
Right to Erasure Request deletion or anonymization of personal data
Right to Restriction Request suspension of data use in specified circumstances
Right to Rectification Ensure data is accurate, complete, and up-to-date
Right to Complain File complaints with the PDPC

 

Note on Data Portability

  • Data subjects can request personal data in machine-readable formats

  • Can request data controllers to send data to another data controller

  • Right to data portability is similar to GDPR Article 20

 

Right to Be Informed

  • Data subjects have the right to be informed about:

    • What data is being collected

    • Why it is being collected

    • The retention period

    • Who it will be shared with

    • Their rights under the PDPA

4. Cross-Border Data Transfers

Adequacy Requirement

  • Personal data may only be transferred to a destination country or international organization with adequate data protection standards

  • Standards are prescribed by the PDPC

 

Exceptions (Transfer Permitted Without Adequacy)

  1. Transfer is made pursuant to applicable laws

  2. Consent is obtained from data subjects (informed of inadequate protection measures)

  3. Transfer is necessary for performance of a contract

  4. Transfer is necessary for compliance with a contract between data controllers for data subject interests

  5. Transfer is to prevent/suppress danger to life, body, or health (data subject incapable of giving consent)

  6. Transfer is necessary for substantial public interest

 

Mechanisms for Compliant Cross-Border Transfers

  • Binding Corporate Rules (BCRs): For intra-group transfers

  • Standard Contractual Clauses (SCCs): For transfers to third parties

  • Adequacy Decisions: Where PDPC deems a country has adequate protection

5. Data Protection Officer (DPO) Appointment

A DPO must be appointed in the following cases:

Condition Description
Public Authority Data controller or processor is a public authority as prescribed by the PDPC
Regular Monitoring Activities require regular monitoring of personal data or systems due to a large volume of personal data
Sensitive Personal Data Core activities involve collection, use, or disclosure of Sensitive Personal Data

 

DPO Responsibilities

  1. Advising on PDPA compliance

  2. Investigating compliance with the PDPA

  3. Coordinating with regulatory authorities

  4. Maintaining confidentiality regarding acquired personal data

  5. Acting as a contact person for data subjects

 

Penalties for Non-Appointment

  • Administrative fine not exceeding THB 1 million

6. Security Requirements

Data controllers must implement appropriate security measures to protect personal data from unauthorized access, use, disclosure, alteration, or destruction.

 

Security Measures Should Include:

  • Organizational Measures: Policies, procedures, training

  • Technical Measures: Encryption, access controls, monitoring

  • Physical Measures: Secure facilities, access restrictions

 

Acceptable Security Frameworks

  • Thailand’s Ministry of Digital Economy and Society accepts ISO 27001 as sufficient evidence of compliance with minimum security standards

  • Other industry-specific frameworks may also be acceptable

 

Security Risk Assessments

  • Required when technology changes

  • When necessary to maintain suitable security and safety requirements

7. Data Breach Notification

Notification Timeline

  • Data controllers must notify the PDPC of a data breach within 72 hours of becoming aware

  • Notification must be made without delay if the breach is likely to result in a risk to the rights and freedoms of data subjects

 

Breach Notification Requirements

  1. Nature of the incident

  2. Contact details of the contact person or DPO

  3. Possible consequences

  4. Measures taken or to be taken to mitigate adverse effects

 

Notification to Data Subjects

  • If a breach is likely to result in critical threats to rights and freedoms:

    • Notify the PDPC and data subjects without delay

  • For breaches involving several data subjects:

    • Notify each subject specifically, or

    • Notify the public via media, social media, or other accessible means

 

Notification from Data Processors

  • Data processors must notify the data controller without undue delay upon discovering a breach

 

Case Example: August 2024

A major private company received Thailand’s first PDPA administrative fine:

  • Amount: THB 7 million (maximum fine)

  • Reasons:

    • Failure to appoint a DPO (THB 1 million)

