{
 "jurisdiction_id": "TH",
 "jurisdiction": "Thailand",
 "url": "https://dataprotection.gi/jurisdictions/thailand/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 48,
  "sub_modules": 57,
  "source_register": 13
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/thailand/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive omnibus statute fully in force since 1 June 2022 with an operational regulator (PDPC) and multiple sub-legislative instruments issued.",
   "claims": [
    {
     "statement": "The Personal Data Protection Committee (PDPC) is tasked with advisory and enforcement powers under the PDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/thailand",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA came into full effect on 1 June 2022, following two prior enforcement suspensions, as Thailand's first comprehensive private-sector data protection law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/thailand",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Four secondary laws accompany the PDPA covering appropriate security measures, ROPA criteria, an SME ROPA exemption, and criteria for administrative fines and orders, effective between June and December 2022.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/thailand",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA excludes from its scope public authorities whose duties concern state security, including financial security, public safety, money-laundering prevention/suppression, forensic science, or cybersecurity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_updated.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA provides exceptions for legislative bodies and credit bureau companies, which remain governed by pre-existing sectoral regulation alongside the PDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_v2_updated.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA mirrors GDPR's extraterritorial applicability, applying to controllers and processors outside Thailand that process personal data of data subjects in Thailand or offer goods/services to, or monitor the behaviour of, such data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_v2_updated.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In lieu of a general registration/filing regime, PDPA controllers and processors must prepare and maintain Records of Processing Activities (ROPA) that must be readily accessible and promptly presented to the Office of the PDPC on request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/thailand/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Lawful-basis and consent architecture is materially GDPR-aligned and in force; primary-text confirmation of the full Section 26 sensitive-category list was not independently retrieved, warranting amber shading on the special_categories sub-module.",
   "claims": [
    {
     "statement": "The PDPA lists consent, performance of a contract, compliance with a legal obligation, legitimate interests, and vital interests as lawful bases for processing personal data, paralleling GDPR Article 6.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_updated.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Research and statistics are recognised as an independent lawful basis for processing personal data under the PDPA, a position that diverges from the GDPR's approach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/harmonizing-research-and-privacy-in-thailand-unpacking-pdpa-notification-on-personal-data-collection-for-research-statistics",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A data subject may withdraw consent at any time under the PDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Royal Thai Government Gazette",
     "source_url": "https://www.dataguidance.com/sites/default/files/entranslation_of_the_personal_data_protection_act_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA prohibits collection of certain sensitive categories of data without explicit consent, save where processing is for scientific, historical or statistical purposes and suitable safeguards are adopted.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_v2_updated.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Processing of sensitive personal data for research purposes attracts the same PDPA obligations as ordinary data but may be subject to a more stringent, risk-based approach for high-risk data, including a requirement to establish an ethics committee.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/harmonizing-research-and-privacy-in-thailand-unpacking-pdpa-notification-on-personal-data-collection-for-research-statistics",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Unlike the GDPR, the PDPA does not define 'anonymised' or 'pseudonymised' data, notwithstanding that it grants data subjects a right to request anonymisation of their personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_updated.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/thailand/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core rights (access, erasure, objection, portability, information) are confirmed and in force, but exact statutory response-deadline figures could not be independently verified from primary sources searched, warranting a gap flag on deadlines_and_response_windows.",
   "claims": [
    {
     "statement": "The PDPA empowers data subjects with rights including the right to access, mirroring the GDPR's Article 15 access right.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_v2_updated.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA allows data subjects to request deletion of their personal data unless exceptions apply, though the scope, exemptions, request forms and response timelines for the erasure right differ from the GDPR's equivalent provision.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_jan_2024_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA provides data subjects a right to object to processing, subject to a carve-out where processing is in the public interest.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_v2_updated.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA grants data subjects a right to data portability analogous to the GDPR's Article 20.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_updated.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/thailand/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Security, breach-notification and ROPA duties are well-documented, in force, and PDPC-enforced; DPIA-equivalent and DPO-trigger detail plus joint-controller and retention specifics carry residual gaps.",
