Educational Information Only — Not Legal Advice

    This site provides educational information only and is not a substitute for professional legal advice. Consult a qualified Thai lawyer for personalized guidance. Laws may change. Full DisclaimerPrivacy Policy

    Skip to main content
    Last updated:
    Share:

    Educational Information Only

    The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.

    Back to Case Studies
    Data Protection

    Case Study: PDPA Enforcement — Company Fined for Data Breach

    A Thai company was fined THB 3 million for failing to protect customer personal data and not notifying the PDPC of a breach within 72 hours.

    Updated:

    This case study is based on anonymized real-world situations and is presented for educational purposes only.

    The Situation

    An e-commerce company operating in Thailand suffered a data breach exposing personal information of 50,000 customers, including names, email addresses, phone numbers, and purchase histories. The breach was caused by inadequate security measures on the company's database server. The company did not notify the PDPC or affected customers for 3 weeks, well beyond the 72-hour requirement.

    What Happened (Process)

    1. 1

      Breach discovered by security researcher who reported it publicly

    2. 2

      PDPC initiated investigation after media reports

    3. 3

      Company finally notified PDPC 21 days after the breach

    4. 4

      PDPC Expert Committee reviewed evidence and security measures

    5. 5

      Company ordered to submit remediation plan within 30 days

    6. 6

      Administrative hearing held where company presented mitigation efforts

    7. 7

      PDPC issued fine and corrective orders

    Outcome

    The company was fined THB 3 million — THB 2 million for inadequate security measures and THB 1 million for failure to notify within 72 hours. The company was ordered to implement specified security improvements within 90 days, appoint a Data Protection Officer, and provide free credit monitoring to affected customers for 1 year.

    Key Lessons

    The 72-hour breach notification requirement is strictly enforced.

    Companies must implement 'appropriate' technical and organizational security measures.

    Having a documented incident response plan is essential.

    The PDPC considers the company's cooperation and remediation efforts when determining penalties.

    Foreign companies processing Thai personal data are equally subject to enforcement.

    Disclaimer: This case study is based on anonymized real-world situations and is presented for educational purposes only.

    Professional Legal Assistance

    When a matter involves investigation, arrest, detention, litigation, or regulatory action, professional legal representation becomes essential.

    Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.

    feedback.wasThisHelpful