You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 12, 2021

Personal Data Protection Act: Royal Decree Extends Compliance Date to June 1, 2022

Further to the Thai Cabinet’s approval in principle of another one-year exemption from certain provisions under the Personal Data Protection Act (the PDPA), Royal Decree Re: the PDPA (No. 2) was issued on May 8, 2021, to implement the decision and definitively confirm the exemption to the end of May 2022.

The royal decree extends the original one-year exemption period (implemented by a previous royal decree, issued in May 2020) from May 2021 to the end of May 2022. As a result, the provisions relating to personal data protection, data subject rights, complaints, civil liabilities, penalties, and grandfather provisions, will not be effective in June 2021, but will instead take effect on June 1, 2022.

The extension is applicable to a wide-ranging list of operations including banking, commercial activities, communications and telecommunications, construction, digital, education, energy, finance, insurance, medical and public health, professional practices, real estate, tourism, and transportation (among others).

What does the extension mean for businesses?

  • The extension will give businesses more flexibility in preparing for compliance with the PDPA.
  • During the extension period, businesses should continue to monitor supplemental regulations that will be issued for public hearings before implementation. As with the principles recognized in the PDPA itself, which are materially influenced by international data protection standards (especially the EU’s General Data Protection Regulation, or GDPR), the government has publicly announced that the supplemental regulations will recognize and follow international standards of personal data protection (again, particularly those of the GDPR).
  • Overseas-established businesses may fall within the scope of the PDPA if they are offering goods or services to data subjects in Thailand (with or without an exchange of money or other valuable property) or monitoring the behavior of data subjects taking place in Thailand. This is sometimes referred to as “extraterritoriality,” and is similar to an internationally recognized principle of the GDPR.
  • Data controllers must still implement security measures for personal data protection, in accordance with the standards prescribed by the Ministry of Digital Economy and Society (MDES). The MDES is expected to issue another notification on those standards in the near future, similar to the prior MDES notification dated July 17, 2020, which is due to expire at the end of this month. The requirements will likely follow the same principles (such as access control standards, user responsibilities, record monitoring, etc.).
  • Businesses that have not yet conducted their self-assessment for compliance with the PDPA should take this opportunity to begin the process, start identifying compliance gaps, and develop their mitigation plans for closing such gaps.

PDPA compliance assessment suggestions

When conducting PDPA compliance-related activities, we recommend that businesses (i.e. data controllers) avoid focusing too much on collecting consent from their individual customers if possible, as relying on consent as the lawful basis is vulnerable and can be withdrawn at any time. As the PDPA is still relatively new, a common misconception has arisen that consent is always required, but this is not the case. In fact there are several more durable lawful bases that data controllers can rely upon, such as contractual necessity, legitimate interest, and legal obligations, which should be made use of where possible.

In addition, when preparing a privacy notice for compliance with the PDPA notification requirements (under section 23 of the act), businesses should ensure that the notice provides “clear and sufficient information” so that the data subjects can understand and reasonably expect the implications that may arise as a result of providing their personal data.

It should be highlighted that, unlike other requirements, the concept and requirements for personal data about children (minors) differ from international standards as they have been localized for Thailand specifically to align with the provisions relating to minors under the Thai Civil and Commercial Code.

With regard to PDPA cross-border transfer requirements, international and local MNCs with affiliates and subsidiaries in multiple jurisdictions may consider preparing their binding corporate rules (or localizing them as appropriate) for cross-border transfers of personal data within their group of companies.

The Personal Data Protection Commission’s supplemental regulations will be issued in due course to give more clarity on the 72-hour data breach notification requirements and the data protection officer (DPO) required qualifications.

Lastly, the PDPA includes a grandfather provision that could enable businesses to continue to collect and use personal data within the scope of their original purpose after the PDPA becomes fully effective in 2022. Business should pay careful attention to those requirements and their implications for existing practices and processes when implementing their compliance plan.