   "claims": [
    {
     "statement": "Although the PDPA does not explicitly mandate DPIAs as under GDPR Article 35, it requires data controllers to implement appropriate security measures and review them periodically when necessary or when technology changes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_jan_2024_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under PDPA Section 41, data controllers and processors must designate a data protection officer where they are a public authority or otherwise meet statutory large-scale/special-category processing triggers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Royal Thai Government Gazette",
     "source_url": "https://www.dataguidance.com/sites/default/files/entranslation_of_the_personal_data_protection_act_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In the PDPC's first administrative enforcement decision, a company was found to have breached the DPO-appointment obligation, having failed to designate a DPO despite processing personal data of over 100,000 individuals as a core business activity.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/first-fine-imposed-under-thailand-s-personal-data-protection-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data processors must prepare and maintain Records of Processing Activities that are readily accessible and must be promptly presented to the Office of the PDPC or data controllers on request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Small and medium-sized enterprises, community/social enterprises, cooperatives, foundations, associations, religious and nonprofit organisations are exempted from the ROPA requirement, except where a data-subject request or objection is rejected.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPC's security-measures notice requires organisational and technical measures ensuring ongoing confidentiality, integrity and availability of personal data, including access control and user-access management, with periodic review obligations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data controllers must notify the PDPC of a personal data breach without undue delay and, when feasible, within 72 hours of becoming aware of it, unless the breach poses no risk to individuals' rights and freedoms.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/thailand-s-pdpc-clarifies-data-breach-notification-requirements",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where a breach carries a high risk to individuals' rights and freedoms, controllers must also notify affected data subjects, per the PDPC's Criteria and Procedures for Handling Personal Data Breaches, effective 15 December 2022.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "If a breach cannot be reported within the 72-hour window, the data controller may request an exemption from penalties, provided the request is submitted no later than 15 days after becoming aware of the breach, accompanied by valid reasons for the delay.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/thailand/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms (adequacy-style assessment, BCRs, appropriate safeguards) are well-documented and in force, but no confirmed bilateral adequacy determinations (granted or received) were located, and localisation-mandate status is unconfirmed.",
   "claims": [
    {
     "statement": "Section 28 of the PDPA requires that cross-border transfers of personal data be made to a destination country or international organisation with adequate data protection standards, subject to exceptions such as legal compliance, informed consent, or contractual necessity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In December 2023 the PDPC issued Criteria on the Protection of Personal Data Sent or Transferred Abroad pursuant to Section 28, clarifying that 'sending or transferring personal data' excludes data transit through intermediaries such as cloud computing services.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPC issued rules on intragroup transfers under Section 29, exempting Section 28 obligations for transfers within a group of undertakings that follow PDPC-approved binding corporate rules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPC's notification on appropriate safeguards recognises standard data protection clauses, certification, or legally binding agreements between Thai and foreign entities as valid transfer mechanisms absent an adequacy determination or approved BCRs.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPC issued updated regulations on binding corporate rules for data protection within corporate groups, effective 17 February 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/thailand",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPC's adequacy criteria assess a destination country's data-protection measures/legal mechanisms and enforcement capacity for consistency with the PDPA, functioning as a transfer-impact-assessment-style test, though the PDPA does not itemise 'adequate data protection standards' in detail.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/thailand/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial-sector (BoT/FIBA) and credit-bureau overlays are well-evidenced and in force; health, telecoms, employment, education and insurance sub-modules lack confirmed PDPA-specific sectoral sub-legislation.",
   "claims": [
    {
     "statement": "The Bank of Thailand requires financial institutions to follow specific data-protection procedures and standards under the Financial Institutions Business Act B.E. 2551 (FIBA), independently of the PDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/thailand-data-protection-financial-sector",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In August 2021, the Bank of Thailand issued an official letter directing banks and financial institutions to prepare for PDPA compliance ahead of the (then) statutory enforcement date.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/thailand-bot-issues-preparation-compliance-letter-pdpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA provides specific exceptions for credit bureau companies, which were subject to sector-specific National Credit Bureau regulation prior to the PDPA and must continue to comply with existing sectoral rules alongside the PDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/thailand",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/thailand/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Direct-marketing multi-regulator overlay is documented and in force; cookie/tracker consent specifics, dark-pattern rules, opt-out signal recognition, clean-room rules, and cross-context-advertising frameworks are unconfirmed gaps.",
