You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 1, 2019

The Reach and Liabilities of the Personal Data Protection Act

Bangkok Post: Human Resources Watch

Earlier this year, Thailand enacted its Personal Data Protection Act (PDPA), which was published in the Government Gazette on 27 May 2019. Most parts of the PDPA will become effective one year after this, on 27 May 2020. As the PDPA will have broad impact across multiple aspects of most businesses—including their human resources operations—lawmakers provided this one-year period for those affected to prepare for compliance with the PDPA.

While the definitions and mechanics of the law in relation to HR operations were covered in a previous Human Resource Watch column (29 April 2019), this article will take a closer look at the civil, criminal, and administrative penalties applicable in the event of non-compliance with the PDPA.

It is important for employers to understand that these liabilities apply to them even if they outsource their company’s HR work. Some employers misunderstand that if they turn over their HR functions to an HR service provider, the employer will not have any liability under the PDPA. Indeed, even if HR functions are outsourced, the employer will still have the same liabilities under the PDPA if the HR service provider breaches the PDPA.

For instance, if an employer assigns an outsourced provider to manage the paying of wages and calculation of social security deductions, where the providers must collect, use or disclose the personal information of employees, both the employer and the HR service provider will be acting in roles defined by the PDPA. In this scenario, the employer would be considered a ‘data controller’, while the HR service provider would be considered a ‘data processor.’ Therefore, both the employer and the HR service provider will have potential liability under the PDPA.

If the employer or HR service provider violates a PDPA provision, such as selling employees’ personal information to a financial institution or other third party without the employees’ consent, the employer as data controller would not only be liable for paying compensation to the employees who own the personal information, but could also face criminal penalties and administrative liability under the PDPA. In addition, the HR service provider, as a data processor, could face civil liability.

The PDPA provides for three types of potential liability for violation of its provisions:

1. Civil Liability

Employers or HR service providers who are found to have violated the PDPA must pay compensation to the employees who own the personal information and who received damages from the violation, regardless of whether the violation was done intentionally or negligently, except where the offender can prove that the damages were caused by force majeure or the employees’ own actions. In addition, offenders who can prove that the violation was a result of their compliance with an order of a government officer exercising his or her duties under the law will not be liable. The compensation includes all necessary expenses associated with actual or likely damages, whether for purposes of prevention or mitigation.

In addition, the court is entitled to award punitive civil damages, up to two times the amount of actual damages.

The prescription period for claiming compensation under the PDPA is three years from the date that the employees who own the personal information became aware of the violation and the identity of the offenders, or ten years from the date on which the violation of the personal data took place.

2. Criminal liability

If an employer as data controller violates the PDPA by the use or disclosure of personal information without consent in a manner that is likely to cause the other person to suffer any damages, impair his or her reputation, or other reason, the offender will face imprisonment of up to six months, a fine of up to Baht 500,000, or both.

In addition, if the offender uses or discloses personal information in order to receive unlawful benefits (or secure benefits for others), the criminal penalties that the offender will face include imprisonment for up to one year, a fine of up to Baht 1 million, or both.

The criminal offence under the PDPA is a compoundable offence, which means that it can be settled by negotiation and agreement between the parties before a court issues a final judgment.

In a case where the offender is a juristic person and the offence occurs as a result of the order or act of any director, manager, or other person in a role of responsibility, those persons must be liable for the relevant penalties. Likewise, these persons can also be penalized for their omission of an instruction or act resulting in the commission of the offence by the juristic person.

3. Administrative liability

The PDPA also imposes administrative liability on any offender in the form of an administrative fine from Baht 500,000 to Baht 5 million, depending on the nature of the violation. The PDPA establishes an expert committee with the authority to order offenders to pay an administrative fine, issue an order for rectification, or issue a warning to the offender. In determining whether to impose an administrative fine, the expert committee will consider the severity of the circumstances of the offence, the size of the business of the data controller (e.g., an employer) or data processor (e.g., HR service provider or HR department), or other circumstances.

It is possible that specific classes of data controller could be exempted from the application of all or part of the provisions of the PDPA (in addition to the excepted activities, on which see the previous article on this topic). However, these exemptions would have to be made by royal decree.

As it stands now, though, exceptions for classes of person have not been promulgated, and employers should not expect that they will be automatically exempt from PDPA compliance. Recent news from Europe of companies being heavily fined for their violations of the EU’s General Data Protection Regulation (upon which much of the PDPA is based) underline the dangers of continuing to neglect the protection of personal data. With Thailand only months away from joining the EU and other jurisdictions around the world in implementing a robust data protection regime, businesses must ensure the compliance of all of their operations—including in-house or outsourced HR functions—to avoid such costly penalties.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks. The original story can be viewed on the Bangkok Post website.

