EnglishTH
Thailand flag

Thailand

Thailand Data Privacy Laws: PDPA Compliance Guide (2026)

By Recording Law Editorial TeamReviewed July 23, 202622 min read
Thailand Data Privacy Laws: PDPA Compliance Guide (2026)

Frequently Asked Questions

Does Thailand's PDPA apply to foreign companies?

Yes. The PDPA has extraterritorial reach. It applies to any organization, regardless of location, that collects, uses, or discloses the personal data of individuals in Thailand. This includes foreign businesses that offer goods or services to people in Thailand, or that monitor the behavior of individuals located within the country. If your website targets Thai consumers or you process data about Thai residents, you are subject to the PDPA.

What is the maximum penalty for violating Thailand's PDPA?

The PDPA establishes three penalty tiers. Administrative fines can reach up to THB 5 million per violation. Criminal penalties under the PDPA include imprisonment of up to one year and fines of up to THB 1 million for unlawful use of sensitive personal data. The Emergency Decree on Technology Crimes (April 2025) adds criminal penalties of up to five years imprisonment for commercial exploitation of personal data. Civil liability allows courts to award punitive damages of up to twice actual losses. Cumulatively, the PDPC has imposed approximately THB 21.5 million in fines across enforcement actions through mid-2026.

How quickly must a data breach be reported under the PDPA?

Data controllers must notify the PDPC within 72 hours of becoming aware of a personal data breach that poses a risk to data subjects' rights and freedoms. If unavoidable circumstances prevent meeting this deadline, the controller has up to 15 days but must explain the delay. When the breach poses a high risk to individuals, the controller must also notify affected data subjects without undue delay. Failure to report within the required timeframe can result in an administrative fine of up to THB 3 million. Breach notification failure was cited in every one of the five enforcement cases announced in August 2025.

Can personal data be transferred outside Thailand under the PDPA?

Yes, but transfer mechanisms are required in most cases. Organizations can use Binding Corporate Rules (BCRs) -- which became fully operational after the PDPC approved its first BCR applications in September 2025 -- Standard Contractual Clauses based on ASEAN or EU models, or explicit informed consent. An adequacy list has not yet been published. The new cross-border transfer regulations have been in effect since March 24, 2024.

Is appointing a Data Protection Officer mandatory in Thailand?

It depends on processing activities. Since December 2023, a DPO is required when the organization is a designated public authority (expanded to all state agencies in October 2025), when core activities involve regular monitoring of personal data systems, when processing occurs on a large scale (100,000 or more data subjects), or when core activities involve large-scale processing of sensitive personal data. Failing to appoint a DPO when required carries an administrative fine of up to THB 1 million and has been treated as an aggravating factor in fine calculations.

What did the 2025 Emergency Decree add to Thailand's data protection framework?

The Emergency Decree on Technology Crimes No. 2 (effective April 13, 2025) added criminal penalties specifically for personal data misuse in connection with crime. Collecting, possessing, or disclosing personal data with criminal intent carries up to one year imprisonment and a THB 100,000 fine. Commercially buying, selling, or profiting from personal data unlawfully carries up to five years imprisonment and a THB 500,000 fine. The Decree also established a new enforcement center (CPOT) and imposed mandatory obligations on payment service providers, digital asset operators, and telecoms providers.

What is the status of Thailand's PDPA amendment process?

In late 2025, the PDPC launched a public consultation on draft amendments to the PDPA. The proposed changes include clarifying controller and processor definitions, restructuring the legal bases hierarchy to reduce over-reliance on consent, revisiting the sensitive personal data categories, and improving the framework for AI-driven processing. The first consultation round has concluded and a revised draft is proceeding through the legislative process. No amendment has been enacted as of May 2026.

Updates

Refresh: added the reported June 2026 PDPC voluntary PDPA certification framework (developing, not yet on the PDPC's English notification list) and interlinked the standard contractual clauses, data protection officer requirements, and data localization guides.

Major refresh: added PDPC enforcement timeline (2024 first fine + August 2025 wave), Emergency Decree on Technology Crimes No. 2 (April 2025), Worldcoin/iris-scan shutdown (November 2025), BCR framework operational (September 2025), draft PDPA amendment consultation, PDPC Eagle Eye Unit, AI guidelines draft (February 2026), and 2026 compliance priorities. Expanded from 2,847 to ~6,200 words.

Sources and References

  1. Personal Data Protection Act B.E. 2562 (2019) -- Full Text (Thai Government Gazette)(pdpathailand.com).gov
  2. Office of the Personal Data Protection Committee (PDPC) -- Official Website(pdpc.or.th).gov
  3. PDPC Notification Re: Criteria and Procedures for Personal Data Breach Notification(pdpathailand.com).gov
  4. Royal Thai Government Gazette (Ratchakitcha) -- Official Government Publication(ratchakitcha.soc.go.th).gov
  5. PDPC First Administrative Penalty -- THB 7 Million Fine for Non-Compliance -- Nishimura & Asahi(nishimura.com)
  6. Thailand PDPC Approved BCRs for Cross-Border Transfers -- Baker McKenzie(bakermckenzie.com)
  7. Thailand: New Cross-Border Data Transfer Rules Officially Published as Law -- Baker McKenzie(insightplus.bakermckenzie.com)
  8. Thailand PDPA Crackdown 2025: Major Fines and Lessons -- DLA Piper(privacymatters.dlapiper.com)
  9. PDPA Fines and Firsts: A 6-Year Timeline of Thailand Data Privacy Enforcement -- Herbert Smith Freehills Kramer(hsfkramer.com)
  10. Data Protection and Privacy 2026 -- Thailand: Trends and Developments -- Chambers and Partners(practiceguides.chambers.com)
  11. Thailand Amends Emergency Decree on Technology Crime -- Tilleke & Gibbins(tilleke.com)
  12. Thailand Establishes Personal Data Protection Commission -- Tilleke & Gibbins(tilleke.com)
  13. Thailand: Operationalising PDPA -- Lawful Basis, Sensitive Personal Data, and Data Processing Safeguards -- Tilleke & Gibbins(tilleke.com)
  14. Thailand Shuts Down World Iris Scanning Operation, Orders Deletion of Biometrics -- Biometric Update(biometricupdate.com)
  15. Thailand PDPC Clarifies Data Breach Notification Requirements -- IAPP(iapp.org)
  16. PDPC Notification Re: DPO Appointment Requirements under Section 41(2), B.E. 2566 (2023) -- Lexology(lexology.com)
  17. Thailand PDPC Signals Tougher Enforcement with Multi-Million Baht Fines -- GALA(blog.galalaw.com)
  18. Thailand PDPA Crackdown 2026: PDPC Issues 8 Fines and Emergency Decree on Tech Crimes -- Saeree ERP(grandlinux.com)
  19. Thailand PDPA and Biometric Data: Enforcement and Lessons from the World Iris Scanning Case -- MPG(mahanakornpartners.com)
  20. Thailand Cross-Border Data Transfer Overview -- Securiti(securiti.ai)
Share: