Thailand PDPA Compliance: A Guide for Businesses
LOGON Software Asia offers comprehensive cybersecurity and data protection solutions to help organizations in Thailand and across Asia safeguard their data and systems.
Contact us today for your PDPA consultation
Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) is the country’s first consolidated data protection law, marking a significant milestone in Thailand’s digital transformation journey. Published in the Royal Thai Government Gazette in May 2019, the PDPA came into full force on June 1, 2022, following multiple extensions to allow organizations time to prepare.
The PDPA is Thailand’s comprehensive response to the growing need for robust data protection in an increasingly digital economy. Heavily influenced by the European Union’s General Data Protection Regulation (GDPR) , the PDPA establishes a framework that protects the personal data of individuals in Thailand while providing clear guidelines for organizations that collect, use, or disclose personal data.
For businesses operating in Thailand or offering goods and services to individuals in Thailand, understanding and complying with the PDPA is essential to avoid significant penalties and maintain customer trust.
Overview of the Thailand PDPA
The Personal Data Protection Act B.E. 2562 (2019) is Thailand’s primary data protection legislation. It regulates the collection, use, and disclosure of personal data by data controllers and data processors, whether in the public or private sector. The law applies to both electronic and non-electronic data processing activities.
Key Developments
-
May 2019:Â PDPA published in the Royal Thai Government Gazette
-
January 2022:Â Personal Data Protection Committee (PDPC) established
-
June 1, 2022:Â PDPA came into full force
-
April 2024:Â Master Plan for Enhancement and Protection of Personal Data (2024-2027) launched
-
August 2024:Â First major administrative fine (THB 7 million) imposed on a company for PDPA violations
-
2025-2026:Â Ongoing issuance of subordinate regulations and guidelines
Who Must Comply?
The PDPA applies to:
-
Data Controllers:Â Persons or juristic persons with authority to make decisions on collection, use, or disclosure of personal data
-
Data Processors:Â Persons processing personal data on behalf of or in compliance with orders from a data controller
-
Extraterritorial Application:Â Organizations outside Thailand that offer goods or services to individuals in Thailand or monitor their behavior
Exemptions
The PDPA does not apply to:
-
Persons conducting personal or household activities
-
Public authorities maintaining state security (financial/public safety)
-
Mass media, fine arts, and literature activities in accordance with professional ethics
-
The House of Representatives, Senate, or Parliament
-
Trial and adjudication courts
-
Credit bureau companies (specific operations)
Key Definitions Under the PDPA
| Term | Definition |
|---|---|
| Personal Data | Any information relating to a person which enables the identification of such person, whether directly or indirectly, but not including information of deceased persons. |
| General Personal Data (GPD) | Information that allows identification of an individual, including names, addresses, contact details, customer ID, age, gender, usernames, passwords, and IP addresses. |
| Sensitive Personal Data (SPD) | Information requiring explicit consent, including race, ethnicity, political opinions, religious beliefs, philosophical beliefs, sexual orientation, criminal records, health data, disabilities, trade union information, genetic data, and biometric data. |
| Data Controller | A person or juristic person with the authority and duty to make decisions regarding the collection, use, or disclosure of personal data. |
| Data Processor | A person or juristic person who collects, uses, or discloses personal data in compliance with orders from a data controller or on behalf of a data controller. |
| Data Subject | The individual to whom the personal data relates. |
| Personal Data Protection Committee (PDPC) | The regulatory authority responsible for enforcing the PDPA, issuing subordinate regulations, and prescribing guidelines. |
The Personal Data Protection Committee (PDPC)
The Personal Data Protection Committee (PDPC) is the official regulator of the PDPA in Thailand, established in January 2022. The committee consists of:
-
A Chairperson
-
Vice-Chairperson
-
Five Commission Members
-
Nine Honorary Commission Members
Key Functions of the PDPC:
-
Establishing a master plan for the promotion and protection of personal data
-
Prescribing measures, criteria, and guidelines for business operators
-
Issuing subordinate regulations and rules under the PDPA
-
Enforcing compliance and imposing penalties
-
Regulating cross-border data transfers
-
Providing guidance on data protection standards
Recent Initiatives:
-
April 2024:Â Launched a master plan for enhancement and protection of personal data (2024-2027)
-
March 2024:Â Released additional sub-regulations on cross-border data transfers and Binding Corporate Rules (BCRs)
-
Ongoing:Â Issuing subordinate regulations to clarify specific compliance requirements
Extraterritorial Application
The PDPA has extraterritorial scope, meaning organizations outside Thailand may be subject to the law if they:
-
Offer goods or services to data subjects in Thailand (regardless of whether payment is made)
-
Monitor the behavior of data subjects in Thailand (e.g., using cookies, Google Analytics, or search panels)
Representative Requirement
Data controllers or data processors located outside Thailand and subject to the PDPA must:
-
Appoint a representative in Thailand (individual or legal person) in writing
-
