You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 1, 2019

The Reach and Liabilities of the Personal Data Protection Act

Bangkok Post: Human Resources Watch

Earlier this year, Thailand enacted its Personal Data Protection Act (PDPA), which was published in the Government Gazette on 27 May 2019. Most parts of the PDPA will become effective one year after this, on 27 May 2020. As the PDPA will have broad impact across multiple aspects of most businesses—including their human resources operations—lawmakers provided this one-year period for those affected to prepare for compliance with the PDPA.

While the definitions and mechanics of the law in relation to HR operations were covered in a previous Human Resource Watch column (29 April 2019), this article will take a closer look at the civil, criminal, and administrative penalties applicable in the event of non-compliance with the PDPA.

It is important for employers to understand that these liabilities apply to them even if they outsource their company’s HR work. Some employers misunderstand that if they turn over their HR functions to an HR service provider, the employer will not have any liability under the PDPA. Indeed, even if HR functions are outsourced, the employer will still have the same liabilities under the PDPA if the HR service provider breaches the PDPA.

For instance, if an employer assigns an outsourced provider to manage the paying of wages and calculation of social security deductions, where the providers must collect, use or disclose the personal information of employees, both the employer and the HR service provider will be acting in roles defined by the PDPA. In this scenario, the employer would be considered a ‘data controller’, while the HR service provider would be considered a ‘data processor.’ Therefore, both the employer and the HR service provider will have potential liability under the PDPA.

If the employer or HR service provider violates a PDPA provision, such as selling employees’ personal information to a financial institution or other third party without the employees’ consent, the employer as data controller would not only be liable for paying compensation to the employees who own the personal information, but could also face criminal penalties and administrative liability under the PDPA. In addition, the HR service provider, as a data processor, could face civil liability.

The PDPA provides for three types of potential liability for violation of its provisions:

1. Civil Liability

Employers or HR service providers who are found to have violated the PDPA must pay compensation to the employees who own the personal information and who received damages from the violation, regardless of whether the violation was done intentionally or negligently, except where the offender can prove that the damages were caused by force majeure or the employees’ own actions. In addition, offenders who can prove that the violation was a result of their compliance with an order of a government officer exercising his or her duties under the law will not be liable. The compensation includes all necessary expenses associated with actual or likely damages, whether for purposes of prevention or mitigation.

In addition, the court is entitled to award punitive civil damages, up to two times the amount of actual damages.

The prescription period for claiming compensation under the PDPA is three years from the date that the employees who own the personal information became aware of the violation and the identity of the offenders, or ten years from the date on which the violation of the personal data took place.

2. Criminal liability

If an employer as data controller violates the PDPA by the use or disclosure of personal information without consent in a manner that is likely to cause the other person to suffer any damages, impair his or her reputation, or other reason, the offender will face imprisonment of up to six months, a fine of up to Baht 500,000, or both.

In addition, if the offender uses or discloses personal information in order to receive unlawful benefits (or secure benefits for others), the criminal penalties that the offender will face include imprisonment for up to one year, a fine of up to Baht 1 million, or both.

The criminal offence under the PDPA is a compoundable offence, which means that it can be settled by negotiation and agreement between the parties before a court issues a final judgment.

In a case where the offender is a juristic person and the offence occurs as a result of the order or act of any director, manager, or other person in a role of responsibility, those persons must be liable for the relevant penalties. Likewise, these persons can also be penalized for their omission of an instruction or act resulting in the commission of the offence by the juristic person.

3. Administrative liability

The PDPA also imposes administrative liability on any offender in the form of an administrative fine from Baht 500,000 to Baht 5 million, depending on the nature of the violation. The PDPA establishes an expert committee with the authority to order offenders to pay an administrative fine, issue an order for rectification, or issue a warning to the offender. In determining whether to impose an administrative fine, the expert committee will consider the severity of the circumstances of the offence, the size of the business of the data controller (e.g., an employer) or data processor (e.g., HR service provider or HR department), or other circumstances.

It is possible that specific classes of data controller could be exempted from the application of all or part of the provisions of the PDPA (in addition to the excepted activities, on which see the previous article on this topic). However, these exemptions would have to be made by royal decree.

As it stands now, though, exceptions for classes of person have not been promulgated, and employers should not expect that they will be automatically exempt from PDPA compliance. Recent news from Europe of companies being heavily fined for their violations of the EU’s General Data Protection Regulation (upon which much of the PDPA is based) underline the dangers of continuing to neglect the protection of personal data. With Thailand only months away from joining the EU and other jurisdictions around the world in implementing a robust data protection regime, businesses must ensure the compliance of all of their operations—including in-house or outsourced HR functions—to avoid such costly penalties.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks. The original story can be viewed on the Bangkok Post website.

