🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
TH · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

Thailand

TH schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 48 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
48Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Lead Signal

Thailand's Personal Data Protection Committee has corrected the recorded date of its first PDPA administrative-fine decision, moving it from an earlier reported 31 July 2024 to 21 August 2024 following cross-referencing of secondary legal sources. The decision imposed a THB 7 million penalty on an online-retail company for failing to appoint a data protection officer, mishandling breach complaints, and enabling continued misuse of personal data by scammers. The correction sits alongside continued PDPC sub-regulatory activity in 2026: updated binding corporate rules regulations took effect 17 February 2026, and a 28 May 2026 clarification confirmed that controllers need not notify the PDPC of breaches posing no risk to individuals' rights and freedoms.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus statute fully in force since 1 June 2022 with an operational regulator (PDPC) and multiple sub-legislative instruments issued.

Primary frameworkPersonal Data Protection Act B.E. 2562 (2019) (PDPA)
Supervisory authorityOffice of the Personal Data Protection Committee (PDPC)
Traffic-light rationale — GreenComprehensive omnibus statute fully in force since 1 June 2022 with an operational regulator (PDPC) and multiple sub-legislative instruments issued.

Sub-modules (5)

Regulator And AuthorityGreen

The PDPC (Committee) and its Office hold advisory and enforcement authority, with an Expert Committee empowered to investigate and sanction violations.

Claims: CLM-TH-3f9a1c02

Act And InstrumentsGreen

PDPA plus four sub-legislative instruments (security measures, ROPA criteria, SME ROPA exemption, administrative fines criteria) and multiple Royal Decrees form the instrument set.

Claims: CLM-TH-7b2e4d81, CLM-TH-9c1f6a55

Material ScopeAmber

Material scope excludes designated state-security-related public authorities and provides sector carve-outs for legislative bodies and credit bureaus.

Claims: CLM-TH-1a8d2b3e, CLM-TH-6e4c9f10

Territorial ScopeGreen

Extraterritorial application mirrors GDPR Art.3 style targeting/monitoring tests.

Claims: CLM-TH-b3d7a209

Regulator Registration And FilingAmber

No general controller registration/filing regime was identified; obligations instead run through mandatory Records of Processing Activities (ROPA) accessible to the PDPC on request, subject to an SME exemption. Searches run: 'Thailand PDPA registration filing controller', 'Thailand PDPC register of controllers' — no dedicated registration portal or filing mandate located distinct from ROPA-keeping duties.

Claims: CLM-TH-e21f5c88

Category narrative211 words

Thailand's data-protection regime is anchored in the Personal Data Protection Act B.E. 2562 (2019) (PDPA), a GDPR-influenced omnibus statute. <cite index="2-1,2-2">The Personal Data Protection Act 2019 (PDPA) came into full effect as of June 1, 2022, following two enforcement suspensions, and is Thailand's first comprehensive law covering private sector entities.</cite> <cite index="61-1">The Personal Data Protection Committee (PDPC) is tasked with advisory and enforcement powers under the PDPA.</cite> <cite index="2-4,2-5">Four secondary laws accompany the PDPA covering security measures, ROPA criteria, an SME ROPA exemption, and administrative fines criteria, which became effective between June and December 2022.</cite> Material scope carves out certain public bodies and sectors: <cite index="5-20">the PDPA excludes public authorities that maintain state security from its scope, including financial security, security of the state or public safety, including duties respecting prevention and suppression of money laundering, forensic science or cybersecurity.</cite> <cite index="3-26">The PDPA also provides exceptions for legislative bodies and credit bureau companies.</cite> Territorial reach is broad: <cite index="3-14">the PDPA mirrors the GDPR's extraterritorial applicability and applies to controllers and processors outside of Thailand if they process personal data of data subjects in Thailand or offer goods and services to, or monitor behaviour of, the data subjects.</cite> There is no general registration/filing regime; instead controllers/processors maintain accessible Records of Processing Activities.

No periodic updates recorded against this sub-brief.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidanceThe Personal Data Protection Committee (PDPC) is tasked with advisory and enforcement powers under the PDPA.
  2. ConfirmedOneTrust DataGuidanceThe PDPA came into full effect on 1 June 2022, following two prior enforcement suspensions, as Thailand's first comprehensive private-sector data protection law.
  3. ConfirmedOneTrust DataGuidanceFour secondary laws accompany the PDPA covering appropriate security measures, ROPA criteria, an SME ROPA exemption, and criteria for administrative fines and orders, effective between June and December 2022.
  4. ConfirmedOneTrust DataGuidanceThe PDPA excludes from its scope public authorities whose duties concern state security, including financial security, public safety, money-laundering prevention/suppression, forensic science, or cybersecurity.
  5. ConfirmedOneTrust DataGuidanceThe PDPA provides exceptions for legislative bodies and credit bureau companies, which remain governed by pre-existing sectoral regulation alongside the PDPA.
  6. ConfirmedOneTrust DataGuidanceThe PDPA mirrors GDPR's extraterritorial applicability, applying to controllers and processors outside Thailand that process personal data of data subjects in Thailand or offer goods/services to, or monitor the behaviour of, such data subjects.
  7. ConfirmedInternational Association of Privacy Professionals (IAPP)In lieu of a general registration/filing regime, PDPA controllers and processors must prepare and maintain Records of Processing Activities (ROPA) that must be readily accessible and promptly presented to the Office of the PDPC on request.

