You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 21, 2016

Online Privacy Policies in Thailand: Designing and Implementing an Effective Policy

Data Privacy Asia

The “Catch-all” Policy in Thailand

In many countries, it is mandatory for site operators to have a privacy policy in place. Catch-all privacy policies, whereby operators may collect, use, and share a wide range of users’ personal information, are widely used by site operators. They are designed to obtain broad agreement from users in respect to processing any personal data that is collected.

The validity and enforceability of catch-all privacy policies have been increasingly challenged. In a country like Thailand, which is still in the process of implementing its first general personal data protection law, questions commonly arise as to the degree to which an online privacy policy and online consent provided by users can be enforced under the present law (i.e., in the absence of a general personal data protection law).

Thailand’s Constitution generally recognizes the principle of privacy protection. It states that “a person shall have the right to privacy,” and “any act which wrongfully violates or affects the rights … or utilization of personal data in any way is prohibited.” In addition, a number of sector-specific statutes impose personal data protection requirements on parties operating within the telecommunications, securities, banking, and other industries.

What Is “Consent” in Thailand?

However, as Thailand lacks a general personal data protection law, there are no regulatory requirements on privacy policies or on obtaining individual consent from users to process personal data. This means that there are no requirements on specific forms of consent (e.g., in writing, express consent, required by Thai law, etc.). Therefore, certain types of implied consent in privacy policies may be acceptable and may constitute a privacy policy agreement with the users under Thai law.

In determining which types of implied consent are effectively sufficient, factors such as the timing of the consent provision, the person to whom consent is given, or the elements of fraud, deception, or misrepresentation, if any, are considered among other related circumstances.

An online privacy policy with an opt-in requirement (i.e., users are required to expressly click “I agree” after scrolling down to the end of the privacy policy terms during the process of site registration), arguably obtains a user’s consent to create an effective privacy policy agreement between the site operator and its users. However, it should be noted that a minor—generally deemed to be a person aged less than 20 years old—who enters into a contractual transaction without parental consent could make the transaction voidable.

Another key concern is the effectiveness of catch-all provisions, which could fall within the ambit of Thailand’s Unfair Contract Terms Act. If catch-all provisions are considered as unfair by the Thai courts (i.e., they impose an excessive burden which is more than a reasonable person could have anticipated), the Unfair Contract Terms Act enables the courts to intervene by voiding or limiting any unfair terms.

There are no Supreme Court decisions on unfair catch-all privacy policies, so it is difficult to ascertain to what degree the court will exercise its discretion when a privacy policy term is found to be unfair. To err on the side of caution, website privacy policies should provide clear and precise explanations of the specific types of information collected, the specific activities for which the information is being used and with whom the information is shared. 

The Importance of Review

Site operators should also keep their privacy policies up to date with current practices. Privacy policies are not one-sided agreements—operators can enforce a policy against users, and users can enforce against operators. Therefore, if an operator has an obligation under its privacy policy to notify affected data subjects about any material changes to personal data handling practices, and there has been a change in the handling practices (e.g., the location of the stored data or the third party vendor handling the collected data has changed), but the operator has failed to notify the affected data subjects, the operator could be seen as having broken the privacy policy. Although monetary damages arising from such a breach would most likely be minimal, the breach could possibly cause reputational damage to the site operators and/or owners.

Site operators should regularly review their privacy policies to ensure they are in line with current practices and do not dissuade users from interacting with their sites. An effective privacy policy can help mitigate exposure to liability in operating a site. An ineffective policy, on the other hand, could lead to costly legal actions and a tarnished reputation.

