You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 22, 2023

Thailand Details Partial Exemption of Data Controllers’ Duties

On August 17, 2023, the Thai government rolled out a royal decree that provides certain exemptions to data controllers’ obligations under the Personal Data Protection Act B.E. 2562 (PDPA). The royal decree, which will come into effect after the lapse of 150 days from its publication in the Government Gazette, reflects the government’s ongoing quest to strike a balance between privacy, state interests, and the data protection regulatory burden on organizations.

The royal decree seeks to clarify the circumstances in which data controllers—including business operators and state agencies—are exempt from certain PDPA requirements on the collection, use, and disclosure of personal data and data subject rights. In doing so, it establishes three foundational pillars in considering exemptions:

  • Collection or requests for personal data are to be for the public interest pursuant to the purpose and scope prescribed by any law authorizing a state agency to carry out a certain action, without imposing an undue burden on the data controller responsible for disclosing the personal information.
  • Data controllers can share personal data without the data subject’s consent if legally authorized state agencies request it and specify the statutory provisions granting authority to request the data.
  • Data subjects and data controllers of requested personal data must have the right to submit complaints to the PDPA’s Expert Committee or seek its expertise for clarification or determination.

Under the three foundational pillars, data controllers will be partially exempted from certain requirements under the PDPA when the following state agencies request personal data:

  • The National Anti-Corruption Commission or other government entities with mandates aligned with anticorruption laws;
  • The Revenue Department, Customs Department, Excise Department, or other governmental units operating under taxation laws;
  • Local governmental bodies recognized by the Personal Data Protection Committee (PDPC), or any government unit with mandates as per the laws related to land and building taxation;
  • The Secretariat of the Cabinet, executing responsibilities as defined by the laws concerning the royal prerogatives of the monarch; and
  • State agencies acting in line with laws concerning significant public interests.

The exemption further extends to the collection, use, and disclosure of personal data by data controllers for international legal matters, covering deportation, extradition, and combating transnational organized crime.

Even with certain provisions exempted, the core duties of data controllers in ensuring data security and accuracy of personal data remain. Data controllers are still obligated to implement security standards meeting the criteria to be set forth by the PDPC within 120 days of publication of the royal decree in the Government Gazette. In certain circumstances, data controllers must also promptly act on a state agency’s instruction to correct and update data subjects’ personal data.

For more details on any aspect of compliance with Thailand’s data protection laws and regulations, please contact Tilleke & Gibbins data privacy specialists Nopparat Lalitkomon at [email protected] or Gvavalin Mahakunkitchareon at [email protected].

