Educational Information Only — Not Legal Advice

    This site provides educational information only and is not a substitute for professional legal advice. Consult a qualified Thai lawyer for personalized guidance. Laws may change. Full DisclaimerPrivacy Policy

    Skip to main content
    Thai LawKNOWLEDGE AUTHORITY
    Last updated:
    Share:

    Educational Information Only

    The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.

    Back to Legal News
    Regulatory Updates

    PDPA Data Protection Officer (DPO) Appointment Threshold

    Section 41 of Thailand's PDPA requires controllers and processors to appoint a Data Protection Officer (DPO) in three scenarios. This guide explains when a DPO must be appointed and what the role's statutory duties are.

    6/15/20265 min read read
    PDPA
    DPO
    data protection
    compliance

    TL;DR

    Under PDPA §41, controllers and processors must appoint a Data Protection Officer (DPO) in three scenarios: (1) public-authority controllers / processors, (2) operations that regularly monitor data subjects on a large scale, and (3) operations whose core activities involve large-scale sensitive personal data. The DPO's contact details must be published and notified to the PDPC. The DPO has statutory protection from dismissal on duty-related grounds (§42).

    Who Must Appoint a DPO

    TriggerExamples
    Public authorityGovernment departments, state enterprises
    Large-scale regular monitoringTelco operators, social platforms, ad-tech, large e-commerce
    Large-scale sensitive dataHospitals, insurers, religious bodies, security companies

    Definitions

    • Large scale: PDPC guidance considers volume, geographic reach, duration, and number of data subjects.
    • Regular monitoring: continuous or systematic observation including tracking, profiling, behavioural advertising.
    • Sensitive data: as enumerated in §26 — racial origin, religious belief, sexual orientation, biometric, criminal record, health, etc.

    DPO Duties (§42)

    1. Advise controller / processor and staff on PDPA obligations.
    2. Monitor compliance.
    3. Coordinate with PDPC investigations.
    4. Be the contact point for data-subject requests.

    DPO Independence (§42-43)

    • Reports directly to the highest management level.
    • Cannot be dismissed for performing DPO duties (employment-law protection).
    • May be internal or external (outsourced).
    • Single DPO can cover a corporate group.

    Common Mistakes

    • Appointing the IT manager without role independence — fails the §42 test.
    • Not publishing DPO contact details on the public-facing website.
    • Combining DPO with conflicting roles (CFO, Head of Marketing).
    • Failing to notify PDPC of the appointment.

    FAQs

    1. Can a law firm be our DPO?

    Yes — outsourced DPO is permitted; independence and accessibility requirements apply.

    2. SME exemption?

    No general SME exemption; PDPA applies; DPO appointment depends on the §41 triggers.

    Related Reading

    Professional Legal Assistance

    blog.ctaContext

    Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.

    blog.templatePromo.title

    blog.templatePromo.description

    blog.templatePromo.cta

    Stay Informed

    Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.

    Subscribing does not create a lawyer-client relationship. Please don't include confidential information. Anglo Siam Law is an educational platform — for representation, contact Anglo Siam Legal.

    Topics you're interested in (optional)

    We respect your privacy. Unsubscribe anytime.

    feedback.wasThisHelpful