Educational Information Only
The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.
PDPA Data Protection Officer (DPO) Appointment Threshold
Section 41 of Thailand's PDPA requires controllers and processors to appoint a Data Protection Officer (DPO) in three scenarios. This guide explains when a DPO must be appointed and what the role's statutory duties are.
TL;DR
Under PDPA §41, controllers and processors must appoint a Data Protection Officer (DPO) in three scenarios: (1) public-authority controllers / processors, (2) operations that regularly monitor data subjects on a large scale, and (3) operations whose core activities involve large-scale sensitive personal data. The DPO's contact details must be published and notified to the PDPC. The DPO has statutory protection from dismissal on duty-related grounds (§42).
Who Must Appoint a DPO
| Trigger | Examples |
|---|---|
| Public authority | Government departments, state enterprises |
| Large-scale regular monitoring | Telco operators, social platforms, ad-tech, large e-commerce |
| Large-scale sensitive data | Hospitals, insurers, religious bodies, security companies |
Definitions
- Large scale: PDPC guidance considers volume, geographic reach, duration, and number of data subjects.
- Regular monitoring: continuous or systematic observation including tracking, profiling, behavioural advertising.
- Sensitive data: as enumerated in §26 — racial origin, religious belief, sexual orientation, biometric, criminal record, health, etc.
DPO Duties (§42)
- Advise controller / processor and staff on PDPA obligations.
- Monitor compliance.
- Coordinate with PDPC investigations.
- Be the contact point for data-subject requests.
DPO Independence (§42-43)
- Reports directly to the highest management level.
- Cannot be dismissed for performing DPO duties (employment-law protection).
- May be internal or external (outsourced).
- Single DPO can cover a corporate group.
Common Mistakes
- Appointing the IT manager without role independence — fails the §42 test.
- Not publishing DPO contact details on the public-facing website.
- Combining DPO with conflicting roles (CFO, Head of Marketing).
- Failing to notify PDPC of the appointment.
FAQs
1. Can a law firm be our DPO?
Yes — outsourced DPO is permitted; independence and accessibility requirements apply.
2. SME exemption?
No general SME exemption; PDPA applies; DPO appointment depends on the §41 triggers.
Reading the Three Triggers
The PDPA does not require every organisation to appoint a Data Protection Officer — only those hit by one of the three §41 triggers: being a public authority; carrying out processing that involves regular, systematic monitoring of data subjects on a large scale; or having core activities that handle large volumes of sensitive personal data. The hard part is judging "large scale" and "regular monitoring," which the PDPC assesses by looking at data volume, the number of data subjects, geographic reach and duration. A small shop with an ordinary customer list generally falls outside; a hospital, insurer, telco, ad-tech platform or large e-commerce operator generally falls inside.
Making the Appointment Count
Appointing a DPO is not a box-ticking formality. The role has to be genuinely independent: the DPO advises and monitors compliance, is the contact point for data subjects and the PDPC, reports to top management, and is protected from dismissal for doing the job. That independence is exactly why naming the IT manager, CFO or head of marketing as DPO tends to fail — those roles conflict with impartial oversight. The DPO can be internal or outsourced (a law firm or specialist provider is fine), and a single DPO can cover a corporate group. Whoever is chosen, the organisation must publish their contact details and notify the PDPC — an appointment nobody can find does not satisfy the Act.
Related Reading
Professional Legal Assistance
blog.ctaContext
Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.
Stay Informed
Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.
We respect your privacy. Unsubscribe anytime.
feedback.wasThisHelpful