Country:泰国 · Data Privacy
Thailand · Data Privacy
Thailand's Personal Data Protection Act (PDPA, 2019) fully took effect on 2022-06-01, with enforcement becoming routine from 2025 (the PDPC has issued multiple fines, the highest single case THB 7 million). It applies domestically and extraterritorially. Data processing requires a lawful basis (such as consent), notice obligations, security measures, and DPIA. Cross-border transfers must be based on adequacy determinations or SCC/BCR. The regulator is the PDPC.
Key points
- PDPA 2019 fully effective; 2025 enforcement intensified (zero data breach target).
- Lawful bases: consent, necessary for contract, legitimate interests, etc.
- Data subject rights: access, rectification, erasure, portability, objection.
- Data breaches must be reported to the PDPC within 72 hours.
- Cross-border transfers: Thailand has not made adequacy determinations (China not listed); SCC/BCR/certification required.
- China data export obligations (pkulaw verified 2026-07): transfers/return of data to China must use one of three routes — security assessment (CAC Order No. 11), standard contract (Order No. 13), or certification (CAC·SAMR Order No. 20, effective 2025-10-14); the 2024–2025 regulatory stance has relaxed — the Provisions on Promoting and Regulating Cross-Border Data Flows (Order No. 16) and the Regulations on Network Data Security Administration (State Council Order No. 790) exempt some situations.
Procedure
- Personal data inventory and processing records (RoPA).
- Publish privacy notices and manage consent.
- High-risk processing requires a DPIA; appoint a DPO where applicable.
- Cross-border transfers require SCCs or adequacy assessments.
- Establish a 72-hour breach notification mechanism.
Hard requirements
- Lawful basis; notice; security measures; DPO (specific cases); cross-border SCC/BCR.
Costs
Compliance system building; DPO; audits.⏱ ⏱ Timeline:PDPA effective since 2022; enforcement routine since 2025.⚠ Common risks
- China has no adequacy determination; cross-border transfers require SCC/BCR.
- Consent defects (pre-checked consent invalid) are penalized.
- Unreported data breaches face heavy penalties (up to THB 5 million or criminal).
- Extraterritorial application: entities without a Thai establishment may be covered.
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese companies processing Thai residents' personal data in Thailand, or transferring it to China (governed by the PDPA 2019, fully effective 2022-06-01, enforcement routine since 2025, supervised by the PDPC with extraterritorial effect).
Prerequisites
- Processing activities and lawful bases (such as consent) clarified.
- Assessment of whether a DPO is required (specific cases).
- Budget reserved for cross-border SCC/BCR and compliance costs.
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Personal data inventory and processing records (RoPA). Map personal data categories, processing purposes, and recipients; establish a record of processing activities (RoPA). | Legal/IT department. | 2 weeks | Internal cost. | Data inventory, RoPA. | Extraterritorial application. Penalty:Fines up to THB 5 million or criminal liability. |
| 2 | Publish privacy notices and manage consent. Publish Thai/English privacy notices and obtain valid consent (pre-checked consent invalid). | Legal | 1–2 weeks. | Internal/translation costs. | Privacy notice, consent records. | Must support withdrawal. Penalty:Same as step 1. |
| 3 | Conduct a DPIA for high-risk processing and appoint a DPO. Conduct a DPIA for high-risk or large-scale sensitive data processing; appoint a DPO in specific cases. | Compliance/management | 2–4 weeks | DPO staffing | DPIA report, DPO appointment | 2025 enforcement intensified (zero breach target) Penalty:Penalized for missing DPIA or DPO. |
| 4 | Cross-border SCC/BCR. China has no adequacy determination; sign SCCs or use BCR/certification, linked to PIPL export. | Legal | 3–6 weeks | Internal/lawyer fees | SCC/BCR, PIPL export documents | Comparable protection must be ensured Penalty:Penalized for transfers without a lawful mechanism. |
| 5 | 72-hour breach notification. Breaches must be reported to the PDPC within 72 hours, with a registration mechanism. | DPO/IT | Within 72 hours | Internal cost | PDPC breach notification | Set automatic triggers Penalty:Unreported breaches heavily penalized (up to THB 5 million/criminal) |
| 6 | Data subject rights response. Establish response mechanisms for access, rectification, erasure, portability, and objection requests. | DPO/customer service | Ongoing | Internal cost | DSAR process | Must be recorded Penalty:Refusing to respond faces penalties. |
| 7 | Continuous compliance and annual review. Regular reviews, policy updates, and training (PDPC has issued multiple fines, highest single case THB 7 million). | Compliance | Annual | Internal cost | Annual audit | Enforcement routine Penalty:Continuous violation accumulation risk. |
✅ Self-check list
⚠ Common pitfalls
China without adequacy but transferring without SCC/BCR影响:Violation (stacked with PIPL penalties)规避:Sign SCC/BCR
Pre-checked consent影响:Penalized for invalid consent规避:Opt-in consent
Ignoring PIPL export for data return to China影响:Dual violation规避:Handle China-side mechanisms in parallel
Breach reported after 72 hours影响:Up to THB 5 million or criminal liability规避:Set automatic reporting triggers
DPO not appointed when required影响:Penalized规避:Appoint per the circumstances
Assuming PDPA is not enforced影响:Routine since 2025规避:Start compliance immediately
📅 Ongoing post-incorporation obligations
- DPO duties (where applicable)
- 72-hour breach notification to the PDPC
- Continuous DSAR response
- SCC/BCR and China PIPL export mechanisms remain effective
- Annual review and training
🔗 Official portals
📎 Source:Thailand Personal Data Protection Committee (PDPC); Personal Data Protection Act (PDPA B.E. 2562, 2019); Cross-Border Transfer Regulations (effective 2024-03); https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.