You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 12, 2021

Personal Data Protection Act: Royal Decree Extends Compliance Date to June 1, 2022

Further to the Thai Cabinet’s approval in principle of another one-year exemption from certain provisions under the Personal Data Protection Act (the PDPA), Royal Decree Re: the PDPA (No. 2) was issued on May 8, 2021, to implement the decision and definitively confirm the exemption to the end of May 2022.

The royal decree extends the original one-year exemption period (implemented by a previous royal decree, issued in May 2020) from May 2021 to the end of May 2022. As a result, the provisions relating to personal data protection, data subject rights, complaints, civil liabilities, penalties, and grandfather provisions, will not be effective in June 2021, but will instead take effect on June 1, 2022.

The extension is applicable to a wide-ranging list of operations including banking, commercial activities, communications and telecommunications, construction, digital, education, energy, finance, insurance, medical and public health, professional practices, real estate, tourism, and transportation (among others).

What does the extension mean for businesses?

  • The extension will give businesses more flexibility in preparing for compliance with the PDPA.
  • During the extension period, businesses should continue to monitor supplemental regulations that will be issued for public hearings before implementation. As with the principles recognized in the PDPA itself, which are materially influenced by international data protection standards (especially the EU’s General Data Protection Regulation, or GDPR), the government has publicly announced that the supplemental regulations will recognize and follow international standards of personal data protection (again, particularly those of the GDPR).
  • Overseas-established businesses may fall within the scope of the PDPA if they are offering goods or services to data subjects in Thailand (with or without an exchange of money or other valuable property) or monitoring the behavior of data subjects taking place in Thailand. This is sometimes referred to as “extraterritoriality,” and is similar to an internationally recognized principle of the GDPR.
  • Data controllers must still implement security measures for personal data protection, in accordance with the standards prescribed by the Ministry of Digital Economy and Society (MDES). The MDES is expected to issue another notification on those standards in the near future, similar to the prior MDES notification dated July 17, 2020, which is due to expire at the end of this month. The requirements will likely follow the same principles (such as access control standards, user responsibilities, record monitoring, etc.).
  • Businesses that have not yet conducted their self-assessment for compliance with the PDPA should take this opportunity to begin the process, start identifying compliance gaps, and develop their mitigation plans for closing such gaps.

PDPA compliance assessment suggestions

When conducting PDPA compliance-related activities, we recommend that businesses (i.e. data controllers) avoid focusing too much on collecting consent from their individual customers if possible, as relying on consent as the lawful basis is vulnerable and can be withdrawn at any time. As the PDPA is still relatively new, a common misconception has arisen that consent is always required, but this is not the case. In fact there are several more durable lawful bases that data controllers can rely upon, such as contractual necessity, legitimate interest, and legal obligations, which should be made use of where possible.

In addition, when preparing a privacy notice for compliance with the PDPA notification requirements (under section 23 of the act), businesses should ensure that the notice provides “clear and sufficient information” so that the data subjects can understand and reasonably expect the implications that may arise as a result of providing their personal data.

It should be highlighted that, unlike other requirements, the concept and requirements for personal data about children (minors) differ from international standards as they have been localized for Thailand specifically to align with the provisions relating to minors under the Thai Civil and Commercial Code.

With regard to PDPA cross-border transfer requirements, international and local MNCs with affiliates and subsidiaries in multiple jurisdictions may consider preparing their binding corporate rules (or localizing them as appropriate) for cross-border transfers of personal data within their group of companies.

The Personal Data Protection Commission’s supplemental regulations will be issued in due course to give more clarity on the 72-hour data breach notification requirements and the data protection officer (DPO) required qualifications.

Lastly, the PDPA includes a grandfather provision that could enable businesses to continue to collect and use personal data within the scope of their original purpose after the PDPA becomes fully effective in 2022. Business should pay careful attention to those requirements and their implications for existing practices and processes when implementing their compliance plan.