The representative acts on behalf of the data controller without limitation of liability
Exemption from Representative Requirement
Organizations that:
-
Are public authorities as prescribed by the PDPC
-
Do not process Sensitive Personal Data
-
Do not have a large amount of personal data requiring regular monitoring
Compliance Obligations for Foreign Entities:
-
Must comply with all PDPA requirements
-
Must appoint a DPO if applicable
-
Must implement Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs) for cross-border transfers
-
Must designate a representative in Thailand for regulatory communication
Key Compliance Requirements
1. Consent Requirements
General Consent
-
Specific consent is required from the data subject prior to or at the time of collection, use, or disclosure
-
Consent must be in writing or via electronic means
-
Data subjects may withdraw consent at any time
-
Consent withdrawal must be as easy as giving consent
Consent for Sensitive Personal Data
-
Explicit consent is required for Sensitive Personal Data
-
Exceptions apply where:
-
Preventing or suppressing danger to life, body, or health
-
The data subject is incapable of giving consent
-
Consent for Direct Marketing
-
Separate, explicit consent required for direct marketing activities
-
Data subjects have the right to object to direct marketing at any time
-
Organizations must provide an easy opt-out mechanism
Consent Withdrawal Method
-
Data controllers must publicize a consent withdrawal method
-
Data subjects must be notified of their right to withdraw consent
-
This applies to personal data collected before June 1, 2022
2. Collection of Personal Data
Lawful Purpose
-
Collection must be for a lawful purpose
-
Must be directly relevant and necessary for the activities of the data controller
Notification Requirements
Data controllers must inform data subjects prior to or at the time of collection of:
-
The purpose of collection, use, or disclosure
-
Whether data supply is mandatory or voluntary (and consequences if not provided)
-
The personal data to be collected
-
The retention period (or criteria for determining it)
-
Categories of persons/entities to whom data may be disclosed
-
Contact details of the data controller and DPO (if applicable)
-
The rights of the data subject under the PDPA
Direct Collection
-
Personal data must typically be collected directly from the data subject
-
Exceptions apply under limited circumstances
Sensitive Personal Data
-
Collection is prohibited without explicit consent
-
Exceptions are strictly limited (e.g., life-saving situations)
3. Rights of Data Subjects
The PDPA grants data subjects comprehensive rights:
| Right | Description |
|---|---|
| Right to Withdraw Consent | Withdraw consent at any time, as easily as it was given |
| Right to Access | Access and obtain a copy of personal data |
| Right to Data Portability | Receive data in machine-readable format and request transfer to another controller |
| Right to Object | Object to collection, use, or disclosure in specified circumstances |
| Right to Erasure | Request deletion or anonymization of personal data |
| Right to Restriction | Request suspension of data use in specified circumstances |
| Right to Rectification | Ensure data is accurate, complete, and up-to-date |
| Right to Complain | File complaints with the PDPC |
Note on Data Portability
-
Data subjects can request personal data in machine-readable formats
-
Can request data controllers to send data to another data controller
-
Right to data portability is similar to GDPR Article 20
Right to Be Informed
-
Data subjects have the right to be informed about:
-
What data is being collected
-
Why it is being collected
-
The retention period
-
Who it will be shared with
-
Their rights under the PDPA
-
4. Cross-Border Data Transfers
Adequacy Requirement
-
Personal data may only be transferred to a destination country or international organization with adequate data protection standards
-
Standards are prescribed by the PDPC
Exceptions (Transfer Permitted Without Adequacy)
-
Transfer is made pursuant to applicable laws
-
Consent is obtained from data subjects (informed of inadequate protection measures)
-
Transfer is necessary for performance of a contract
-
Transfer is necessary for compliance with a contract between data controllers for data subject interests
-
Transfer is to prevent/suppress danger to life, body, or health (data subject incapable of giving consent)
-
Transfer is necessary for substantial public interest
Mechanisms for Compliant Cross-Border Transfers
-
Binding Corporate Rules (BCRs):Â For intra-group transfers
-
Standard Contractual Clauses (SCCs):Â For transfers to third parties
-
Adequacy Decisions:Â Where PDPC deems a country has adequate protection
5. Data Protection Officer (DPO) Appointment
A DPO must be appointed in the following cases:
| Condition | Description |
|---|---|
| Public Authority | Data controller or processor is a public authority as prescribed by the PDPC |
| Regular Monitoring | Activities require regular monitoring of personal data or systems due to a large volume of personal data |
| Sensitive Personal Data | Core activities involve collection, use, or disclosure of Sensitive Personal Data |
DPO Responsibilities
-
Advising on PDPA compliance
-
Investigating compliance with the PDPA
-
Coordinating with regulatory authorities
-
Maintaining confidentiality regarding acquired personal data
-
Acting as a contact person for data subjects
Penalties for Non-Appointment
-
Administrative fine not exceeding THB 1 million
6. Security Requirements
Data controllers must implement appropriate security measures to protect personal data from unauthorized access, use, disclosure, alteration, or destruction.
