Educational Information Only
The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.
PDPA Data Protection Officer (DPO) Appointment Threshold
Section 41 of Thailand's PDPA requires controllers and processors to appoint a Data Protection Officer (DPO) in three scenarios. This guide explains when a DPO must be appointed and what the role's statutory duties are.
TL;DR
Under PDPA §41, controllers and processors must appoint a Data Protection Officer (DPO) in three scenarios: (1) public-authority controllers / processors, (2) operations that regularly monitor data subjects on a large scale, and (3) operations whose core activities involve large-scale sensitive personal data. The DPO's contact details must be published and notified to the PDPC. The DPO has statutory protection from dismissal on duty-related grounds (§42).
Who Must Appoint a DPO
| Trigger | Examples |
|---|---|
| Public authority | Government departments, state enterprises |
| Large-scale regular monitoring | Telco operators, social platforms, ad-tech, large e-commerce |
| Large-scale sensitive data | Hospitals, insurers, religious bodies, security companies |
Definitions
- Large scale: PDPC guidance considers volume, geographic reach, duration, and number of data subjects.
- Regular monitoring: continuous or systematic observation including tracking, profiling, behavioural advertising.
- Sensitive data: as enumerated in §26 — racial origin, religious belief, sexual orientation, biometric, criminal record, health, etc.
DPO Duties (§42)
- Advise controller / processor and staff on PDPA obligations.
- Monitor compliance.
- Coordinate with PDPC investigations.
- Be the contact point for data-subject requests.
DPO Independence (§42-43)
- Reports directly to the highest management level.
- Cannot be dismissed for performing DPO duties (employment-law protection).
- May be internal or external (outsourced).
- Single DPO can cover a corporate group.
Common Mistakes
- Appointing the IT manager without role independence — fails the §42 test.
- Not publishing DPO contact details on the public-facing website.
- Combining DPO with conflicting roles (CFO, Head of Marketing).
- Failing to notify PDPC of the appointment.
FAQs
1. Can a law firm be our DPO?
Yes — outsourced DPO is permitted; independence and accessibility requirements apply.
2. SME exemption?
No general SME exemption; PDPA applies; DPO appointment depends on the §41 triggers.
Related Reading
Professional Legal Assistance
blog.ctaContext
Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.
Stay Informed
Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.
We respect your privacy. Unsubscribe anytime.
feedback.wasThisHelpful