PDPA Compliance in Thailand: What Every Business Must Do
0 Views

Who the Act Applies To
The Act applies to the collection, use, or disclosure of personal data by a data controller or data processor located in Thailand, whether the processing itself happens inside or outside the country.
It also has extraterritorial reach. Where the controller or processor is outside Thailand, the Act still applies to processing of data belonging to people in Thailand, where the activity involves offering goods or services to them, whether or not payment is required, or monitoring their behaviour in Thailand.
For an overseas company selling to Thai customers or tracking Thai website visitors, that is a direct compliance obligation, not a theoretical one.
Consent, and Why It Is Not the Answer to Everything
A data controller may not collect, use, or disclose personal data without the data subject's prior consent, unless the Act or another law permits it.
Where consent is used, the requirements are strict. It must be given expressly, in writing or through an electronic system, unless that is not possible by nature. The purpose must be disclosed when consent is requested. The request must be clearly separated from other content, in a form that is easy to access and understand, in plain language, and it must not be deceptive or misleading.
There is also an anti-bundling rule. In entering a contract, including the provision of any service, consent must not be made a condition where the data is not necessary or related to that contract or service. A business cannot require customers to accept marketing as the price of buying something.
Consent may be withdrawn at any time, and withdrawal must be as easy as giving it. Where withdrawal affects the data subject, the controller must inform them of the consequences. Consent obtained in breach of these rules does not bind the data subject and does not entitle the controller to process the data.
The practical implication is that consent is often the weakest basis to rely on, because it can be withdrawn. Where processing is genuinely necessary, for example to perform a contract, comply with a legal obligation, or pursue a legitimate interest, the Act's other lawful bases are usually more stable, and using them correctly is a large part of good compliance design.
The Purpose Limitation Rule
A controller must collect, use, or disclose personal data only for the purposes notified to the data subject before or at the time of collection. Processing for a different purpose is prohibited unless the new purpose has been notified and consent obtained beforehand, or another law permits it.
This is where many businesses fail. Data collected for one purpose, such as fulfilling a booking, is later used for another, such as a marketing campaign, without any further notification. That is a breach even though the data was lawfully collected in the first place.
Collecting Data from Third Parties
Collecting personal data from a source other than the data subject is prohibited, subject to exceptions. The main route is to notify the data subject of the collection without delay, and in any event within thirty days, and to obtain consent, unless the processing falls within an exemption from consent under the Act.
Where the notification route applies, the controller must inform the data subject within thirty days of collection. If the data is to be used to contact the data subject, notification must be given at the first contact, and if it is to be disclosed, notification must be given before the first disclosure.
This provision applies squarely to purchased marketing lists, data received from business partners, and background information gathered on customers or candidates.
Sensitive Data Requires Explicit Consent
A separate and stricter regime governs sensitive personal data. The Act prohibits collecting personal data concerning racial or ethnic origin, political opinions, cult, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade union information, genetic data, biometric data, or other similar data as the Committee may prescribe, without the explicit consent of the data subject.
Biometric data is expressly defined to include facial recognition data, iris recognition data, and fingerprint recognition data. Any business using fingerprint or facial recognition for staff attendance or building access is processing sensitive data and needs explicit consent or another applicable exemption.
There are limited exceptions, including preventing danger to life where consent cannot be given, data made public with explicit consent, necessity for legal claims, and various obligations relating to healthcare, employment protection, social security, scientific or statistical research, and substantial public interest, each subject to appropriate safeguards. Criminal record data may only be collected under the control of a competent authority or with prescribed safeguards.
The Controller's Core Duties
The Act imposes four practical duties that define what compliance looks like day to day.
The first is security. A controller must implement appropriate security measures to prevent loss, unauthorised or unlawful access, use, alteration, correction, or disclosure, and must review those measures when necessary or when technology changes, meeting the minimum standards prescribed by the Committee.
The second concerns third parties. Where personal data must be provided to any person or entity other than the controller, the controller must take steps to prevent that recipient from using or disclosing the data unlawfully or without authority. In practice this means written data processing agreements with vendors, cloud providers, payroll firms, and agencies.
The third is deletion. A controller must maintain a review system for deleting or destroying personal data when the retention period expires, when the data is irrelevant or beyond the purpose of collection, when the data subject requests it, or when consent is withdrawn, subject to specific exemptions such as freedom of expression and the establishment or defence of legal claims. A retention schedule is not optional.
The fourth is breach notification, and it carries the tightest deadline in the Act.
