AuditXYZ

Compliance Framework

Personal Data Protection Act B.E. 2562 (2019) (Thailand) (PDPA (Thailand))

Thailand's PDPA is a comprehensive data protection law modeled on the GDPR, establishing consent requirements, data subject rights, breach notification obligations, and cross-border transfer restrictions for organizations processing personal data in Thailand.

$5,000–$70,0003–9 months2019 (fully enforced June 1, 2022)
Issuing BodyNational Legislative Assembly of Thailand / Personal Data Protection Committee (PDPC)
First Published2019-05-27
Latest Version2019 (fully enforced June 1, 2022)
Typical Cost$5,000–$70,000
Typical Timeline3–9 months
Audit RequiredNo
Audit FrequencyNo mandatory external audit. The PDPC may investigate complaints. Data controllers must maintain records of processing activities.
Geographythailand

PDPA Thailand: The Complete Guide

Thailand's Personal Data Protection Act, enacted in 2019 and fully enforceable since June 1, 2022, is the country's first comprehensive data protection law. Heavily influenced by the GDPR, the PDPA establishes a framework for protecting personal data collected, used, or disclosed by organizations operating in Thailand or targeting Thai residents. Thailand's status as a major tourism, manufacturing, and service hub means the PDPA affects a wide range of international businesses with Thai operations or customers.

What the PDPA Is and Who Enforces It

The PDPA was enacted by Thailand's National Legislative Assembly and published in the Royal Gazette in May 2019. Implementation was delayed twice due to the COVID-19 pandemic before taking full effect on June 1, 2022. The Personal Data Protection Committee (PDPC) is the primary regulatory authority, supported by the Expert Committee (which adjudicates compensation claims from data subjects) and the Complaint Committee (which investigates breaches).

The Office of the PDPC Secretariat handles enforcement inquiries, and the law designates the Office of the National Cybersecurity Agency (NCSA) as an operational partner. Thailand's enforcement is still developing institutional capacity, but the PDPC has issued guidance on consent, privacy notices, and sector-specific obligations. Organizations should expect increasing enforcement activity as the regulator matures.

Territorial and Material Scope

The PDPA applies to:

  • Data controllers and processors that collect, use, or disclose personal data in Thailand, regardless of where the processing occurs.
  • Organizations outside Thailand that offer goods or services to individuals in Thailand, or monitor the behavior of individuals in Thailand.

This extraterritorial reach means foreign companies with Thai users, customers, or digital services targeting Thailand fall within scope. Personal data is broadly defined as any information relating to an identified or identifiable natural person.

Key exemptions apply to government agencies acting in public interest under specific statutes, data controllers established outside Thailand for transit purposes, media acting in journalistic or public interest capacities, and certain research and historical record activities.

Six Lawful Bases for Processing

The PDPA recognizes six lawful bases, closely mirroring the GDPR:

  1. Consent — Freely given, specific, informed, and unambiguous, and must be as easy to withdraw as to give.
  2. Contractual necessity — Processing necessary for the performance of a contract with the data subject.
  3. Vital interests — Processing necessary to protect life.
  4. Legal obligation — Processing necessary for compliance with a legal obligation.
  5. Public interest — Processing necessary for carrying out a public interest task or exercising official authority.
  6. Legitimate interests — Processing necessary for the legitimate interests of the controller or a third party, balanced against the individual's rights.

Consent is valid only if given separately from other terms and conditions, and may not be bundled with acceptance of a service agreement. Controllers must retain evidence of consent.

Sensitive Personal Data

The PDPA protects sensitive personal data, defined to include: racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual behavior, criminal records, health data, disabilities, trade union membership, genetic data, and biometric data. Processing sensitive data requires explicit consent from the data subject, except where necessary for specific statutory purposes including legal claims, vital interests where the subject cannot consent, and public health purposes.

Organizations processing sensitive data face heightened obligations and should implement separate consent flows, access controls, and audit trails for these categories.

Data Subject Rights

Data subjects are granted comprehensive rights that controllers must honor within 30 days (extendable by an additional 30 days with notice to the data subject):

  • Right to access — Receive information about data held and processing activities.
  • Right to data portability — Receive data in a machine-readable format for transfer where technically feasible.
  • Right to objection — Object to processing based on legitimate interests or for direct marketing.
  • Right to erasure — Request deletion when data is no longer necessary, consent is withdrawn, or processing is unlawful.
  • Right to restriction — Request a pause on processing in specified circumstances.
  • Right to rectification — Request correction of inaccurate or incomplete data.

Refusals of requests must be communicated in writing with reasons. Data subjects may file complaints to the PDPC or seek compensation through the Expert Committee.

Data Protection Officer

A DPO must be appointed where:

  • The controller or processor carries out large-scale monitoring of data subjects, or
  • The controller or processor's core activities involve processing sensitive personal data on a large scale, or
  • The controller or processor is a public authority.

The DPO must have expert knowledge of data protection law and practices. Unlike the GDPR's DPO, the Thai PDPA DPO is not explicitly protected from dismissal, though PDPC guidance encourages appropriate independence. The DPO must advise the controller on compliance and act as a contact point for the PDPC.

Breach Notification

Controllers must notify the PDPC within 72 hours of becoming aware of a personal data breach, where the breach is likely to harm the rights and freedoms of individuals. Where the breach is likely to result in high risk, affected data subjects must also be notified without undue delay.

Notification to the PDPC must include: the nature of the breach, categories and estimated number of individuals affected, contact details of the DPO, likely consequences, and measures taken or proposed to mitigate harm.

