Country:泰国 · Data Privacy
High confidenceUpdated 2026-08-03Handbook

Thailand · Data Privacy

Thailand's Personal Data Protection Act (PDPA, 2019) fully took effect on 2022-06-01, with enforcement becoming routine from 2025 (the PDPC has issued multiple fines, the highest single case THB 7 million). It applies domestically and extraterritorially. Data processing requires a lawful basis (such as consent), notice obligations, security measures, and DPIA. Cross-border transfers must be based on adequacy determinations or SCC/BCR. The regulator is the PDPC.

Key points

Procedure

  1. Personal data inventory and processing records (RoPA).
  2. Publish privacy notices and manage consent.
  3. High-risk processing requires a DPIA; appoint a DPO where applicable.
  4. Cross-border transfers require SCCs or adequacy assessments.
  5. Establish a 72-hour breach notification mechanism.

Hard requirements

Costs

Compliance system building; DPO; audits.⏱ ⏱ Timeline:PDPA effective since 2022; enforcement routine since 2025.

⚠ Common risks

  • China has no adequacy determination; cross-border transfers require SCC/BCR.
  • Consent defects (pre-checked consent invalid) are penalized.
  • Unreported data breaches face heavy penalties (up to THB 5 million or criminal).
  • Extraterritorial application: entities without a Thai establishment may be covered.
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese companies processing Thai residents' personal data in Thailand, or transferring it to China (governed by the PDPA 2019, fully effective 2022-06-01, enforcement routine since 2025, supervised by the PDPC with extraterritorial effect).

Prerequisites

  • Processing activities and lawful bases (such as consent) clarified.
  • Assessment of whether a DPO is required (specific cases).
  • Budget reserved for cross-border SCC/BCR and compliance costs.
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Personal data inventory and processing records (RoPA).
Map personal data categories, processing purposes, and recipients; establish a record of processing activities (RoPA).
Legal/IT department.2 weeksInternal cost.Data inventory, RoPA.Extraterritorial application.
Penalty:Fines up to THB 5 million or criminal liability.
2Publish privacy notices and manage consent.
Publish Thai/English privacy notices and obtain valid consent (pre-checked consent invalid).
Legal1–2 weeks.Internal/translation costs.Privacy notice, consent records.Must support withdrawal.
Penalty:Same as step 1.
3Conduct a DPIA for high-risk processing and appoint a DPO.
Conduct a DPIA for high-risk or large-scale sensitive data processing; appoint a DPO in specific cases.
Compliance/management2–4 weeksDPO staffingDPIA report, DPO appointment2025 enforcement intensified (zero breach target)
Penalty:Penalized for missing DPIA or DPO.
4Cross-border SCC/BCR.
China has no adequacy determination; sign SCCs or use BCR/certification, linked to PIPL export.
Legal3–6 weeksInternal/lawyer feesSCC/BCR, PIPL export documentsComparable protection must be ensured
Penalty:Penalized for transfers without a lawful mechanism.
572-hour breach notification.
Breaches must be reported to the PDPC within 72 hours, with a registration mechanism.
DPO/ITWithin 72 hoursInternal costPDPC breach notificationSet automatic triggers
Penalty:Unreported breaches heavily penalized (up to THB 5 million/criminal)
6Data subject rights response.
Establish response mechanisms for access, rectification, erasure, portability, and objection requests.
DPO/customer serviceOngoingInternal costDSAR processMust be recorded
Penalty:Refusing to respond faces penalties.
7Continuous compliance and annual review.
Regular reviews, policy updates, and training (PDPC has issued multiple fines, highest single case THB 7 million).
ComplianceAnnualInternal costAnnual auditEnforcement routine
Penalty:Continuous violation accumulation risk.

✅ Self-check list

⚠ Common pitfalls

China without adequacy but transferring without SCC/BCR影响:Violation (stacked with PIPL penalties)规避:Sign SCC/BCR
Pre-checked consent影响:Penalized for invalid consent规避:Opt-in consent
Ignoring PIPL export for data return to China影响:Dual violation规避:Handle China-side mechanisms in parallel
Breach reported after 72 hours影响:Up to THB 5 million or criminal liability规避:Set automatic reporting triggers
DPO not appointed when required影响:Penalized规避:Appoint per the circumstances
Assuming PDPA is not enforced影响:Routine since 2025规避:Start compliance immediately

📅 Ongoing post-incorporation obligations

  • DPO duties (where applicable)
  • 72-hour breach notification to the PDPC
  • Continuous DSAR response
  • SCC/BCR and China PIPL export mechanisms remain effective
  • Annual review and training

🔗 Official portals

📎 Source:Thailand Personal Data Protection Committee (PDPC); Personal Data Protection Act (PDPA B.E. 2562, 2019); Cross-Border Transfer Regulations (effective 2024-03); https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.