Educational Information Only — Not Legal Advice

    This site provides educational information only and is not a substitute for professional legal advice. Consult a qualified Thai lawyer for personalized guidance. Laws may change. Full DisclaimerPrivacy Policy

    Skip to main content
    Last updated:
    Share:

    Educational Information Only

    The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.

    Back to Legal News
    Regulatory Updates

    PDPA Implementation in Thailand: DPO Appointment, DPA Contracts, and 72-Hour Breach Notification

    Beyond the basics, Personal Data Protection Act B.E. 2562 (2019) compliance requires appointing a Data Protection Officer (DPO), executing Data Processing Agreements (DPAs) with processors, and notifying the PDPC within 72 hours of a personal data breach. This guide covers the operational implementation that organisations get wrong.

    5/19/202612 min read read
    PDPA
    DPO
    DPA
    breach-notification
    PDPC
    cross-border-transfer
    DPIA

    TL;DR

    Two years after the Personal Data Protection Act B.E. 2562 (2019) took full effect on 1 June 2022, the Personal Data Protection Committee Office (สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล / PDPC) has shifted from education to enforcement. The depth issues that catch organisations are not the consent banner — it is the operational triangle of (1) Data Protection Officer (DPO) appointment under Section 41, (2) Data Processing Agreements (DPAs) with processors under Sections 27 and 40, and (3) 72-hour breach notification under Section 37. Administrative fines run to THB 5 million per violation under Section 78, with criminal liability under Section 79 for wilful breach of PDPC orders. Cross-border transfers require an adequacy finding or specific safeguards under Section 28; data-subject rights (access, correction, erasure, portability) under Sections 30-34 have statutory response windows; high-risk processing triggers a Data Protection Impact Assessment (DPIA). The compliance programme is not optional and the PDPC has begun publishing decisions.

    The Statutory Framework Beyond the Basics

    The PDPA was enacted on 27 May 2019 as B.E. 2562 (2019) and, after pandemic-driven extensions, became fully effective on 1 June 2022. The substantive obligations sit in five clusters:

    • Sections 19-29: lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests, scientific research) and cross-border transfer rules.
    • Sections 30-36: data subject rights and the controller's response obligations.
    • Sections 37-40: security obligations, breach notification, and the controller-processor relationship.
    • Section 41: Data Protection Officer appointment triggers.
    • Sections 72-90: the penalty regime — administrative, criminal, and civil.

    DPO Appointment Under Section 41

    Section 41 makes DPO appointment mandatory in three scenarios:

    TriggerSourceTypical examples
    Public authoritySection 41(1)Ministries, state enterprises, local administrative organisations
    Core activities require regular monitoring of data subjects on a large scaleSection 41(2)Telcos, banks, hospitals, large e-commerce, ad-tech, security/CCTV operators
    Core activities involve large-scale sensitive personal data processingSection 41(3)Medical providers, biometric authentication, religion/political-opinion processors

    The DPO must have sufficient knowledge of data protection law and the organisation's processing, must be able to perform duties independently, and may be an employee or a contractor. The DPO's contact details must be published and notified to the PDPC. The DPO is the operational interface for data subject rights, breach response, and PDPC liaison — and a poorly briefed DPO is itself a finding-grade weakness in any audit.

    The Controller-Processor Boundary and DPAs (Sections 27 & 40)

    Section 27 imposes the lawful-basis obligation on the controller; Section 40 then governs the controller's relationship with processors. The controller must:

    • Use only processors that provide sufficient guarantees for PDPA compliance.
    • Execute a written contract — a Data Processing Agreement (DPA) — specifying subject matter, duration, nature and purpose of processing, types of personal data, categories of data subjects, and the controller's instructions.
    • Bind the processor to confidentiality, security measures, sub-processor controls, breach notification to the controller, deletion or return at end of contract, and audit rights.

    Standard SaaS terms of service almost never satisfy Section 40 without a PDPA addendum. Cross-border processors require additional Section 28 documentation.

    Breach Notification: The 72-Hour Clock (Section 37)

    Section 37(4) requires the controller to notify the PDPC of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of the breach, except where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is high-risk to data subjects (e.g., sensitive data exposure, large-scale financial impact), the controller must also notify affected data subjects without undue delay.

    StepStatutory deadlineWho acts
    Detection / awarenessT0 (clock starts)Security team / DPO
    Triage and risk assessmentT0 + 24 hours targetDPO + incident response
    PDPC notificationT0 + 72 hours (Section 37(4))DPO or controller representative
    Data subject notification (where high risk)"Without undue delay" — practical 7-14 daysCommunications + legal
    Remediation and post-incident reportPer PDPC follow-upWhole organisation

    The notification must describe the nature of the breach, categories and approximate numbers of data subjects and records affected, likely consequences, and measures taken or proposed. Knowing what to say in three days requires the IR plan to exist before the breach.