RELATED INSIGHTS​ 

August 27, 2026
Franchising in Thailand has matured into a sizeable commercial sector, but the rules governing franchisor–franchisee relationships remain scattered across general legislation rather than consolidated in a dedicated franchise statute. In this environment, the decisions of the Trade Competition Commission of Thailand (TCCT) have emerged as valuable practical guidance. Thailand follows a civil-law system in which judicial and administrative decisions do not create binding precedent; however, past rulings are nonetheless influential. This article examines the most instructive recent TCCT decisions and distills the practical compliance considerations for franchisors and franchisees operating in Thailand. Postcontract Changes: Justified or Unfair? A recurring issue is whether a franchisor may alter the terms of engagement after contract execution. The TCCT has established that midterm modifications are not inherently unfair; the determinative factors are whether there was a reasonable business justification, adequate advance notice, and a transparent process. In a 2023 coffee franchise matter, for instance, the TCCT declined to find a violation where a franchisor increased raw material prices, noting the increase had been communicated in advance and supported by demonstrable cost pressures. A bubble tea franchise matter reinforces this principle. The TCCT found that postcontract mandatory purchases of branded syrup and flavorings were justified, as the agreement reserved the franchisor’s right to modify product requirements, the materials were sold at or below market prices, and the branded ingredients possessed distinctive qualities deemed essential to franchise quality. The complaint was dismissed, with the additional requirements characterized as a legitimate measure to preserve brand consistency. Considered together, these decisions indicate that post‑contract modifications will be evaluated against three criteria: (1) whether there is a legitimate business rationale, (2) whether adequate advance notice was provided, and (3) whether franchisees were treated equitably throughout the transition. Discriminatory Treatment: Are Renewals and Information Equal? A 2024 automotive dealership
August 25, 2026
Vietnam has enacted a new decree establishing administrative penalties for violations in the fields of cybersecurity and personal data protection. Decree No. 330/2026/NĐ-CP (Decree 330), issued and effective from August 19, 2026, provides a detailed sanctions framework for noncompliance with the Law on Personal Data Protection (including its implementing regulations under Decree 356/2025/ND-CP) and the Law on Cybersecurity, together with their guiding decrees. The issuance of Decree 330 signals that the practical grace period previously perceived by many businesses may be drawing to a close, with active regulatory enforcement in these areas expected to commence in earnest. Scope and Key Provisions Decree 330 has extraterritorial effect and applies to both onshore and offshore companies. For offshore companies, it applies to those that (1) provide telecommunications, internet, online-content, information-technology, cybersecurity, or cross-border services and (2) are involved in or related to the processing of personal data of Vietnamese citizens and certain other people of Vietnamese origin. Decree 330’s key provisions cover the following areas: Administrative penalties for violations relating to the protection of national security and public order in cyberspace, including the dissemination of unlawful, false, or unverified information. Sanctions for cyberattacks, unauthorized access, introduction of harmful code or programs, and failure to cooperate with specialized cybersecurity forces. Sanctions for personal data protection violations, such as consent, cross-border data transfers, impact assessments, breach notification, and data-subject rights, among others—with maximum fines of up to 5% of an organization’s preceding-year revenue for cross-border transfer violations, or up to VND 3 billion for other data-protection breaches. Personal Data Protection Penalties The key sanctions for personal data protection violations are as follows: Consent violations: Fines of up to VND 70 million (approx. USD 2,642), plus potential additional sanctions and remedial measures including irreversible deletion of personal data collected without consent and confiscation of
August 25, 2026
Thailand’s Electronic Transactions Development Agency (ETDA) is studying potential new regulatory measures for digital platform services that could significantly expand the country’s digital platform governance framework. The ETDA has already conducted one public consultation session on the proposed measures and will hold additional sessions on August 25 and September 2, 2026, covering five types of platform services under the Royal Decree on Digital Platform Services B.E. 2565 (2022). The measures under study are preliminary and may be changed based on consultation outcomes. Foundational Measures Applicable to All Platform Types Seven baseline obligations would apply across all digital platform categories: Transparency reports. Platforms must prepare and publish statistical reports on platform governance activities, including the number of content items removed or restricted and appeal outcomes, in a comparable format. Notice and action mechanism. Platforms must establish minimum standards for channels to report potentially illegal content or goods, conduct case-by-case review, provide explanations when content is removed or restricted, and maintain an internal appeals channel. Rights over automated decision-making. Users significantly affected by automated decisions are granted rights to request an explanation, request human review, and contest the decision. Service level agreements (SLAs). Platforms must publish minimum standards for response times, processing timelines, progress notifications, and remedies for incidents on the platform. Labeling of AI-generated content. Content generated or modified by AI must carry visible labels and machine-readable metadata, with exceptions for creative works that disclose AI use in a nonmisleading manner. Prohibition of dark patterns. User interface designs that deceive, coerce, or distort user decision-making are prohibited, including hiding critical information, creating false urgency, or making service cancellation unreasonably difficult. Business user fairness. Platforms must meet minimum standards for the treatment of sellers, workers, and content creators, including advance notice of term changes, explanation of account suspensions or visibility reductions,
August 20, 2026
Thailand has established a new cross-ministerial committee to oversee data center operations nationwide. On August 5, 2026, the Thai cabinet approved the Prime Minister’s Office Regulation on the Data Center Business Policy Committee, which was published in the Government Gazette on August 13, 2026, and is now in effect. The regulation reflects the government’s policy to elevate Thailand’s digital economy and promote investment in digital infrastructure and AI. The key features of the new committee are outlined below. Definition of “Data Center” Under the regulation, “data center” is defined as a building, premises, or structure that uses electronic equipment to provide services related to the collection, storage, processing, hosting, or transmission of data by electronic means to third parties that are not affiliates, as further determined by the Data Center Business Policy Committee. Committee Composition The committee will be chaired by a deputy prime minister designated by the prime minister, and will have three vice-chairs comprising the ministers of digital economy and society, interior, and energy. The committee also includes 12 ex-officio members: the permanent secretaries of finance, agriculture, natural resources, energy, interior, digital economy, industry, and commerce; the secretaries-general of the Board of Investment (BOI), Energy Regulatory Commission, National Broadcasting and Telecommunications Commission (NBTC), and National Water Resources Office; and the director of the Energy Policy and Planning Office. Up to three expert members may be appointed by the prime minister for two-year terms, renewable once. The secretary-general of the National Economic and Social Development Council (NESDC) serves as member and secretary, with up to two NESDC officials serving as assistant secretaries. Powers and Duties The committee is empowered to: Propose policies, standards, and operational frameworks for government agencies in approving, licensing, issuing investment promotion certificates, or providing services to data center operators in Thailand; Study, analyze, and