Educational Information Only — Not Legal Advice

    This site provides educational information only and is not a substitute for professional legal advice. Consult a qualified Thai lawyer for personalized guidance. Laws may change. Full DisclaimerPrivacy Policy

    Skip to main content
    Last updated:
    Share:

    Educational Information Only

    The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.

    Back to Legal News
    Regulatory Updates

    PDPA Data Protection Officer (DPO) Appointment Threshold

    Section 41 of Thailand's PDPA requires controllers and processors to appoint a Data Protection Officer (DPO) in three scenarios. This guide explains when a DPO must be appointed and what the role's statutory duties are.

    6/15/20265 min read read
    PDPA
    DPO
    data protection
    compliance

    TL;DR

    Under PDPA §41, controllers and processors must appoint a Data Protection Officer (DPO) in three scenarios: (1) public-authority controllers / processors, (2) operations that regularly monitor data subjects on a large scale, and (3) operations whose core activities involve large-scale sensitive personal data. The DPO's contact details must be published and notified to the PDPC. The DPO has statutory protection from dismissal on duty-related grounds (§42).

    Who Must Appoint a DPO

    TriggerExamples
    Public authorityGovernment departments, state enterprises
    Large-scale regular monitoringTelco operators, social platforms, ad-tech, large e-commerce
    Large-scale sensitive dataHospitals, insurers, religious bodies, security companies

    Definitions

    • Large scale: PDPC guidance considers volume, geographic reach, duration, and number of data subjects.
    • Regular monitoring: continuous or systematic observation including tracking, profiling, behavioural advertising.
    • Sensitive data: as enumerated in §26 — racial origin, religious belief, sexual orientation, biometric, criminal record, health, etc.

    DPO Duties (§42)

    1. Advise controller / processor and staff on PDPA obligations.
    2. Monitor compliance.
    3. Coordinate with PDPC investigations.
    4. Be the contact point for data-subject requests.

    DPO Independence (§42-43)

    • Reports directly to the highest management level.
    • Cannot be dismissed for performing DPO duties (employment-law protection).
    • May be internal or external (outsourced).
    • Single DPO can cover a corporate group.

    Common Mistakes

    • Appointing the IT manager without role independence — fails the §42 test.
    • Not publishing DPO contact details on the public-facing website.
    • Combining DPO with conflicting roles (CFO, Head of Marketing).
    • Failing to notify PDPC of the appointment.

    FAQs

    1. Can a law firm be our DPO?

    Yes — outsourced DPO is permitted; independence and accessibility requirements apply.

    2. SME exemption?

    No general SME exemption; PDPA applies; DPO appointment depends on the §41 triggers.

    Reading the Three Triggers

    The PDPA does not require every organisation to appoint a Data Protection Officer — only those hit by one of the three §41 triggers: being a public authority; carrying out processing that involves regular, systematic monitoring of data subjects on a large scale; or having core activities that handle large volumes of sensitive personal data. The hard part is judging "large scale" and "regular monitoring," which the PDPC assesses by looking at data volume, the number of data subjects, geographic reach and duration. A small shop with an ordinary customer list generally falls outside; a hospital, insurer, telco, ad-tech platform or large e-commerce operator generally falls inside.

    Making the Appointment Count

    Appointing a DPO is not a box-ticking formality. The role has to be genuinely independent: the DPO advises and monitors compliance, is the contact point for data subjects and the PDPC, reports to top management, and is protected from dismissal for doing the job. That independence is exactly why naming the IT manager, CFO or head of marketing as DPO tends to fail — those roles conflict with impartial oversight. The DPO can be internal or outsourced (a law firm or specialist provider is fine), and a single DPO can cover a corporate group. Whoever is chosen, the organisation must publish their contact details and notify the PDPC — an appointment nobody can find does not satisfy the Act.

    Related Reading

    Professional Legal Assistance

    blog.ctaContext

    Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.

    blog.templatePromo.title

    blog.templatePromo.description

    blog.templatePromo.cta

    Stay Informed

    Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.

    Subscribing does not create a lawyer-client relationship. Please don't include confidential information. Anglo Siam Law is an educational platform — for representation, contact Anglo Siam Legal.

    Topics you're interested in (optional)

    We respect your privacy. Unsubscribe anytime.

    feedback.wasThisHelpful