Cross-Border Transfer Safeguards

Article 28 of the PDPA restricts personal data transfers to countries that do not have adequate personal data protection standards, unless:

  • The data subject has consented to the transfer with full knowledge of the inadequate protection.
  • The transfer is necessary for contractual performance, legal proceedings, vital interests, or significant public benefit.
  • The controller has implemented appropriate safeguards such as standard contractual clauses or binding corporate rules.

The PDPC has been developing adequacy criteria and guidance on acceptable transfer safeguards. Organizations using EU SCCs as a basis for Thailand-related transfers should verify whether the PDPC recognizes these as equivalent.

Enforcement and Penalties

The PDPA establishes three categories of penalties:

Administrative fines — The PDPC may impose administrative fines of up to 5 million Thai Baht (approximately $140,000) for violations.

Criminal penalties — Certain offenses carry criminal liability. Sending personal data abroad without adequate safeguards or consent where explicit consent is required attracts fines of up to 5 million Baht and imprisonment of up to one year. Using personal data without lawful basis for personal benefit carries fines of up to 1 million Baht and up to six months imprisonment.

Civil compensation — Data subjects may claim compensation through the Expert Committee, which may award actual damages plus a punitive element.

PDPA Thailand vs. GDPR and Regional Laws

Thailand's PDPA shares approximately 65% structural overlap with the GDPR, making it one of the more GDPR-aligned laws in Southeast Asia. The main divergences are in enforcement infrastructure maturity, the absence of an explicit adequacy decision process, and less developed guidance on specific topics.

Compared to Singapore's PDPA (70% overlap), Thailand's PDPA has similar structure and consent requirements. Singapore has a more mature enforcement track record and the Do Not Call Registry as a distinctive element. Thailand's tourism and hospitality sector dominance creates sector-specific compliance considerations — particularly around hotel guest data, medical tourism data, and cross-border tourist monitoring — that Singapore's more finance-and-tech-focused enforcement does not emphasize as heavily.

Compared to Japan's APPI (50% overlap), both are GDPR-inspired frameworks but APPI has a longer history, a mutual adequacy finding with the EU, and more detailed guidance through the PPC.

Compliance Steps and Timeline

PhaseActivitiesTypical Duration
AssessmentData mapping, lawful basis review, DPO need assessment3-5 weeks
DesignConsent notices, rights workflows, breach notification plan4-7 weeks
ImplementationRecords of processing, cross-border safeguards, vendor contracts4-8 weeks
OngoingBreach monitoring, rights fulfillment, PDPC guidance trackingContinuous

Key compliance steps:

  1. Lawful basis assessment — Identify and document the legal basis for each processing activity, maintaining records of the basis applied.
  2. Consent management — Implement mechanisms for obtaining, recording, and withdrawing consent, ensuring separation from general terms of service.
  3. Data subject rights — Build intake and response workflows meeting the 30-day deadline for all data subject rights categories.
  4. DPO appointment — Assess whether your processing volume or type requires a DPO and designate one with documented responsibilities.
  5. Cross-border transfers — Map all international data flows and implement safeguards or obtain explicit consent for transfers to non-adequate countries.
  6. Records of processing — Maintain written records of all processing activities as required under the PDPA.
  7. Breach response — Establish a 72-hour notification process with documented escalation paths to the PDPC and affected data subjects.

How Privacy Automation Helps

Thailand's PDPA compliance shares operational infrastructure needs with other GDPR-derived frameworks: consent management, data mapping, DSR fulfillment, and breach notification. TruePrivacy covers Thailand's PDPA among its 12-plus supported frameworks alongside GDPR, CCPA, Singapore PDPA, and PIPL. AI data discovery across 128-plus sources supports the comprehensive data mapping needed for records of processing activities.

At $5,000 per year with 24-hour onboarding and an 88/100 AuditXYZ score, TruePrivacy is well-suited for organizations building Thailand PDPA programs, particularly those managing multiple ASEAN jurisdictions simultaneously. Compare options at best privacy management tools.

Frequently Asked Questions

Does Thailand's PDPA apply to companies based outside Thailand with Thai customers? Yes. The PDPA explicitly applies to organizations outside Thailand that offer goods or services to individuals in Thailand or monitor their behavior, even without a physical presence in Thailand. A foreign airline with Thai passengers, a hotel booking platform serving Thai travelers, or a streaming service available in Thailand all fall within scope.

What is the difference between the PDPC, Expert Committee, and Complaint Committee? The PDPC is the primary regulatory and rulemaking authority. The Expert Committee adjudicates compensation claims from data subjects who have suffered harm from violations. The Complaint Committee investigates alleged violations by controllers and processors and recommends actions to the PDPC. This tripartite structure creates multiple channels through which compliance failures can be identified and remedied.

Is prior explicit consent always required for employee data? Not always. While consent is one valid basis, contractual necessity covers processing required for the employment relationship (payroll, benefits, legal obligations). However, consent is typically required for processing beyond what is strictly necessary for employment purposes — such as health monitoring, social media tracking, or sharing data with third parties for purposes unrelated to employment.

How do we handle sensitive data from healthcare patients in Thailand? Thailand's tourism-driven medical sector means many healthcare providers must process sensitive health data of foreign patients. This requires: explicit consent for all health data processing, security safeguards appropriate to health data sensitivity, restricted access controls, and — for any cross-border transfers such as sending records back to the patient's home country — either explicit informed consent or a PDPC-approved transfer safeguard.

Are records of processing activities mandatory under the Thai PDPA? Yes. Controllers must maintain records of processing activities that include: the name and contact details of the controller and DPO, the purposes of processing, categories of personal data and data subjects, recipients to whom data is disclosed, cross-border transfers and safeguards, retention periods, and security measures. These records must be available for PDPC inspection on request.

Request a PDPA (Thailand) consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

PDPA SingaporeMedium70%
GDPRMedium65%

Get matched with a PDPA (Thailand) auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.