You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 30, 2026

Key Takeaways from Thailand’s Data Privacy Day 2026

Thailand’s Data Privacy Day 2026, hosted by the Office of the Personal Data Protection Committee (PDPC), underscored the country’s commitment to strengthening personal data protection, advancing regulatory maturity, and preparing organizations for the next phase of PDPA enforcement. The event marked a clear shift from policy-level compliance toward “Privacy in Action,” signaling that operational readiness and real-world implementation are now priorities.

The Office of the PDPC also emphasized that data protection is now a national economic enabler that supports digital trust, competitiveness, and sustainable growth, not just a compliance obligation.

The following insights summarize the key takeaways from the Data Privacy Day 2026 event.

PDPA in Real Life: What Happens to Your Data Today

The Office of the PDPC provided concrete data on enforcement trends and real-world compliance issues facing organizations across Thailand.

Complaints and trends. The Office of the PDPC’s Personal Data Protection Act (PDPA) Center recorded 2,672 PDPA-related complaints as of January 2026, with the highest volumes involving failure to comply with the data minimization principle, collection without lawful basis, and use and disclosure without lawful basis.

Administrative penalties. Several administrative penalties have been imposed on data controllers and data processors across various sectors, including government, healthcare, retail, SMEs and e-commerce, ranging from tens of thousands to several million baht. Most violations stemmed from weak security measures, failure to notify data breaches within the required timeline, absence of a data protection officer (DPO) when required, and noncompliance with governance requirements such as the Record of Processing Activities (ROPA) and data processing agreements with data processors.

Case studies. The Office of the PDPC highlighted specific examples of violations:

  • Hospitals misused personal data for purposes beyond their intended scope (e.g., using personal data collected for providing medical services to send birthday cards)
  • Vendors compromised systems due to inadequate password protocols and the absence of firewalls, resulting in unauthorized access

AI and Privacy: Regulatory Expectations in the Emerging Landscape

Thailand is moving toward a clearer regulatory framework for AI, with the AI Act currently in draft form. While the PDPA does not regulate AI itself, it governs personal data used within AI systems, meaning organizations, not the AI, remain fully accountable for any misuse or unlawful processing of personal data.

Key expectations highlighted for businesses include:

  • The use of AI is allowed, but accountability remains fundamental. Organizations must take full responsibility for how personal data is processed through AI systems.
  • Strong resource and access governance is necessary. Organizations must prevent uncontrolled AI usage and avoid over-sharing of data through proper data classification to restrict AI access to relevant datasets.
  • AI deployment may trigger obligations under other laws. While there is currently no specific law regulating the use of AI, AI deployment may trigger obligations under civil and commercial law, road traffic laws in relation to autonomous systems, and other regulations, reinforcing the need for comprehensive risk assessment.
  • Alignment with forthcoming guidelines. The Office of the PDPC is currently developing practical guidelines on personal data protection in the use and development of AI technologies. Organizations should align AI use with these forthcoming guidelines aimed at supporting safe innovation while adhering to PDPA requirements.

International Cooperation and Cross-Border Transfers

Efforts continue to advance Thailand’s participation in the Global Cross-Border Privacy Rules (CBPR) and strengthen alignment with regional data-protection frameworks. Organizations operating across borders should expect tighter scrutiny of cross-border transfers, including more rigorous requirements for risk assessments and transfer impact analyses to ensure compliance in multi-jurisdictional environments.

Data Breach Incident Monitoring

The PDPC Eagle Eye, a division within the Office of the PDPC, has launched advanced tools such as the PDPC Eagle Eye Crawler, which enables continuous URL access and facilitates 24-hour monitoring of data breach incidents. Additionally, the PDPC Eagle Eye shared details about their plan to send inspection letters to organizations for advisory reasons.

Privacy Maturity Model and Privacy Index

The Office of the PDPC introduced new tools to help organizations assess and improve their data protection practices.

The Privacy Maturity Model assesses an organization’s readiness for personal data protection. The Privacy Index measures data protection levels using both privacy data (such as survey results and Privacy Maturity Model scores) and secondary data (like public information), giving organizations an overview of their privacy risk management capabilities.

Information derived from the Privacy Maturity Model and Privacy Index can then be used toward obtaining the Personal Data Protection Certification Mark, an upcoming certification program to recognize compliant organizations.

Outlook for 2026

Based on the Office of the PDPC’s roadmap and expert discussions during the Data Privacy Day event, organizations should expect several key developments in the coming year:

  • Data privacy must go beyond policy and legal compliance to practical implementation in all systems and operations.
  • Heightened enforcement, driven by expanded automated surveillance capabilities such as the PDPC Eagle Eye Crawler and the rollout of inspection letters for advisory purposes.
  • Stronger national PDPA infrastructure, with continued development of PDPA Centers and Trustmark certification.
  • Closer alignment with international privacy standards, supporting Thailand’s role in cross-border digital trade and strengthened mechanisms to support trusted cross-border data flows.
  • Increased regulatory attention on AI governance, with forthcoming guidance to ensure AI use complies with data-protection principles and standards.
  • A nationwide push toward a “new data-ethics culture” emphasizing legal compliance, incident prevention, organizational cooperation, and the use of technology to strengthen national and public trust, anchored in the national goal of improving data security, attracting investments, and enhancing quality of life.