    • Inadequate security measures (Section 37(1))

    • Failure to report data breaches (Section 37(4))

  • Remedial Actions Ordered:

    • Enhance security measures

    • Train staff

    • Report improvements to PDPC within 7 days

8. Record of Processing Activities (RoPA)

General Requirement

  • Data controllers and data processors must keep full records of personal data processing activities

  • Ensures preparedness for inspection by or submission to the PDPC

 

SME Exemption

  • Small and Medium-Sized Enterprises (SMEs) are exempt from RoPA requirements

  • Definition: Organizations qualifying under the Small and Medium-Sized Enterprise Promotions Act

  • Exception: Some SMEs must still prepare RoPA if their data processing poses a risk to data subject rights and freedoms

9. Vendor Privacy Contracts

Contractual Requirements

  • Data controllers and data processors must enter into contractual agreements

  • Contracts must require both parties to comply with all PDPA requirements

 

Types of Agreements:

  • Data Processing Agreement (DPA): When vendors act as data processors

  • Data Sharing/Transfer Agreement: When vendors act as data controllers

 

Key Contractual Elements:

  • Clear definition of roles (controller vs. processor)

  • Security measures to be implemented

  • Breach notification procedures

  • Sub-processing restrictions

  • Data deletion requirements

10. Grandfathering Provisions

Personal Data Collected Before June 1, 2022

Data controllers may continue to use personal data collected before the PDPA came into force, provided:

  1. Same Purpose: Data is only used for the same purpose for which it was originally collected

  2. Consent Withdrawal Method: The data controller prepares and publicizes a consent withdrawal method

  3. Notice: Data subjects are notified of their right to withdraw consent

 

Expanded Processing

  • If data is used or disclosed beyond the original purpose:

    • New explicit consent is required for each separate purpose


Fines and Penalties

Type of Violation Maximum Penalty
Administrative Fine (General) Up to THB 5 million
Administrative Fine (DPO Non-Appointment) Up to THB 1 million
Criminal Penalties Fines and potential imprisonment
Civil Liability Compensation for damages
Failure to Report Breach Up to THB 5 million
Inadequate Security Measures Up to THB 5 million

 

Recent Enforcement:

  • August 2024: First major administrative fine of THB 7 million imposed

  • Company failed to appoint DPO, had inadequate security measures, and delayed breach notification

  • Demonstrates aggressive enforcement posture

 

Factors in Determining Penalties

  1. Nature and gravity of the violation

  2. Volume and sensitivity of personal data affected

  3. Mitigation efforts

  4. Cooperation with the PDPC

  5. Previous instances of non-compliance


How LOGON Software Asia Can Help Different Industries in Thailand

Banking, Financial Services & Insurance (BFSI)

BFSI organizations handle highly sensitive financial data and are prime targets for cyberattacks. The PDPA imposes strict requirements for consent, security, and breach notification.

How LOGON Can Help:

  • Application Security Testing: Comprehensive web and mobile application penetration testing to identify vulnerabilities before they are exploited
  • Data Loss Prevention (DLP): Preventing unauthorized disclosure of sensitive financial and customer data
  • Identity & Access Management (IAM): Implementing IAM solutions with least privilege access and multi-factor authentication
  • Security Monitoring & SOC: 24/7 monitoring to detect and respond to threats
  • Data Classification: Automatically discovering and classifying sensitive personal data
  • Vendor Risk Management: Ensuring third-party processors meet PDPA security standards
Healthcare & Pharmaceuticals

Healthcare data qualifies as Sensitive Personal Data under the PDPA, requiring explicit consent and enhanced security measures. Data breaches in healthcare can result in severe harm to patients.