#

Lawful-basis and consent architecture is materially GDPR-aligned and in force; primary-text confirmation of the full Section 26 sensitive-category list was not independently retrieved, warranting amber shading on the special_categories sub-module.

Primary frameworkPersonal Data Protection Act B.E. 2562 (2019), Chapter 2 (Sections 19-27)
Supervisory authorityOffice of the Personal Data Protection Committee (PDPC)
Traffic-light rationale — GreenLawful-basis and consent architecture is materially GDPR-aligned and in force; primary-text confirmation of the full Section 26 sensitive-category list was not independently retrieved, warranting amber shading on the special_categories sub-module.

Sub-modules (4)

Lawful BasesGreen

Consent, contract, legal obligation, legitimate interest, vital interest, and a distinctive research/statistics basis are recognised.

Claims: CLM-TH-44a9d1c6, CLM-TH-0d7b3e92

Special CategoriesAmber

A consent-plus regime applies to sensitive categories, with narrow statutory derogations for scientific/historical/statistical processing and heightened, risk-based obligations including ethics-committee review for research use of sensitive data.

Claims: CLM-TH-a17e9b30, CLM-TH-d64f2c88

Pseudonymisation And AnonymisationAmber

The PDPA grants a right to request anonymisation but, unlike the GDPR, does not statutorily define 'anonymised' or 'pseudonymised' data.

Claims: CLM-TH-2b9a7e15

Category narrative212 words

The PDPA's Chapter 2 provisions parallel GDPR Articles 6, 7 and 9. <cite index="5-9">Both texts have similar provisions regarding the legal basis of processing, as both list consent, performance of a contract, legal obligations, legitimate interests, or vital interests as a legal basis.</cite> Notably, <cite index="96-6,96-7">research and statistics are recognized as a lawful basis for processing personal data under the PDPA, contrasting with the EU GDPR, under which research and statistics necessitate separate lawful bases.</cite> On consent, <cite index="4-16">the data subject may withdraw his or her consent at any time.</cite> Special/sensitive categories are protected by a consent-plus model: <cite index="94-4">the PDPA outlines that any collection of certain types of data is prohibited without explicit consent except where it is for scientific, historical, or statistical purposes and suitable measures have been taken to protect the fundamental rights of the data subjects.</cite> <cite index="96-1,96-2">In the case of sensitive personal data, the same obligations apply but may be more stringent based on a risk-based approach for high-risk personal data, and the data controller must establish an ethics committee to review and approve related research.</cite> On anonymisation, <cite index="5-14">although the PDPA states that a data subject has the right to anonymise their personal data, unlike the GDPR, the PDPA does not define anonymised or pseudonymised data.</cite>

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidanceThe PDPA lists consent, performance of a contract, compliance with a legal obligation, legitimate interests, and vital interests as lawful bases for processing personal data, paralleling GDPR Article 6.
  2. ConfirmedInternational Association of Privacy Professionals (IAPP)Research and statistics are recognised as an independent lawful basis for processing personal data under the PDPA, a position that diverges from the GDPR's approach.
  3. ConfirmedRoyal Thai Government GazetteA data subject may withdraw consent at any time under the PDPA.
  4. ConfirmedOneTrust DataGuidanceThe PDPA prohibits collection of certain sensitive categories of data without explicit consent, save where processing is for scientific, historical or statistical purposes and suitable safeguards are adopted.
  5. ProbableInternational Association of Privacy Professionals (IAPP)Processing of sensitive personal data for research purposes attracts the same PDPA obligations as ordinary data but may be subject to a more stringent, risk-based approach for high-risk data, including a requirement to establish an ethics committee.
  6. ConfirmedOneTrust DataGuidanceUnlike the GDPR, the PDPA does not define 'anonymised' or 'pseudonymised' data, notwithstanding that it grants data subjects a right to request anonymisation of their personal data.

#

Core rights (access, erasure, objection, portability, information) are confirmed and in force, but exact statutory response-deadline figures could not be independently verified from primary sources searched, warranting a gap flag on deadlines_and_response_windows.

Primary frameworkPersonal Data Protection Act B.E. 2562 (2019), Chapter 3 (Sections 30-42)
Supervisory authorityOffice of the Personal Data Protection Committee (PDPC)
Traffic-light rationale — AmberCore rights (access, erasure, objection, portability, information) are confirmed and in force, but exact statutory response-deadline figures could not be independently verified from primary sources searched, warranting a gap flag on deadlines_and_response_windows.

Sub-modules (5)

Access RightGreen

Right to access is enumerated alongside the other core PDPA rights, GDPR-aligned in substance.

Claims: CLM-TH-f83c1a90

Rectification And ErasureAmber

Right to erasure exists but on a narrower statutory basis than GDPR Art.17, tied to purpose-exhaustion or unlawful processing.

Claims: CLM-TH-6a5d9e21

Restriction And ObjectionGreen

Right to object mirrors GDPR, subject to a public-interest carve-out.

Claims: CLM-TH-13f8c4b7

Data PortabilityGreen

Portability right is recognised, analogous to GDPR Art.20.

