You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 22, 2023

Thailand Details Partial Exemption of Data Controllers’ Duties

On August 17, 2023, the Thai government rolled out a royal decree that provides certain exemptions to data controllers’ obligations under the Personal Data Protection Act B.E. 2562 (PDPA). The royal decree, which will come into effect after the lapse of 150 days from its publication in the Government Gazette, reflects the government’s ongoing quest to strike a balance between privacy, state interests, and the data protection regulatory burden on organizations.

The royal decree seeks to clarify the circumstances in which data controllers—including business operators and state agencies—are exempt from certain PDPA requirements on the collection, use, and disclosure of personal data and data subject rights. In doing so, it establishes three foundational pillars in considering exemptions:

  • Collection or requests for personal data are to be for the public interest pursuant to the purpose and scope prescribed by any law authorizing a state agency to carry out a certain action, without imposing an undue burden on the data controller responsible for disclosing the personal information.
  • Data controllers can share personal data without the data subject’s consent if legally authorized state agencies request it and specify the statutory provisions granting authority to request the data.
  • Data subjects and data controllers of requested personal data must have the right to submit complaints to the PDPA’s Expert Committee or seek its expertise for clarification or determination.

Under the three foundational pillars, data controllers will be partially exempted from certain requirements under the PDPA when the following state agencies request personal data:

  • The National Anti-Corruption Commission or other government entities with mandates aligned with anticorruption laws;
  • The Revenue Department, Customs Department, Excise Department, or other governmental units operating under taxation laws;
  • Local governmental bodies recognized by the Personal Data Protection Committee (PDPC), or any government unit with mandates as per the laws related to land and building taxation;
  • The Secretariat of the Cabinet, executing responsibilities as defined by the laws concerning the royal prerogatives of the monarch; and
  • State agencies acting in line with laws concerning significant public interests.

The exemption further extends to the collection, use, and disclosure of personal data by data controllers for international legal matters, covering deportation, extradition, and combating transnational organized crime.

Even with certain provisions exempted, the core duties of data controllers in ensuring data security and accuracy of personal data remain. Data controllers are still obligated to implement security standards meeting the criteria to be set forth by the PDPC within 120 days of publication of the royal decree in the Government Gazette. In certain circumstances, data controllers must also promptly act on a state agency’s instruction to correct and update data subjects’ personal data.

For more details on any aspect of compliance with Thailand’s data protection laws and regulations, please contact Tilleke & Gibbins data privacy specialists Nopparat Lalitkomon at [email protected] or Gvavalin Mahakunkitchareon at [email protected].