RELATED INSIGHTS​ 

August 20, 2026
As part of its membership in Lex Mundi, Tilleke & Gibbins has released the latest edition of its Guide to Doing Business in Thailand, providing an overview of the legal, regulatory, and commercial considerations for companies establishing or expanding operations in Thailand. The 2026 edition offers practical insight into the country’s business environment, investment framework, and operational requirements. The guide covers a wide range of topics relevant to foreign and domestic investors, including: Investment incentives and promotion schemes Financial facilities and banking regulations Exchange controls and money transfers Import and export regulations Business structures and incorporation options Requirements for establishing a business Operational and compliance considerations Business cessation and insolvency procedures Employment and labor laws Taxation Immigration and visa requirements Prepared by Tilleke & Gibbins lawyers across multiple practice areas, the publication outlines key aspects of doing business in Thailand, including foreign investment restrictions, regulatory compliance obligations, corporate structures, employment requirements, and recent legal and economic developments affecting investors. The publication forms part of Lex Mundi’s Country Guides series, a global collection of jurisdiction-specific reference materials prepared by member firms around the world. Together, these guides help companies evaluate opportunities, compare regulatory environments, and plan international business activities across multiple markets. The full Guide to Doing Business in Thailand 2026 is available through the button below.
August 14, 2026
Thailand’s Office of the Insurance Commission (OIC) has issued guidelines clarifying the boundaries between permissible and prohibited activities for unlicensed individuals—including influencers, bloggers, and content creators—when communicating about insurance products on social media. The Good Practice Guidelines for Persons Not Licensed as Insurance Agents or Brokers Regarding the Dissemination of Insurance Content Through Digital Media B.E. 2569 (2026) took effect on July 24, 2026. Activities Requiring a License The guidelines reserve the following activities for licensed agents and brokers: Soliciting or facilitating insurance contracts. Providing personalized advice on product suitability. Recommending policy cancellation to purchase promoted products. Creating links that facilitate contract formation. Receiving performance-based compensation tied to policies or premiums generated. Importantly, boilerplate disclaimers such as “this is not a recommendation to buy insurance” will not shield individuals from liability if the OIC views the content as personalized advice or solicitation. Permitted Activities Unlicensed persons may present general educational content about insurance—such as explaining terminology, sharing industry statistics, reporting news, or sharing personal experiences—provided the content does not target specific individuals to purchase from specific companies. The guidelines also set out best practices for communication, including presenting information in a fair and balanced manner that covers both benefits and limitations, encouraging consumers to read policy terms and consult licensed professionals, verifying information from credible sources before dissemination, and exercising special care when the audience may include vulnerable groups such as persons aged 60 and older. Prohibited Practices Prohibited practices include fear-based marketing, creating artificial urgency, omitting material limitations, making exaggerated claims, falsely claiming professional credentials, using fake engagement mechanisms, and sharing false or misleading content. The guidelines also reinforce the prohibitions under section 83 of the Life Insurance Act B.E. 2535 and section 78 of the Non-Life Insurance Act B.E. 2535 against soliciting insurance contracts with foreign operators
August 13, 2026
On August 6, 2026, the National Bank of Cambodia (NBC) issued a notice calling on business owners that issue electronic money, such as e-wallet accounts and stored-value membership cards, to notify the central bank within 90 days. The notice targets businesses that are not licensed banking or financial institutions or payment service providers, but have been issuing e-money to facilitate payments within their own networks. Failure to notify the NBC may result in legal action. Background and Regulatory Basis The NBC has observed that certain businesses, including cafes, restaurants, transportation companies, entertainment centers, and gas stations, have been issuing e-money through e-wallet accounts in mobile apps or membership cards to facilitate customer payments for products or services within their own networks. Customers create e-wallet accounts and load balances to pay for goods or services at the issuing business. The NBC describes this as “single-purpose e-money.” Under the 1999 Law on Banking and Financial Institutions, providing payment facilities to customers forms part of the operations of banking and financial institutions and requires an NBC license. In addition, article 20 of the 2017 Prakas on the Management of Payment Service Institutions further prohibits legal entities other than banking and financial institutions and payment service institutions from issuing e-money. However, article 20 also provides that issuing e-money in certain limited cases does not require a license, but the NBC must be notified in advance in writing. A business may issue single-purpose e-money without a payment service institution license provided it meets all the following conditions and submits written notice to the NBC: The maximum balance per account is KHR 200,000 (approximately USD 50) or equivalent. The total aggregate balance across all accounts does not exceed KHR 800 million (approximately USD 200,000) or equivalent. The e-money is used to pay for products or
August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public