Claims: CLM-TH-9e2a6d40

Deadlines And Response WindowsRed

No specific statutory day-count for controller response windows was independently confirmed in this pass. Searches run: 'Thailand PDPA data subject rights deadline 30 days', 'Thailand PDPA access request response window'. Secondary sources reference differing 'timeframes' and fee rules without itemising a specific number of days from the primary Act text.

Category narrative142 words

<cite index="3-15">Both the GDPR and the PDPA empower data subjects with several rights, including the right to erasure, the right to be informed, the right to object, the right to data portability, and the right to access.</cite> On erasure, <cite index="103-16,103-17">both the GDPR and the PDPA allow data subjects to request deletion of their personal information unless exceptions apply, though the scope of, and exemptions to, the right of erasure — including forms of request and response timelines — vary between the two regimes.</cite> On objection, <cite index="94-5">both the GDPR and the PDPA provide data subjects with the right to object to processing unless it is in the public interest.</cite> Portability rights are also mirrored from the GDPR framework. Specific statutory response-window figures (e.g., exact day-counts for access/erasure responses) were not independently confirmed from the primary PDPA text in this research pass.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedOneTrust DataGuidanceThe PDPA empowers data subjects with rights including the right to access, mirroring the GDPR's Article 15 access right.
  2. ConfirmedOneTrust DataGuidanceThe PDPA allows data subjects to request deletion of their personal data unless exceptions apply, though the scope, exemptions, request forms and response timelines for the erasure right differ from the GDPR's equivalent provision.
  3. ConfirmedOneTrust DataGuidanceThe PDPA provides data subjects a right to object to processing, subject to a carve-out where processing is in the public interest.
  4. ConfirmedOneTrust DataGuidanceThe PDPA grants data subjects a right to data portability analogous to the GDPR's Article 20.

#

Security, breach-notification and ROPA duties are well-documented, in force, and PDPC-enforced; DPIA-equivalent and DPO-trigger detail plus joint-controller and retention specifics carry residual gaps.

Primary frameworkPersonal Data Protection Act B.E. 2562 (2019), Chapters 4-5 and PDPC sub-regulations
Supervisory authorityOffice of the Personal Data Protection Committee (PDPC)
Traffic-light rationale — GreenSecurity, breach-notification and ROPA duties are well-documented, in force, and PDPC-enforced; DPIA-equivalent and DPO-trigger detail plus joint-controller and retention specifics carry residual gaps.

Sub-modules (7)

Accountability And DpiaAmber

No standalone DPIA mechanism; accountability discharged via mandatory, periodically-reviewed security measures.

Claims: CLM-TH-c47b1e92

Dpo RequirementsGreen

DPO appointment is mandatory for public authorities and large-scale/special-category processors; enforcement precedent confirms the threshold is actively applied.

Claims: CLM-TH-751ad3f6, CLM-TH-8b0e6c14

Ropa RequirementsGreen

ROPA duties apply to controllers and processors, with an SME/nonprofit carve-out.

Claims: CLM-TH-3d9f7a52, CLM-TH-a6c1e908

Joint Controller ArrangementsRed

No PDPA-specific joint-controller apportionment regime distinct from general controller/processor definitions was identified. Searches run: 'Thailand PDPA joint controller', 'PDPA co-controller liability'.

Security MeasuresGreen

PDPC notice mandates organisational and technical security measures with periodic review obligations.

Claims: CLM-TH-f209b6d3

Breach NotificationGreen

72-hour PDPC notification standard with conditional data-subject notification and a documented penalty-exemption request pathway.

Claims: CLM-TH-15e8a7c4, CLM-TH-b8d3f612, CLM-TH-6c1a9e07

Retention And DisposalRed

No generally-applicable statutory retention-period schedule beyond breach-context and sector-specific retention references was independently located. Searches run: 'Thailand PDPA retention period', 'PDPA data disposal requirement'.

