Thailand's Personal Data Protection Act B.E. 2562 (2019) — commonly known as the Thailand PDPA — became the first comprehensive personal data protection law in Southeast Asia to come into full force. After a series of phased delays, the full enforcement period began on June 1, 2022. The law is administered by the Personal Data Protection Committee (PDPC) and its Office (OOPDPA), and applies to any organisation that collects, uses, or discloses the personal data of individuals in Thailand — regardless of where the organisation is based.
Who Must Comply With the Thailand PDPA?
The Thailand PDPA has extraterritorial reach under Section 5. Any organisation — Thai or foreign — that:
- Collects, uses, or discloses personal data of individuals in Thailand; or
- Offers goods or services to individuals in Thailand; or
- Monitors the behaviour of individuals in Thailand
…must comply with the PDPA. This means foreign SaaS companies, e-commerce platforms, and app developers with Thai users are in scope even if they have no physical presence in Thailand.
Key Definitions Under the Thailand PDPA
- Personal data: Information that enables the identification of an individual — directly or indirectly. Includes name, address, national ID, email, IP address, location data, cookies that identify individuals.
- Sensitive personal data (Section 26): Nine categories subject to explicit consent and heightened safeguards: racial or ethnic origin; political opinions; religious or philosophical beliefs; sexual behaviour; criminal history; health data; disability; trade union membership; genetic data; biometric data capable of identifying an individual.
- Data Controller: Any person or organisation that has the authority to make decisions on the collection, use, or disclosure of personal data.
- Data Processor: Any person or organisation that collects, uses, or discloses personal data pursuant to the instructions of the Data Controller.
Lawful Bases for Processing
The Thailand PDPA (Sections 19–26) provides six lawful bases for processing:
- Consent — freely given, specific, informed, unambiguous; written or electronic; separate from other agreements; no bundling
- Contract performance — necessary to perform a contract with the data subject
- Vital interest — necessary to prevent or suppress danger to life, body, or health
- Public interest — for the exercise of official authority or public tasks
- Legitimate interest — necessary for the legitimate interests of the controller or third party, except where overridden by the data subject's interests or fundamental rights
- Compliance with a legal obligation — necessary for legal compliance
Sensitive personal data may only be processed with explicit consent (or narrow exceptions for vital interests, legal claims, non-profit purposes, medical treatment, or public health). There is no legitimate interests basis available for sensitive data.
Thailand PDPA Consent Requirements
Under Sections 19–26, valid consent must be:
- Freely given — no coercion or adverse consequences for refusal
- Specific — linked to a defined, stated purpose
- Informed — data subject understands what they are consenting to
- Unambiguous — clear affirmative action required; no pre-ticked boxes or implied consent
- Separate from other matters — consent request cannot be bundled with terms of service
- Withdrawable without detriment — withdrawal must be as easy as giving consent
Children's consent: Under Section 20, if the data subject is under 10 years old, consent must be given by a parent or legal guardian. If 10–19 years old, both the minor and the parent/guardian must consent.
Data Subject Rights Under the Thailand PDPA
Thai data subjects have six core rights (Sections 30–43), with a standard 30-day response deadline:
- Right of access (Section 30): Request a copy of their personal data and information about how it is processed
- Right to data portability (Section 31): Receive personal data in a structured, machine-readable format and transfer to another controller
- Right to erasure (Section 33): Request deletion or anonymisation when purpose is complete, consent withdrawn, data collected unlawfully, or legal obligation requires
- Right to restriction (Section 34): Request suspension of processing while a challenge to accuracy or objection is resolved
- Right to object (Section 32): Object to processing based on legitimate interest or direct marketing
- Right to correct (Section 35): Request correction of inaccurate, incomplete, or misleading personal data
Personal Data Breach Notification
Under Section 37, Data Controllers must:
- Notify the PDPC within 72 hours of becoming aware of a personal data breach that is likely to affect the rights and freedoms of individuals
- Notify affected individuals without undue delay when the breach is likely to result in high risk to their rights and freedoms
- Maintain a breach incident log documenting all breaches, their assessment, and response measures
The 72-hour clock starts when the controller has reasonable certainty that a breach has occurred — not from initial suspicion. Controllers should have documented procedures for breach detection, assessment, and notification to avoid missing the 72-hour window.
DPO Appointment Obligation
Section 41 requires Data Controllers and Data Processors to appoint a Data Protection Officer (DPO) if they:
- Are a government agency or public authority
- Conduct activities that require large-scale, regular and systematic monitoring of data subjects
- Process sensitive personal data at scale as their core activity
The DPO must have sufficient authority and resources, be accessible to data subjects, and their contact details must be published. The DPO must be independent and report to the highest management level.
Cross-Border Transfer Rules
Under Sections 28–29, personal data may only be transferred internationally to:
- Countries on the PDPC adequacy list (countries with adequate data protection standards); or
- Countries where the controller has implemented appropriate safeguards such as Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or intra-group agreements; or
- Where the data subject has given explicit consent after being informed that the destination country may not offer adequate protection
PDPC Enforcement and Penalties
The PDPC has enforcement powers including:
- Criminal penalties: Up to THB 5 million per violation for wilful or negligent breaches; up to THB 3 million for failing to provide data subject rights; up to THB 1 million for breach notification failures
- Civil damages: Courts may award civil damages plus punitive damages up to double the actual damage
- Director/executive liability: Criminal liability can attach to directors and executives who authorise or fail to prevent violations
The PDPC has issued enforcement guidance, consent framework guidance, and cross-border transfer guidance since full enforcement began in 2022. Non-compliance is a genuine enforcement risk, particularly for organisations processing health data, financial data, or biometric information at scale.
Use the free Thailand PDPA Compliance Checker to assess your organisation across all 42 key obligations, generate a tailored compliance report, and build a prioritised remediation roadmap before your next PDPC engagement.