Thailand PDPA Compliance with ConsentX
Personal Data Protection Act B.E. 2562
Thailand
Fully in force since 2022
The Personal Data Protection Act was enacted in 2019, with its main provisions becoming fully effective on 1 June 2022.
Asia & Africa
Who must comply with Thailand's PDPA?
The PDPA applies to data controllers and data processors that collect, use, or disclose personal data within the scope of the Act. It can also apply to organisations located outside Thailand when their processing activities relate to offering goods or services to individuals in Thailand, or monitoring the behaviour of individuals in Thailand. Organisations should therefore assess both their physical presence and their activities involving individuals in Thailand.
Penalties under Thailand's PDPA
Thailand's PDPA provides administrative, civil, and criminal consequences for certain violations. Administrative fines can reach THB 5 million for certain serious infringements. Criminal penalties and compensation may also apply in circumstances established by the Act, particularly for certain unlawful processing or disclosure involving sensitive personal data. The applicable penalty depends on the specific provision breached and the circumstances of the violation.
Key obligations under Thailand's PDPA
- Identify a valid legal basis before processing personal data.
- Obtain valid consent where consent is the applicable legal basis.
- Provide an appropriate privacy notice.
- Collect personal data only for legitimate and specified purposes.
- Process personal data in accordance with the stated purposes.
- Respect data subject rights.
- Implement appropriate technical and organisational security measures.
- Maintain appropriate records and compliance documentation.
- Notify qualifying personal data breaches within the required timeframe.
- Appoint a Data Protection Officer where required.
- Comply with international data transfer requirements.
- Apply enhanced safeguards to sensitive personal data.
Thailand's official government guidance also provides resources for consent forms, data processing agreements, data subject rights requests, breach notifications, and records of processing activities.
Lawful bases for processing personal data
Consent is not the only legal basis under Thailand's PDPA.
Depending on the processing activity, organisations may be able to rely on other lawful bases recognised under the Act.
These can include circumstances relating to:
- Contractual necessity
- Legal obligations
- Vital interests
- Public task or public interest
- Legitimate interests
- Other circumstances specifically recognised by the PDPA
Organisations should therefore determine the appropriate legal basis for each processing purpose rather than automatically requesting consent for every activity.
Consent requirements
Where consent is required, the PDPA establishes specific requirements for obtaining valid consent.
Consent should generally be:
- Freely given
- Specific
- Informed
- Unambiguous
- Clearly distinguishable from other matters
Individuals should be provided with sufficient information to understand what they are agreeing to.
Consent should also be capable of being withdrawn, subject to the applicable legal requirements and consequences of withdrawal.
For websites, organisations should therefore avoid:
- Pre-selected consent options
- Bundled consent for unrelated purposes
- Unclear consent language
- Consent hidden inside lengthy terms
- Making unnecessary processing appear mandatory
Sensitive personal data
Thailand's PDPA provides additional protection for sensitive personal data.
Sensitive categories include information such as:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Sexual behaviour
- Criminal records
- Health information
- Disability
- Trade union information
- Genetic data
- Biometric data
Processing sensitive personal data is subject to stricter requirements than ordinary personal data.
Where explicit consent is required, organisations should obtain it separately and ensure that individuals understand the specific sensitive data processing involved.
Data subject rights
Thailand's PDPA provides individuals with several rights relating to their personal data.
These include:
- Right to access - individuals can request access to their personal data and information concerning its processing.
- Right to data portability - under applicable circumstances, individuals may request their personal data in a format that can be transmitted to another controller.
- Right to rectification - individuals can request correction of inaccurate or incomplete personal data.
- Right to erasure - individuals may request deletion or destruction of personal data where the legal requirements are satisfied.
- Right to restriction - individuals may request restriction of certain processing activities in circumstances established by the PDPA.
- Right to object - individuals can object to certain processing activities, including processing based on legitimate interests in applicable circumstances.
- Right to withdraw consent - where processing relies on consent, individuals may withdraw that consent, subject to applicable legal requirements.
Organisations should maintain documented workflows for receiving, verifying, tracking, and responding to these requests.
Privacy notices and transparency
Organisations must provide individuals with appropriate information about the collection and processing of their personal data.
A privacy notice should clearly communicate relevant information such as:
- Identity and contact details of the controller
- Personal data being collected
- Purpose of collection and processing
- Applicable legal basis
- Retention period or relevant criteria
- Categories of recipients
- International transfers where applicable
- Data subject rights
- How individuals can exercise their rights
- Contact details for privacy-related enquiries
Thailand's government guidance also emphasises communicating the purposes for which personal data will be collected, used, or disclosed.
Data security
Data controllers and processors should implement appropriate security measures to protect personal data against:
- Unauthorised access
- Loss
- Destruction
- Alteration
- Disclosure
- Unauthorised use
Security measures should be appropriate to the nature and risks of the processing.
A comprehensive PDPA compliance programme should include:
- Access controls
- Data classification
- Encryption where appropriate
- Security monitoring
- Employee training
- Incident response
- Vendor management
- Data retention controls
- Regular security reviews
Data breach notification
Thailand's PDPA establishes obligations concerning personal data breaches.