Category narrative345 words

PDIA-equivalent accountability is indirect: <cite index="54-32,54-33">while the GDPR specifically provides for DPIAs, the PDPA outlines that data controllers have a duty to provide appropriate security measures and review them when necessary, or when technology has changed, to maintain appropriate security standards.</cite> DPO appointment is mandatory in defined circumstances per PDPA Section 41 (public-authority status, large-scale/systematic processing, or large-scale special-category processing), though the full statutory trigger list was only partially retrievable from the primary text in this pass. Enforcement confirms real-world application: <cite index="13-2,13-3">the PDPC found a company failed to appoint a DPO despite handling personal data for over 100,000 individuals as a core activity, which triggered the PDPA's DPO-designation requirement.</cite> On ROPA, <cite index="1-10,1-11">the PDPC released Rules and Procedures for the Preparation and Maintenance of the Record of Processing Activities by the Data Processor, requiring records to be readily accessible and promptly presented to the Office of the PDPC or data controllers.</cite> <cite index="14-18,14-19">Small businesses, community/social enterprises, cooperatives, foundations, associations, religious and nonprofit organisations are exempted from the ROPA requirement except for instances involving rejection of a data subject's request or objection.</cite> Security: <cite index="25-11,25-12,25-13">security measures must consist of appropriate organizational and technical measures ensuring ongoing confidentiality, integrity and availability of personal data, including access control and user access management, with periodic review required.</cite> Breach notification: <cite index="6-1">under Section 37(4) of the PDPA and Section 5(3) of the notification, data controllers are required to notify the PDPC of a personal data breach without undue delay and, when feasible, within 72 hours of becoming aware of the breach.</cite> <cite index="1-13,1-14">If the breach carries a high risk to rights and freedoms, controllers must also notify affected data subjects, per the PDPC's Criteria and Procedures for Handling Personal Data Breaches, effective 15 Dec 2022.</cite> <cite index="1-17,1-18">If a breach cannot be reported within 72 hours, the controller may request an exemption from penalties, provided the request is submitted no later than 15 days after becoming aware of the breach with valid reasons for the delay.</cite> Joint-controller-specific rules and detailed statutory retention/disposal periods were not independently located in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (9)
  1. ConfirmedOneTrust DataGuidanceAlthough the PDPA does not explicitly mandate DPIAs as under GDPR Article 35, it requires data controllers to implement appropriate security measures and review them periodically when necessary or when technology changes.
  2. ProbableRoyal Thai Government GazetteUnder PDPA Section 41, data controllers and processors must designate a data protection officer where they are a public authority or otherwise meet statutory large-scale/special-category processing triggers.
  3. ConfirmedInternational Association of Privacy Professionals (IAPP)In the PDPC's first administrative enforcement decision, a company was found to have breached the DPO-appointment obligation, having failed to designate a DPO despite processing personal data of over 100,000 individuals as a core business activity.
  4. ConfirmedInternational Association of Privacy Professionals (IAPP)Data processors must prepare and maintain Records of Processing Activities that are readily accessible and must be promptly presented to the Office of the PDPC or data controllers on request.
  5. ConfirmedInternational Association of Privacy Professionals (IAPP)Small and medium-sized enterprises, community/social enterprises, cooperatives, foundations, associations, religious and nonprofit organisations are exempted from the ROPA requirement, except where a data-subject request or objection is rejected.
  6. ConfirmedInternational Association of Privacy Professionals (IAPP)The PDPC's security-measures notice requires organisational and technical measures ensuring ongoing confidentiality, integrity and availability of personal data, including access control and user-access management, with periodic review obligations.
  7. ConfirmedInternational Association of Privacy Professionals (IAPP)Data controllers must notify the PDPC of a personal data breach without undue delay and, when feasible, within 72 hours of becoming aware of it, unless the breach poses no risk to individuals' rights and freedoms.
  8. ConfirmedInternational Association of Privacy Professionals (IAPP)Where a breach carries a high risk to individuals' rights and freedoms, controllers must also notify affected data subjects, per the PDPC's Criteria and Procedures for Handling Personal Data Breaches, effective 15 December 2022.
  9. ConfirmedInternational Association of Privacy Professionals (IAPP)If a breach cannot be reported within the 72-hour window, the data controller may request an exemption from penalties, provided the request is submitted no later than 15 days after becoming aware of the breach, accompanied by valid reasons for the delay.

#

Transfer mechanisms (adequacy-style assessment, BCRs, appropriate safeguards) are well-documented and in force, but no confirmed bilateral adequacy determinations (granted or received) were located, and localisation-mandate status is unconfirmed.

Primary frameworkPDPA Sections 28-29 and PDPC transfer notifications
Supervisory authorityOffice of the Personal Data Protection Committee (PDPC)
Traffic-light rationale — AmberTransfer mechanisms (adequacy-style assessment, BCRs, appropriate safeguards) are well-documented and in force, but no confirmed bilateral adequacy determinations (granted or received) were located, and localisation-mandate status is unconfirmed.

Sub-modules (6)

Transfer MechanismsGreen

Section 28 requires an adequacy-style standard or a statutory derogation (legal compliance, informed consent, contractual necessity) for cross-border transfers.

Claims: CLM-TH-d92f4b18, CLM-TH-4a7e2c95

Adequacy ReceivedRed

No confirmed record of Thailand having formally received an adequacy determination from another regime was located. Searches run: 'Thailand PDPA adequacy decision received EU'.

Adequacy GrantedRed

No PDPC-published list of destination countries formally granted PDPA adequacy status was located; the PDPC instead applies a case-by-case adequacy-factor assessment. Searches run: 'Thailand PDPC adequacy list countries granted'.

Sccs And BcrsGreen

BCR approval pathway (Section 29) and standard-clause/certification-based appropriate safeguards are both operative, with BCR rules updated effective February 2026.

Claims: CLM-TH-e1b6d3a0, CLM-TH-79c4f8e2, CLM-TH-2f8b1d64

Transfer Impact AssessmentAmber

The PDPC's adequacy criteria function as a TIA-style destination-country assessment but are not itemised into a discrete formal TIA obligation.

Claims: CLM-TH-9d0a5c73

Data LocalisationRed

No general data-localisation mandate was identified in the PDPA beyond the Section 28/29 transfer-conditionality regime. Searches run: 'Thailand PDPA data localisation requirement'.

