Asia-Pacific Thailand

Thailand PDPA Cross-Border Transfers: The 2024 Rules

Transferring personal data out of Thailand: sections 28-29, the December 2023 PDPC notifications, contractual clauses, binding corporate rules, and exceptions.

Regulation

PDPA B.E. 2562 sections 28-29; PDPC transfer notifications (December 2023, effective March 2024)

Max Penalty

Administrative fines up to THB 5 million per violation

Enforcing Authority

Personal Data Protection Committee (PDPC Thailand)

Official Source

www.mdes.go.th

Executive Summary

  • PDPA section 28 allows transfers abroad only to destinations with adequate protection (as prescribed by the PDPC) or under listed exceptions, including explicit consent after being informed of inadequate protection.
  • Section 29 provides the intra-group route: binding corporate rules reviewed and certified by the PDPC, plus 'appropriate safeguards' mechanisms.
  • Two PDPC notifications issued in December 2023 (effective 24 March 2024) operationalized the regime: criteria for adequacy assessment and requirements for contractual clauses and BCRs.
  • The clause route accepts model contracts aligned with recognized templates, including the ASEAN Model Contractual Clauses and EU-style SCC structures, making multi-framework paper practical.
  • No adequacy list has been published yet, so practical transfers run on contractual clauses, BCRs, consent, and the statutory exceptions.

Thailand’s transfer regime spent its first eighteen months as an unloaded gun: section 28 restricted transfers to “adequate” destinations, but the PDPC had defined neither adequacy nor the safeguard mechanisms. The December 2023 notifications, effective 24 March 2024, filled in the machinery, and did it pragmatically: recognized-template contractual clauses (ASEAN MCCs explicitly among them), PDPC-certified BCRs, and adequacy criteria for a future list. The practical message: paper your Thai transfer flows with clauses now, and stop relying on the informal tolerance of the gap years.

ProvisionsPDPA ss. 28-29 + PDPC notifications (eff. 24 March 2024)
Adequacy listCriteria published; no designations yet
WorkhorseContractual clauses (ASEAN MCC-compatible)
Intra-groupPDPC-certified binding corporate rules
RegulatorPDPC Thailand, under MDES

Building the Thai transfer file

Inventory the flows. Cloud hosting abroad, regional shared services, offshore support, analytics SaaS, marketing platforms: each is a section 28 transfer once personal data leaves Thailand. Processor-to-subprocessor hops count.

Pick per-flow mechanisms. Default to contractual clauses meeting the notification’s content list; use the ASEAN MCCs where counterparties span Southeast Asia (the same paper can serve Singapore and other ASEAN transfers), or a Thai rider on EU SCCs where the counterparty already signed those. Reserve consent for one-off, user-initiated transfers. Groups with permanent Thai operations should cost out a section 29 BCR certification.

Mind the overlay duties. The transfer mechanism does not replace the general PDPA duties: the receiving processing still needs a lawful basis, sensitive data keeps its explicit-consent rules, and breach duties follow the data. Security requirements from the PDPC’s 2022 notification apply to the transferring controller regardless of destination.

Document like the EU. The notifications import a GDPR-shaped logic, so a GDPR-style transfer register (flow, mechanism, safeguards, review date) is the audit-ready format. Regional context: Thailand’s regime now sits closer to Singapore’s comparable-protection model than to China’s regulator-gated filings.

The domestic rulebook these transfers plug into is covered in the Thailand PDPA guide. Check which third-country endpoints your Thai-facing site actually ships data to with a free scan.

Frequently Asked Questions

What are the lawful routes for sending data out of Thailand?

Four families: (1) destination adequacy as prescribed by the PDPC (list still pending); (2) statutory exceptions under section 28, legal compliance, explicit consent after disclosure of inadequate protection, contract necessity, public interest, vital interests; (3) appropriate safeguards via contractual clauses per the 2023 notification; (4) PDPC-certified binding corporate rules for intra-group transfers under section 29.

What do the December 2023 notifications actually require?

The safeguards notification sets minimum content for transfer contracts: enforceable data-subject rights, purpose and retention limits, security obligations, onward-transfer restrictions, and liability allocation, and recognizes standardized templates such as the ASEAN Model Contractual Clauses. The adequacy notification sets the criteria the PDPC will use to designate adequate destinations (legal framework, enforcement, redress).

Can we use our EU SCCs for Thai transfers?

Largely yes, with a gap check. The notification's required elements overlap heavily with EU SCC content, so most companies annex a Thailand rider to existing SCCs or adopt the ASEAN MCCs, which were designed for exactly this multi-jurisdiction reuse. The clauses must reflect Thai data-subject rights and PDPA definitions, not just copy EU citations.

How do BCRs work under section 29?

Groups submit binding internal rules covering all participating affiliates to the PDPC for review and certification; once certified, intra-group transfers flow without per-transfer mechanisms. Content requirements track the contractual-clause notification (rights, security, liability, audit). For conglomerates with Thai entities, it is the long-term cost saver, comparable to EU BCRs.

Is consent a workable transfer basis?

It exists but is deliberately unattractive: the data subject must be informed that the destination lacks adequate protection before consenting, an admission most brands prefer not to make at scale, and withdrawal breaks the flow. Use it for edge cases, not architectures; contractual clauses are the standard route.

Regulatory Crosswalk

GDPR Chapter VThailand PDPAASEAN MCCs

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.