Thailand’s transfer regime spent its first eighteen months as an unloaded gun: section 28 restricted transfers to “adequate” destinations, but the PDPC had defined neither adequacy nor the safeguard mechanisms. The December 2023 notifications, effective 24 March 2024, filled in the machinery, and did it pragmatically: recognized-template contractual clauses (ASEAN MCCs explicitly among them), PDPC-certified BCRs, and adequacy criteria for a future list. The practical message: paper your Thai transfer flows with clauses now, and stop relying on the informal tolerance of the gap years.
| Provisions | PDPA ss. 28-29 + PDPC notifications (eff. 24 March 2024) |
|---|---|
| Adequacy list | Criteria published; no designations yet |
| Workhorse | Contractual clauses (ASEAN MCC-compatible) |
| Intra-group | PDPC-certified binding corporate rules |
| Regulator | PDPC Thailand, under MDES |
Building the Thai transfer file
Inventory the flows. Cloud hosting abroad, regional shared services, offshore support, analytics SaaS, marketing platforms: each is a section 28 transfer once personal data leaves Thailand. Processor-to-subprocessor hops count.
Pick per-flow mechanisms. Default to contractual clauses meeting the notification’s content list; use the ASEAN MCCs where counterparties span Southeast Asia (the same paper can serve Singapore and other ASEAN transfers), or a Thai rider on EU SCCs where the counterparty already signed those. Reserve consent for one-off, user-initiated transfers. Groups with permanent Thai operations should cost out a section 29 BCR certification.
Mind the overlay duties. The transfer mechanism does not replace the general PDPA duties: the receiving processing still needs a lawful basis, sensitive data keeps its explicit-consent rules, and breach duties follow the data. Security requirements from the PDPC’s 2022 notification apply to the transferring controller regardless of destination.
Document like the EU. The notifications import a GDPR-shaped logic, so a GDPR-style transfer register (flow, mechanism, safeguards, review date) is the audit-ready format. Regional context: Thailand’s regime now sits closer to Singapore’s comparable-protection model than to China’s regulator-gated filings.
The domestic rulebook these transfers plug into is covered in the Thailand PDPA guide. Check which third-country endpoints your Thai-facing site actually ships data to with a free scan.