RELATED INSIGHTS​ 

April 22, 2025
Thailand’s Immigration Bureau has announced the launch of the Thailand Digital Arrival Card (TDAC) as part of ongoing efforts to improve entry procedures and streamline immigration processing. Effective May 1, 2025, all foreign nationals with any type of visa entering Thailand by any means will be required to complete the TDAC online prior to arrival. This requirement does not apply to individuals transiting or transferring through Thailand without passing through immigration control, or to those entering with a border pass. Foreign nationals planning to enter Thailand must complete and submit their TDAC within the three days prior to their arrival date. The form, which collects passport information, personal details, travel information (e.g., flight number), Thai accommodation information, and a health declaration—can be filled out in English online at https://tdac.immigration.go.th. Once the form is submitted, an acknowledgment will be sent to the email address entered on the form. This acknowledgment must be presented at the immigration checkpoint in Thailand along with travel documents for verification. The Thai government strongly encourages all foreign passport holders to complete the TDAC ahead of their departure to prevent any entry delays or issues at the checkpoint.
April 18, 2025
On March 31, 2025, Cambodia’s Ministry of Labour and Vocational Training (MLVT) issued Notification 009/25, which grants an extension for the renewal of foreign workers’ work permits and employment books in 2025. This extension is to ensure that those who have not yet applied for the renewal of their work permits are provided with sufficient time to complete the application process, as there have been delays in the submission of work permit extension requests. The new deadline for the submission of renewal applications for work permits and employment books is April 30, 2025. Applications and renewals must be processed via the MLVT’s online Foreign Workforce Centralized Management System before the specified deadline. Failure to extend the validity of work permits and employment books for foreign workers before the deadline may result in significant monetary penalties for both employers and foreign nationals. All foreign workers should renew their work permits and employment books within the extended deadline to ensure continued validity for working in Cambodia.
March 13, 2025
The recent freeze on US foreign aid has led to the suspension of billions of dollars in foreign assistance as well as widespread layoffs at contracting organizations around the world. Under this situation, USAID-funded offices in all jurisdictions, including Cambodia, may face the challenge of determining whether they need to lay off their employees. Employers in Cambodia may take different steps in response to this and other instances of sudden financial stress in order to manage their workforce in accordance with Cambodian laws and regulations. Suspension Cambodia’s Labor Law allows employers to suspend employment contracts due to a major economic or material issue or any unexpected difficulty that results in the suspension of operations. To impose this employment contract suspension, the employer must initially submit a suspension request to the Ministry of Labor and Vocational Training (MLVT), detailing the reasons for the requested suspension. If the reasons are deemed valid and the request is approved, the suspension period cannot exceed two months. During the suspension period, the employer must continue providing accommodation for employees if this benefit is already being provided. In some circumstances, the suspension period can be extended if necessary (as happened during the COVID-19 pandemic). However, financial difficulties alone may not be a valid reason for extension. The decision is at the discretion of the MLVT labor inspectors on a case-by-case basis. Therefore, given the uncertain timeline of financial difficulties that may significantly impact the employer’s budget, suspending employment contracts might be ineffective. Mass Layoffs Under Cambodia’s Labor Law, mass layoffs due to a significant reduction in an establishment’s operation or an internal reorganization foreseen by the employer are permissible. The layoff order must be based on professional qualifications, seniority period, and family burdens of the employees. The first employees to be laid off must be
February 25, 2025
On February 4, 2025, Thailand’s Board of Investment (BOI) issued Announcement No. Por. 3/2568, introducing updated qualifications, criteria, and conditions for long-term resident (LTR) visas. The updated requirements took effect immediately upon issuance of the announcement. The LTR program is intended to stimulate the economy and attract high-potential foreign nationals to Thailand, and these latest updates aim to expand access to a wider range of experts, investors, and executives to reinforce Thailand’s foreign talent pool and enhance its competitiveness. The recent updates primarily affect three categories under the LTR visa program: work-from-Thailand professionals, wealthy global citizens, and high-skilled professionals, as detailed below. Work-from-Thailand Professionals The updated LTR visa program includes some changes to the eligibility criteria for visa applicants in the work-from-Thailand professionals category: The revenue requirement for visa applicants’ employers is now USD 50 million over a three-year period, down from USD 150 million previously. Eligible foreign employers now include wholly owned subsidiaries of: companies listed on any stock exchange in any country; or private companies that have been in operation for at least three years and have generated a combined revenue of at least USD 50 million over the past three years. There are no longer work experience requirements. The other requirements remain the same. Wealthy Global Citizens For the wealthy global citizens category, the latest updates remove the requirement to have an annual personal income of USD 80,000, while the other criteria remain. Highly Skilled Professionals For the highly skilled professionals category, the latest updates expand eligibility to include lecturers in vocational or higher education, and remove work experience requirements. Other categories The updated LTR visa program does not introduce any changes for the wealthy pensioners category. However, the announcement does expand the scope of eligible dependents of LTR visa holders to cover parents and a