The Seventy-Two Hour Breach Rule
A controller must notify the Office of a personal data breach without delay and, where feasible, within seventy-two hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
Where the breach involves a high risk to those rights and freedoms, the controller must also notify the affected data subjects without delay, together with the remedial measures.
Seventy-two hours is short, and it runs from awareness, not from the completion of an internal investigation. Businesses that have not decided in advance who assesses a suspected breach, and who signs off the notification, do not meet this deadline. A written incident response procedure is the single most valuable document a business can prepare here.
One further duty applies to foreign businesses. A controller falling under the extraterritorial provision must appoint a representative in writing, and that representative must be in Thailand and authorised to act on the controller's behalf without any limitation of liability relating to the processing.
Penalties
The Act provides for administrative fines, civil liability, and in some cases criminal penalties.
Administrative fines of up to three million baht apply to a range of controller breaches, including processing outside the notified purpose, failures relating to collection from third parties, non-compliance with the core duties including security and breach notification, obtaining consent by deception or in a way that misleads the data subject as to the purpose, and unlawful cross-border transfers.
There is also a criminal offence for a person who learns personal data of another through performing duties under the Act and discloses it to another person, punishable by imprisonment of up to six months, a fine of up to five hundred thousand baht, or both, subject to defined exceptions including disclosure under a duty, for investigation or court proceedings, to authorised state agencies, with the data subject's specific written consent, or where the data relates to litigation already disclosed publicly.
Data subjects may also pursue compensation for damage suffered, so the exposure is not limited to regulatory fines.
What Practical Compliance Looks Like
Start by mapping what personal data you actually hold, where it came from, why you have it, who you share it with, and how long you keep it. Most businesses discover they hold considerably more than they thought.
Then identify a lawful basis for each processing activity rather than defaulting to consent for everything. Publish a privacy notice that reflects reality rather than a template. Put written agreements in place with every vendor that touches personal data. Set retention periods and build a mechanism that actually deletes data when they expire. Prepare a procedure for handling data subject requests and a separate one for breaches, with named responsible people and the seventy-two hour clock built in. Train the staff who handle customer and employee data, since most breaches are operational rather than technical. And review consent forms for the separation, plain language, and anti-bundling requirements.
Frequently Asked Questions
Does the PDPA apply to my small business?
Almost certainly. If you hold customer or employee personal data, you are a data controller. The Act does not exempt businesses by size.
My company is registered overseas. Am I covered?
You may well be. The Act applies to controllers and processors outside Thailand who offer goods or services to people in Thailand or monitor their behaviour here, and such controllers must appoint a representative in Thailand.
Do I need consent for everything?
No, and relying on consent for everything is usually a mistake because it can be withdrawn. The Act provides other lawful bases, and the correct approach is to identify the right basis for each activity.
We use fingerprint scanners for staff attendance. Is that a problem?
Biometric data is sensitive personal data, which requires explicit consent unless a specific exemption applies, so this needs to be documented properly.
How quickly must we report a data breach?
Notify the Office without delay and where feasible within seventy-two hours of becoming aware, and notify affected individuals as well where the breach carries a high risk to their rights and freedoms.
Speak to a Thai Data Protection Lawyer
PDPA compliance is not a document exercise. It is a set of operational commitments with short deadlines and real financial exposure. Our bilingual lawyers conduct data audits, draft privacy notices, consent forms, and data processing agreements, prepare breach response procedures, advise on cross-border transfers, and act for businesses facing complaints or investigations. Contact us before a breach, not after one.
Disclaimer
This article provides general legal information only and does not constitute legal advice. Obligations under the Personal Data Protection Act depend on the nature of the data and the activities of each business. Please consult a licensed Thai attorney before acting.
The Act applies to the collection, use, or disclosure of personal data by a data controller or data processor located in Thailand, whether the processing itself happens inside or outside the country.
It also has extraterritorial reach. Where the controller or processor is outside Thailand, the Act still applies to processing of data belonging to people in Thailand, where the activity involves offering goods or services to them, whether or not payment is required, or monitoring their behaviour in Thailand.
For an overseas company selling to Thai customers or tracking Thai website visitors, that is a direct compliance obligation, not a theoretical one.
Consent, and Why It Is Not the Answer to Everything
A data controller may not collect, use, or disclose personal data without the data subject's prior consent, unless the Act or another law permits it.