Security Measures Should Include:
-
Organizational Measures:Â Policies, procedures, training
-
Technical Measures:Â Encryption, access controls, monitoring
-
Physical Measures:Â Secure facilities, access restrictions
Acceptable Security Frameworks
-
Thailand’s Ministry of Digital Economy and Society accepts ISO 27001 as sufficient evidence of compliance with minimum security standards
-
Other industry-specific frameworks may also be acceptable
Security Risk Assessments
-
Required when technology changes
-
When necessary to maintain suitable security and safety requirements
7. Data Breach Notification
Notification Timeline
-
Data controllers must notify the PDPC of a data breach within 72 hours of becoming aware
-
Notification must be made without delay if the breach is likely to result in a risk to the rights and freedoms of data subjects
Breach Notification Requirements
-
Nature of the incident
-
Contact details of the contact person or DPO
-
Possible consequences
-
Measures taken or to be taken to mitigate adverse effects
Notification to Data Subjects
-
If a breach is likely to result in critical threats to rights and freedoms:
-
Notify the PDPC and data subjects without delay
-
-
For breaches involving several data subjects:
-
Notify each subject specifically, or
-
Notify the public via media, social media, or other accessible means
-
Notification from Data Processors
-
Data processors must notify the data controller without undue delay upon discovering a breach
Case Example: August 2024
A major private company received Thailand’s first PDPA administrative fine:
-
Amount:Â THB 7 million (maximum fine)
-
Reasons:
-
Failure to appoint a DPO (THB 1 million)
-
Inadequate security measures (Section 37(1))
-
Failure to report data breaches (Section 37(4))
-
-
Remedial Actions Ordered:
-
Enhance security measures
-
Train staff
-
Report improvements to PDPC within 7 days
-
8. Record of Processing Activities (RoPA)
General Requirement
-
Data controllers and data processors must keep full records of personal data processing activities
-
Ensures preparedness for inspection by or submission to the PDPC
SME Exemption
-
Small and Medium-Sized Enterprises (SMEs) are exempt from RoPA requirements
-
Definition: Organizations qualifying under the Small and Medium-Sized Enterprise Promotions Act
-
Exception:Â Some SMEs must still prepare RoPA if their data processing poses a risk to data subject rights and freedoms
9. Vendor Privacy Contracts
Contractual Requirements
-
Data controllers and data processors must enter into contractual agreements
-
Contracts must require both parties to comply with all PDPA requirements
Types of Agreements:
-
Data Processing Agreement (DPA):Â When vendors act as data processors
-
Data Sharing/Transfer Agreement:Â When vendors act as data controllers
Key Contractual Elements:
-
Clear definition of roles (controller vs. processor)
-
Security measures to be implemented
-
Breach notification procedures
-
Sub-processing restrictions
-
Data deletion requirements
10. Grandfathering Provisions
Personal Data Collected Before June 1, 2022
Data controllers may continue to use personal data collected before the PDPA came into force, provided:
-
Same Purpose:Â Data is only used for the same purpose for which it was originally collected
-
Consent Withdrawal Method:Â The data controller prepares and publicizes a consent withdrawal method
-
Notice:Â Data subjects are notified of their right to withdraw consent
Expanded Processing
-
If data is used or disclosed beyond the original purpose:
-
New explicit consent is required for each separate purpose
-
Fines and Penalties
| Type of Violation | Maximum Penalty |
|---|---|
| Administrative Fine (General) | Up to THB 5 million |
| Administrative Fine (DPO Non-Appointment) | Up to THB 1 million |
| Criminal Penalties | Fines and potential imprisonment |
| Civil Liability | Compensation for damages |
| Failure to Report Breach | Up to THB 5 million |
| Inadequate Security Measures | Up to THB 5 million |
Recent Enforcement:
-
August 2024: First major administrative fine of THB 7 million imposed
