You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 30, 2026

Key Takeaways from Thailand’s Data Privacy Day 2026

Thailand’s Data Privacy Day 2026, hosted by the Office of the Personal Data Protection Committee (PDPC), underscored the country’s commitment to strengthening personal data protection, advancing regulatory maturity, and preparing organizations for the next phase of PDPA enforcement. The event marked a clear shift from policy-level compliance toward “Privacy in Action,” signaling that operational readiness and real-world implementation are now priorities.

The Office of the PDPC also emphasized that data protection is now a national economic enabler that supports digital trust, competitiveness, and sustainable growth, not just a compliance obligation.

The following insights summarize the key takeaways from the Data Privacy Day 2026 event.

PDPA in Real Life: What Happens to Your Data Today

The Office of the PDPC provided concrete data on enforcement trends and real-world compliance issues facing organizations across Thailand.

Complaints and trends. The Office of the PDPC’s Personal Data Protection Act (PDPA) Center recorded 2,672 PDPA-related complaints as of January 2026, with the highest volumes involving failure to comply with the data minimization principle, collection without lawful basis, and use and disclosure without lawful basis.

Administrative penalties. Several administrative penalties have been imposed on data controllers and data processors across various sectors, including government, healthcare, retail, SMEs and e-commerce, ranging from tens of thousands to several million baht. Most violations stemmed from weak security measures, failure to notify data breaches within the required timeline, absence of a data protection officer (DPO) when required, and noncompliance with governance requirements such as the Record of Processing Activities (ROPA) and data processing agreements with data processors.

Case studies. The Office of the PDPC highlighted specific examples of violations:

  • Hospitals misused personal data for purposes beyond their intended scope (e.g., using personal data collected for providing medical services to send birthday cards)
  • Vendors compromised systems due to inadequate password protocols and the absence of firewalls, resulting in unauthorized access

AI and Privacy: Regulatory Expectations in the Emerging Landscape

Thailand is moving toward a clearer regulatory framework for AI, with the AI Act currently in draft form. While the PDPA does not regulate AI itself, it governs personal data used within AI systems, meaning organizations, not the AI, remain fully accountable for any misuse or unlawful processing of personal data.

Key expectations highlighted for businesses include:

  • The use of AI is allowed, but accountability remains fundamental. Organizations must take full responsibility for how personal data is processed through AI systems.
  • Strong resource and access governance is necessary. Organizations must prevent uncontrolled AI usage and avoid over-sharing of data through proper data classification to restrict AI access to relevant datasets.
  • AI deployment may trigger obligations under other laws. While there is currently no specific law regulating the use of AI, AI deployment may trigger obligations under civil and commercial law, road traffic laws in relation to autonomous systems, and other regulations, reinforcing the need for comprehensive risk assessment.
  • Alignment with forthcoming guidelines. The Office of the PDPC is currently developing practical guidelines on personal data protection in the use and development of AI technologies. Organizations should align AI use with these forthcoming guidelines aimed at supporting safe innovation while adhering to PDPA requirements.

International Cooperation and Cross-Border Transfers

Efforts continue to advance Thailand’s participation in the Global Cross-Border Privacy Rules (CBPR) and strengthen alignment with regional data-protection frameworks. Organizations operating across borders should expect tighter scrutiny of cross-border transfers, including more rigorous requirements for risk assessments and transfer impact analyses to ensure compliance in multi-jurisdictional environments.

Data Breach Incident Monitoring

The PDPC Eagle Eye, a division within the Office of the PDPC, has launched advanced tools such as the PDPC Eagle Eye Crawler, which enables continuous URL access and facilitates 24-hour monitoring of data breach incidents. Additionally, the PDPC Eagle Eye shared details about their plan to send inspection letters to organizations for advisory reasons.

Privacy Maturity Model and Privacy Index

The Office of the PDPC introduced new tools to help organizations assess and improve their data protection practices.

