Asia-Pacific Thailand

Thailand PDPA Guide: Compliance with B.E. 2562 (2019)

Thailand's Personal Data Protection Act, fully effective June 2022: lawful bases, consent rules, 72-hour breach reporting, DPO triggers, and PDPC enforcement.

Regulation

Personal Data Protection Act B.E. 2562 (2019), fully effective 1 June 2022

Max Penalty

Administrative fines up to THB 5 million; criminal penalties up to 1 year imprisonment; punitive damages up to 2x actual damages

Enforcing Authority

Personal Data Protection Committee (PDPC Thailand)

Official Source

www.mdes.go.th

Executive Summary

  • Thailand's PDPA was enacted in 2019 and, after two pandemic postponements, became fully effective on 1 June 2022 as the country's first comprehensive privacy law.
  • It is closely modeled on GDPR: six-plus lawful bases including legitimate interests and contract, extraterritorial reach to offering goods/services or monitoring in Thailand, and controller/processor roles.
  • Sensitive data (health, biometrics, religion, sexual orientation, criminal records, and more) requires explicit consent or narrow statutory exceptions.
  • Breaches likely to risk individuals' rights must be reported to the PDPC within 72 hours; high-risk breaches also require notifying affected individuals.
  • Sanctions run three tracks: administrative fines to THB 5 million per violation, criminal liability (including for responsible directors) to 1 year imprisonment, and civil claims with punitive damages up to double actual loss.

Thailand wrote its privacy law by translating GDPR into Thai legal architecture, then took three years of postponements and sub-regulations to switch it on. Since 1 June 2022 the PDPA has been fully operative, and since 2024 the PDPC has shown it will fine: the first major penalty (THB 7 million, against an e-commerce operator whose leaked customer data fed scam call centers) targeted exactly the unglamorous failures, no DPO, weak security, slow breach handling, that GDPR authorities also punish most.

RegulationPDPA B.E. 2562 (2019), fully effective 1 June 2022
Max penaltyTHB 5M administrative per violation; 1 year criminal; 2x punitive damages
Enforcing authorityPDPC Thailand, under MDES
ModelGDPR-derived

The GDPR mapping, with Thai differences

Most GDPR machinery ports directly: lawful bases, purpose limitation, data-subject rights (access, rectification, erasure, restriction, portability, objection), DPIA expectations for high-risk processing, processor contracts, and records of processing (with a small-business carve-out). The differences that matter:

  • Criminal liability. Unlawful disclosure or use of sensitive data can mean imprisonment, and responsible directors and managers can be personally liable where violations stem from their orders or omissions, a board-level attention device GDPR lacks.
  • Punitive damages. Thai courts may award up to twice actual damages, and class-action-style claims are procedurally available, giving breaches a private-litigation tail.
  • Consent formalities. Consent requests must be explicit, in clear language, and not deceptive; the PDPC has issued guidance against bundled consent. Sensitive-data consent must be express and separate.
  • Committee-driven detail. Like Singapore’s guideline model, the operative detail arrives through PDPC notifications: security standards (2022), breach criteria, DPO rules, and the 2023-2024 transfer notifications covered in the Thailand transfers guide.

Compliance sequence for Thailand

Scope first (Thai establishment or targeting/monitoring of people in Thailand, and appoint the local representative if offshore); map data with sensitive categories flagged, Thai datasets commonly include religion (on ID cards historically) and health data with distinct cultural sensitivity; align lawful bases with GDPR mappings where you have them; stand up the 72-hour breach pipeline with the PDPC’s report content; test DPO triggers; and paper processors with PDPA-compliant clauses. Then verify the cross-border transfer position, the newest and least-understood layer. A free scan shows what your Thai-facing web properties collect and disclose today.

Frequently Asked Questions

Who has to comply with Thailand's PDPA?

Controllers and processors in Thailand, and those abroad who offer goods or services to people in Thailand or monitor their behavior there, GDPR-style extraterritoriality. Offshore entities in scope must appoint a representative in Thailand. Limited exemptions cover personal/household use, state security, and legislative and judicial functions.

What lawful bases does the PDPA recognize?

Consent plus non-consent bases mirroring GDPR: contract performance, legal obligation, vital interests, public task, legitimate interests balanced against fundamental rights, plus research/statistics and documented-archive purposes. Sensitive data narrows the menu to explicit consent and specific exceptions like vital interests, employment law, public health, and legal claims.

When is a DPO required in Thailand?

For public authorities, controllers or processors whose core activities require regular monitoring at large scale, and those whose core activities involve large-scale sensitive-data processing, a translation of GDPR Article 37's triggers. Group and outsourced DPOs are allowed; the DPO's contact must be notified to the PDPC and published.

How does breach notification work?

Report to the Office of the PDPC without delay and within 72 hours of becoming aware, where the breach risks individuals' rights and freedoms; where the risk is high, also notify affected data subjects with remediation guidance. A 2022 PDPC notification details the assessment and reporting content, and processors must alert their controllers promptly.

What has enforcement looked like since 2022?

The PDPC built out sub-regulations through 2022-2024 (security minimums, breach reporting, DPIA guidance, transfer rules) before turning to penalties. In August 2024 it issued its first significant administrative fine, THB 7 million against a large online retailer for failing to appoint a DPO and inadequate security after customer data leaked to scam call centers, signaling that the grace period is over.

Regulatory Crosswalk

GDPRThailand PDPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.