You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 20, 2020

COVID-19 Prevention Measures under Thailand’s Personal Data Protection Act

Measures to limit the spread of COVID-19 are being implemented in Thailand just as the country approaches the implementation of its landmark new Personal Data Protection Act (PDPA), which will come into effect in May 2020. This adds another layer of complexity to the COVID-19 issue, as employers find that they need to consider new categories of employee personal data, just as restrictions on doing so are due to come into force. From an employment perspective, employers are considered to be personal data controllers under the PDPA, and will thus be subject to extensive requirements when collecting, using, or disclosing employees’ personal data, once the PDPA comes into force.

To help employers stay compliant, we address below the most common questions about the legality of common COVID-19 prevention measures under the PDPA. Note that, while these FAQs specifically address issues for employers, the PDPA also protects the personal data of customers, business partners, vendors, and any other individuals whose data you might hold or process. Businesses should therefore be ready to comply with the PDPA in relation to all personal data that they hold.

Screening Measures: Checking Physical/Health Conditions

Can you check the temperature of visitors for the purpose of preventing the outbreak?

Yes.

Can you record their temperature? Can it be detailed with the individual’s personal data?

The temperature of visitors can be recorded, but the purpose should be communicated to the individuals, and it is imperative to keep information about a person’s COVID-19 status strictly confidential.

The data in question is considered to be personal data under the law, so retention of the data must be in strict compliance with the requirements and restrictions of the PDPA. Moreover, a person’s temperature reading, when combined with other personal data (e.g., name, contact information, physical symptoms), could be considered what the law terms “sensitive personal data,” for which the PDPA provides enhanced requirements, restrictions, and penalties.

Thus, it is preferable from a compliance point of view to refrain from recording the temperature of everyone entering the premises alongside their personal details. Regardless, the Communicable Disease Act also requires that this type of information, if retained or processed, be kept confidential and processed anonymously.

Forced Disclosure of Certain Physical or Health Conditions

Can you order your staff to disclose symptoms associated with COVID-19?

This is allowed under current data privacy and employment law, and employers may ask employees to disclose this information to HR. Employers can also require a health certificate or medical report.

Once the PDPA is fully effective, any such information already held may still be kept. However, restrictions on obtaining such sensitive personal data (i.e., health-related data) may need to be revisited.

Can you order your staff to disclose their travel history?

Yes—this is also allowable under both data privacy and employment regulations, and the requirement can be issued as a single announcement together with the requirement to disclose symptoms. This position will be unaffected by the PDPA.

Can you order your staff to disclose the travel history of their family members or close contacts?

Yes. However, it would be prudent to request this information only on a need-to-know basis—a practice referred to as “data minimization.”

If a COVID-19 Infection Is Confirmed

Can you publically communicate the presence of a confirmed case?

Yes. However, any data that could identify the infected individual should not be disclosed. All written communications should be carefully drafted, keeping in mind that information that might not identify an individual to one audience (such as the public) could identify them to another (such as coworkers).

Can you require (and retain) a medical certificate to confirm the case?

Yes. However, once the PDPA is fully effective, the infected individual, once fully recovered, is entitled to exercise his or her right to be forgotten.