The Privacy Maturity Model assesses an organization’s readiness for personal data protection. The Privacy Index measures data protection levels using both privacy data (such as survey results and Privacy Maturity Model scores) and secondary data (like public information), giving organizations an overview of their privacy risk management capabilities.

Information derived from the Privacy Maturity Model and Privacy Index can then be used toward obtaining the Personal Data Protection Certification Mark, an upcoming certification program to recognize compliant organizations.

Outlook for 2026

Based on the Office of the PDPC’s roadmap and expert discussions during the Data Privacy Day event, organizations should expect several key developments in the coming year:

  • Data privacy must go beyond policy and legal compliance to practical implementation in all systems and operations.
  • Heightened enforcement, driven by expanded automated surveillance capabilities such as the PDPC Eagle Eye Crawler and the rollout of inspection letters for advisory purposes.
  • Stronger national PDPA infrastructure, with continued development of PDPA Centers and Trustmark certification.
  • Closer alignment with international privacy standards, supporting Thailand’s role in cross-border digital trade and strengthened mechanisms to support trusted cross-border data flows.
  • Increased regulatory attention on AI governance, with forthcoming guidance to ensure AI use complies with data-protection principles and standards.
  • A nationwide push toward a “new data-ethics culture” emphasizing legal compliance, incident prevention, organizational cooperation, and the use of technology to strengthen national and public trust, anchored in the national goal of improving data security, attracting investments, and enhancing quality of life.

Organizations should treat 2026 as a critical year for operationalizing privacy compliance, building robust governance frameworks, and preparing for more active regulatory oversight. The shift from policy to practice means that demonstrable implementation, not just documentation, will be the standard by which compliance is measured.