Organizations should treat 2026 as a critical year for operationalizing privacy compliance, building robust governance frameworks, and preparing for more active regulatory oversight. The shift from policy to practice means that demonstrable implementation, not just documentation, will be the standard by which compliance is measured.

RELATED INSIGHTS​ 

July 1, 2025
Now halfway through 2025, Thailand continues to advance in the realm of data privacy, with the ambitious goal of achieving zero data breaches. The Personal Data Protection Committee (PDPC), an independent government body established by the Personal Data Protection Act (PDPA), is taking a more proactive approach, having published several rulings and orders to enhance data protection measures and clarify compliance expectations for businesses. Here is a look back at Thailand’s data privacy developments in the first half of the year. Strengthening Law Enforcement and New Guidance for Compliance Enforcement of existing data protection laws and regulations has taken a step forward this year. Some of the specific initiatives include: Increased enforcement by the PDPC. A key trend to watch from the first half of 2025 is the PDPC’s active enforcement of the PDPA as it intensifies oversight through compliance orders and public warnings against noncompliant organizations while ramping up efforts to prevent and halt the illegal trading of personal data by actively monitoring emerging societal issues. Call center scams and cyber fraud control. Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Orders from the Expert Committee. Several orders issued by the Expert Committee under the PDPA were announced in the first half of this year. These include directives for data controllers to take corrective actions to comply with the PDPA, as well as initiatives to raise awareness of data privacy within organizations, reflecting the regulator’s focus on promoting organizational awareness and compliance. A guideline report summarizing the Expert Committee’s decisions and orders was also published to serve as a reference for compliance. Public issue monitoring. The PDPC has been taking a more proactive approach
June 27, 2025
Three American giants are actively protecting their intellectual property rights against generative AI, as two legal battles commence on both sides of the Atlantic. In the UK, Seattle-based media company Getty Images accuses UK-based Stability AI of multiple IP infringements. In the US, The Walt Disney Company and Universal Studios are teaming up against Midjourney, an AI startup, with their main ground being copyright infringement. Both cases are centered around questions legal minds have been posing since the introduction of generative AI: Is the output of generative AI an infringement? And who is ultimately responsible for the output, the platform or the user? Getty Images v. Stability AI Getty initially filed a claim in the High Court in 2023, which resulted in Stability applying for reverse summary judgment on the grounds that Getty had no real prospect of success, arguing that their operations took place outside the UK. However, the High Court judge hearing the case decided that the claims brought by Getty did have a real prospect of succeeding in court. Despite this, Stability saw a small victory when the court ruled that the representative action brought by Getty would not succeed due to the difficulties in identifying who qualified for the class. The proposed class was comprised of 50,000 rightsholders who alleged their rights were also infringed. Stability was successful in arguing that identifying these individuals would be challenging due to the unclear definition of the class. This current trial is centered around four main grounds: Copyright infringement. Getty accuses Stability of using content that Getty owns or has an exclusive license for when training their model, Stable Diffusion, resulting in the generated output containing substantial parts of that content. Getty is also alleging secondary copyright infringement, arguing that Stability is importing an article into the UK
June 26, 2025
Vietnam’s new Personal Data Protection Law (PDPL) was passed by the National Assembly on June 26, 2025, and will enter into force on January 1, 2026. The PDPL introduces several new concepts, exemptions, and obligations in comparison with the current Decree No. 13/2023/ND-CP on personal data protection (PDPD), while other contents remain essentially the same. The relationship between the PDPD and the PDPL has not been clearly addressed; however, it is expected that the government will issue a new decree providing necessary guidance on certain requirements under the PDPL, and the PDPD will remain in effect until it is replaced by this new decree. Some key points of the new PDPL include the following: Personal data will be further defined by lists of basic personal data and sensitive personal data to be issued by the government. The consent-centric approach of the PDPD remains in place, along with additional exemptions for certain data processing activities. The requirements for the data processing impact assessment (DPIA) and transfer impact assessment (TIA) remain unchanged. However, there are new exemptions for the TIA, including for the processing and storing in the cloud of employee data, and when the data subject is the person sending its own data outside of Vietnam. Consent obtained under the PDPD remains valid under the PDPL. DPIAs and TIAs submitted under the PDPD are valid under the PDPL but may need to be updated to be in line with the requirements of the PDPL. Administrative fines depend on the type of violation. The fine for sale and purchase of personal data will be 10 times the revenue from the sale or VND 3 billion (about USD 115,000), whichever is higher. The fine for cross-border transfer violations is 5% of the violator’s revenue of the preceding year or VND 3 billion,
June 25, 2025
Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption. The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight. For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues. The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks. Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully. Risks of GenAI Use The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant: Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training.