Category narrative205 words

<cite index="1-19">Section 28 of the PDPA stipulates the need for sending or transferring data to a destination country or international organization with adequate data protection standards.</cite> <cite index="25-16,25-17">In December 2023 the PDPC issued Criteria on the Protection of Personal Data Sent or Transferred Abroad pursuant to Section 28, clarifying that 'sending or transferring personal data' excludes data transit where personal data passes through an intermediary such as cloud computing services.</cite> <cite index="25-18,25-19">Adequacy is not itemised in detail but is assessed against factors including measures or legal mechanisms in the destination country consistent with the PDPA and the presence of enforcing agencies there.</cite> On intragroup transfers, <cite index="14-7,14-8">the PDPC issued rules on intragroup transfers under Section 29, exempting Section 28 obligations for transfers within a group of undertakings that follow PDPC-approved binding corporate rules.</cite> <cite index="14-10,14-11">Appropriate safeguards recognised absent adequacy or approved BCRs include standard data protection clauses, certification, or legally binding agreements between Thai and foreign entities.</cite> Most recently, <cite index="29-13">the PDPC issued updated regulations on BCRs for data protection within corporate groups, effective 17 February 2026.</cite> No PDPC-published list of jurisdictions formally granted or receiving Thai-PDPA adequacy status was identified, and no general data-localisation mandate distinct from the Section 28/29 transfer regime was located.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedInternational Association of Privacy Professionals (IAPP)Section 28 of the PDPA requires that cross-border transfers of personal data be made to a destination country or international organisation with adequate data protection standards, subject to exceptions such as legal compliance, informed consent, or contractual necessity.
  2. ConfirmedInternational Association of Privacy Professionals (IAPP)In December 2023 the PDPC issued Criteria on the Protection of Personal Data Sent or Transferred Abroad pursuant to Section 28, clarifying that 'sending or transferring personal data' excludes data transit through intermediaries such as cloud computing services.
  3. ConfirmedInternational Association of Privacy Professionals (IAPP)The PDPC issued rules on intragroup transfers under Section 29, exempting Section 28 obligations for transfers within a group of undertakings that follow PDPC-approved binding corporate rules.
  4. ConfirmedInternational Association of Privacy Professionals (IAPP)The PDPC's notification on appropriate safeguards recognises standard data protection clauses, certification, or legally binding agreements between Thai and foreign entities as valid transfer mechanisms absent an adequacy determination or approved BCRs.
  5. ConfirmedOneTrust DataGuidanceThe PDPC issued updated regulations on binding corporate rules for data protection within corporate groups, effective 17 February 2026.
  6. ConfirmedInternational Association of Privacy Professionals (IAPP)The PDPC's adequacy criteria assess a destination country's data-protection measures/legal mechanisms and enforcement capacity for consistency with the PDPA, functioning as a transfer-impact-assessment-style test, though the PDPA does not itemise 'adequate data protection standards' in detail.

#

Financial-sector (BoT/FIBA) and credit-bureau overlays are well-evidenced and in force; health, telecoms, employment, education and insurance sub-modules lack confirmed PDPA-specific sectoral sub-legislation.

Primary frameworkPDPA (general) with Financial Institutions Business Act B.E. 2551 (FIBA) overlay
Supervisory authorityOffice of the Personal Data Protection Committee (PDPC)
Traffic-light rationale — AmberFinancial-sector (BoT/FIBA) and credit-bureau overlays are well-evidenced and in force; health, telecoms, employment, education and insurance sub-modules lack confirmed PDPA-specific sectoral sub-legislation.

Sub-modules (7)

Financial Sector OverlayGreen

Bank of Thailand imposes independent FIBA-based data-protection procedures on financial institutions, layered atop PDPA obligations.

Claims: CLM-TH-b4e7f209, CLM-TH-1c6a8d35

Health Sector OverlayRed

No PDPA-specific health-sector sub-legislation was identified distinct from the general PDPA framework. Searches run: 'Thailand PDPA health sector overlay Ministry of Public Health'.

Telecoms And EprivacyRed

No PDPA-specific telecoms/ePrivacy sub-legislation was identified beyond the general PDPA framework and pre-existing telecom sector regulation referenced in overview sources. Searches run: 'Thailand PDPA telecoms ePrivacy NBTC'.

Employment DataRed

No PDPA-specific employment-data sub-legislation was identified in this pass. Searches run: 'Thailand PDPA employment data employer'.

Credit And ScoringAmber

Credit bureau companies retain a distinct PDPA carve-out and continued sectoral regulation.

Claims: CLM-TH-5e9b2f41

EducationRed

No PDPA-specific education-sector sub-legislation was identified in this pass. Searches run: 'Thailand PDPA education sector'.

InsuranceRed

No PDPA-specific insurance-sector sub-legislation was identified in this pass. Searches run: 'Thailand PDPA insurance sector overlay'.

