Educational Information Only
The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.
PDPA Implementation in Thailand: DPO Appointment, DPA Contracts, and 72-Hour Breach Notification
Beyond the basics, Personal Data Protection Act B.E. 2562 (2019) compliance requires appointing a Data Protection Officer (DPO), executing Data Processing Agreements (DPAs) with processors, and notifying the PDPC within 72 hours of a personal data breach. This guide covers the operational implementation that organisations get wrong.
TL;DR
Two years after the Personal Data Protection Act B.E. 2562 (2019) took full effect on 1 June 2022, the Personal Data Protection Committee Office (สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล / PDPC) has shifted from education to enforcement. The depth issues that catch organisations are not the consent banner — it is the operational triangle of (1) Data Protection Officer (DPO) appointment under Section 41, (2) Data Processing Agreements (DPAs) with processors under Sections 27 and 40, and (3) 72-hour breach notification under Section 37. Administrative fines run to THB 5 million per violation under Section 78, with criminal liability under Section 79 for wilful breach of PDPC orders. Cross-border transfers require an adequacy finding or specific safeguards under Section 28; data-subject rights (access, correction, erasure, portability) under Sections 30-34 have statutory response windows; high-risk processing triggers a Data Protection Impact Assessment (DPIA). The compliance programme is not optional and the PDPC has begun publishing decisions.
The Statutory Framework Beyond the Basics
The PDPA was enacted on 27 May 2019 as B.E. 2562 (2019) and, after pandemic-driven extensions, became fully effective on 1 June 2022. The substantive obligations sit in five clusters:
- Sections 19-29: lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests, scientific research) and cross-border transfer rules.
- Sections 30-36: data subject rights and the controller's response obligations.
- Sections 37-40: security obligations, breach notification, and the controller-processor relationship.
- Section 41: Data Protection Officer appointment triggers.
- Sections 72-90: the penalty regime — administrative, criminal, and civil.
DPO Appointment Under Section 41
Section 41 makes DPO appointment mandatory in three scenarios:
| Trigger | Source | Typical examples |
|---|---|---|
| Public authority | Section 41(1) | Ministries, state enterprises, local administrative organisations |
| Core activities require regular monitoring of data subjects on a large scale | Section 41(2) | Telcos, banks, hospitals, large e-commerce, ad-tech, security/CCTV operators |
| Core activities involve large-scale sensitive personal data processing | Section 41(3) | Medical providers, biometric authentication, religion/political-opinion processors |
The DPO must have sufficient knowledge of data protection law and the organisation's processing, must be able to perform duties independently, and may be an employee or a contractor. The DPO's contact details must be published and notified to the PDPC. The DPO is the operational interface for data subject rights, breach response, and PDPC liaison — and a poorly briefed DPO is itself a finding-grade weakness in any audit.
The Controller-Processor Boundary and DPAs (Sections 27 & 40)
Section 27 imposes the lawful-basis obligation on the controller; Section 40 then governs the controller's relationship with processors. The controller must:
- Use only processors that provide sufficient guarantees for PDPA compliance.
- Execute a written contract — a Data Processing Agreement (DPA) — specifying subject matter, duration, nature and purpose of processing, types of personal data, categories of data subjects, and the controller's instructions.
- Bind the processor to confidentiality, security measures, sub-processor controls, breach notification to the controller, deletion or return at end of contract, and audit rights.
Standard SaaS terms of service almost never satisfy Section 40 without a PDPA addendum. Cross-border processors require additional Section 28 documentation.
Breach Notification: The 72-Hour Clock (Section 37)
Section 37(4) requires the controller to notify the PDPC of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of the breach, except where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is high-risk to data subjects (e.g., sensitive data exposure, large-scale financial impact), the controller must also notify affected data subjects without undue delay.
| Step | Statutory deadline | Who acts |
|---|---|---|
| Detection / awareness | T0 (clock starts) | Security team / DPO |
| Triage and risk assessment | T0 + 24 hours target | DPO + incident response |
| PDPC notification | T0 + 72 hours (Section 37(4)) | DPO or controller representative |
| Data subject notification (where high risk) | "Without undue delay" — practical 7-14 days | Communications + legal |
| Remediation and post-incident report | Per PDPC follow-up | Whole organisation |
The notification must describe the nature of the breach, categories and approximate numbers of data subjects and records affected, likely consequences, and measures taken or proposed. Knowing what to say in three days requires the IR plan to exist before the breach.
