Educational Information Only — Not Legal Advice

    This site provides educational information only and is not a substitute for professional legal advice. Consult a qualified Thai lawyer for personalized guidance. Laws may change. Full DisclaimerPrivacy Policy

    Skip to main content
    Thai LawKNOWLEDGE AUTHORITY
    Last updated:
    Share:

    Educational Information Only

    The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.

    Back to Legal News
    Regulatory Updates

    Thai Data Localisation + Cross-Border Transfer Rules

    Thailand has no general data-localisation requirement — but sectoral rules (BOT, OIC, NBTC) apply, and PDPA §28-29 governs cross-border transfer of personal data. This guide explains the patchwork.

    6/15/20265 min read read
    PDPA
    data localisation
    cross-border transfer
    BOT

    TL;DR

    Thailand has no general data-localisation requirement. Sectoral rules (BOT for banks, OIC for insurers, NBTC for telcos) impose specific localisation or notification for sensitive operational data. The PDPA §28-29 governs cross-border transfer of personal data — requiring an adequacy assessment by PDPC, binding contractual clauses, consent, or other lawful mechanisms.

    PDPA Cross-Border Transfer Mechanisms

    MechanismPDPA SectionNotes
    Adequacy by PDPC§28Country recognised — limited list to date
    Standard contractual clauses§29(1)PDPC-approved clauses
    Binding corporate rules§29(2)For intra-group transfers
    Consent§29(3)Informed + specific
    Performance of contract§29(4)Necessary for the contract
    Public interest / vital interest / legal claim§29(5-7)Narrow

    Sectoral Localisation Examples

    • BOT — bank core systems with operational-resilience requirements.
    • OIC — insurer policy data backup.
    • NBTC — telco subscriber records (under SIM-registration rules).
    • Healthcare — sensitive records subject to enhanced safeguards.

    Operational Programme

    1. Data inventory + lawful-basis mapping.
    2. Identify all cross-border flows.
    3. Select PDPA §29 mechanism per flow.
    4. Sectoral overlay check.
    5. Annual review + record-keeping.

    Common Mistakes

    • Assuming consent is the universal mechanism.
    • Missing sectoral overlay for banks / insurers / telcos.
    • Not documenting BCRs / SCCs.
    • Onward transfer ignored.

    FAQs

    1. Are SCCs available?

    PDPC has published model contractual clauses; sector-specific guidance evolves.

    Related Reading

    Professional Legal Assistance

    blog.ctaContext

    Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.

    blog.templatePromo.title

    blog.templatePromo.description

    blog.templatePromo.cta

    Stay Informed

    Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.

    Subscribing does not create a lawyer-client relationship. Please don't include confidential information. Anglo Siam Law is an educational platform — for representation, contact Anglo Siam Legal.

    Topics you're interested in (optional)

    We respect your privacy. Unsubscribe anytime.

    feedback.wasThisHelpful