Category narrative135 words

Financial services carry an independent overlay: <cite index="72-2,72-3">the Bank of Thailand (BoT) requires financial institutions to follow specific data-protection and privacy procedures under the Financial Institutions Business Act B.E. 2551 (FIBA), although these requirements are independent from other data protection and privacy legislation.</cite> <cite index="75-3,75-4">In August 2021, the BoT issued an official letter directing banks and financial institutions to prepare for PDPA compliance ahead of the (then) enforcement date.</cite> Credit reporting retains sector specificity: <cite index="71-8,71-9">before the PDPA, data protection regulation was limited to specific sectors including government agencies, telecommunications, and the National Credit Bureau, and the PDPA now mandates continued compliance with both existing sectoral regulation and the PDPA for these sectors.</cite> No PDPA-specific sub-legislation distinct from the general framework was independently identified for health, telecoms/ePrivacy, employment, education, or insurance sectors in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceThe Bank of Thailand requires financial institutions to follow specific data-protection procedures and standards under the Financial Institutions Business Act B.E. 2551 (FIBA), independently of the PDPA.
  2. ConfirmedOneTrust DataGuidanceIn August 2021, the Bank of Thailand issued an official letter directing banks and financial institutions to prepare for PDPA compliance ahead of the (then) statutory enforcement date.
  3. ConfirmedOneTrust DataGuidanceThe PDPA provides specific exceptions for credit bureau companies, which were subject to sector-specific National Credit Bureau regulation prior to the PDPA and must continue to comply with existing sectoral rules alongside the PDPA.

#

Direct-marketing multi-regulator overlay is documented and in force; cookie/tracker consent specifics, dark-pattern rules, opt-out signal recognition, clean-room rules, and cross-context-advertising frameworks are unconfirmed gaps.

Primary frameworkPDPA plus Direct Sale and Direct Marketing Act B.E. 2545, Consumer Protection Act B.E. 2522, Computer-Related Crime Act B.E. 2550
Supervisory authorityOffice of the Personal Data Protection Committee (PDPC)
Traffic-light rationale — AmberDirect-marketing multi-regulator overlay is documented and in force; cookie/tracker consent specifics, dark-pattern rules, opt-out signal recognition, clean-room rules, and cross-context-advertising frameworks are unconfirmed gaps.

Sub-modules (6)

Cookies And TrackersRed

No PDPC-specific cookie/tracker consent standard distinct from general PDPA consent principles was independently confirmed. Searches run: 'Thailand PDPC cookies consent guideline'.

Dark PatternsRed

No dedicated dark-pattern prohibition under the PDPA or consumer-protection framework was identified. Searches run: 'Thailand PDPA dark patterns consumer protection'.

Opt Out SignalsRed

No PDPC recognition of Global Privacy Control or DAA-style opt-out signals was identified. Searches run: 'Thailand PDPA Global Privacy Control opt-out signal'.

Clean Rooms And DcrRed

No PDPC guidance on data clean rooms or collaboration rooms was identified. Searches run: 'Thailand PDPA data clean room'.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising framework exists under the PDPA. Searches run: 'Thailand PDPA cross-context advertising sale share'.

Direct MarketingAmber

Direct marketing is jointly regulated by the OCPB (Consumer Protection Act), the PDPC (PDPA), and other authorities under the Direct Sale and Direct Marketing Act and Computer-Related Crime Act.

Claims: CLM-TH-8f1d6a92

Category narrative81 words

Direct marketing is multi-regulator: <cite index="52-4,52-6,52-9">direct-marketing activity in Thailand is governed by the Direct Sale and Direct Marketing Act B.E. 2545, the Consumer Protection Act B.E. 2522, the PDPA, and the Computer-Related Crime Act B.E. 2550, with the Office of the Consumer Protection Board and the PDPC both issuing relevant guidance.</cite> No PDPC-specific cookie-consent notification, dark-pattern prohibition, Global-Privacy-Control-style opt-out-signal recognition, clean-room/data-collaboration-room rule, or cross-context-advertising ('sale'/'share') framework distinct from general PDPA consent principles was identified in the sources reviewed for this run.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceDirect-marketing activities in Thailand are jointly regulated by the Office of the Consumer Protection Board under the Consumer Protection Act, the Office of the PDPC under the PDPA, and other authorities under the Direct Sale and Direct Marketing Act and the Computer-Related Crime Act.

#

State-surveillance carve-out is confirmed and in force; AI governance is presently non-binding soft law/consultation-stage, and profiling/ADM-transparency, biometric, and genetic sub-modules lack dedicated PDPA provisions confirmed in this pass.

Primary frameworkPDPA (general) plus non-binding ETDA/Bank of Thailand AI guidance
Supervisory authorityOffice of the Personal Data Protection Committee (PDPC)
Traffic-light rationale — AmberState-surveillance carve-out is confirmed and in force; AI governance is presently non-binding soft law/consultation-stage, and profiling/ADM-transparency, biometric, and genetic sub-modules lack dedicated PDPA provisions confirmed in this pass.

Sub-modules (6)

Profiling RestrictionsRed

No PDPA-specific profiling-restriction provision distinct from general lawful-basis/consent rules was identified. Searches run: 'Thailand PDPA profiling restrictions'.

Automated Decision Making TransparencyRed

No Article-22-style automated-decision-making transparency or explanation right distinct from general information/notification duties was identified. Searches run: 'Thailand PDPA automated decision making transparency'.

Ai Risk AssessmentsAmber

AI governance is at the non-binding, consultation/soft-law stage via ETDA and sector regulators (e.g., Bank of Thailand), not yet codified as a PDPA-linked statutory AI risk-assessment duty.

