Educational Information Only — Not Legal Advice

    This site provides educational information only and is not a substitute for professional legal advice. Consult a qualified Thai lawyer for personalized guidance. Laws may change. Full DisclaimerPrivacy Policy

    Skip to main content
    Thai LawKNOWLEDGE AUTHORITY
    Last updated:
    Share:

    Educational Information Only

    The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.

    Back to Legal News
    Regulatory Updates

    PDPA Violation Fines by Type in Thailand

    Thailand's PDPA imposes administrative fines up to THB 5 million per violation, criminal penalties under §79-83, and statutory civil compensation. This guide breaks down the fine ranges by violation type.

    6/15/20266 min read read
    PDPA
    fines
    data protection
    PDPC

    TL;DR

    The Personal Data Protection Act B.E. 2562 (2019), in force from 1 June 2022, imposes three layers of consequence: (1) administrative fines up to THB 5 million per violation, (2) criminal penalties under §79-83 (imprisonment up to 1 year + fines up to THB 1 million for sensitive-data misuse), and (3) civil compensation per Section 77, statutorily presumed against the controller / processor.

    Administrative Fines (Indicative, by §)

    ViolationSectionFine ceiling
    Failing to obtain lawful basis for processing§83(1)THB 1 million
    Failing to provide §23 privacy notice§83(2)THB 1 million
    Failing to honour data-subject rights (§30-36)§82(3)THB 3 million
    Cross-border transfer without lawful mechanism (§28-29)§83(4)THB 5 million
    Failure to notify breach within 72 hours (§37)§82(2)THB 3 million
    Failure to appoint DPO where required (§41)§82(4)THB 1 million

    Criminal Penalties (§79-83)

    • Using or disclosing sensitive personal data unlawfully for personal gain: imprisonment up to 1 year and / or fine up to THB 1 million.
    • Disclosing personal data obtained through duties: imprisonment up to 6 months and / or fine up to THB 500,000.
    • Causes injury through unlawful processing: courts factor harm in addition.

    Civil Compensation (§77)

    • Data-subject loss is statutorily presumed against the controller / processor.
    • Punitive damages up to 2x actual damages possible (§78).
    • Class-action via Consumer Protection Procedure Act framework may be available.

    Mitigation Factors

    • Demonstrated good-faith compliance programme.
    • Voluntary disclosure of breach to PDPC.
    • Cooperation with PDPC investigation.
    • Remedial measures taken within reasonable time.

    Common Mistakes

    • Assuming the foreign-incorporated SaaS controller is outside scope — PDPA has extraterritorial effect on Thai-data-subject processing.
    • Treating consent as the universal lawful basis — six bases exist; consent is often the weakest.
    • Missing the 72-hour breach notification window.

    FAQs

    1. Are fines per violation or per affected data subject?

    Per violation, but multiple-data-subject incidents can multiply.

    2. Can the PDPC reduce a fine?

    Yes — mitigation factors apply; settlement mechanism via PDPC.

    Related Reading

    Professional Legal Assistance

    blog.ctaContext

    Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.

    blog.templatePromo.title

    blog.templatePromo.description

    blog.templatePromo.cta

    Stay Informed

    Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.

    Subscribing does not create a lawyer-client relationship. Please don't include confidential information. Anglo Siam Law is an educational platform — for representation, contact Anglo Siam Legal.

    Topics you're interested in (optional)

    We respect your privacy. Unsubscribe anytime.

    feedback.wasThisHelpful