Educational Information Only — Not Legal Advice

    This site provides educational information only and is not a substitute for professional legal advice. Consult a qualified Thai lawyer for personalized guidance. Laws may change. Full DisclaimerPrivacy Policy

    Skip to main content
    Last updated:
    Share:

    Educational Information Only

    The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.

    Back to Legal News
    Regulatory Updates

    PDPA Enforcement Intensifies: Major Fines Issued in Early 2025

    Thailand's Personal Data Protection Commission issues first major penalties, signaling stricter enforcement of data privacy laws.

    1/28/202515 min read
    PDPA
    Data Privacy
    Compliance
    Enforcement
    Data Protection

    PDPA Enforcement Enters New Phase

    The Personal Data Protection Committee (PDPC) has issued its first significant penalties under the PDPA in early 2025, marking a shift from the advisory phase to active enforcement. The Personal Data Protection Act B.E. 2562 (2019), commonly known as the PDPA, came into full effect on June 1, 2022, after several postponements. During its first two years, the PDPC focused primarily on issuing guidance and warnings. The 2025 enforcement actions signal that the grace period is definitively over.

    The PDPA applies to any organization — Thai or foreign — that collects, uses, or discloses personal data of individuals in Thailand, regardless of whether the data controller or processor is located in the Kingdom (Section 5). This extraterritorial scope means that foreign businesses serving Thai customers must comply with the PDPA even if they have no physical presence in Thailand. For a comprehensive compliance overview, see the PDPA Compliance Guide.

    Notable Cases

    #

    Case 1: E-commerce Platform (THB 3.5 Million) A major e-commerce platform was fined for failing to obtain proper consent for marketing communications and sharing customer data with third-party advertisers without explicit agreement.

    The PDPC found that the platform had relied on pre-ticked consent checkboxes in its registration process, which do not constitute valid consent under Section 19 of the PDPA. Valid consent must be "freely given, specific, informed, and unambiguous," and must involve an affirmative action by the data subject. The platform also failed to provide a mechanism for users to withdraw consent easily, as required by Section 19(5), which states that withdrawing consent must be as easy as giving it.

    #

    Case 2: Hospital Data Breach (THB 2.8 Million) A private hospital received penalties for inadequate data security measures that led to patient records being accessible via unsecured API endpoints.

    This case is particularly significant because health data is classified as "sensitive personal data" under Section 26 of the PDPA, which requires explicit consent and heightened security measures. The PDPC determined that the hospital had failed to implement "appropriate security measures" as required by Section 37(1), including encryption of sensitive data, access controls, and regular security audits. The fine reflected both the severity of the breach (affecting over 10,000 patient records) and the sensitive nature of the data involved.

    #

    Case 3: Financial Services Company (Administrative Order)

    A financial services company received an administrative order requiring it to appoint a Data Protection Officer (DPO) and revise its data retention policies. The company had been retaining customer identification documents indefinitely, well beyond the period necessary for the original purpose of collection, violating the data minimization principle under Section 22. Under the PDPA, personal data should be retained only for as long as necessary for the purpose for which it was collected.

    Understanding PDPA Penalties

    The PDPA provides for three categories of penalties. Administrative fines of up to THB 5 million per violation may be imposed by the PDPC Expert Committee (Section 90). Criminal penalties include imprisonment of up to 1 year and fines of up to THB 1 million for unauthorized use or disclosure of sensitive personal data that causes harm (Sections 79-80). Civil liability includes compensation for actual damages, and courts may award punitive damages of up to twice the actual damages (Section 77-78). Directors and officers who order or authorize the violation may be held personally liable alongside the organization.

    Compliance Requirements

    All organizations must ensure:

  1. Clear consent mechanisms for data collection
  2. Data Processing Agreements with vendors
  3. Appointed Data Protection Officers where required
  4. Data breach notification procedures (within 72 hours)
  5. Cross-border data transfer safeguards

    #

    Consent Requirements in Detail

    Under Section 19, consent must be: (1) freely given — the data subject must have a genuine choice, and consent cannot be bundled with a service agreement as a condition; (2) specific — consent must identify the specific purpose for data processing; (3) informed — the data controller must provide clear information about what data is collected and how it will be used; (4) unambiguous — consent must be demonstrated through a clear affirmative action (pre-ticked boxes are not valid). For sensitive data categories (health, biometric, racial or ethnic data, political opinions, religious beliefs, criminal records, trade union membership, genetic data, and sexual orientation), explicit consent is required under Section 26.

    #

    Data Protection Officer Requirements

    Organizations must appoint a DPO if they: (1) are a public authority, (2) carry out regular and systematic monitoring of data subjects on a large scale, or (3) process sensitive personal data on a large scale as a core activity (Section 41). The DPO must have professional qualifications or expertise in data protection law and practice. The DPO's duties include advising the organization on PDPA compliance, monitoring compliance, cooperating with the PDPC, and maintaining confidentiality (Section 42).