How LOGON Can Help:

  • Data Discovery & Classification: Identifying and securing sensitive health data across IT environments
  • Encryption: Implementing strong encryption for data at rest and in transit
  • Secure Data Sharing: Platforms for sharing medical data between healthcare providers while maintaining compliance
  • Incident Response: Breach response frameworks to ensure timely notification within 72 hours
  • ISO 27001 Compliance: Supporting certification to demonstrate compliance with PDPA security standards
  • DPO Support: Assisting with DPO appointment and responsibilities
E-commerce, Retail & Consumer Goods

Retail businesses process vast amounts of customer data for marketing, loyalty programs, and personalization. Direct marketing consent and data subject rights management are key compliance areas.

How LOGON Can Help:

  • Consent Management Platforms: Technologies to capture, manage, and maintain auditable consent records
  • DSAR Automation: Automating the receipt, verification, and response to data subject access requests
  • Lifecycle Management: Automated data retention and deletion policies
  • Data Mapping: Understanding personal data flows across systems
  • Web Application Security: Testing online storefronts to prevent data breaches
Technology & IT Services

Tech companies process massive volumes of personal data across complex, multi-cloud environments with extensive third-party integrations and are often subject to extraterritorial application.

How LOGON Can Help:

  • Attack Surface Management: Inventorying and continuously monitoring internet-facing applications and assets
  • Automated Security Testing: DAST and manual penetration testing to meet security requirements
  • Cloud Security: Securing cloud environments and ensuring compliance with PDPA cross-border transfer requirements
  • Vendor Risk Management: Ensuring third-party processors comply with PDPA requirements
  • Binding Corporate Rules (BCRs): Assisting in implementing BCRs for intra-group transfers
  • DPO Services: Assisting with DPO appointment and responsibilities
SMEs & Small Businesses

SMEs must comply with the PDPA but may have limited resources. Exemptions exist for RoPA, but other obligations remain.

How LOGON Can Help:

  • Tiered Compliance Solutions: Scalable solutions based on business size and data processing volume
  • DPO Outsourcing: Cost-effective outsourced DPO services
  • Consent Management: Simple, affordable consent management solutions
  • Security Assessments: Basic security assessments to identify and address risks

Is Your Organization PDPA-Compliant? Contact us Today!

This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form

Privacy Policy Company Overview

COMPANY

Our Location Career with LOGON Our Partners

SERVICES

Training Services Implementation Services Pre-Sales and Post-Sales Services Best Practices Consulting

GET IN TOUCH

Phone:
Hong Kong: +852 2512 8491
India: +91 70220 22744 / +91 63668 26133
Email: [email protected] ©2025 LOGON International Ltd. All rights reserved
logon logo WHITE

Search engine

Use this form to find things you need on this site

More results...

Fill in the form below
  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Watch On-demand Webinar

  • This field is for validation purposes and should be left unchanged.

Get Your Free UserLock Trial

  • This field is for validation purposes and should be left unchanged.

Download Your Free Trial 10-Day Trial Today

  • Downloading and evaluating Smart Package Studio is quick and easy
  • Includes a short introductory guide that suggests smart features to try
  • Access the full functionality of Smart Package Studio during the trial
  • This field is for validation purposes and should be left unchanged.

Request for Priority Support with our support team

  • This field is for validation purposes and should be left unchanged.
  • Drop files here or
    Max. file size: 30 MB.

    Get Free Assessment of your Web Asset

    Request a free non-intrusive security assessment of your website. Get a report with an overview of client-side security risks.

    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form

    Recommend a Topic

    • This field is for validation purposes and should be left unchanged.

    Partner with Us on the next episode

    • This field is for validation purposes and should be left unchanged.

    Request Quote for Lansweeper

    Oops! We could not locate your form.

    Watch On-demand Webinar

    • This field is for validation purposes and should be left unchanged.
    Start PreCrime Network for Free

    Oops! We could not locate your form.

    Book a Free Demo Today

    Get Your Free Trial

    Oops! We could not locate your form.

    Get Your Free Trial
    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form
    • This field is hidden when viewing the form
    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form