-
Company failed to appoint DPO, had inadequate security measures, and delayed breach notification
-
Demonstrates aggressive enforcement posture
Factors in Determining Penalties
-
Nature and gravity of the violation
-
Volume and sensitivity of personal data affected
-
Mitigation efforts
-
Cooperation with the PDPC
-
Previous instances of non-compliance
How LOGON Software Asia Can Help Different Industries in Thailand
Banking, Financial Services & Insurance (BFSI)
BFSI organizations handle highly sensitive financial data and are prime targets for cyberattacks. The PDPA imposes strict requirements for consent, security, and breach notification.
How LOGON Can Help:
- Application Security Testing: Comprehensive web and mobile application penetration testing to identify vulnerabilities before they are exploited
- Data Loss Prevention (DLP): Preventing unauthorized disclosure of sensitive financial and customer data
- Identity & Access Management (IAM): Implementing IAM solutions with least privilege access and multi-factor authentication
- Security Monitoring & SOC: 24/7 monitoring to detect and respond to threats
- Data Classification: Automatically discovering and classifying sensitive personal data
- Vendor Risk Management: Ensuring third-party processors meet PDPA security standards
Healthcare & Pharmaceuticals
Healthcare data qualifies as Sensitive Personal Data under the PDPA, requiring explicit consent and enhanced security measures. Data breaches in healthcare can result in severe harm to patients.
How LOGON Can Help:
- Data Discovery & Classification: Identifying and securing sensitive health data across IT environments
- Encryption: Implementing strong encryption for data at rest and in transit
- Secure Data Sharing: Platforms for sharing medical data between healthcare providers while maintaining compliance
- Incident Response: Breach response frameworks to ensure timely notification within 72 hours
- ISO 27001 Compliance: Supporting certification to demonstrate compliance with PDPA security standards
- DPO Support: Assisting with DPO appointment and responsibilities
E-commerce, Retail & Consumer Goods
Retail businesses process vast amounts of customer data for marketing, loyalty programs, and personalization. Direct marketing consent and data subject rights management are key compliance areas.
How LOGON Can Help:
- Consent Management Platforms: Technologies to capture, manage, and maintain auditable consent records
- DSAR Automation: Automating the receipt, verification, and response to data subject access requests
- Lifecycle Management: Automated data retention and deletion policies
- Data Mapping: Understanding personal data flows across systems
- Web Application Security: Testing online storefronts to prevent data breaches
Technology & IT Services
Tech companies process massive volumes of personal data across complex, multi-cloud environments with extensive third-party integrations and are often subject to extraterritorial application.
How LOGON Can Help:
- Attack Surface Management: Inventorying and continuously monitoring internet-facing applications and assets
- Automated Security Testing: DAST and manual penetration testing to meet security requirements
- Cloud Security: Securing cloud environments and ensuring compliance with PDPA cross-border transfer requirements
- Vendor Risk Management: Ensuring third-party processors comply with PDPA requirements
- Binding Corporate Rules (BCRs): Assisting in implementing BCRs for intra-group transfers
- DPO Services: Assisting with DPO appointment and responsibilities
SMEs & Small Businesses
SMEs must comply with the PDPA but may have limited resources. Exemptions exist for RoPA, but other obligations remain.
How LOGON Can Help:
- Tiered Compliance Solutions: Scalable solutions based on business size and data processing volume
- DPO Outsourcing: Cost-effective outsourced DPO services
- Consent Management: Simple, affordable consent management solutions
- Security Assessments: Basic security assessments to identify and address risks