Cross-Border Transfers Under Section 28
Section 28 prohibits transferring personal data to a destination country that does not have adequate protection unless one of the listed safeguards applies: data subject's explicit consent after being informed of the inadequacy; performance of a contract with the data subject; performance of a contract in the data subject's interest; compliance with the law; vital interests; or binding corporate rules or other PDPC-approved mechanism. The PDPC has begun publishing draft standard contractual clauses (SCCs) aligning loosely with GDPR SCCs; until those are formalised, contract-by-contract Section 28 analyses are necessary.
Data Subject Rights — Statutory Response Windows
| Right | PDPA section | Response window |
|---|---|---|
| Right of access | Section 30 | 30 days (extendable with notice) |
| Right to rectification | Section 31 | 30 days |
| Right to erasure | Section 32 | 30 days |
| Right to restriction | Section 33 | 30 days |
| Right to data portability | Section 34 | 30 days, machine-readable format |
| Right to object | Section 32(1) | 30 days |
The 30-day clock is a frequent miss. The controller must also document the request, the response, and the reasoning for any refusal — those records are PDPC audit material.
DPIA for High-Risk Processing
Although the statute does not use the exact phrase, Section 37(1) requires the controller to provide appropriate security measures and the PDPC's guidelines require a Data Protection Impact Assessment (DPIA) for high-risk processing: large-scale sensitive data, systematic monitoring of public spaces, automated decision-making with legal effects, profiling of minors, large-scale biometric authentication. The DPIA must document the processing description, necessity and proportionality, risks to data subjects, and mitigations. Skipping the DPIA on a project that needed one is a regulator-flagged failing.
Retention and Records of Processing
Section 37(2) requires controllers to retain a Record of Processing Activities (ROPA). Section 37(3) requires deletion or anonymisation when the lawful basis expires. "Forever-retain everything" is unlawful — the retention schedule must be documented, defensible, and operationalised in IT systems.
Penalty Regime
| Category | Maximum | Source |
|---|---|---|
| Administrative fines per violation | THB 5,000,000 | Section 78 |
| Civil compensation (with punitive multiplier) | Up to 2× actual damages | Section 77 |
| Criminal — unlawful sensitive data disclosure | Up to 1 year and/or THB 1,000,000 | Section 79 |
| Criminal — non-compliance with PDPC orders | Up to 6 months and/or THB 500,000 | Section 89 |
Common Mistakes
Avoid these traps:
- Treating the consent banner as the compliance programme. Consent is one of seven lawful bases and often the wrong one.
- No DPA with cloud and ad-tech vendors. Marketing pixels, analytics, and CRM all process personal data; vendor terms-of-service rarely meet Section 40.
- No DPO when Section 41 triggers it. Hospitals and large e-commerce sites routinely qualify and routinely forget.
- 72-hour clock starts at awareness, not investigation completion. The clock keeps ticking while you triage.
- "Indefinite retention because we might need it." Section 37(3) makes that unlawful.
- Cross-border transfer with no Section 28 analysis. Sending HR data to a parent in a non-adequate jurisdiction is a high-frequency finding.
- Consent fatigue from re-asking under every base change. Consent must be specific and informed; layered notices are the lawful answer.
FAQs
1. Does my SME need a DPO?
Only if Section 41 triggers apply — large-scale monitoring, large-scale sensitive data, or public authority. Pure B2B service businesses rarely qualify but should still document the analysis.
2. Can the DPO be the IT manager?
Yes, provided there is no conflict of interest, the DPO has independent reporting to top management, and has time and competence for the role. Combining DPO with general-counsel or compliance officer is common.
3. What is "without undue delay" for high-risk breach notification to data subjects?
The PDPC has not fixed a number but consistently treats anything beyond 14 days as questionable; 7 days or sooner is the practical benchmark for clear high-risk breaches.
4. Are GDPR SCCs valid in Thailand?
Not automatically — but they are evidentially useful and the PDPC's draft SCCs are closely modelled on GDPR. Using GDPR SCCs as a baseline with a Thai PDPA addendum is the common practice pending formal PDPC clauses.
5. Can I rely on legitimate interests for everything?
No — legitimate interests requires a documented balancing test against data subject rights, cannot be used for sensitive data (Section 26), and must be available for PDPC inspection.
6. Does the PDPA apply to non-Thai entities?
Yes — it applies to controllers or processors outside Thailand if they offer goods or services to data subjects in Thailand, or monitor data subjects' behaviour in Thailand (Section 5 extraterritorial scope).
Related Reading
Professional Legal Assistance
blog.ctaContext
Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.
Stay Informed
Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.
We respect your privacy. Unsubscribe anytime.
feedback.wasThisHelpful