#
Comprehensive omnibus statute fully in force since 1 June 2022 with an operational regulator (PDPC) and multiple sub-legislative instruments issued.
Sub-modules (5)
Regulator And AuthorityGreen
The PDPC (Committee) and its Office hold advisory and enforcement authority, with an Expert Committee empowered to investigate and sanction violations.
Claims: CLM-TH-3f9a1c02
Act And InstrumentsGreen
PDPA plus four sub-legislative instruments (security measures, ROPA criteria, SME ROPA exemption, administrative fines criteria) and multiple Royal Decrees form the instrument set.
Claims: CLM-TH-7b2e4d81, CLM-TH-9c1f6a55
Material ScopeAmber
Material scope excludes designated state-security-related public authorities and provides sector carve-outs for legislative bodies and credit bureaus.
Claims: CLM-TH-1a8d2b3e, CLM-TH-6e4c9f10
Territorial ScopeGreen
Extraterritorial application mirrors GDPR Art.3 style targeting/monitoring tests.
Claims: CLM-TH-b3d7a209
Regulator Registration And FilingAmber
No general controller registration/filing regime was identified; obligations instead run through mandatory Records of Processing Activities (ROPA) accessible to the PDPC on request, subject to an SME exemption. Searches run: 'Thailand PDPA registration filing controller', 'Thailand PDPC register of controllers' — no dedicated registration portal or filing mandate located distinct from ROPA-keeping duties.
Claims: CLM-TH-e21f5c88
No periodic updates recorded against this sub-brief.
Sources and claims (7)
- ConfirmedOneTrust DataGuidance — The Personal Data Protection Committee (PDPC) is tasked with advisory and enforcement powers under the PDPA.
- ConfirmedOneTrust DataGuidance — The PDPA came into full effect on 1 June 2022, following two prior enforcement suspensions, as Thailand's first comprehensive private-sector data protection law.
- ConfirmedOneTrust DataGuidance — Four secondary laws accompany the PDPA covering appropriate security measures, ROPA criteria, an SME ROPA exemption, and criteria for administrative fines and orders, effective between June and December 2022.
- ConfirmedOneTrust DataGuidance — The PDPA excludes from its scope public authorities whose duties concern state security, including financial security, public safety, money-laundering prevention/suppression, forensic science, or cybersecurity.
- ConfirmedOneTrust DataGuidance — The PDPA provides exceptions for legislative bodies and credit bureau companies, which remain governed by pre-existing sectoral regulation alongside the PDPA.
- ConfirmedOneTrust DataGuidance — The PDPA mirrors GDPR's extraterritorial applicability, applying to controllers and processors outside Thailand that process personal data of data subjects in Thailand or offer goods/services to, or monitor the behaviour of, such data subjects.
- ConfirmedInternational Association of Privacy Professionals (IAPP) — In lieu of a general registration/filing regime, PDPA controllers and processors must prepare and maintain Records of Processing Activities (ROPA) that must be readily accessible and promptly presented to the Office of the PDPC on request.