You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 24, 2024

IAPP Global Legislative Predictions 2024 – Thailand

International Association of Privacy Professionals

Thailand’s Personal Data Protection Act came into full effect on 1 June 2022 and various subordinate regulations have since been issued by the Personal Data Protection Committee. These include regulations on security measures to be implemented by data controllers, data breach notification requirements, a mandatory obligation to appoint a data protection officer when the processing activity requires regular monitoring of personal data or a system due to the large scale of personal data, administrative measures and data processors’ record of processing activities.

As some areas under the PDPA still require further clarifications, a series of public consultations for the remaining draft subordinate regulations is anticipated in 2024. Potential areas include data protection impact assessments and cross-border transfers of personal data, which are crucial for organizations and particularly for entities with establishments in other jurisdictions.

PDPA enforcement by Thai regulators was silent until the last quarter of 2023, when the PDPC published details about complaints that have been lodged to the Expert Committee. The committee is designated by virtue of the PDPA and has the power to make determinations related to imposing administrative fines and other penalties. Enforcement in 2024 is expected to become more active and potentially more serious, which means organizations should pay closer attention to ensure compliance with the PDPA.

Similar to the GDPR, the PDPA also has extraterritorial effect. Once the subordinate regulation on international cooperation has been issued by the PDPC, this should clarify how PDPA enforcement against organizations located outside of Thailand will be conducted by Thai regulators.

With respect to sector-specific data protection legislation, in September 2023, Thailand’s National Broadcasting and Telecommunications Commission issued the Notification of the NBTC Re: Measures to Protect Telecommunications Service Users’ Rights in regard to Personal Data, Privacy Rights, and Freedom of Telecommunications, which replaces the previous notification. The notification aims to enhance the protection of personal data and privacy rights for telecommunication users and to align its data protection requirements with the provisions of the PDPA. The development of specific data protection laws for other sectors is still silent.

 

Athistha (Nop) Chitranukroh and Gvavalin Mahakunkitchareon provided this update as part of the “IAPP Global Legislative Predictions 2024” from the International Association of Privacy Professionals. Tilleke & Gibbins also provided the Vietnam update.

RELATED INSIGHTS​ 

August 23, 2024
Thailand’s Securities and Exchange Commission (SEC) amended its utility token supervisory framework by issuing seven notifications that came into effect on August 13, 2024. Ready-to-use utility tokens (tokens that can be used immediately to acquire specific goods or services), which were previously unregulated, are now subject to the supervisory scheme set forth by the seven new notifications in both primary and secondary markets. This is intended to provide an investor protection mechanism that responds to the characteristics, risks, and usage of the different types of ready-to-use utility tokens. Under the new notifications, ready-to-use utility tokens are categorized into two groups. These are detailed below. Group 1 Utility Tokens Group 1 utility tokens include ready-to-use utility tokens issued for consumption purposes or as a digital representation of a certificate. Examples include loyalty points, digital movie or concert tickets, NFTs, and carbon credits, among others. Principally, there is no change in the regulation of group 1 utility tokens under the new notifications. In the primary market, issuance of this type of token is not subject to the initial coin offering (ICO) requirements. In the secondary market, providing services related to group 1 utility tokens is not considered to be the same as operating a digital asset business with licensing requirements under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). Licensed digital asset operators (including exchanges, brokers, and dealers) are not permitted to list or trade group 1 utility tokens. To provide services in relation to group 1 utility tokens, these licensed digital asset operators must establish a separate entity to provide those services and must not use names or messages that could cause the public to misunderstand that the separate entity is engaged in a digital asset business under SEC supervision. Group 2 Utility Tokens Group 2 utility tokens
August 22, 2024
The Personal Data Protection Committee (PDPC) of Thailand’s Ministry of Digital Economy and Society (MDES) has announced the first administrative fine under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). A major private company was fined THB 7 million for noncompliance with specific PDPA requirements, resulting in the unauthorized disclosure of personal data to a call center gang (phone scam fraudsters). Key Findings of Noncompliance The PDPC determined that there were three key violations of specific requirements of the PDPA: Failure to appoint a data protection officer (DPO): Despite processing personal data for over 100,000 individuals as part of its core operations, the company did not appoint a DPO. Inadequate security measures: The company lacked the required security measures, leading to a data breach involving a call center gang, causing widespread damage. Delayed data breach notification: The company did not notify authorities of the data breach within the required timeframe and failed to address the breach promptly, making it impossible to remedy the situation. In addition to the monetary fine, the PDPC, along with the PDPA’s Expert Committee, issued a corrective order requiring the company to undertake the following actions and notify the Office of the PDPC of the relevant correction measures within seven days of receiving the order: Implement up-to-date security measures: The company must improve its current security measures to prevent future breaches and ensure that the security measures are up-to-date with changing technologies. Raise awareness of personnel: The company must provide training to relevant personnel to ensure awareness of data compliance and protection practices. This significant administrative action establishes a precedent for addressing data breaches in both governmental and commercial sectors in Thailand. It also confirms the importance of PDPA compliance, particularly the need for robust security measures, timely breach notifications, and the appointment of
August 15, 2024
On August 9, 2024, Thailand’s Electronic Transactions Development Agency (ETDA) opened a period for public feedback regarding the 2022 Royal Decree on Digital Platforms and its subregulations. To collect this feedback, the ETDA has prepared a 44-question survey on specific attributes of the royal decree and its requirements, covering issues such as the definition of digital platform services (DPSs), types of services that are subject to notification requirements, information that must be submitted annually, and the royal decree’s extraterritorial scope. Business operators that fall within the scope of the royal decree and wish to provide feedback on its effectiveness should prepare and submit the survey online to the ETDA by the end of August 2024. Royal Decree on Digital Platforms Thailand’s Royal Decree on Digital Platforms was published in the Government Gazette on December 22, 2022. It defines a DPS as any service that facilitates or mediates transactions between users through a digital platform, such as e-commerce, food delivery, ride-hailing, online travel agency, online payment provider, or social media platform. The decree requires DPS operators to notify the ETDA before commencing operations, with some limited exemptions. The decree also empowers the ETDA to issue notifications (i.e., subregulations) and guidelines for implementing the decree and to monitor and enforce compliance by DPS operators. The ETDA may impose administrative sanctions, such as warnings, fines, service suspension, or revocation of notification, for any violation of the royal decree or the ETDA’s subregulations. In-scope DPS operators should take this opportunity to provide comments to the ETDA in order to voice their opinions on the practicality of the requirements and support the regulator in shaping the requirements of the royal decree and its subregulations. For more information on this initiative from the ETDA, or on any aspect related to the Royal Decree on Digital
August 5, 2024
On June 28, 2024, Thailand’s Board of Investment (BOI) updated its list of promoted activities to include data hosting, which is listed as “Activity 8.2.4 Data Hosting Services.” Qualifying data hosting services are eligible for a corporate income tax exemption (capped) for eight years, along with other tax and nontax incentives, such as import duty exemption on imported machinery to be used in the project, the right for foreigners to own land, and work permit and visa facilitation for expats, among others. To be eligible for these BOI incentives, projects must: Provide services for leasing host servers for data storage (data hosting); Have at least two data centers located in Thailand that meet or exceed the ISO/IEC 27001 data center standards; and Have an investment amount (excluding cost of land and working capital) of at least THB 5 billion. Apart from the above specific criteria, projects also need to comply with the general BOI criteria, such as a debt-to-equity ratio no higher than 3:1, submission of a feasibility study report, and use of new machinery, among others. For more details on BOI incentives for software and data center activities, or on any aspect of investment promotion in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], or Napassorn Lertussavavivat at [email protected].