Where consent is used, the requirements are strict. It must be given expressly, in writing or through an electronic system, unless that is not possible by nature. The purpose must be disclosed when consent is requested. The request must be clearly separated from other content, in a form that is easy to access and understand, in plain language, and it must not be deceptive or misleading.
There is also an anti-bundling rule. In entering a contract, including the provision of any service, consent must not be made a condition where the data is not necessary or related to that contract or service. A business cannot require customers to accept marketing as the price of buying something.
Consent may be withdrawn at any time, and withdrawal must be as easy as giving it. Where withdrawal affects the data subject, the controller must inform them of the consequences. Consent obtained in breach of these rules does not bind the data subject and does not entitle the controller to process the data.
The practical implication is that consent is often the weakest basis to rely on, because it can be withdrawn. Where processing is genuinely necessary, for example to perform a contract, comply with a legal obligation, or pursue a legitimate interest, the Act's other lawful bases are usually more stable, and using them correctly is a large part of good compliance design.
The Purpose Limitation Rule
A controller must collect, use, or disclose personal data only for the purposes notified to the data subject before or at the time of collection. Processing for a different purpose is prohibited unless the new purpose has been notified and consent obtained beforehand, or another law permits it.
This is where many businesses fail. Data collected for one purpose, such as fulfilling a booking, is later used for another, such as a marketing campaign, without any further notification. That is a breach even though the data was lawfully collected in the first place.
Collecting Data from Third Parties
Collecting personal data from a source other than the data subject is prohibited, subject to exceptions. The main route is to notify the data subject of the collection without delay, and in any event within thirty days, and to obtain consent, unless the processing falls within an exemption from consent under the Act.
Where the notification route applies, the controller must inform the data subject within thirty days of collection. If the data is to be used to contact the data subject, notification must be given at the first contact, and if it is to be disclosed, notification must be given before the first disclosure.
This provision applies squarely to purchased marketing lists, data received from business partners, and background information gathered on customers or candidates.
Sensitive Data Requires Explicit Consent
A separate and stricter regime governs sensitive personal data. The Act prohibits collecting personal data concerning racial or ethnic origin, political opinions, cult, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade union information, genetic data, biometric data, or other similar data as the Committee may prescribe, without the explicit consent of the data subject.
Biometric data is expressly defined to include facial recognition data, iris recognition data, and fingerprint recognition data. Any business using fingerprint or facial recognition for staff attendance or building access is processing sensitive data and needs explicit consent or another applicable exemption.
There are limited exceptions, including preventing danger to life where consent cannot be given, data made public with explicit consent, necessity for legal claims, and various obligations relating to healthcare, employment protection, social security, scientific or statistical research, and substantial public interest, each subject to appropriate safeguards. Criminal record data may only be collected under the control of a competent authority or with prescribed safeguards.
The Controller's Core Duties
The Act imposes four practical duties that define what compliance looks like day to day.
The first is security. A controller must implement appropriate security measures to prevent loss, unauthorised or unlawful access, use, alteration, correction, or disclosure, and must review those measures when necessary or when technology changes, meeting the minimum standards prescribed by the Committee.
The second concerns third parties. Where personal data must be provided to any person or entity other than the controller, the controller must take steps to prevent that recipient from using or disclosing the data unlawfully or without authority. In practice this means written data processing agreements with vendors, cloud providers, payroll firms, and agencies.
The third is deletion. A controller must maintain a review system for deleting or destroying personal data when the retention period expires, when the data is irrelevant or beyond the purpose of collection, when the data subject requests it, or when consent is withdrawn, subject to specific exemptions such as freedom of expression and the establishment or defence of legal claims. A retention schedule is not optional.
The fourth is breach notification, and it carries the tightest deadline in the Act.
The Seventy-Two Hour Breach Rule
A controller must notify the Office of a personal data breach without delay and, where feasible, within seventy-two hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
Where the breach involves a high risk to those rights and freedoms, the controller must also notify the affected data subjects without delay, together with the remedial measures.
Seventy-two hours is short, and it runs from awareness, not from the completion of an internal investigation. Businesses that have not decided in advance who assesses a suspected breach, and who signs off the notification, do not meet this deadline. A written incident response procedure is the single most valuable document a business can prepare here.
One further duty applies to foreign businesses. A controller falling under the extraterritorial provision must appoint a representative in writing, and that representative must be in Thailand and authorised to act on the controller's behalf without any limitation of liability relating to the processing.
Penalties
The Act provides for administrative fines, civil liability, and in some cases criminal penalties.
