You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 12, 2021

Personal Data Protection Act: Royal Decree Extends Compliance Date to June 1, 2022

Further to the Thai Cabinet’s approval in principle of another one-year exemption from certain provisions under the Personal Data Protection Act (the PDPA), Royal Decree Re: the PDPA (No. 2) was issued on May 8, 2021, to implement the decision and definitively confirm the exemption to the end of May 2022.

The royal decree extends the original one-year exemption period (implemented by a previous royal decree, issued in May 2020) from May 2021 to the end of May 2022. As a result, the provisions relating to personal data protection, data subject rights, complaints, civil liabilities, penalties, and grandfather provisions, will not be effective in June 2021, but will instead take effect on June 1, 2022.

The extension is applicable to a wide-ranging list of operations including banking, commercial activities, communications and telecommunications, construction, digital, education, energy, finance, insurance, medical and public health, professional practices, real estate, tourism, and transportation (among others).

What does the extension mean for businesses?

  • The extension will give businesses more flexibility in preparing for compliance with the PDPA.
  • During the extension period, businesses should continue to monitor supplemental regulations that will be issued for public hearings before implementation. As with the principles recognized in the PDPA itself, which are materially influenced by international data protection standards (especially the EU’s General Data Protection Regulation, or GDPR), the government has publicly announced that the supplemental regulations will recognize and follow international standards of personal data protection (again, particularly those of the GDPR).
  • Overseas-established businesses may fall within the scope of the PDPA if they are offering goods or services to data subjects in Thailand (with or without an exchange of money or other valuable property) or monitoring the behavior of data subjects taking place in Thailand. This is sometimes referred to as “extraterritoriality,” and is similar to an internationally recognized principle of the GDPR.
  • Data controllers must still implement security measures for personal data protection, in accordance with the standards prescribed by the Ministry of Digital Economy and Society (MDES). The MDES is expected to issue another notification on those standards in the near future, similar to the prior MDES notification dated July 17, 2020, which is due to expire at the end of this month. The requirements will likely follow the same principles (such as access control standards, user responsibilities, record monitoring, etc.).
  • Businesses that have not yet conducted their self-assessment for compliance with the PDPA should take this opportunity to begin the process, start identifying compliance gaps, and develop their mitigation plans for closing such gaps.

PDPA compliance assessment suggestions

When conducting PDPA compliance-related activities, we recommend that businesses (i.e. data controllers) avoid focusing too much on collecting consent from their individual customers if possible, as relying on consent as the lawful basis is vulnerable and can be withdrawn at any time. As the PDPA is still relatively new, a common misconception has arisen that consent is always required, but this is not the case. In fact there are several more durable lawful bases that data controllers can rely upon, such as contractual necessity, legitimate interest, and legal obligations, which should be made use of where possible.

In addition, when preparing a privacy notice for compliance with the PDPA notification requirements (under section 23 of the act), businesses should ensure that the notice provides “clear and sufficient information” so that the data subjects can understand and reasonably expect the implications that may arise as a result of providing their personal data.

It should be highlighted that, unlike other requirements, the concept and requirements for personal data about children (minors) differ from international standards as they have been localized for Thailand specifically to align with the provisions relating to minors under the Thai Civil and Commercial Code.

With regard to PDPA cross-border transfer requirements, international and local MNCs with affiliates and subsidiaries in multiple jurisdictions may consider preparing their binding corporate rules (or localizing them as appropriate) for cross-border transfers of personal data within their group of companies.

The Personal Data Protection Commission’s supplemental regulations will be issued in due course to give more clarity on the 72-hour data breach notification requirements and the data protection officer (DPO) required qualifications.

Lastly, the PDPA includes a grandfather provision that could enable businesses to continue to collect and use personal data within the scope of their original purpose after the PDPA becomes fully effective in 2022. Business should pay careful attention to those requirements and their implications for existing practices and processes when implementing their compliance plan.