    #

    Cross-Border Data Transfer Rules

    Section 28 restricts the transfer of personal data to foreign countries unless the destination country has "adequate data protection standards" as determined by the PDPC. Exceptions include: explicit consent of the data subject, performance of a contract, compliance with legal obligations, protection of vital interests, and transfers subject to appropriate safeguards (binding corporate rules, standard contractual clauses). As of 2025, the PDPC has not yet published a list of countries with adequate standards, meaning most cross-border transfers currently rely on consent or contractual safeguards.

    Step-by-Step Compliance Guide

    Step 1: Data mapping. Identify all personal data your organization collects, processes, and stores. Document the categories of data, purposes of processing, legal basis for each processing activity, and data flows (including to third parties and overseas).

    Step 2: Legal basis review. For each data processing activity, identify the appropriate legal basis under Section 24: consent, contractual necessity, legal obligation, vital interests, public interest/official authority, or legitimate interests. Relying on legitimate interests requires a balancing test against the data subject's rights.

    Step 3: Privacy policy update. Prepare or update your privacy notice in compliance with Section 23, which requires disclosure of: data collected, purpose, retention period, categories of recipients, data subject rights, and contact details for the data controller and DPO (if applicable). The notice must be written in clear, plain language. For businesses serving Thai consumers, a Thai language version is advisable.

    Step 4: Consent mechanism implementation. Revise all consent forms, cookie notices, and registration flows to meet PDPA standards. Implement a consent management system that records when and how consent was given, and provides easy withdrawal mechanisms.

    Step 5: Data breach response plan. Establish procedures for detecting, investigating, and reporting data breaches. Under Section 37(4), data controllers must notify the PDPC of breaches within 72 hours. If the breach is likely to pose a high risk to data subjects' rights and freedoms, the data subjects must also be notified without delay.

    Common Mistakes and Traps

    Relying solely on consent: Many organizations default to consent as the legal basis for all data processing. However, consent can be withdrawn at any time, which may disrupt business operations. Where another legal basis applies (such as contractual necessity or legitimate interests), it is often more practical to rely on that basis and reserve consent for processing that genuinely requires it.

    Ignoring employee data: The PDPA applies to employee personal data, not just customer data. HR departments must comply with consent requirements, data minimization principles, and retention limits for employment records, background check results, and health information. This is an area where many businesses in Thailand have significant compliance gaps.

    Cookie consent failures: Websites accessible in Thailand must implement proper cookie consent mechanisms. Implied consent (continuing to browse after a notice) does not meet PDPA standards for non-essential cookies. Only strictly necessary cookies may be placed without consent.

    Insufficient vendor management: Data controllers remain responsible for the actions of their data processors (Section 40). Organizations must ensure that service providers handling personal data on their behalf are contractually bound to comply with PDPA requirements through Data Processing Agreements (DPAs) that specify the purpose, duration, types of data, and security measures.

    Action Items for Businesses

    1. Conduct PDPA compliance audit

  6. 2. Update privacy policies and consent forms 3. Train staff on data handling procedures 4. Implement data breach response plans

    Frequently Asked Questions

    Does the PDPA apply to small businesses?

    Yes. The PDPA applies to all organizations that collect or process personal data, regardless of size. There are no small business exemptions. However, the scope of compliance obligations scales with the volume and sensitivity of data processed — a small retail shop has simpler obligations than a hospital or e-commerce platform.

    What is the difference between a data controller and a data processor?

    A data controller (Section 3) determines the purposes and means of data processing — this is typically your organization. A data processor processes data on behalf of the controller — such as a cloud hosting provider, payroll service, or marketing agency. Both have obligations under the PDPA, but the controller bears primary responsibility for compliance. For businesses using third-party services, see the e-commerce consumer rights overview for related obligations.

    Can individuals file complaints directly with the PDPC?

    Yes. Data subjects may file complaints with the Expert Committee appointed by the PDPC (Section 73). Complaints must be filed within 3 years of the date the data subject becomes aware of the violation. The Expert Committee will investigate and may order remedial action, impose administrative fines, or refer the matter for criminal prosecution.

    How does the PDPA interact with other Thai laws?

    The PDPA does not override sector-specific data protection requirements. Financial institutions remain subject to Bank of Thailand regulations, healthcare providers must comply with the Mental Health Act and medical confidentiality rules, and telecommunications companies have obligations under the NBTC regulations. Where sector-specific rules impose stricter requirements, both must be satisfied.

    Are there any exemptions for data processing?

    Section 4 provides limited exemptions for: personal or household activities, credit bureau operations (governed by the Credit Bureau Act), mass media activities for journalistic purposes, parliamentary and judicial functions, and cybersecurity operations by government agencies. These exemptions are narrowly construed.

    Professional Legal Assistance

    blog.ctaContext

    Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.

    blog.templatePromo.title

    blog.templatePromo.description

    blog.templatePromo.cta

    Stay Informed

    Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.

    Subscribing does not create a lawyer-client relationship. Please don't include confidential information. Anglo Siam Law is an educational platform — for representation, contact Anglo Siam Legal.

    Topics you're interested in (optional)

    We respect your privacy. Unsubscribe anytime.

    feedback.wasThisHelpful