RELATED INSIGHTS​ 

December 2, 2022
On November 11, 2022, Myanmar’s Ministry of Commerce (MOC) announced a pilot period for importing electric vehicles into Myanmar, which came into force with MOC Order No. 62/2022, issued under the Import and Export Law. A separate order (No. 61/2022) issued on the same day specifies rules for importation of motorcycles by companies that do not have a certificate to open a showroom, as well as rules for opening motorcycle showrooms. Electric Vehicle Importation According to the order, which takes effect January 1, 2023, “electric vehicles” includes only battery electric vehicles (BEVs) for both personal use and passenger use. In order to import electric vehicles into Myanmar without having a certificate to open a showroom, companies must: Be registered as a company, either wholly owned by nationals or a joint venture, at the Directorate of Investment and Company Administration (DICA); Be able to present the purchase and sales agreement for each brand of imported electric vehicles; Receive approval from the National Steering Committee for Development of Electric Vehicles and Associated Businesses, and import according to the quality and quantity of electric vehicles permitted by the committee; Arrange the necessary warranty, spare parts availability, and after-sales service for the imported electric vehicles; Deposit a bank guarantee of MMK 50 million at a bank recognized by the Central Bank of Myanmar; and Apply for a purchase permit at the MOC, for the purpose of registering the imported vehicles with the Road Transport Administration Department. BEV Tax Exemption Following MOC Order No. 62/2022, BEVs and their batteries are now exempted from commercial tax and special goods tax, which came into force with the Law Amending the Union Tax Law 2022 (State Administrative Council Law No. 48/2022) dated November 17, 2022. These tax exemptions will be effective from October 1, 2022, to March
November 4, 2022
Lawyers from Tilleke & Gibbins in Cambodia, Laos, Myanmar, Thailand, and Vietnam have contributed to the new Multilaw Global Checklist for Monitoring Staff Data, which compiles essential information on regulations related to collection of data on employees. Such collection of data is an increasingly important concern for employers and entrepreneurs as the world pays closer attention to diversity, equality, and antidiscrimination in the workplace. The checklist contains fundamental information for each jurisdiction on legal considerations pertaining to employment diversity surveys and what can and cannot be asked. The table-style list is global in scope, with a separate line for each jurisdiction. The jurisdictional entries are grouped by region, allowing the reader to quickly compare how various countries treat different issues in each part of the world. In each column is a common question about how employers can monitor staff data in full compliance with the law, covering issues such as: Requesting data from employees; Type and format of data captured; Data storage and access; Retention of data; Intra-group cross-border data transfers; and Specific considerations for each jurisdiction. Multilaw, of which Tilleke & Gibbins is a member, is a global network of carefully selected, independent law firms consisting of over 10,000 commercial lawyers in more than 100 countries, able to provide expert legal advice in complex environments around the globe. The full checklist is available for free on the Multilaw website.
November 1, 2022
Background Thailand’s Personal Data Protection Act 2019 (‘PDPA’) is the country’s first unified data privacy legislation for personal data protection. Coming at a time when people around the world are increasingly aware of the risks and negative consequences of their personal data being compromised, the PDPA seeks to align with international standards, such as the General Data Protection Regulation (Regulation (EU) 2016/679) (‘GDPR’). Prior to the enactment of the PDPA, privacy rights were recognised in the Constitution of the Kingdom of Thailand. Beyond this, the handling of personal data was governed by specific regulations for a handful of sectors, such as telecommunications, financial institutions, securities, and life sciences. The PDPA was announced in the Royal Gazette of the Kingdom of Thailand on 27 May 2019, with an exemption for the enforcement of its requirements in relation to the collection, use, disclosure, and transfer (‘process’ or ‘processing’) of personal data, as well as its provisions on data subjects rights. After some delays caused by the impact of the COVID-19 pandemic over the past two years, the PDPA finally came fully into force on 1 June 2022. Unlike most legislation in Thailand, the PDPA has an extraterritorial aspect whereby data controllers and data processors outside Thailand may be subject to the PDPA if the processing activities they undertake fall under the criteria prescribed in the PDPA. The basics The PDPA defines personal data as any data pertaining to a living natural person that enables the identification of that person, whether directly or indirectly, such as phone number, address, email address, or anything else that might enable the data subject’s identification. The PDPA applies to personal data in any form, whether digital or otherwise. The PDPA introduces two main roles relating to the handling of others’ personal data: the data controller and the
October 21, 2022
On September 21, 2022, the Electronic Transactions Development Agency (ETDA) held another public hearing on the draft Royal Decree on Digital Platforms and its sub-regulations. This updated draft Royal Decree on Digital Platforms (which is subsequent to a previous round of updates last year) is anticipated to be the final draft before it is proposed to the king for endorsement. Thereafter, it will be published in the Government Gazette and will become effective 240 days after the publication date. The key issues under the latest draft royal decree are as follows: Exemption for certain regulated businesses. The current draft royal decree exempts business operators that are regulated by the Bank of Thailand or the Securities and Exchange Commission, as well as digital platforms operated by government agencies for noncommercial purposes, from the application of the royal decree. Nevertheless, these business operators must ensure that their digital platform has transparency, fairness, and standards which are not less than those required under the Royal Decree. Definition of digital platform. According to the public hearing, the definition of a digital platform has been amended to exclude digital platforms that are used to offer the goods or services of a digital platform provider or its affiliate acting on its behalf, regardless of whether the offering of such goods or services is made to a third party or the affiliate. Appointment of a local contact. Instead of appointing a local representative with no limit of liability, the current draft royal decree only requires offshore digital platform providers to appoint a local contact to coordinate with the ETDA. The local contact must not operate any business in Thailand under the Foreign Business Act. Notification of the ETDA. Digital platforms as defined under the royal decree must notify the ETDA of certain information—such as the name