RELATED INSIGHTS​ 

June 8, 2023
At a conference organized by Vietnam’s Ministry of Public Security (MPS) on June 7, 2023, government officials provided more guidance on the recently issued Personal Data Protection Decree (PDPD), which is set to take effect on July 1, 2023. Key takeaways included the following: A national portal on personal data protection for online submission of notifications and registrations will be launched before July 1, 2023. The MPS also plans to issue templates for data processing impact assessments (DPIAs) and transfer impact assessments (TIAs) in the near future. The PDPD requires data controllers, data processors, and data controller-processors to prepare a DPIA at the start of personal data processing. The MPS clarified that the DPIA is expected to be prepared and submitted once. Only changes to its content would require submission of an updated DPIA. Both DPIAs and TIAs (which are for cross-border data transfers) must be prepared in Vietnamese. Since the sale and purchase of personal data is strictly prohibited unless explicitly permitted by law, the MPS has handled approximately 14 cases involving unlawful trading of personal data, including sensitive data. Under the PDPD, sensitive data has a broader definition than under the GDPR (the European Union’s General Data Protection Regulation), and also includes location data, creditworthiness, and personal financial data. Consent is not a legal basis for the trading of personal data, including sensitive data. The 72-hour timeline for responding to a data subject’s request does not mean 72 working or business hours. Rather, it means 72 actual consecutive hours. Any organization transferring the personal data of Vietnamese citizens outside of Vietnam must comply with the PDPD, regardless of the organization’s location. For organizations incorporated overseas that must comply with the PDPD, there is no requirement to appoint a local representative (unlike the GDPR)—but appointment of a data
June 2, 2023
In Southeast Asia, artificial intelligence (AI) products and services are being leveraged across industries such as finance, healthcare, retail, agriculture, and manufacturing. Governments across the region are recognizing the benefits of harnessing AI and the positive impact of AI technology on economic development. As the rise in AI deployment creates opportunities for economic growth in Southeast Asia, regulatory and digital governance efforts should focus on ethical, inclusivity, and cybersecurity concerns to help ensure that the widespread use of AI technology in the region is sustainable. Two jurisdictions in the region that have already made significant strides in developing initiatives surrounding AI are Singapore and Thailand. Singapore Due to its more advanced technological infrastructure, Singapore was one of the first countries in the region to address AI-related issues. Singapore has been aligning its data protection policies and regulations with the changing digital landscape since 2012—the year Singapore passed its Personal Data Protection Act. In 2019, Singapore unveiled its National AI Strategy to increase the use of AI technologies and deploy “scalable, impactful AI solutions in key verticals by 2030.” The goal is to align talent, regulation, and business growth to ensure AI applications serve society. Singapore’s approach is to facilitate innovation while safeguarding consumer interests, as it strives to become one of the regional leaders in the field of AI. In terms of Singapore’s regulatory landscape, Singapore’s Personal Data Protection Commission (PDPC) oversees data and AI, including AI developers and AI-using companies, which consist of backroom operations, front-end usage companies, and distributors of equipment with AI features. The Singapore Academy of Law (SAL) oversees all laws applicable to AI systems and decides on issues that impact the AI industry. Singapore has joined various bilateral and regional trade arrangements to facilitate research, development, and collaboration in support of its growing digital
May 24, 2023
The draft Royal Decree on Artificial Intelligence System Service Business, which was introduced by the Office of the National Digital Economy and Society Commission earlier for public comment in October last year, focuses on potential risks from artificial intelligence (AI) systems to public health, safety, and freedoms. The framework emphasizes the importance of risk assessment, reporting requirements, and the establishment of specific measures and criteria deemed necessary to minimize AI risks. AI Systems Defined by the Decree Under the draft royal decree, an AI system is defined as a machine-based system that can make predictions, recommendations, or decisions that affect real or virtual environments pursuant to the objectives set by humans. The definition clarifies that artificial intelligence systems are designed to operate at different levels of autonomy, including: machine learning AI; logic-based and knowledge-based AI; statistical AI; Bayesian estimation AI; and search and optimization AI. Risk-based Approach The draft AI royal decree takes a risk-based approach to regulation and specifically identifies prohibited or high-risk AI services that could cause harm or engage in unethical practices to ensure that AI systems do not pose major risks to public health, safety, or freedoms. The extent of regulatory scrutiny applied to an AI system corresponds to the level of risk presented by the AI system. For example, AI systems that pose unacceptable risks are generally prohibited, AI systems considered to be high-risk are subject to a conformity assessment, and AI systems considered to be limited-risk are subject to transparency requirements. Compliance with specified criteria and procedures to minimize potential risks of each AI service would be further outlined in subregulations. Prohibited AI Systems The draft AI royal decree prohibits AI systems that: employ subliminal techniques to covertly influence human behavior (below the threshold of conscious awareness); utilize social scoring; access sensitive personal
May 17, 2023
In Myanmar, a Union Tax Law is enacted each year to announce the rates of tax set out in the Income Tax Law 1974, the Commercial Tax Law 1990, and the Special Goods Tax Law 2016. The Union Tax Law 2023 (UTL 2023) came into force on April 1, 2023. It sets the rates of special goods tax (SGT), income tax (IT), and commercial tax (CT) for the period of April 1, 2023, to March 31, 2024, and exempts certain goods and services from these taxes. The key changes implemented by the UTL 2023 are summarized below. Special Goods Tax The UTL 2023 exempts battery electric vehicles (BEVs) from SGT. At the same time, it increases the rate of SGT on imported liquor. Previously, the rate of SGT ranged from 190 MMK per liter to 60 percent of the per-liter price of imported liquor in the previous fiscal year. The UTL 2023 raises the minimum rate to 209 MMK per liter while leaving the upper rate unchanged. Commercial Tax and Customs Tariffs BEVs imported into Myanmar were made exempt from CT under the Law Amending the Union Tax Law 2022. The UTL 2023 extends the exemption until the end of the 2023–24 fiscal year, along with two- and three-wheeler BEVs, BEV batteries, and related parts for specific use in BEVs. The CT exemption for battery charging services for BEVs, also introduced in 2022, has similarly been extended. Following enactment of the UTL 2023, the Ministry of Planning and Finance (MOPF) issued Notification No. 31/2023, reducing to zero the customs tariffs on imported BEVs, including those imported completely built up (CBU), completely knocked down (CKD), or semi-knocked down (SKD). The tariffs on spare parts and materials for BEVs have also been reduced to zero. In addition to exempting BEVs from