RELATED INSIGHTS​ 

May 14, 2025
Following the amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes in mid-April 2025, new measures were introduced by the Electronic Transactions Development Agency (ETDA) in a hearing session held on May 13, 2025, to establish shared liability between online social media platform operators and other in-scope operators for damages arising from technological crimes. Stakeholders are being invited to submit their comments on the proposed new provisions directly to the ETDA by May 20, 2025. The concept of the new measures for social media platform operators is that to be released from liability for damages arising from technological crimes, social media platform operators must demonstrate compliance with the relevant technological crime prevention standards and measures prescribed by their respective regulators (“safe harbor rules”). Safe Harbor Rules Under the principles of the proposed safe harbor rules, social media platform operators and the relevant service providers would be required to comply with the following obligations: Immediate takedown and suspension of dissemination: Disable access, remove the content from the system, or suspend the relevant service within 24 hours of receiving an official notification from the Cyber Crime Investigation Bureau’s Anti-Online Scam Operation Center (AOC) that a service or social media platform is disseminating content that is or may be used to commit or support technological crimes. Establishment of notification channels: Establish a system or channel to receive notifications from the AOC. User registration and identity verification: Require user registration (including identity verification and authentication) before allowing content to be posted, with sufficient information to identify the user. Suspending dissemination of suspect advertisements: Disable access to advertisements reasonably suspected of involving or potentially involving the commission of technology-related crimes. Reporting: Report on actions taken, including details like account owner information, IP address, email, or phone number used for account
May 5, 2025
On April 29, 2025, the government of Vietnam promulgated Decree No. 94/2025/ND-CP with regulations on a controlled “sandbox” for innovative fintech solutions in the banking sector (Decree 94). The decree aims to promote innovation, modernize banking, and enhance financial inclusion while assessing risks and benefits of fintech solutions in a controlled testing environment. Fintech Sandbox Currently, the fintech sandbox focuses on three specific areas: Credit scoring Open API data sharing Peer-to-peer (P2P) lending Eligible participants for the fintech sandbox include: Credit institutions and foreign bank branches (except for P2P lending) Fintech companies operating in Vietnam Cross-border supply by foreign providers is not included in the sandbox framework. Eligible participants are permitted to provide fintech solutions only within the scope specified in the Certificate of Sandbox Participation issued by the State Bank of Vietnam in consultation with other ministries. P2P lending companies face specific restrictions within the fintech sandbox, including prohibitions against: Providing security for customer loans Operating as a customer (i.e., P2P lender or borrower) Providing P2P lending solutions to pawn shops The maximum sandbox period is two years, with the possibility of extension as permitted by law. The outcomes of the fintech sandbox will serve as a practical basis for authorities to develop and refine future fintech regulations. It is worth noting that participation in the sandbox does not guarantee that participants will meet relevant business and investment conditions that may be stipulated in future regulations. Decree 94 will take effect on July 1, 2025, signaling that the Vietnamese government intends to take a proactive approach to fostering fintech development. Implications Parties interested in participating in the fintech sandbox should begin preparing now to be ready to apply for a Certificate of Sandbox Participation when the decree takes effect.
May 2, 2025
Attorneys from Tilleke & Gibbins have updated the latest edition of Doing Business in Thailand, a Q&A-style guide from Thomson Reuters Practical Law that offers an overview of key legal considerations for companies operating in jurisdictions worldwide. The contribution outlines the country’s legal and regulatory framework for foreign investment and business operations and reflects the latest legislative developments. The chapter addresses the following core topics: Legal system: Structure of the courts and the codified nature of Thai law. Foreign investment: Business restrictions under the Foreign Business Act, sector-specific regulations, exchange control rules, and investment incentives. Business vehicles: Overview of partnerships, private and public limited companies, and other legal entities. Employment: Labor protections, employment contracts, foreign worker requirements, and termination procedures. Tax: Corporate and personal income tax, indirect taxes, and tax obligations for residents and non-residents. Intellectual property: Registration and enforcement of patents, trademarks, designs, and copyrights. Data protection: Key provisions of the Personal Data Protection Act and related compliance obligations. Competition law: Regulatory framework under the Trade Competition Act. Anti-bribery and corruption: Relevant legislation and enforcement mechanisms. E-commerce and digital business: Legal regime for online transactions and digital platforms. Marketing and advertising: Consumer protection laws and regulations affecting advertising and marketing practices. Product regulation and liability: Safety standards, liability regimes, and roles of enforcement authorities. Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The insurance and reinsurance guide is a valuable resource for legal practitioners, covering numerous jurisdictions worldwide. To view the latest version of the guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
April 30, 2025
With a favorable crypto climate from the Trump administration in the United States, Thailand is ready for digital asset platforms and has market appetite. This article highlights the country’s regulatory initiatives supporting the growth of digital assets like crypto, stablecoins, and smart contracts, along with efforts to establish clear oversight. Bank of Thailand Sandbox Stablecoins used as a medium of payment, particularly those pegged to the Thai baht (THB) for public use, are considered as mirroring fiat currency, which violates the Currency Act B.E. 2501 (1958). These can also be classified as e-money under the Payment Systems Act B.E. 2560 (2017). The Bank of Thailand (BOT) urges issuers to engage in preconsultation prior to implementation, due to concerns about stablecoins being used in place of THB currency. Other FX- or asset-backed stablecoins are not recognized as legal tender under Thai law, and users must bear their own risks. The BOT recognizes the potential and benefits of these technologies in reducing operational costs for financial service providers and addressing the needs of financial service users. Consequently, the BOT issued a sandbox framework in June 2024. In particular, the enhanced regulatory sandbox allows nonlicensed entities to test financial innovations in controlled conditions. These tests must have a clearly defined duration (usually under one year) and involve a limited user group with an exit strategy. Several programmable payment projects—automated transactions with predefined conditions for the payment of goods and services—were piloted under this sandbox, which closed for applications in September 2024. Eight participants are planning to launch their test runs this year, some of which include asset tokenization or exchange global stablecoins in their programmable payment projects. Thai Securities and Exchange Commission Sandbox Given that digital asset businesses fall under the Royal Decree on Digital Asset Businesses B.E. 2561 (2018), supervised by