    Cross-Border Transfers Under Section 28

    Section 28 prohibits transferring personal data to a destination country that does not have adequate protection unless one of the listed safeguards applies: data subject's explicit consent after being informed of the inadequacy; performance of a contract with the data subject; performance of a contract in the data subject's interest; compliance with the law; vital interests; or binding corporate rules or other PDPC-approved mechanism. The PDPC has begun publishing draft standard contractual clauses (SCCs) aligning loosely with GDPR SCCs; until those are formalised, contract-by-contract Section 28 analyses are necessary.

    Data Subject Rights — Statutory Response Windows

    RightPDPA sectionResponse window
    Right of accessSection 3030 days (extendable with notice)
    Right to rectificationSection 3130 days
    Right to erasureSection 3230 days
    Right to restrictionSection 3330 days
    Right to data portabilitySection 3430 days, machine-readable format
    Right to objectSection 32(1)30 days

    The 30-day clock is a frequent miss. The controller must also document the request, the response, and the reasoning for any refusal — those records are PDPC audit material.

    DPIA for High-Risk Processing

    Although the statute does not use the exact phrase, Section 37(1) requires the controller to provide appropriate security measures and the PDPC's guidelines require a Data Protection Impact Assessment (DPIA) for high-risk processing: large-scale sensitive data, systematic monitoring of public spaces, automated decision-making with legal effects, profiling of minors, large-scale biometric authentication. The DPIA must document the processing description, necessity and proportionality, risks to data subjects, and mitigations. Skipping the DPIA on a project that needed one is a regulator-flagged failing.

    Retention and Records of Processing

    Section 37(2) requires controllers to retain a Record of Processing Activities (ROPA). Section 37(3) requires deletion or anonymisation when the lawful basis expires. "Forever-retain everything" is unlawful — the retention schedule must be documented, defensible, and operationalised in IT systems.

    Penalty Regime

    CategoryMaximumSource
    Administrative fines per violationTHB 5,000,000Section 78
    Civil compensation (with punitive multiplier)Up to 2× actual damagesSection 77
    Criminal — unlawful sensitive data disclosureUp to 1 year and/or THB 1,000,000Section 79
    Criminal — non-compliance with PDPC ordersUp to 6 months and/or THB 500,000Section 89

    Common Mistakes

    Avoid these traps:
    • Treating the consent banner as the compliance programme. Consent is one of seven lawful bases and often the wrong one.
    • No DPA with cloud and ad-tech vendors. Marketing pixels, analytics, and CRM all process personal data; vendor terms-of-service rarely meet Section 40.
    • No DPO when Section 41 triggers it. Hospitals and large e-commerce sites routinely qualify and routinely forget.
    • 72-hour clock starts at awareness, not investigation completion. The clock keeps ticking while you triage.
    • "Indefinite retention because we might need it." Section 37(3) makes that unlawful.
    • Cross-border transfer with no Section 28 analysis. Sending HR data to a parent in a non-adequate jurisdiction is a high-frequency finding.
    • Consent fatigue from re-asking under every base change. Consent must be specific and informed; layered notices are the lawful answer.

    FAQs

    1. Does my SME need a DPO?

    Only if Section 41 triggers apply — large-scale monitoring, large-scale sensitive data, or public authority. Pure B2B service businesses rarely qualify but should still document the analysis.

    2. Can the DPO be the IT manager?

    Yes, provided there is no conflict of interest, the DPO has independent reporting to top management, and has time and competence for the role. Combining DPO with general-counsel or compliance officer is common.

    3. What is "without undue delay" for high-risk breach notification to data subjects?

    The PDPC has not fixed a number but consistently treats anything beyond 14 days as questionable; 7 days or sooner is the practical benchmark for clear high-risk breaches.

    4. Are GDPR SCCs valid in Thailand?

    Not automatically — but they are evidentially useful and the PDPC's draft SCCs are closely modelled on GDPR. Using GDPR SCCs as a baseline with a Thai PDPA addendum is the common practice pending formal PDPC clauses.

    5. Can I rely on legitimate interests for everything?

    No — legitimate interests requires a documented balancing test against data subject rights, cannot be used for sensitive data (Section 26), and must be available for PDPC inspection.

    6. Does the PDPA apply to non-Thai entities?

    Yes — it applies to controllers or processors outside Thailand if they offer goods or services to data subjects in Thailand, or monitor data subjects' behaviour in Thailand (Section 5 extraterritorial scope).

    Related Reading

    Professional Legal Assistance

    blog.ctaContext

    Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.

    blog.templatePromo.title

    blog.templatePromo.description

    blog.templatePromo.cta

    Stay Informed

    Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.

    Subscribing does not create a lawyer-client relationship. Please don't include confidential information. Anglo Siam Law is an educational platform — for representation, contact Anglo Siam Legal.

    Topics you're interested in (optional)

    We respect your privacy. Unsubscribe anytime.

    feedback.wasThisHelpful