RELATED INSIGHTS​ 

March 27, 2026
In response to the rapid advancement of artificial intelligence (AI) and evolving global digital trends, Thailand has undertaken significant efforts to establish a comprehensive national policy framework aimed at fostering an AI ecosystem. This framework seeks to promote the responsible development and deployment of AI technology to enhance Thailand’s economic competitiveness and improve quality of life, with targeted implementation by 2027. In furtherance of this national AI policy, regulatory authorities have initiated efforts to develop and refine the applicable legal framework, including the drafting of Thailand’s first unified AI legislation. Pending the composing and enactment of such comprehensive legislation, sector-specific regulators have proactively issued guidelines applicable to regulated entities within their respective jurisdictions, including financial institutions, banks, insurance companies, securities and derivatives business operators, and digital asset service providers. Concurrently, cross-sectoral regulatory bodies, notably the Personal Data Protection Committee (PDPC) and the National Cyber Security Agency (NCSA), have promulgated guidelines applicable to all business operators within their regulatory purview. While unified AI legislation has not been enacted, the design, development and use of AI in Thailand in various industries is still subject to existing sector-specific legislation. National AI policy The Thai cabinet approved the Thailand National AI Strategy and Action Plan (2022-2027) in July 2022, aiming to establish an AI development and application ecosystem by 2027. The strategy is built around five pillars: Preparing social, ethical, legal and regulatory readiness for AI; Developing national infrastructure; Increasing human capability and AI education; Driving AI technology and innovation; and Promoting AI adoption in public and private sectors. The above-mentioned national AI committee, under the National Digital Economy and Society Committee (NDESC), was established in August 2022, chaired by the prime minister. Comprehensive legislation Following the national AI strategy, the government has been developing comprehensive AI legislation to govern and promote AI
March 20, 2026
Thailand’s Board of Investment (BOI) now requires data center projects to demonstrate measurable benefits for local workforce development, R&D, SME capability, and domestic supply chains to qualify for corporate income tax (CIT) exemptions. BOI Notification No. Por. 3/2569, issued on February 6, 2026, updates the requirements for projects seeking promotion under BOI category 8.2.1 (data centers). All data center projects must now submit and implement plans covering development of Thai human resources and domestic supply chain support before benefiting from any CIT exemption. Human Resources Development Plan The BOI seeks to promote local talent development beyond basic training. Plans must include the following elements: Training for data center design, construction, and operations targeting vocational students, engineering and ICT undergraduates and postgraduates, and energy and building personnel in Thailand. Joint curricula with Thai universities and technical institutes. Collaborative R&D with Thai nationals or institutions in areas including AI, resource allocation, high-performance computing, and data center hardware and systems. Thai SME upskilling in electrical and energy systems and IT services. Domestic Supply Chain Support Plan Plans must demonstrate knowledge transfer in design, construction, cooling, security, and power and water management. Projects must also include usage or installation of domestically manufactured equipment or engage specialist domestic entities. Criteria for BOI Evaluation The BOI will assess data center operators’ eligibility for CIT incentives based on two criteria: Scale requirement: Training and joint-curriculum initiatives must reach a total participants equal to at least 10 times the project headcount and run for the duration of the CIT incentive. If this threshold is not met, the applicant must also implement continuous R&D or SME skills-development plans throughout the incentive period. Substantiality test: Supply-chain plans must be substantive, meet industry standards, and show measurable development of the domestic digital and data center supply base. To ensure compliance,
March 19, 2026
Thailand’s Electronic Transactions Development Agency (ETDA), which describes itself as a “co-creation regulator” working collaboratively with industry rather than imposing top-down rules, has unveiled its regulatory roadmap for digital platform businesses under the Royal Decree on Digital Platform Service Businesses B.E. 2565 (2022). The 2026 regulatory approach is guided by three core principles—“practicable, verifiable, shared responsibility”—aimed at elevating digital services to be safe, transparent, and fair. These principles inform ETDA’s 2026 priorities, which focus on three key dimensions: product and service standards on platforms, fair competition and fee transparency, and online fraud prevention. Product and Service Standards ETDA’s 2026 agenda addresses product and service standards across several platform categories: Online marketplace platforms. The Notification on Additional Measures for Online Marketplace Platforms under Section 18(2) came into force on December 31, 2025, designating 21 marketplace platforms that must verify products and merchants. Among other obligations, covered platforms must remove or suspend substandard products under the “notice and take down” principle. The ETDA has collaborated with the Food and Drug Administration and the Thai Industrial Standards Institute to develop inspection manuals and coordinate compliance procedures. Social commerce. The ETDA is preparing a new notification under Section 18(2) specifically targeting social commerce platforms with sales support functions, aiming to align regulation with evolving digital market conditions. Ride sharing. Since the postponement of the deadline to comply with the ETDA’s notification on ride-sharing platforms to March 31, 2026, the ETDA has supported drivers in registering with the Department of Land Transport through the Driver Verify registration system, which has already issued certifications to approximately 27,900 riders. The ETDA is also examining structural issues relating to appropriate insurance packages, motorcycle engine capacity expansion, and fair leasing fees and contract transfer costs in coordination with the Department of Land Transport, the Office of Insurance Commission,
March 19, 2026
Thailand’s Personal Data Protection Committee (PDPC) has launched a public consultation period to gather input for a forthcoming set of guidelines under the country’s Personal Data Protection Act (PDPA). This initiative follows the PDPC’s issuance of guidelines on consent and notification requirements in September 2022. The main consultation period, using an online questionnaire to gather feedback, runs until March 23, 2026. In addition, an interview-style online session for private-sector participants was held on March 17, and a two-day in-person event will be held on April 1–2—this is already fully booked and  walk-ins will not be accepted, but the session will be livestreamed on the PDPC’s Facebook page. The PDPC will use the public feedback to design draft guidelines that accurately reflect the operational realities of both public and private organizations, after which the guidelines will be shared with the public. Consultation Scope The PDPC has identified six priority areas for which upcoming guidance may be issued: Legal bases for processing: The online questionnaire assesses respondents’ understanding of consent requirements and seeks views on priority issues, such as explanations of the legal bases and considerations for selecting an appropriate legal basis depending on the nature of the processing activity. Security measures and data breach notification: The questionnaire examines respondents’ understanding of data breach reporting and security measure obligations. Topics proposed for inclusion in the guidelines include data breach prevention measures, incident response plans, risk assessment methods, and reporting procedures. Data protection officers: Respondents are invited to share their expectations regarding the DPO’s role and their experiences in contacting a DPO. The survey also asks respondents to identify priority issues, such as response timeframes for data subject requests and complaint procedures. Marketing and direct marketing: The online questionnaire seeks input on preferred topics for guidance, including individuals’ rights to refuse marketing