Claims: CLM-TH-c0e4b81f, CLM-TH-6b2f9d17

Biometric RegimeRed

No dedicated PDPA biometric-data regime distinct from general special-category rules was identified. Searches run: 'Thailand PDPA biometric facial recognition regime'.

Genetic DataRed

No dedicated PDPA genetic-data regime distinct from general special-category rules was identified. Searches run: 'Thailand PDPA genetic data regime'.

State Surveillance CarveoutsAmber

State-security-related public authorities (including AML, forensic science, cybersecurity functions) are excluded from PDPA scope.

Claims: CLM-TH-3a7c9e05

Category narrative121 words

The PDPA carries a state-security carve-out but no dedicated algorithmic/biometric/genetic sub-regime: <cite index="5-20">the PDPA excludes public authorities that maintain state security — including financial security, public safety, prevention/suppression of money laundering, forensic science, and cybersecurity — from its scope.</cite> On AI, governance remains soft-law and sector-specific rather than binding, cross-cutting legislation: <cite index="43-5">Thailand's Electronic Transactions Development Agency (ETDA) has launched a public consultation on draft AI-data-protection guidelines to balance innovation with privacy rights and ensure PDPA compliance,</cite> and separately <cite index="61-16">the Bank of Thailand has sought public input on AI guidelines for financial services, focusing on risk management and transparency.</cite> No PDPA-specific Article-22-style automated-decision-making transparency right, dedicated biometric-data regime, or genetic-data regime distinct from the general special-category rules was independently identified.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceThe PDPA excludes from its scope public authorities whose duties concern state security, including financial security, public safety, money-laundering prevention/suppression, forensic science, or cybersecurity.
  2. ProbableOneTrust DataGuidanceThailand's Electronic Transactions Development Agency (ETDA) has launched a public consultation on draft AI-data-protection guidelines intended to balance innovation with privacy rights and ensure PDPA compliance, reflecting a soft-law rather than binding-statute approach to AI governance.
  3. ProbableOneTrust DataGuidanceThe Bank of Thailand has sought public input on AI guidelines for financial services, focusing on risk management and transparency, as a non-binding sector-specific complement to PDPA obligations.

#

Minors' consent-capacity rule is confirmed and in force, but it is a civil-law-referential mechanism rather than a fixed statutory age threshold, and age-verification, minor-profiling-ban, education-setting, and dependent-adults sub-modules lack independently confirmed PDPA provisions.

Primary frameworkPersonal Data Protection Act B.E. 2562 (2019), read with the Thai Civil and Commercial Code
Supervisory authorityOffice of the Personal Data Protection Committee (PDPC)
Traffic-light rationale — AmberMinors' consent-capacity rule is confirmed and in force, but it is a civil-law-referential mechanism rather than a fixed statutory age threshold, and age-verification, minor-profiling-ban, education-setting, and dependent-adults sub-modules lack independently confirmed PDPA provisions.

Sub-modules (5)

Age VerificationRed

No PDPA-specific age-verification mechanism was identified beyond reliance on civil-law capacity concepts. Searches run: 'Thailand PDPA age verification minors'.

Minor Profiling BansRed

No PDPA-specific ban on profiling of minors distinct from general consent rules was identified. Searches run: 'Thailand PDPA minor profiling ban'.

Education SettingsRed

No PDPA-specific education-setting data-protection rule was identified. Searches run: 'Thailand PDPA education settings minors school data'.

Dependent AdultsRed

No PDPA-specific dependent-adults (elderly/incapacitated) provision distinct from general capacity/consent rules was identified. Searches run: 'Thailand PDPA dependent adults incapacitated consent'.

Category narrative106 words

Minors' consent capacity is governed by reference to Thai civil-law majority/sui-juris concepts rather than a fixed statutory age threshold as in GDPR Art.8: <cite index="31-1,31-2">unlike the GDPR — under which children under 16 must have parental/guardian consent, with Member States able to lower the threshold to 13 — the PDPA provides that minors who are not sui juris by marriage or otherwise lack capacity as a sui juris person under the Civil and Commercial Code require consent to be given on their behalf.</cite> No PDPA-specific age-verification mechanism, minor-profiling ban, education-sector-specific rule, or dependent-adults provision distinct from these general consent-capacity rules was independently identified in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ProbableOneTrust DataGuidanceThe PDPA provides that minors who are not sui juris by marriage, or who otherwise lack capacity as a sui juris person under the Civil and Commercial Code, require consent to processing of their personal data to be given on their behalf, rather than applying a fixed statutory age threshold as under GDPR Article 8.

#

The PDPC is demonstrably active (first fine issued 2024, ongoing sub-regulation issuance into 2026) with clear administrative and criminal penalty structures in force; funding/capacity transparency and a distinct private-right-of-action mechanism remain unconfirmed gaps.

Primary frameworkPersonal Data Protection Act B.E. 2562 (2019), Chapters 6-7 and the Administrative Fines Law
Supervisory authorityOffice of the Personal Data Protection Committee (PDPC)
Traffic-light rationale — GreenThe PDPC is demonstrably active (first fine issued 2024, ongoing sub-regulation issuance into 2026) with clear administrative and criminal penalty structures in force; funding/capacity transparency and a distinct private-right-of-action mechanism remain unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

PDPC Expert Committee holds investigative and sanctioning powers; penalties combine administrative fines with potential criminal imprisonment of up to one year.