RELATED INSIGHTS​ 

September 2, 2025
On August 26, 2025, the Thai cabinet approved a one-year postponement of mandatory contributions to the Employee Welfare Fund. Originally scheduled to take effect on October 1, 2025, the enforcement date has been deferred to October 1, 2026. The decision to delay the implementation stems from ongoing economic uncertainties in Thailand, driven by several external and domestic factors. These include increased trade tariffs imposed by the United States, the recent rise in the national minimum wage, and continued geopolitical tensions resulting from unresolved disputes with neighboring countries. These challenges have placed significant pressure on both businesses and the labor market, prompting the government to offer temporary relief through this deferral. As a result of the postponement, the following regulations will now come into effect on October 1, 2026: Royal Decree determining the Commencement Period for Savings and Contributions to the Employee Welfare Fund; Ministerial Notification specifying the Rates of Savings and Contributions; and Ministerial Notification outlining the Criteria and Procedures for Employers to Provide Assistance in Cases of Termination of Employment or Death. The Labour Welfare Fund Committee has formally endorsed the postponement. Contribution Rates Unchanged Although the implementation has been delayed, the contribution rates remain unchanged: October 1, 2026–September 30, 2031: Employers and employees each contribute 0.25% of the employee’s wage to the fund. From October 1, 2031, onward: Contributions increase to 0.5% of the employee’s wage for both parties. All other rules and conditions concerning the Employee Welfare Fund remain in full effect.
August 29, 2025
On August 15, 2025, Laos’ Immigration Police Department introduced a pilot online arrival registration system for foreign passport holders entering the country. Under the new system, visitors to Laos will be able to register their arrival online up to three days in advance and will be exempt from filling out paper forms at the border. Starting September 1, 2025, online registrations will be accepted at four major international border checkpoints: Wattay International Airport in Vientiane, Luang Prabang International Airport, Pakse International Airport in Champasak Province, and the First Lao-Thai Friendship Bridge linking Vientiane and Nong Khai Province in Thailand. Foreign passport holders arriving in Laos from this date onward will be able to complete the online registration via the official website of the Department of Immigration: http://www.immigration.gov.la/. Upon successful registration, travelers will receive a QR code valid for three days, which must be presented to border authorities upon arrival to verify the registration. During the pilot phase, which is expected to run until early 2026, travelers who have not registered online will still have the option to complete a paper form at the checkpoint. After the pilot phase, the online registration system will become mandatory nationwide, and paper forms will no longer be accepted. This initiative marks a significant step toward modernizing Laos’ immigration procedures. Transitioning from traditional paper-based entry forms to a streamlined digital system will greatly enhance efficiency at border checkpoints. The submission of traveler information ahead of arrival is expected to drastically reduce processing times and alleviate congestion at arrival counters, especially during peak travel periods.
August 20, 2025
On August 7, 2025, the government of Vietnam promulgated Decree No. 219/2025/ND-CP on foreign workers working in Vietnam (Decree 219), introducing substantial reforms to the management of foreign employees. Taking immediate effect upon issuance, and superseding earlier regulations on foreign employees under Decree No. 152/2020/ND-CP as amended by Decree No. 70/2023/ND-CP (collectively referred to as “Decree 152”), Decree 219 sets out clear timeframes and application requirements for work permit issuance, while adopting more flexible policies to support business operations. The key new provisions are as follows: 1. Relaxed Requirements Regarding Job-Posting Under Decree 152, employers were required to follow a complex process to apply for work permits or work permit exemption certificates for foreign employees. This included posting an advertisement for any position the employer wished to fill with a foreign employee on a designated online portal for a given amount of time, to demonstrate that the company tried, but failed, to find a suitable Vietnamese candidate for the position. This job-posting step now only applies when the foreigner will work in Vietnam under a local labor contract. Foreigners coming to Vietnam as intra-corporate transferees (i.e., as secondees) or working under service contracts are exempt. The job-posting period is also reduced from 15 calendar days to five business days. Employers may also now post the advertisements on multiple websites instead of only the online portal of the Ministry of Labor, Invalids and Social Affairs (now the Ministry of Home Affairs after government restructuring) or the provincial-level employment service center. 2. Work Permit Application Dossier Previously, employers were required to complete a preapproval step, whereby they had to submit a dossier explaining their foreign labor demand that required approval from the labor authority. Once approval for the foreign labor demand was granted, the approval dossier was an integral part of
August 20, 2025
With the shift in US policy to discourage DEI programs among government and private-sector employers, some companies have been cutting back. But US companies should be cautious in eliminating their DEI programs globally, as some elements of these programs are obligations under local laws in Vietnam, Thailand, and Cambodia.