You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 1, 2025

More Than a Warning: Eight Serious Fines Imposed in Thai Data Protection Cases

Thailand’s Personal Data Protection Committee (PDPC) announced to the press on August 1, 2025, that it had issued eight new administrative fines under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) in five cases of noncompliance by public and private entities. The enforcement actions reflect a growing commitment by the PDPC to penalize noncompliance across all sectors, regardless of organizational type or size. The total amount imposed to date was approximately THB 21.5 million (approx. USD 654,690), underscoring the financial risks tied to PDPA violations.

The five cases—one involving a state agency and the remainder in the private sector—are summarized below.

Case 1: State Agency Providing Online Services to the Public

The order in this case stemmed from a cyberattack on a state agency’s web app, resulting in personal data of 200,000 data subjects being leaked to and sold on the dark web. The software developer was also found to have implemented no privacy by design, lacked an access control system, had no data breach prevention measures, and failed to conduct risk assessments or review existing security measures.

Key noncompliance identified:

  • Lack of appropriate security measures
  • Weak password protection
  • No risk assessment or ongoing review of security measures
  • No data processing agreement with software developer that acted as data processor

The state agency and the developer were each fined THB 153,120 (approx. USD 4,670).

Case 2: Private Hospital

This case involved a hospital that engaged an individual contractor to destroy patient medical record documents. However, the contractor stored the documents at their own premises, failed to follow the required destruction protocols, and ultimately used the medical records to wrap sweets, resulting in the leak of over 1,000 records during the destruction process. The contractor also failed to notify the hospital of the data breach. Although there was a written agreement between the parties, hospital’s failure to properly monitor and control the destruction process in accordance with the prescribed standards led to the medical records not being destroyed and being used for other purposes. The images of the wrapped sweets were later posted on social media and discovered by the PDPC.

Key noncompliance identified:

  • Lack of appropriate security measures
  • Failure to report data breach incidents

The hospital was fined THB 1,210,000 (approx. USD 36,880), while the individual contractor was fined THB 16,940 (approx. USD 515).

Case 3: Computer and Accessories Trading Giant

Over 100 data subjects filed complaints with the PDPC following a call center scam resulting from a data breach incident. The company did not provide remedial action for the affected data subjects within the specified timeframe.

Key noncompliance identified:

  • Lack of appropriate security measures
  • Failure to report data breach incidents
  • No appointment of a data protection officer (DPO)

The company was fined THB 7 million (approx. USD 213,380). The company’s revenue and size were taken into account when determining the fine amount.

Case 4: Cosmetics Company

In this case, a cosmetics company failed to implement adequate security measures as required by the PDPA, resulting in leakage of personal data to a call-center gang (scam operators). The company also failed to notify the Office of the PDPC of the data breach incident as required by the PDPA. However, the company did provide remedial action for the affected data subjects.

Key noncompliance identified:

  • Lack of appropriate security measures
  • Failure to notify the PDPC of data breach incident.

The company was fined THB 2.5 million (approx. USD 76,210).

Case 5: Collectible Toy Company

This case involved a collectible toy company that hired a data processor to manage its reservation system. The system was compromised and accessed by an unauthorized party for about 10 minutes, resulting in approximately 200,000 personal data records being amended without authorization. The toy company, as the data controller, promptly provided remedial action for the affected data subjects. However, the data processor failed to (1) take prompt action to contain the incident, (2) notify the data controller of the incident, and (3) provide remedial action for the affected data subjects.

Key noncompliance identified:

  • Lack of appropriate security measures
  • Failure to comply with data breach notification

The collectible toy retailer was fined THB 500,000 (approx. USD 15,240), while its data processor was fined THB 3,000,000 (approx. USD 91,450).

Considerations

The five cases highlight three common failures that can lead to the imposition of administrative fines:

  • Lack of appropriate security measures or regular review of the measures
  • Failure to report data breach incidents
  • Failure to appoint a DPO

The PDPC reiterated its “zero data breach” objective and stated that organizations are required to comply with the PDPA, ensure appropriate security measures are in place, regularly conduct risk assessments, and establish transparent monitoring systems.

This latest wave of enforcement confirms that PDPA compliance is no longer optional or merely a matter of paperwork, as both public and private entities are now subject to active scrutiny and penalties requiring strict adherence. The recurrence of key noncompliance issues across all five cases provides a clear roadmap of regulatory expectations. Organizations subject to the PDPA should act without delay to reassess their data protection frameworks, address compliance gaps, and ensure preparedness for future enforcement actions.

