Thailand wrote its privacy law by translating GDPR into Thai legal architecture, then took three years of postponements and sub-regulations to switch it on. Since 1 June 2022 the PDPA has been fully operative, and since 2024 the PDPC has shown it will fine: the first major penalty (THB 7 million, against an e-commerce operator whose leaked customer data fed scam call centers) targeted exactly the unglamorous failures, no DPO, weak security, slow breach handling, that GDPR authorities also punish most.
| Regulation | PDPA B.E. 2562 (2019), fully effective 1 June 2022 |
|---|---|
| Max penalty | THB 5M administrative per violation; 1 year criminal; 2x punitive damages |
| Enforcing authority | PDPC Thailand, under MDES |
| Model | GDPR-derived |
The GDPR mapping, with Thai differences
Most GDPR machinery ports directly: lawful bases, purpose limitation, data-subject rights (access, rectification, erasure, restriction, portability, objection), DPIA expectations for high-risk processing, processor contracts, and records of processing (with a small-business carve-out). The differences that matter:
- Criminal liability. Unlawful disclosure or use of sensitive data can mean imprisonment, and responsible directors and managers can be personally liable where violations stem from their orders or omissions, a board-level attention device GDPR lacks.
- Punitive damages. Thai courts may award up to twice actual damages, and class-action-style claims are procedurally available, giving breaches a private-litigation tail.
- Consent formalities. Consent requests must be explicit, in clear language, and not deceptive; the PDPC has issued guidance against bundled consent. Sensitive-data consent must be express and separate.
- Committee-driven detail. Like Singapore’s guideline model, the operative detail arrives through PDPC notifications: security standards (2022), breach criteria, DPO rules, and the 2023-2024 transfer notifications covered in the Thailand transfers guide.
Compliance sequence for Thailand
Scope first (Thai establishment or targeting/monitoring of people in Thailand, and appoint the local representative if offshore); map data with sensitive categories flagged, Thai datasets commonly include religion (on ID cards historically) and health data with distinct cultural sensitivity; align lawful bases with GDPR mappings where you have them; stand up the 72-hour breach pipeline with the PDPC’s report content; test DPO triggers; and paper processors with PDPA-compliant clauses. Then verify the cross-border transfer position, the newest and least-understood layer. A free scan shows what your Thai-facing web properties collect and disclose today.