RELATED INSIGHTS​ 

April 10, 2026
Thailand has introduced new regulatory guidance requiring digital platform operators to adopt structured, transparent, and fair fee practices. On March 16, 2026, the Electronic Transactions Development Agency (ETDA) published Announcement No. DPS 2/2569, titled “Guidelines for Transparency and Fairness in Digital Platform Service Fee Determination,” issued under the Royal Decree on Digital Platform Service Business Operations B.E. 2565 (2022). The guidelines establish a framework governing how digital platform operators should set, disclose, and adjust fees charged to users and related service providers such as logistics and payment providers. Although framed as best-practice guidance rather than legally binding rules with explicit penalties, the guidelines carry regulatory weight under the royal decree and represent a significant step toward structured governance of digital platform fee practices in Thailand. The guidelines establish various transparency principles and divide fees into two distinct categories—compulsory and additional—with specific governance principles for each. Transparency Principles The guidelines recommend that digital platform operators adopt several transparency measures to ensure that users can fully understand the costs of using a platform. Fee catalog. All fees should be consolidated into a single, accessible location, which should include the fee name, definition, scope of covered services, calculation methodology, rate, billing period, and calculation examples. Minimum service disclosure. Operators should disclose the minimum service that users can expect, such as baseline visibility, product listing capabilities, access to transaction data, and back-end dashboard access. Price structure disclosure. Operators should disclose the categories of costs underlying their fees, such as system maintenance, cybersecurity, and operational costs. While exact cost figures need not be made public, operators should be able to provide numerical data to regulators upon request. Clear fee formulas. Fee calculations should be simple and easy to understand—for example, percentage of net sales, cost per order, or cost per product listing. Operators should
April 10, 2026
As digital commerce continues to reshape consumer behavior in Thailand, the Office of the Consumer Protection Board (OCPB) has been taking steps to review and update key regulations for online platforms. The OCPB has had a particular focus on addressing the risks posed by e-marketplace businesses—from misleading product information to fraudulent online transactions. Some of the regulator’s current legislative efforts related to Thailand’s labeling regulations as well as potential changes to the country’s law on direct sales and marketing. Proposed Changes to Consumer Protection Labeling Regulations On February 24, 2026, the OCPB convened a public hearing to review the Notification of the Committee on Labels re: Specification of Goods as Controlled Label Goods B.E. 2565 (2022) and its annex issued under the Consumer Protection Act. The closed-door session, which started the OPCD’s process of seeking feedback on the proposed changes, brought together representatives from government agencies, business operators, and consumer groups. The OCPB explained that its review of the labeling regulations aims to address regulatory gaps arising from evolving commercial practices, particularly the expansion of e-commerce and cross-border transactions. Authorities highlighted recurring issues involving product information that is unclear, incomplete, or potentially misleading in digital sales channels. The proposed revisions are intended to improve consumers’ access to accurate and complete product information, ensure that label disclosures remain relevant amid the growth of e-commerce, and strengthen protections against deceptive or misleading digital advertising. The review is being undertaken pursuant to the Consumer Protection Act B.E. 2522 (1979). As part of the initiative, the OCPB signaled a potential update to the categories of “controlled label products” as well as enhanced disclosure obligations for business operators, with the broader aim of promoting greater transparency, reinforcing operator accountability, and aligning Thailand’s labeling framework with current market conditions. The OCPB secretary general emphasized that
April 9, 2026
As part of its ongoing public consultation process for the development of new practical guidelines under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), Thailand’s Personal Data Protection Committee (PDPC) held a two‑day public hearing on April 1–2, 2026. The hearing followed an online questionnaire and stakeholder engagement activities conducted in March 2026 and reflects the PDPC’s continued efforts to develop guidance that aligns international regulatory standards with Thai operational realities. The public hearing provided a forum for participants from both the public and private sectors to exchange views with the PDPC on the proposed guidance so that it responds to the needs of the business community while supporting effective and balanced enforcement of the PDPA. The PDPC emphasized that the consultation process is part of a wider policy objective to build trust in the convenient, secure, and internationally aligned exchange of data. Structure of the Consultation Process According to the PDPC, the initiative to develop the draft PDPA guidelines is being implemented through three core phases: Review of international best practices. The PDPC has conducted a comparative review of data protection guidance and regulatory approaches in jurisdictions with internationally recognized standards, including Singapore, the United Kingdom, the European Union (EU), and Japan. These materials are intended to serve as a reference point for developing practical recommendations across key subject areas under the PDPA. Identification of practical issues and challenges. To ensure that the guidelines respond to real‑world compliance challenges in Thailand, the PDPC has gathered views from a broad range of stakeholders across the public sector, the private sector, and the general public. This phase included focus group discussions and questionnaires aimed at identifying areas to provide organizations with greater clarity and consistency on regulatory expectations. Preparation of draft guidelines. Insights from the comparative study and stakeholder
April 3, 2026
On March 16, 2026, Vietnam’s Ministry of Public Security released a draft version of a new Decree on the Prevention and Combating of Cybercrime and High-Tech Crime to replace the currently effective Decree 25/2014/ND-CP. In the draft, the ministry has proposed a comprehensive regulatory framework aimed at addressing violations occurring within the cybersecurity domain, including measures related to intellectual property. Acts of Online IP Infringement Article 9 of the draft decree notably introduces specific provisions addressing online intellectual property infringement, with detailed lists of acts considered to constitute infringement in the online environment. Copyright and related rights infringement includes: Uploading or sharing works, performances, sound recordings, video recordings, broadcasts, computer programs, software, research, documents, theses, or other intellectual creations on digital platforms without the consent of the rights holder. Unauthorized livestreaming of copyrighted television programs, sporting events, or artistic performances. Uploading, sharing, storing, transmitting, or providing links to infringing works or digital content via websites, social networks, applications, or digital platforms. Providing or using software, tools, devices, or access codes to circumvent technological protection measures or evade lawful control mechanisms implemented by rights holders. Using artificial intelligence (AI) tools to replicate the ideas or structure of another person’s work without significant new creativity or without proper attribution, thereby causing damage to the original author. Industrial property infringement includes: Manufacturing, trading, advertising, or distributing counterfeit goods bearing counterfeit trademarks, geographical indications, or industrial designs, as well as goods infringing industrial property rights through online platforms. Unauthorized registration, appropriation, or use of domain names, account names, or digital identifiers that create confusion regarding the rights holder or the origin of goods or services. Producing, using, or offering for sale products containing all or part of a patented invention via online platforms. Advertising or introducing products with technical features or characteristics identical