RELATED INSIGHTS​ 

July 27, 2026
Vietnam’s new E-Commerce Law, which took effect on 1 July 2026 along with its implementing Decree No. 248/2026/ND-CP (Decree 248), marks a significant development in the country’s approach to online intellectual property (IP) enforcement, reflecting a clear shift from a reactive model of intermediary liability to one that expects platforms to play a more active role in preventing infringement. From notice-and-takedown to platform responsibility The most significant change introduced by the E-Commerce Law is the transformation of the legal role of e-commerce platforms. The existing safe harbor provisions under the IP Law and the copyright notice-and-takedown regime established by Decree 17/2023/ND-CP (Decree 17) largely required intermediaries to act only after receiving notice of infringement. Once infringing content had been removed, the platform’s legal obligation was generally considered fulfilled. The new legislation adopts a fundamentally different approach. Article 17 of the E-Commerce Law requires intermediary platforms to screen information relating to goods and services before publication in order to prevent listings involving counterfeit or IP-infringing goods, and goods of unknown origin. Rather than relying exclusively on complaints from rights holders, platforms are now expected to implement preventive measures before infringing listings become publicly available. Decree 248 further requires platforms to update keyword filters based on recommendations issued by competent authorities. These filtering mechanisms are intended to prevent prohibited listings from appearing on the platform and represent a further move away from a purely complaint-driven enforcement model. The legislation also introduces Vietnam’s first statutory stay-down obligation. Under the E-Commerce Law and Decree 248, major digital platforms must maintain automated systems capable of reviewing, warning against, and removing unlawful listings while also implementing measures to prevent repeat violations, defined under Decree 248 as conduct that has previously been identified and handled by the platform, but continues to recur. This obligation addresses one
July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 21, 2026
Thailand’s Ministry of Digital Economy and Society (MDES) published a notification establishing an expedited court-ordered takedown mechanism for online content in cases of “urgent necessity.” The notification, which was issued on July 17, 2026, under the Computer Crime Act B.E. 2550 (2007), as amended, took effect the following day. It significantly expands the categories of content subject to rapid government-initiated removal. Content Categories Subject to Takedown The notification defines “urgent necessity” (section 20, paragraph 5, of the Computer Crime Act) as circumstances where any delay in suppressing computer data may impact national security, religion, the monarchy, good morals, social culture, or public order. In this regard, it establishes four broad categories of content: Computer Crime Act offenses. National security offenses. IP and other criminal offenses, where it is contrary to public order or good morals and a competent officer has requested its suppression. Content contrary to public order or good morals, a broad residual category encompassing 14 subcategories approved by the Computer Data Screening Committee. The fourth category is the most expansive. Its 14 subcategories include: Content defaming, mocking, satirizing, or devaluing the monarchy. Online gambling advertising or facilitation. Offering illegal firearms for sale. Offering baraku (hookah) products or e-cigarettes for sale. Offering cannabis inflorescences or processed cannabis products for sale. Advertising or soliciting prostitution. Content inciting violence, hatred, or social division. Unauthorized overseas employment advertising. Offering boiled kratom juice for sale. Online sale or advertising of alcoholic beverages. Content satirizing or degrading Buddhism. Money lending at interest rates exceeding legally prescribed limits. Advertising or disseminating information about surrogacy services. Forgery of documents, cards, or official documents. Enforcement Procedure In cases of urgent necessity, a competent official assigned by the MDES permanent secretary must file a petition with supporting evidence to the court with jurisdiction, requesting an order to
July 20, 2026
On July 16, 2026, Thailand’s Personal Data Protection Committee (PDPC) published a notification in the Government Gazette establishing detailed rules governing data subjects’ right of access under section 30 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notification will take effect 60 days after publication—mid-September 2026—giving data controllers a limited window to bring their processes into compliance. Scope The notification covers requests to access or obtain copies of personal data and requests for disclosure of the source of data collected without consent. Data subjects may exercise their rights directly or through authorized representatives. Key Requirements Important requirements set by the notification include the following: Required request channels. Controllers must provide at least two request channels: direct submission at the business location and registered mail. Electronic channels are optional but, if offered, may also be used for fulfilling requests. Request contents. Requests must be in writing or in electronic form and include the data subject’s name, the preferred access method, details of the data requested, and the requester’s signature. Controllers may request additional identifying information as needed. Identity and authority verification. Controllers may require official identity documents for verification. Authorized representatives must provide authorization documents and identity documents for both the data subject and the representative. Alternative verification methods (e.g., digital authentication) are permitted if they do not unreasonably obstruct data subjects’ rights. Review and response timelines. Controllers must review requests within 15 days. If the request is incomplete, the controller must notify the requester and allow at least 15 days to correct deficiencies. If not corrected, the request may be treated as abandoned. Once verified, controllers must fulfill requests within 30 days, extendable by another 30 days for large-volume or complex requests with notice to the requester. Methods for providing access or copies. Controllers may fulfill