Educational Information Only — Not Legal Advice

    This site provides educational information only and is not a substitute for professional legal advice. Consult a qualified Thai lawyer for personalized guidance. Laws may change. Full DisclaimerPrivacy Policy

    Skip to main content
    Last updated:
    Share:

    Educational Information Only

    The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.

    Back to Legal News
    Regulatory Updates

    Thai Data Localisation + Cross-Border Transfer Rules

    Thailand has no general data-localisation requirement — but sectoral rules (BOT, OIC, NBTC) apply, and PDPA §28-29 governs cross-border transfer of personal data. This guide explains the patchwork.

    6/15/20265 min read read
    PDPA
    data localisation
    cross-border transfer
    BOT

    TL;DR

    Thailand has no general data-localisation requirement. Sectoral rules (BOT for banks, OIC for insurers, NBTC for telcos) impose specific localisation or notification for sensitive operational data. The PDPA §28-29 governs cross-border transfer of personal data — requiring an adequacy assessment by PDPC, binding contractual clauses, consent, or other lawful mechanisms.

    PDPA Cross-Border Transfer Mechanisms

    MechanismPDPA SectionNotes
    Adequacy by PDPC§28Country recognised — limited list to date
    Standard contractual clauses§29(1)PDPC-approved clauses
    Binding corporate rules§29(2)For intra-group transfers
    Consent§29(3)Informed + specific
    Performance of contract§29(4)Necessary for the contract
    Public interest / vital interest / legal claim§29(5-7)Narrow

    Sectoral Localisation Examples

    • BOT — bank core systems with operational-resilience requirements.
    • OIC — insurer policy data backup.
    • NBTC — telco subscriber records (under SIM-registration rules).
    • Healthcare — sensitive records subject to enhanced safeguards.

    Operational Programme

    1. Data inventory + lawful-basis mapping.
    2. Identify all cross-border flows.
    3. Select PDPA §29 mechanism per flow.
    4. Sectoral overlay check.
    5. Annual review + record-keeping.

    Common Mistakes

    • Assuming consent is the universal mechanism.
    • Missing sectoral overlay for banks / insurers / telcos.
    • Not documenting BCRs / SCCs.
    • Onward transfer ignored.

    FAQs

    1. Are SCCs available?

    PDPC has published model contractual clauses; sector-specific guidance evolves.

    When You Can Send Personal Data Abroad

    Cross-border transfers are governed by Sections 28–29 of the Personal Data Protection Act B.E. 2562 (2019). As a general rule, personal data may be transferred to a destination country or international organisation only where that destination has an adequate level of protection, as assessed against PDPC criteria. Where adequacy is not established, the transfer can still be lawful if the data controller or processor has put in place appropriate safeguards — for example binding corporate rules (BCRs) approved by the PDPC, or standard contractual clauses (SCCs) — that make enforceable rights and effective remedies available to the data subject.

    The Exceptions

    Even without adequacy or safeguards, a transfer may proceed on limited statutory grounds: the data subject's informed consent (having been told of the possible inadequacy at the destination), performance of a contract with or for the data subject, compliance with a legal obligation, protection of vital interests, or an important public interest. Thailand does not impose a blanket "data localisation" mandate on all businesses, but sector rules (for example in banking or telecommunications) can require certain data to be kept or processed locally, so the transfer analysis should be done alongside any sector-specific requirement. Document the legal basis, the safeguard used, and any onward-transfer terms — regulators expect a clear paper trail.

    2. Do intra-group transfers still need safeguards?

    Yes. Sending data to an overseas parent or affiliate is a cross-border transfer, so it needs an adequacy finding, BCRs/SCCs, or one of the exceptions — being in the same corporate group is not itself a legal basis.

    Related Reading

    Professional Legal Assistance

    blog.ctaContext

    Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.

    blog.templatePromo.title

    blog.templatePromo.description

    blog.templatePromo.cta

    Stay Informed

    Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.

    Subscribing does not create a lawyer-client relationship. Please don't include confidential information. Anglo Siam Law is an educational platform — for representation, contact Anglo Siam Legal.

    Topics you're interested in (optional)

    We respect your privacy. Unsubscribe anytime.

    feedback.wasThisHelpful