Educational Information Only
The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.
Case Study: PDPA Enforcement — Company Fined for Data Breach
A Thai company was fined THB 3 million for failing to protect customer personal data and not notifying the PDPC of a breach within 72 hours.
This case study is based on anonymized real-world situations and is presented for educational purposes only.
The Situation
An e-commerce company operating in Thailand suffered a data breach exposing personal information of 50,000 customers, including names, email addresses, phone numbers, and purchase histories. The breach was caused by inadequate security measures on the company's database server. The company did not notify the PDPC or affected customers for 3 weeks, well beyond the 72-hour requirement.
Legal Issues Involved
Failure to implement appropriate security measures (PDPA Section 37)
Failure to notify the PDPC of a data breach within 72 hours (PDPA Section 37(4))
Failure to notify affected data subjects without delay
Inadequate data protection impact assessment
What Happened (Process)
- 1
Breach discovered by security researcher who reported it publicly
- 2
PDPC initiated investigation after media reports
- 3
Company finally notified PDPC 21 days after the breach
- 4
PDPC Expert Committee reviewed evidence and security measures
- 5
Company ordered to submit remediation plan within 30 days
- 6
Administrative hearing held where company presented mitigation efforts
- 7
PDPC issued fine and corrective orders
Outcome
The company was fined THB 3 million — THB 2 million for inadequate security measures and THB 1 million for failure to notify within 72 hours. The company was ordered to implement specified security improvements within 90 days, appoint a Data Protection Officer, and provide free credit monitoring to affected customers for 1 year.
Key Lessons
The 72-hour breach notification requirement is strictly enforced.
Companies must implement 'appropriate' technical and organizational security measures.
Having a documented incident response plan is essential.
The PDPC considers the company's cooperation and remediation efforts when determining penalties.
Foreign companies processing Thai personal data are equally subject to enforcement.
Disclaimer: This case study is based on anonymized real-world situations and is presented for educational purposes only.
Professional Legal Assistance
When a matter involves investigation, arrest, detention, litigation, or regulatory action, professional legal representation becomes essential.
Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.
feedback.wasThisHelpful