Claims: CLM-TH-9f4e7b20, CLM-TH-2d8c5a93, CLM-TH-7a1f3e64, CLM-TH-4c9a2f17

Enforcement Activity IndexGreen

First administrative fine issued July 2024 (THB 7 million) marks the PDPC's initial major enforcement milestone; activity has continued with subsequent guidance and sub-regulation.

Claims: CLM-TH-e6b0d9c8

Regulator Funding And CapacityRed

No specific budget or headcount disclosure for the Office of the PDPC was identified in this pass. Searches run: 'PDPC Thailand budget headcount capacity'.

Collective Redress And Class ActionsAmber

Professional legal commentary references potential class-action exposure alongside administrative fines for PDPA noncompliance, though a dedicated statutory collective-redress mechanism was not independently itemised from primary text.

Claims: CLM-TH-b1d7e40a

Private Right Of ActionRed

No standalone private-right-of-action provision distinct from the PDPC complaint/administrative-fine pathway and general civil-liability principles was independently confirmed. Searches run: 'Thailand PDPA private right of action civil suit'.

Recent Developments 180DGreen

Within the 180-day window: PDPC BCR regulations effective 17 February 2026, and a 2026 PDPC public-consultation-driven clarification of breach-notification exemption criteria.

Claims: CLM-TH-8e3c6f92, CLM-TH-0a5d8b34

Category narrative227 words

<cite index="25-8">The Expert Committee is authorized to consider complaints, investigate and impose punitive measures for PDPA violations.</cite> <cite index="5-14">Violations of the PDPA can, alongside monetary and administrative penalties, result in imprisonment for a term not exceeding one year.</cite> <cite index="47-1,47-2">Pre-enforcement legal commentary indicated administrative fines could reach up to THB 5,000,000 (approximately EUR 141,000).</cite> In practice, <cite index="13-7,13-8">on 31 July 2024 — two years after the PDPA became fully enforceable — the Expert Committee issued its first administrative fine, a THB 7 million penalty against an online-retail company for notable compliance failures,</cite> a figure exceeding the commonly-cited single-violation cap and suggesting aggregation across multiple concurrent breaches (failure to appoint a DPO, mishandling of complaints, and inadequate remediation of ongoing customer-data misuse). <cite index="1-6,1-7">In setting fines, the Expert Committee weighs factors including offence severity, the size of the controller/processor's business, benefits derived and harm caused, broader implications for related industries, the offender's level of responsibility, and remedial or mitigating action taken.</cite> Recent developments within the 180-day window include <cite index="29-13">PDPC BCR regulations effective 17 February 2026</cite> and <cite index="82-9,82-10">a 2026 PDPC clarification, issued in response to a company-led public consultation, detailing the Section 12 risk-evaluation criteria that determine when a breach-notification exemption applies.</cite> Regulator funding/headcount data and a standalone private-right-of-action mechanism (distinct from the PDPC complaint/administrative-fine pathway and referenced class-action potential) were not independently confirmed in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (8)
  1. ConfirmedInternational Association of Privacy Professionals (IAPP)The PDPC's Expert Committee is authorised to consider complaints, investigate, and impose administrative fines and other punitive measures for PDPA violations.
  2. ConfirmedOneTrust DataGuidancePDPA violations may, in addition to administrative and monetary penalties, result in criminal imprisonment for a term not exceeding one year for certain offences.
  3. ProbableOneTrust DataGuidancePre-enforcement legal commentary indicated PDPA administrative fines could reach up to THB 5,000,000 (approximately EUR 141,000) per violation under the Administrative Fines Law, though the PDPC's first enforcement decision (THB 7 million) suggests fines may be aggregated across multiple concurrent violations.
  4. ConfirmedInternational Association of Privacy Professionals (IAPP)In setting administrative fines, the Expert Committee considers factors including offence severity, the size of the controller/processor's business, benefits derived and harm caused, wider implications for related industries, the offender's level of responsibility, and remedial or mitigating action taken.
  5. ConfirmedInternational Association of Privacy Professionals (IAPP)On 31 July 2024, the PDPC's Expert Committee issued its first administrative fine under the PDPA — a THB 7 million penalty against an online-retail company for failing to appoint a DPO, mishandling customer breach complaints, and enabling continued misuse of personal data by scammers.
  6. ProbableOneTrust DataGuidancePDPA noncompliance may, according to professional legal commentary, give rise to class-action exposure in addition to administrative fines, though a dedicated statutory collective-redress mechanism was not independently itemised from primary text in this pass.
  7. ConfirmedOneTrust DataGuidanceThe PDPC issued updated regulations on binding corporate rules for data protection within corporate groups, effective 17 February 2026.
  8. ConfirmedInternational Association of Privacy Professionals (IAPP)In a 2026 clarification issued in response to a company-led public consultation, the PDPC confirmed that data controllers are exempt from notifying it of a breach where the event poses no risk to individuals' rights and freedoms, and detailed the Section 12 risk-evaluation criteria underpinning that exemption.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Thailand
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 48 claim(s), 13 source(s) in the cumulative register.