Personal Data Protection Act B.E. 2562 (2019)
Personal Data Protection Committee
Personal Data Protection Committee
Thailand's main data protection law is the Personal Data Protection Act, B.E. 2562 (2019), commonly called the Thai PDPA. It regulates the collection, use and disclosure of personal data and creates a structured compliance framework for data controllers and data processors. The law is strongly influenced by modern privacy principles: clear consent, lawful purpose, data minimisation, transparency, special protection for sensitive data, data subject rights, security, breach notification and cross-border transfer controls.
The PDPA applies to data controllers and data processors in Thailand, regardless of whether the actual collection, use or disclosure takes place inside or outside Thailand. It also applies to controllers or processors outside Thailand where they offer goods or services to data subjects in Thailand, or monitor behaviour taking place in Thailand.
Consent is important, but not the only basis. Section 19 sets the general rule that personal data must not be collected, used or disclosed unless the data subject has given consent, or unless the Act or another law permits it. Section 24 then provides non-consent bases for collection, including contract, legal obligation, vital interests, public task, legitimate interests and research or statistics with safeguards.
Purpose limitation is central. Data controllers must collect, use and disclose personal data according to the purpose notified to the data subject. If the controller wants to use data for a new or different purpose, it generally needs to inform the data subject and obtain consent unless another legal permission applies.
Controllers carry the main accountability burden. Controllers must provide notices, limit collection, maintain records, implement security measures, delete data when no longer needed, notify breaches, respond to rights requests, control processors and, in some cases, appoint a representative in Thailand and a data protection officer.
The law defines personal data as information relating to a natural person that enables identification directly or indirectly, but excludes information of deceased persons. It distinguishes between the Data Controller, who decides the purposes and means of collection, use or disclosure, and the Data Processor, who acts under the controller's instructions.
The PDPA uses the phrase “collection, use or disclosure” instead of a single broad “processing” concept. That matters because the Act separately regulates collection, use, disclosure, transfer, security, records, breach notification and data subject rights. A business must therefore check each stage of the data lifecycle: how data is collected, why it is collected, whether it is used only for the notified purpose, whether it is disclosed lawfully, whether it is transferred abroad safely, and whether it can be erased, restricted or ported when a data subject exercises rights.
Special categories receive heightened protection. Section 26 prohibits collection of data such as racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade union information, genetic data, biometric data and similar sensitive data unless explicit consent is obtained or a statutory exception applies.
Start with a data map and lawful basis review. For each category of personal data, identify the purpose, data source, whether data is collected directly from the data subject, whether consent is needed, whether sensitive data is involved, who receives the data, whether it leaves Thailand, and how long it is retained.
Then review notices and consent. Consent requests must be clearly distinguishable from other matters, easy to access, intelligible, written in clear and plain language, not deceptive or misleading, and freely given. Withdrawal must be as easy as giving consent, unless limited by law or by a contract that benefits the data subject.
Finally, test operational workflows. Controllers should be able to respond to access, portability, objection, erasure, restriction and accuracy requests; maintain records under section 39; notify the Office within 72 hours where feasible after becoming aware of a risky breach; notify data subjects without delay where high risk exists; and support a DPO where required.
Personal Data Protection Act, B.E. 2562 (2019) - Thailand's core personal data protection law regulating collection, use, disclosure, data subject rights, controller and processor duties, sensitive data, cross-border transfers, breach notification, complaints, civil liability and penalties.
Thailand PDPA compliance is not just a privacy notice exercise. You need a lawful basis, a notified purpose, valid consent where required, special handling for sensitive data, processor contracts, security controls, records, breach notification procedures, cross-border transfer checks and working rights-response workflows. The law analysis explains the operational requirements in detail.