You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 24, 2024

IAPP Global Legislative Predictions 2024 – Thailand

International Association of Privacy Professionals

Thailand’s Personal Data Protection Act came into full effect on 1 June 2022 and various subordinate regulations have since been issued by the Personal Data Protection Committee. These include regulations on security measures to be implemented by data controllers, data breach notification requirements, a mandatory obligation to appoint a data protection officer when the processing activity requires regular monitoring of personal data or a system due to the large scale of personal data, administrative measures and data processors’ record of processing activities.

As some areas under the PDPA still require further clarifications, a series of public consultations for the remaining draft subordinate regulations is anticipated in 2024. Potential areas include data protection impact assessments and cross-border transfers of personal data, which are crucial for organizations and particularly for entities with establishments in other jurisdictions.

PDPA enforcement by Thai regulators was silent until the last quarter of 2023, when the PDPC published details about complaints that have been lodged to the Expert Committee. The committee is designated by virtue of the PDPA and has the power to make determinations related to imposing administrative fines and other penalties. Enforcement in 2024 is expected to become more active and potentially more serious, which means organizations should pay closer attention to ensure compliance with the PDPA.

Similar to the GDPR, the PDPA also has extraterritorial effect. Once the subordinate regulation on international cooperation has been issued by the PDPC, this should clarify how PDPA enforcement against organizations located outside of Thailand will be conducted by Thai regulators.

With respect to sector-specific data protection legislation, in September 2023, Thailand’s National Broadcasting and Telecommunications Commission issued the Notification of the NBTC Re: Measures to Protect Telecommunications Service Users’ Rights in regard to Personal Data, Privacy Rights, and Freedom of Telecommunications, which replaces the previous notification. The notification aims to enhance the protection of personal data and privacy rights for telecommunication users and to align its data protection requirements with the provisions of the PDPA. The development of specific data protection laws for other sectors is still silent.

 

Athistha (Nop) Chitranukroh and Gvavalin Mahakunkitchareon provided this update as part of the “IAPP Global Legislative Predictions 2024” from the International Association of Privacy Professionals. Tilleke & Gibbins also provided the Vietnam update.

