You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 22, 2023

Thailand Details Partial Exemption of Data Controllers’ Duties

On August 17, 2023, the Thai government rolled out a royal decree that provides certain exemptions to data controllers’ obligations under the Personal Data Protection Act B.E. 2562 (PDPA). The royal decree, which will come into effect after the lapse of 150 days from its publication in the Government Gazette, reflects the government’s ongoing quest to strike a balance between privacy, state interests, and the data protection regulatory burden on organizations.

The royal decree seeks to clarify the circumstances in which data controllers—including business operators and state agencies—are exempt from certain PDPA requirements on the collection, use, and disclosure of personal data and data subject rights. In doing so, it establishes three foundational pillars in considering exemptions:

  • Collection or requests for personal data are to be for the public interest pursuant to the purpose and scope prescribed by any law authorizing a state agency to carry out a certain action, without imposing an undue burden on the data controller responsible for disclosing the personal information.
  • Data controllers can share personal data without the data subject’s consent if legally authorized state agencies request it and specify the statutory provisions granting authority to request the data.
  • Data subjects and data controllers of requested personal data must have the right to submit complaints to the PDPA’s Expert Committee or seek its expertise for clarification or determination.

Under the three foundational pillars, data controllers will be partially exempted from certain requirements under the PDPA when the following state agencies request personal data:

  • The National Anti-Corruption Commission or other government entities with mandates aligned with anticorruption laws;
  • The Revenue Department, Customs Department, Excise Department, or other governmental units operating under taxation laws;
  • Local governmental bodies recognized by the Personal Data Protection Committee (PDPC), or any government unit with mandates as per the laws related to land and building taxation;
  • The Secretariat of the Cabinet, executing responsibilities as defined by the laws concerning the royal prerogatives of the monarch; and
  • State agencies acting in line with laws concerning significant public interests.

The exemption further extends to the collection, use, and disclosure of personal data by data controllers for international legal matters, covering deportation, extradition, and combating transnational organized crime.

Even with certain provisions exempted, the core duties of data controllers in ensuring data security and accuracy of personal data remain. Data controllers are still obligated to implement security standards meeting the criteria to be set forth by the PDPC within 120 days of publication of the royal decree in the Government Gazette. In certain circumstances, data controllers must also promptly act on a state agency’s instruction to correct and update data subjects’ personal data.

For more details on any aspect of compliance with Thailand’s data protection laws and regulations, please contact Tilleke & Gibbins data privacy specialists Nopparat Lalitkomon at [email protected] or Gvavalin Mahakunkitchareon at [email protected].

