Personal Data Protection Act B.E. 2562
Thailand
Fully in force since 2022
The Personal Data Protection Act was enacted in 2019, with its main provisions becoming fully effective on 1 June 2022.
Asia & Africa
The PDPA applies to data controllers and data processors that collect, use, or disclose personal data within the scope of the Act. It can also apply to organisations located outside Thailand when their processing activities relate to offering goods or services to individuals in Thailand, or monitoring the behaviour of individuals in Thailand. Organisations should therefore assess both their physical presence and their activities involving individuals in Thailand.
Thailand's PDPA provides administrative, civil, and criminal consequences for certain violations. Administrative fines can reach THB 5 million for certain serious infringements. Criminal penalties and compensation may also apply in circumstances established by the Act, particularly for certain unlawful processing or disclosure involving sensitive personal data. The applicable penalty depends on the specific provision breached and the circumstances of the violation.
Thailand's official government guidance also provides resources for consent forms, data processing agreements, data subject rights requests, breach notifications, and records of processing activities.
Consent is not the only legal basis under Thailand's PDPA.
Depending on the processing activity, organisations may be able to rely on other lawful bases recognised under the Act.
These can include circumstances relating to:
Organisations should therefore determine the appropriate legal basis for each processing purpose rather than automatically requesting consent for every activity.
Where consent is required, the PDPA establishes specific requirements for obtaining valid consent.
Consent should generally be:
Individuals should be provided with sufficient information to understand what they are agreeing to.
Consent should also be capable of being withdrawn, subject to the applicable legal requirements and consequences of withdrawal.
For websites, organisations should therefore avoid:
Thailand's PDPA provides additional protection for sensitive personal data.
Sensitive categories include information such as:
Processing sensitive personal data is subject to stricter requirements than ordinary personal data.
Where explicit consent is required, organisations should obtain it separately and ensure that individuals understand the specific sensitive data processing involved.
Thailand's PDPA provides individuals with several rights relating to their personal data.
These include:
Organisations should maintain documented workflows for receiving, verifying, tracking, and responding to these requests.
Organisations must provide individuals with appropriate information about the collection and processing of their personal data.
A privacy notice should clearly communicate relevant information such as:
Thailand's government guidance also emphasises communicating the purposes for which personal data will be collected, used, or disclosed.
Data controllers and processors should implement appropriate security measures to protect personal data against:
Security measures should be appropriate to the nature and risks of the processing.
A comprehensive PDPA compliance programme should include:
Thailand's PDPA establishes obligations concerning personal data breaches.
Where a qualifying breach occurs, the data controller must assess the risk to individuals and determine whether notification to the Personal Data Protection Committee (PDPC) is required.
Where the breach is likely to result in a risk to individuals' rights and freedoms, the controller must notify the PDPC without delay and, where feasible, within 72 hours of becoming aware of the breach.
Where a breach is likely to result in a high risk to individuals, notification to affected data subjects may also be required.
Organisations should therefore maintain an incident response process that can:
Thailand's PDPA requires certain organisations to appoint a Data Protection Officer (DPO).
The requirement can apply based on factors such as the nature of the organisation's activities and the scale or characteristics of personal data processing.
A DPO may be responsible for:
Organisations should assess their processing activities to determine whether a DPO is required.
Thailand's PDPA regulates the transfer of personal data to other countries.
Organisations transferring personal data outside Thailand should assess:
The PDPA framework includes rules concerning transfers to countries with adequate data protection standards and mechanisms for certain transfers to destinations that do not meet the applicable standard.
For transfers within corporate groups, Binding Corporate Rules (BCRs) may be relevant where the applicable requirements are satisfied.
Organisations using third-party vendors to process personal data should establish appropriate contractual arrangements.
A Data Processing Agreement (DPA) can define matters such as:
Thailand's government resources include model documentation and guidance relating to Data Processing Agreements.
Cookies, pixels, analytics tools, advertising technologies, and other online tracking technologies may involve the collection or use of personal data.
Website operators should therefore assess each technology according to:
For non-essential cookies and tracking technologies where consent is required, organisations should obtain consent before activation.
A compliant implementation should:
Organisations should not retain personal data indefinitely when it is no longer necessary for the relevant purpose or legal obligation.
A privacy programme should define appropriate retention periods based on:
When retention is no longer justified, organisations should securely delete, anonymise, or otherwise dispose of the information in accordance with applicable requirements.
Capture consent before applicable non-essential cookies and trackers are activated.
Explain the purposes associated with analytics, advertising, personalisation, and other processing activities.
Support separate and clearly identifiable consent experiences for sensitive personal data where explicit consent is required.
Scan websites to identify cookies and trackers and control applicable non-essential technologies.
Maintain evidence of user choices and relevant information about the consent event.
Support workflows for access, deletion, rectification, objection, and other applicable rights.
Use ConsentX's region rule engine to provide a Thailand-specific consent experience for relevant visitors.
Scan your website → Identify trackers → Map processing purposes → Configure consent → Block applicable trackers → Record consent → Manage privacy requests. Create a transparent and auditable consent experience for users in Thailand.
This page provides a plain-English summary of Thailand's personal data protection framework for general informational purposes and is not legal advice. Organisations should assess their specific processing activities and consult qualified Thai legal counsel where necessary.
Scan your website to identify cookies, pixels, trackers, scripts, and third-party technologies.
Identify what each technology does and determine the applicable legal basis for each processing activity.
Where consent is required, create a banner that clearly explains the processing purpose and provides an appropriate choice to the user.
Prevent applicable non-essential cookies and trackers from activating until the required consent has been obtained.
Store consent choices and relevant contextual information in auditable consent records.
Centralise requests for access, deletion, rectification, objection, portability, and other applicable rights.
Regularly scan for new cookies, trackers, vendors, and scripts that may change your privacy compliance requirements.