Where a qualifying breach occurs, the data controller must assess the risk to individuals and determine whether notification to the Personal Data Protection Committee (PDPC) is required.
Where the breach is likely to result in a risk to individuals' rights and freedoms, the controller must notify the PDPC without delay and, where feasible, within 72 hours of becoming aware of the breach.
Where a breach is likely to result in a high risk to individuals, notification to affected data subjects may also be required.
Organisations should therefore maintain an incident response process that can:
- Detect the breach.
- Assess the affected data.
- Evaluate the risk.
- Document the incident.
- Determine notification obligations.
- Notify the PDPC where required.
- Notify affected individuals where required.
- Implement corrective measures.
Data Protection Officer
Thailand's PDPA requires certain organisations to appoint a Data Protection Officer (DPO).
The requirement can apply based on factors such as the nature of the organisation's activities and the scale or characteristics of personal data processing.
A DPO may be responsible for:
- Advising the organisation on PDPA obligations
- Monitoring compliance
- Supporting privacy impact assessments
- Advising on data subject rights
- Cooperating with the PDPC
- Providing privacy guidance internally
Organisations should assess their processing activities to determine whether a DPO is required.
International data transfers
Thailand's PDPA regulates the transfer of personal data to other countries.
Organisations transferring personal data outside Thailand should assess:
- Destination country
- Recipient organisation
- Categories of personal data
- Purpose of transfer
- Applicable safeguards
- Adequacy requirements
- Appropriate contractual mechanisms
- Applicable exemptions
The PDPA framework includes rules concerning transfers to countries with adequate data protection standards and mechanisms for certain transfers to destinations that do not meet the applicable standard.
For transfers within corporate groups, Binding Corporate Rules (BCRs) may be relevant where the applicable requirements are satisfied.
Data processors and Data Processing Agreements
Organisations using third-party vendors to process personal data should establish appropriate contractual arrangements.
A Data Processing Agreement (DPA) can define matters such as:
- Processing instructions
- Scope and purpose of processing
- Security requirements
- Confidentiality
- Sub-processors
- Data breach procedures
- Data deletion or return
- Assistance with data subject requests
Thailand's government resources include model documentation and guidance relating to Data Processing Agreements.
Cookies and online tracking
Cookies, pixels, analytics tools, advertising technologies, and other online tracking technologies may involve the collection or use of personal data.
Website operators should therefore assess each technology according to:
- What information it collects
- Whether it identifies or can be linked to an individual
- The purpose of processing
- The applicable legal basis
- Whether third parties receive the data
- Whether data is transferred internationally
For non-essential cookies and tracking technologies where consent is required, organisations should obtain consent before activation.
A compliant implementation should:
- Identify cookies and trackers
- Categorise them by purpose
- Explain their purpose clearly
- Provide appropriate consent choices
- Prevent applicable trackers from firing before consent
- Record the user's consent decision
Data retention
Organisations should not retain personal data indefinitely when it is no longer necessary for the relevant purpose or legal obligation.
A privacy programme should define appropriate retention periods based on:
- Purpose of processing
- Legal obligations
- Contractual requirements
- Security requirements
- Business needs
- Data subject rights
When retention is no longer justified, organisations should securely delete, anonymise, or otherwise dispose of the information in accordance with applicable requirements.
How ConsentX helps with Thailand PDPA compliance
Prior consent capture
Capture consent before applicable non-essential cookies and trackers are activated.
Purpose-based consent
Explain the purposes associated with analytics, advertising, personalisation, and other processing activities.
Sensitive-data consent
Support separate and clearly identifiable consent experiences for sensitive personal data where explicit consent is required.
Cookie and tracker management
Scan websites to identify cookies and trackers and control applicable non-essential technologies.
Consent receipts
Maintain evidence of user choices and relevant information about the consent event.
Data subject request management
Support workflows for access, deletion, rectification, objection, and other applicable rights.
Regional compliance
Use ConsentX's region rule engine to provide a Thailand-specific consent experience for relevant visitors.
Get Thailand PDPA ready with ConsentX
Scan your website → Identify trackers → Map processing purposes → Configure consent → Block applicable trackers → Record consent → Manage privacy requests. Create a transparent and auditable consent experience for users in Thailand.
This page provides a plain-English summary of Thailand's personal data protection framework for general informational purposes and is not legal advice. Organisations should assess their specific processing activities and consult qualified Thai legal counsel where necessary.
How to comply with Thailand PDPA using ConsentX
- 1
Scan your website
Scan your website to identify cookies, pixels, trackers, scripts, and third-party technologies.
- 2
Map processing purposes
Identify what each technology does and determine the applicable legal basis for each processing activity.
- 3
Configure a Thailand-ready consent banner
Where consent is required, create a banner that clearly explains the processing purpose and provides an appropriate choice to the user.
- 4
Block applicable trackers before consent
Prevent applicable non-essential cookies and trackers from activating until the required consent has been obtained.
- 5
Record consent evidence
Store consent choices and relevant contextual information in auditable consent records.
- 6
Manage data subject requests
Centralise requests for access, deletion, rectification, objection, portability, and other applicable rights.
- 7
Monitor your website
Regularly scan for new cookies, trackers, vendors, and scripts that may change your privacy compliance requirements.