RELATED INSIGHTS​ 

December 27, 2022
Thailand has issued the Royal Decree on Digital Platforms, which was published in the Government Gazette on December 22, 2022. The royal decree provides a grace period of 240 days from its publication for digital platform providers to take the actions necessary to ensure compliance. The key requirements are outlined below. Definitions After going through various amendments in its draft stages, the published royal decree’s definition of “digital platform” refers to the provision of an electronic intermediary platform that manages information to create connections between “merchants,” “consumers,” and “users” via a computer network in order to create electronic transactions—regardless of whether payment is actually made. However, this does not include digital platforms that offer goods or services of the digital platform operator or an affiliated company acting as its representative, regardless of whether the goods or services are offered to third parties or to affiliated companies. Notification Exemption Under the royal decree, a digital platform provider under the supervision of other authorities, such as the Bank of Thailand and the Securities and Exchange Commission, or falling under the Electronic Transactions Commission’s list of exempted digital platform providers is exempted from the requirement to notify the Electronic Transactions Development Agency (ETDA) of the operation of its digital platform. The commission may also exempt any other digital platform service as it sees fit. Extraterritorial Effect Certain digital platforms located outside Thailand are subject to the royal decree and must appoint a coordinating person in Thailand. This requirement to appoint a local coordinator does not mean that overseas digital platforms have to establish their business in Thailand. Digital Platform Certification Mark The royal decree introduces an ETDA certification mark for digital platforms. Display of the mark appears not to be mandatory, but more specific rules, procedures, and other details will be prescribed
December 23, 2022
On December 15, 2022, Thailand’s Personal Data Protection Committee (PDPC) issued the Notification on the Criteria and Procedures for Handling Personal Data Breaches. What Constitutes a “Data Breach”? A “personal data breach” refers to a breach of security measures that causes unlawful or unauthorized loss, access, use, modification, or disclosure of personal data, resulting from an intentional, willful, negligent, accidental, unauthorized, or unlawful act, or an act related to computer crimes, cyber threats, mistakes or accidents, or any other act. The notification also classifies personal data breaches into three categories: confidentiality breach, integrity breach, and availability breach. Upon being informed of an actual or suspected personal data breach, a data controller must take the following actions: To the extent possible, assess the reliability of the information and investigate the facts related to the personal data breach, including all aspects concerning security measures, such as organizational measures, technical measures, and physical measures; Conduct a data breach assessment to consider whether the personal data breach is likely to result in a risk to an individual’s rights and freedom; Notify the Office of the PDPC, any affected data subjects, or both as required; and Take necessary and appropriate action to prevent further consequences resulting from the personal data breach. Breach Assessment When conducting a data breach assessment, the following factors must be taken into account if there is a risk to an individual’s rights and freedom. Nature and the type of data breach; Nature, type, and volume of personal data involved; Nature, type, and status of the affected data subject; Severity of the consequences of the personal data breach for any affected data subjects, and the effectiveness of the measures taken to prevent the data breach; Impact of the data breach on the operation of the business or on the public; Storage
December 2, 2022
On November 11, 2022, Myanmar’s Ministry of Commerce (MOC) announced a pilot period for importing electric vehicles into Myanmar, which came into force with MOC Order No. 62/2022, issued under the Import and Export Law. A separate order (No. 61/2022) issued on the same day specifies rules for importation of motorcycles by companies that do not have a certificate to open a showroom, as well as rules for opening motorcycle showrooms. Electric Vehicle Importation According to the order, which takes effect January 1, 2023, “electric vehicles” includes only battery electric vehicles (BEVs) for both personal use and passenger use. In order to import electric vehicles into Myanmar without having a certificate to open a showroom, companies must: Be registered as a company, either wholly owned by nationals or a joint venture, at the Directorate of Investment and Company Administration (DICA); Be able to present the purchase and sales agreement for each brand of imported electric vehicles; Receive approval from the National Steering Committee for Development of Electric Vehicles and Associated Businesses, and import according to the quality and quantity of electric vehicles permitted by the committee; Arrange the necessary warranty, spare parts availability, and after-sales service for the imported electric vehicles; Deposit a bank guarantee of MMK 50 million at a bank recognized by the Central Bank of Myanmar; and Apply for a purchase permit at the MOC, for the purpose of registering the imported vehicles with the Road Transport Administration Department. BEV Tax Exemption Following MOC Order No. 62/2022, BEVs and their batteries are now exempted from commercial tax and special goods tax, which came into force with the Law Amending the Union Tax Law 2022 (State Administrative Council Law No. 48/2022) dated November 17, 2022. These tax exemptions will be effective from October 1, 2022, to March
November 4, 2022
Lawyers from Tilleke & Gibbins in Cambodia, Laos, Myanmar, Thailand, and Vietnam have contributed to the new Multilaw Global Checklist for Monitoring Staff Data, which compiles essential information on regulations related to collection of data on employees. Such collection of data is an increasingly important concern for employers and entrepreneurs as the world pays closer attention to diversity, equality, and antidiscrimination in the workplace. The checklist contains fundamental information for each jurisdiction on legal considerations pertaining to employment diversity surveys and what can and cannot be asked. The table-style list is global in scope, with a separate line for each jurisdiction. The jurisdictional entries are grouped by region, allowing the reader to quickly compare how various countries treat different issues in each part of the world. In each column is a common question about how employers can monitor staff data in full compliance with the law, covering issues such as: Requesting data from employees; Type and format of data captured; Data storage and access; Retention of data; Intra-group cross-border data transfers; and Specific considerations for each jurisdiction. Multilaw, of which Tilleke & Gibbins is a member, is a global network of carefully selected, independent law firms consisting of over 10,000 commercial lawyers in more than 100 countries, able to provide expert legal advice in complex environments around the globe. The full checklist is available for free on the Multilaw website.