RELATED INSIGHTS​ 

September 11, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has published a new five-year master plan that will bring significant regulatory changes to the broadcasting and digital media sectors, including formal licensing requirements for internet-based audiovisual services. The Master Plan for Broadcasting and Television, 3rd Edition (B.E. 2569–2573/2026–2030) was published in the Government Gazette on September 1, 2026, and will affect OTT platforms, internet-based audiovisual service providers, and traditional broadcasters. Licensing Reform The NBTC will develop new licensing frameworks ahead of existing digital television license expirations, which are slated to occur between 2028 and 2030. This creates both uncertainty and opportunity for incumbents and new market entrants. New licensing criteria will also be developed for audiovisual services delivered over the internet, meaning previously unregulated internet-based providers may face licensing, fee, and content obligations for the first time. The plan also calls for a new law to govern converged communications services. OTT Regulation and Content Oversight The plan explicitly acknowledges and aims to lessen the regulatory asymmetry between traditional broadcasters—which are subject to licensing, fees, and content regulation—and internet-based services that currently face fewer obligations. The NBTC intends to develop regulatory frameworks to bring internet-based audiovisual services, including OTT platforms, streaming services, and user-generated content platforms, under content, consumer protection, and licensing requirements. Consumer Protection and Digital Rights The NBTC will strengthen its oversight of broadcasting, television, and telecommunications operators to ensure compliance with consumer protection and personal data protection requirements. This includes updating relevant notifications and orders and more strictly enforcing rules against practices that unfairly exploit consumers. These measures may layer NBTC-specific requirements on top of Thailand’s existing Personal Data Protection Act obligations. Stricter enforcement against practices that exploit consumers is a priority, with particular scrutiny on advertising practices. The NBTC will modernize complaint resolution processes, meaning service providers should
September 9, 2026
On August 5, 2026, the Consumer Case Division of Thailand’s Civil Court rendered a judgment in a case involving a beauty clinic that advertised acne scar treatments using claims that the clinic was operated by a specialist physician and that the treatment, allegedly involving stem cell technology, could permanently remove acne scars. The plaintiff brought a claim against both the physician-owner and the clinic company, alleging that the advertisements were false and induced her to purchase the treatment. The court found that the clinic was liable for the false representations and that the physician-owner, as both the authorized director of the company and the medical practitioner who provided treatment, was jointly responsible. Although the plaintiff could not fully prove all damages claimed, the court awarded compensation of THB 20,000, together with interest. While the judgment arose from a consumer protection dispute, it serves as a valuable reminder that medical facility advertisements in Thailand are regulated and may expose clinics and healthcare providers not only to regulatory enforcement but also to civil liability from patients who rely on misleading promotional claims. Regulatory Framework Governing Medical Facility Advertisements Medical facility advertising in Thailand is governed by the Medical Facility Act B.E. 2541 (1998), as amended by the Medical Facility Act (No. 4) B.E. 2559 (2016). The principal secondary legislation is the Department of Health Service Support (DoHSS) Notification Re: Rules, Procedures, Conditions, and Fees for an Advertisement or Publication Concerning a Medical Facility, which came into force on November 25, 2019. Under this notification, “advertising” includes any act, by any means, that causes members of the public to see, hear, or otherwise become aware of a message, sound, or image for the commercial benefit of a medical facility. This broad definition covers not only traditional media but also clinic websites, social
September 9, 2026
On June 30, 2026, Indonesia’s National Agency of Drug and Food Control (BPOM) issued BPOM Regulation No. 11 of 2026 on Food Packaging, which expands the list of approved food-contact substances and recognizes a broader range of permissible functions for those substances. The new regulation, which revokes BPOM Regulation No. 20 of 2019, reflects developments in packaging technology and materials science. Although the new regulation provides more advantages to business actors by adding more food contact substances to the approved list for use in food packaging, there are more stringent rules and restrictions for testing. One of the most significant changes is a comprehensive migration-testing framework that sets out requirements for packaging materials, testing conditions, food simulants, and specific migration limits. Overall and Specific Migration Under BPOM Regulation No. 20 of 2019, migration requirements were primarily set out within the lists of approved food-contact substances and packaging materials. BPOM Regulation No. 11 of 2026 instead expressly requires packaging materials that come into direct contact with food to meet both overall and specific migration limits. These are defined as follows: Overall migration: The total quantity of all substances that migrate from the packaging, regardless of whether the substances are hazardous or nonhazardous to health. Specific migration: The quantity of a particular identified substance known to be hazardous to health that migrates from the packaging. Stricter Limits on Heavy Metals The overall migration limit for plastic packaging remains unchanged under both regulations at 60 mg/kg or 10 mg/dm². However, the new regulation introduces significant changes to the regulation of heavy metals. Under the 2019 regulation, four heavy metals—lead, cadmium, chromium VI, and mercury—were subject to a single combined limit of 1 mg/kg. The 2026 regulation, however, requires each heavy metal to meet its own individual specific migration limit, adds arsenic as
September 7, 2026
On September 4, 2026, Thailand’s prime minister convened the first meeting of the Data Center Business Policy Committee. The committee endorsed a draft policy framework for the data center industry and tasked four subcommittees with developing the standards that would sit beneath it, shifting away from fragmented, agency-by-agency approvals toward a unified national strategy aiming to maximize economic value while managing environmental and infrastructure concerns. Proposed Scope and Pillars of the National Data Center Policy Framework The proposed framework would cover all types of data centers, including internal or captive facilities operated within a company or its affiliates, rather than only commercial third-party providers. If adopted in this form, companies running private data centers purely for internal purposes would also become subject to regulatory oversight. Minimum safety and operational standards would be established, with uniform enforcement across all categories. The committee endorsed a draft policy framework with four key pillars: Industrial classification: Data centers exceeding 2 MW would be classified as industrial operations, which may require factory licenses and environmental impact assessments under the Factory Act. Resource pricing: Utility rates would be structured to reflect both direct and indirect costs, supporting green energy and green data center standards. Centralized screening: A centralized review would evaluate project suitability and resource allocation. Operators may be required to submit proposals through periodic “pitching” rounds, where projects are competitively assessed on their potential economic and strategic benefits to Thailand. Digital ecosystem: The framework would prioritize data sovereignty, tax incentives, and conditions promoting domestic digital businesses, AI, and cloud infrastructure. Multidimensional Evaluation Criteria and Subcommittees Four subcommittees will be established to develop standards responsible for the following dimensions: Economic: Criteria for assessing the economic viability of data center projects, for use in prioritizing data centers based on infrastructure readiness, demand type (including AI factories),