RELATED INSIGHTS​ 

February 3, 2025
On January 28, 2025, the Office of the Personal Data Protection Committee (PDPC) hosted Data Privacy Day 2025, bringing together over 1,000 participants from both the public and private sectors. The event underscored the importance of personal data protection and aimed to raise nationwide awareness while fostering a culture of compliance. During the event, the PDPC reaffirmed its commitment to strengthening Thailand’s data protection framework to align with international standards. The initiative also emphasized the collective goal of achieving zero data breaches. During the first session of the event, Mr. Prasert Jantararuangtong, deputy prime minister and minister of digital economy and society, delivered a speech highlighting the role of personal data protection in fostering Thailand’s digital economy. He emphasized that strong data protection measures enhance business credibility, build consumer trust, and attract foreign investment. He also addressed the PDPC’s “zero data breach” policy and the ongoing issue of data leaks, which have been exploited by call-center scam operations to deceive the public and cause financial harm. Additionally, Mr. Prasert announced that the Thai cabinet has approved a draft amendment to the Emergency Decree on Cyber Crime Prevention and Suppression B.E. 2566 (2023), commonly referred to as the “Cyber Crime Decree.” The draft will now proceed to the Council of State for review before its official enactment. Key provisions of the amendment include holding financial institutions, telecom providers, and social media platforms accountable for technology-related crimes; requiring compensation for victims; and enforcing stricter security measures. Cyber offenses, including personal data trading, face harsher penalties of up to THB 5 million in fines or five years of imprisonment. Authorities are also empowered to suspend suspicious SIM cards for committing illegal activities and expedite monetary refunds for victims without court approval. In the second session, the Office of the PDPC presented its
January 30, 2025
The Thai cabinet has approved a draft amendment of the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes as proposed by the Ministry of Digital Economy and Society to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Following the Council of State’s review, the emergency decree will be become effective immediately upon its enactment and publication in the Government Gazette. While the draft amendment is not yet publicly available, the government recently indicated that the emergency decree aims to empower authorities with decisive measures to combat cybercrime effectively. It underscores the shared responsibility among various sectors, including banking, telecommunications, and online platforms, in safeguarding against technological crimes. Key provisions of the draft amendment of the emergency decree include: Telecommunications provider obligations: Telecommunications service providers must suspend SIM cards associated with criminal activities. The National Broadcasting and Telecommunications Commission and mobile service providers themselves are authorized to temporarily suspend mobile phone numbers if there is reasonable suspicion of involvement in criminal activities. Banking responsibilities: Financial institutions are required to promptly report mule accounts to the Anti-Money Laundering Office to facilitate quick restitution to victims. The Anti-Money Laundering Transaction Committee is empowered to order the return of funds to victims without requiring a final court ruling. Penalties for noncompliance: The amended emergency decree introduces penalties for noncompliance by regulated entities that fail to prevent criminal activities for offenses related to technology crimes in the following cases: Digital asset services: Those engaged in the buying, selling, or exchanging of digital assets, such as cryptocurrencies and digital tokens, as well as digital asset businesses that launder money obtained from online crimes by converting it into digital currency, will be subject to imprisonment for up to one year, a fine of up to THB 100,000,
January 24, 2025
Following Vietnam’s adoption of the new Law on Data (“Data Law”) on November 30, 2024, there remained uncertainty as to what impact the new framework would have on businesses in Vietnam and abroad. The government has now released a package of four draft legal documents aimed at guiding the implementation of the Data Law: (1) a decree on the National Data Development Fund (“NDDF Decree”), (2) a decree related to regulations on scientific, technological, and innovation activities and data products and services (“Decree on Specific Activities”), (3) a decree detailing a number of articles and measures to implement the Data Law (“Implementation Decree”), and (4) a decision on the lists of important data and core data. This article will provide an overview of the draft legislation. 1. NDDF Decree The draft NDDF Decree relates to the establishment, management and use of a National Data Development Fund (“NDDF”), which is a non-profit and non-budgetary state financial fund established and managed by the Minister of the Ministry of Public Security (MPS). The NDDF has legal personality and is fully state owned, operating similarly to a single-member limited liability company. Its main objectives are to support, promote, and invest in artificial intelligence (AI), the Internet of Things (IoT), and other new technologies and innovation. The NDDF may lend to, invest in, or otherwise support eligible organizations. The draft NDDF Decree also proposes a series of regulations on donations to the NDDF and from the NDDF (through expense support), the lending activities of the NDDF to commercial banks, which will in turn lend to eligible organizations, the investment activities in data products and services innovative start-ups, and other kinds of support. The government commits to provide VND 1 trillion (approx. USD 40 million) to the NDDF, evidencing the importance the government places on
January 23, 2025
Thailand’s Ministry of Digital Economy and Society, through the Digital Economy Promotion Agency (DEPA), recently held a focus group hearing on the draft Gaming Industry Promotion Act. This legislation seeks to strike a balance by promoting the growth of the online game industry while safeguarding society, with a particular focus on protecting youth from potential negative impacts and enhancing a positive gaming environment. From the public releases, the draft act is expected to address several key aspects, including: Registration requirements for key industry players, such as developers and platform providers. It is also worth monitoring whether these requirements will also apply to offshore entities offering services to users in Thailand. Governance measures, such as game rating systems and measures to address online gambling and violence in games. Incentives, such as the establishment of a fund to support the gaming industry, and tax incentives to promote Thai gaming businesses. DEPA plans to incorporate feedback from the focus group hearing to refine the Draft Act. The legislation is expected to be submitted to the cabinet for approval by April 2025, with enactment expected by the end of 2025. As this draft law is still at an early stage, amendments may be introduced during the legislative process. Businesses and stakeholders in the gaming industry are encouraged to monitor the matter closely and assess how the developing legislation may impact their operations.