   "claims": [
    {
     "statement": "Direct-marketing activities in Thailand are jointly regulated by the Office of the Consumer Protection Board under the Consumer Protection Act, the Office of the PDPC under the PDPA, and other authorities under the Direct Sale and Direct Marketing Act and the Computer-Related Crime Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/thailand-emarketing",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/thailand/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "State-surveillance carve-out is confirmed and in force; AI governance is presently non-binding soft law/consultation-stage, and profiling/ADM-transparency, biometric, and genetic sub-modules lack dedicated PDPA provisions confirmed in this pass.",
   "claims": [
    {
     "statement": "The PDPA excludes from its scope public authorities whose duties concern state security, including financial security, public safety, money-laundering prevention/suppression, forensic science, or cybersecurity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_updated.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Thailand's Electronic Transactions Development Agency (ETDA) has launched a public consultation on draft AI-data-protection guidelines intended to balance innovation with privacy rights and ensure PDPA compliance, reflecting a soft-law rather than binding-statute approach to AI governance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/thailand",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Bank of Thailand has sought public input on AI guidelines for financial services, focusing on risk management and transparency, as a non-binding sector-specific complement to PDPA obligations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/thailand",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/thailand/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Minors' consent-capacity rule is confirmed and in force, but it is a civil-law-referential mechanism rather than a fixed statutory age threshold, and age-verification, minor-profiling-ban, education-setting, and dependent-adults sub-modules lack independently confirmed PDPA provisions.",
   "claims": [
    {
     "statement": "The PDPA provides that minors who are not sui juris by marriage, or who otherwise lack capacity as a sui juris person under the Civil and Commercial Code, require consent to processing of their personal data to be given on their behalf, rather than applying a fixed statutory age threshold as under GDPR Article 8.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_v2_updated.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/thailand/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "The PDPC is demonstrably active (first fine issued 2024, ongoing sub-regulation issuance into 2026) with clear administrative and criminal penalty structures in force; funding/capacity transparency and a distinct private-right-of-action mechanism remain unconfirmed gaps.",
   "claims": [
    {
     "statement": "The PDPC's Expert Committee is authorised to consider complaints, investigate, and impose administrative fines and other punitive measures for PDPA violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PDPA violations may, in addition to administrative and monetary penalties, result in criminal imprisonment for a term not exceeding one year for certain offences.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_thailand_updated.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Pre-enforcement legal commentary indicated PDPA administrative fines could reach up to THB 5,000,000 (approximately EUR 141,000) per violation under the Administrative Fines Law, though the PDPC's first enforcement decision (THB 7 million) suggests fines may be aggregated across multiple concurrent violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/resource/thailands-personal-data-protection-act-pdpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In setting administrative fines, the Expert Committee considers factors including offence severity, the size of the controller/processor's business, benefits derived and harm caused, wider implications for related industries, the offender's level of responsibility, and remedial or mitigating action taken.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/key-developments-in-thailands-pdpa-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 31 July 2024, the PDPC's Expert Committee issued its first administrative fine under the PDPA — a THB 7 million penalty against an online-retail company for failing to appoint a DPO, mishandling customer breach complaints, and enabling continued misuse of personal data by scammers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/first-fine-imposed-under-thailand-s-personal-data-protection-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PDPA noncompliance may, according to professional legal commentary, give rise to class-action exposure in addition to administrative fines, though a dedicated statutory collective-redress mechanism was not independently itemised from primary text in this pass.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/resource/thailands-personal-data-protection-act-pdpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPC issued updated regulations on binding corporate rules for data protection within corporate groups, effective 17 February 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/thailand",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In a 2026 clarification issued in response to a company-led public consultation, the PDPC confirmed that data controllers are exempt from notifying it of a breach where the event poses no risk to individuals' rights and freedoms, and detailed the Section 12 risk-evaluation criteria underpinning that exemption.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals (IAPP)",
     "source_url": "https://iapp.org/news/a/thailand-s-pdpc-clarifies-data-breach-notification-requirements",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}