Educational Information Only
The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.
PDPA Violation Fines by Type in Thailand
Thailand's PDPA imposes administrative fines up to THB 5 million per violation, criminal penalties under §79-83, and statutory civil compensation. This guide breaks down the fine ranges by violation type.
TL;DR
The Personal Data Protection Act B.E. 2562 (2019), in force from 1 June 2022, imposes three layers of consequence: (1) administrative fines up to THB 5 million per violation, (2) criminal penalties under §79-83 (imprisonment up to 1 year + fines up to THB 1 million for sensitive-data misuse), and (3) civil compensation per Section 77, statutorily presumed against the controller / processor.
Administrative Fines (Indicative, by §)
| Violation | Section | Fine ceiling |
|---|---|---|
| Failing to obtain lawful basis for processing | §83(1) | THB 1 million |
| Failing to provide §23 privacy notice | §83(2) | THB 1 million |
| Failing to honour data-subject rights (§30-36) | §82(3) | THB 3 million |
| Cross-border transfer without lawful mechanism (§28-29) | §83(4) | THB 5 million |
| Failure to notify breach within 72 hours (§37) | §82(2) | THB 3 million |
| Failure to appoint DPO where required (§41) | §82(4) | THB 1 million |
Criminal Penalties (§79-83)
- Using or disclosing sensitive personal data unlawfully for personal gain: imprisonment up to 1 year and / or fine up to THB 1 million.
- Disclosing personal data obtained through duties: imprisonment up to 6 months and / or fine up to THB 500,000.
- Causes injury through unlawful processing: courts factor harm in addition.
Civil Compensation (§77)
- Data-subject loss is statutorily presumed against the controller / processor.
- Punitive damages up to 2x actual damages possible (§78).
- Class-action via Consumer Protection Procedure Act framework may be available.
Mitigation Factors
- Demonstrated good-faith compliance programme.
- Voluntary disclosure of breach to PDPC.
- Cooperation with PDPC investigation.
- Remedial measures taken within reasonable time.
Common Mistakes
- Assuming the foreign-incorporated SaaS controller is outside scope — PDPA has extraterritorial effect on Thai-data-subject processing.
- Treating consent as the universal lawful basis — six bases exist; consent is often the weakest.
- Missing the 72-hour breach notification window.
FAQs
1. Are fines per violation or per affected data subject?
Per violation, but multiple-data-subject incidents can multiply.
2. Can the PDPC reduce a fine?
Yes — mitigation factors apply; settlement mechanism via PDPC.
Related Reading
Professional Legal Assistance
blog.ctaContext
Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.
Stay Informed
Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.
We respect your privacy. Unsubscribe anytime.
feedback.wasThisHelpful