Administrative fines of up to three million baht apply to a range of controller breaches, including processing outside the notified purpose, failures relating to collection from third parties, non-compliance with the core duties including security and breach notification, obtaining consent by deception or in a way that misleads the data subject as to the purpose, and unlawful cross-border transfers.
There is also a criminal offence for a person who learns personal data of another through performing duties under the Act and discloses it to another person, punishable by imprisonment of up to six months, a fine of up to five hundred thousand baht, or both, subject to defined exceptions including disclosure under a duty, for investigation or court proceedings, to authorised state agencies, with the data subject's specific written consent, or where the data relates to litigation already disclosed publicly.
Data subjects may also pursue compensation for damage suffered, so the exposure is not limited to regulatory fines.
What Practical Compliance Looks Like
Start by mapping what personal data you actually hold, where it came from, why you have it, who you share it with, and how long you keep it. Most businesses discover they hold considerably more than they thought.
Then identify a lawful basis for each processing activity rather than defaulting to consent for everything. Publish a privacy notice that reflects reality rather than a template. Put written agreements in place with every vendor that touches personal data. Set retention periods and build a mechanism that actually deletes data when they expire. Prepare a procedure for handling data subject requests and a separate one for breaches, with named responsible people and the seventy-two hour clock built in. Train the staff who handle customer and employee data, since most breaches are operational rather than technical. And review consent forms for the separation, plain language, and anti-bundling requirements.
Frequently Asked Questions
Does the PDPA apply to my small business?
Almost certainly. If you hold customer or employee personal data, you are a data controller. The Act does not exempt businesses by size.
My company is registered overseas. Am I covered?
You may well be. The Act applies to controllers and processors outside Thailand who offer goods or services to people in Thailand or monitor their behaviour here, and such controllers must appoint a representative in Thailand.
Do I need consent for everything?
No, and relying on consent for everything is usually a mistake because it can be withdrawn. The Act provides other lawful bases, and the correct approach is to identify the right basis for each activity.
We use fingerprint scanners for staff attendance. Is that a problem?
Biometric data is sensitive personal data, which requires explicit consent unless a specific exemption applies, so this needs to be documented properly.
How quickly must we report a data breach?
Notify the Office without delay and where feasible within seventy-two hours of becoming aware, and notify affected individuals as well where the breach carries a high risk to their rights and freedoms.
Speak to a Thai Data Protection Lawyer
PDPA compliance is not a document exercise. It is a set of operational commitments with short deadlines and real financial exposure. Our bilingual lawyers conduct data audits, draft privacy notices, consent forms, and data processing agreements, prepare breach response procedures, advise on cross-border transfers, and act for businesses facing complaints or investigations. Contact us before a breach, not after one.
Disclaimer
This article provides general legal information only and does not constitute legal advice. Obligations under the Personal Data Protection Act depend on the nature of the data and the activities of each business. Please consult a licensed Thai attorney before acting.
Related Content
Building a house or villa in Thailand goes wrong more often than most owners expect. The contractor stops showing up. The pool leaks within a year. The finish bears no resemblance to the specification. Thai law gives an employer real remedies against a contractor, including the right to have defective work put right at the contractor's cost, a reduction of the price, and compensation for defects. But it also contains traps that quietly destroy strong claims: terminating too quickly, accepting the work without objection, and a limitation period measured in a single year from the day a defect appears. This guide explains what a contractor owes, how long they remain liable, and what an owner must do to preserve a claim.
17 Aug 2026
Winning a case in Thailand and actually getting paid are two different things. Many creditors discover this the hard way: they obtain a judgment, assume the money will follow, and then find years later that the debtor has moved assets, or worse, that the right to enforce has expired altogether. Thai law gives creditors real teeth, including seizure of property, attachment of bank accounts and salary, and bankruptcy proceedings. But it also regulates how debts may be demanded in the first place, and it imposes a hard deadline on enforcement. This guide explains how debt collection in Thailand works from the first demand letter through to seizure and sale, and the traps that cost creditors their money.
22 Jul 2026
When a marriage ends, nothing matters more than what happens to the children, and this is the area where Thai law departs most sharply from what foreign parents expect. Thailand does not use the language of joint and sole custody. Instead it works with parental power, a defined bundle of legal rights over a child, and it asks a single question when deciding who should hold it: what serves the welfare and interests of the child. This guide explains how parental power is allocated on divorce, how it can later be changed, the right of contact that survives regardless of who holds it, how child support is fixed, and the special position of children born outside marriage.
1 Aug 2026


