You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 22, 2023

Thailand Details Partial Exemption of Data Controllers’ Duties

On August 17, 2023, the Thai government rolled out a royal decree that provides certain exemptions to data controllers’ obligations under the Personal Data Protection Act B.E. 2562 (PDPA). The royal decree, which will come into effect after the lapse of 150 days from its publication in the Government Gazette, reflects the government’s ongoing quest to strike a balance between privacy, state interests, and the data protection regulatory burden on organizations.

The royal decree seeks to clarify the circumstances in which data controllers—including business operators and state agencies—are exempt from certain PDPA requirements on the collection, use, and disclosure of personal data and data subject rights. In doing so, it establishes three foundational pillars in considering exemptions:

  • Collection or requests for personal data are to be for the public interest pursuant to the purpose and scope prescribed by any law authorizing a state agency to carry out a certain action, without imposing an undue burden on the data controller responsible for disclosing the personal information.
  • Data controllers can share personal data without the data subject’s consent if legally authorized state agencies request it and specify the statutory provisions granting authority to request the data.
  • Data subjects and data controllers of requested personal data must have the right to submit complaints to the PDPA’s Expert Committee or seek its expertise for clarification or determination.

Under the three foundational pillars, data controllers will be partially exempted from certain requirements under the PDPA when the following state agencies request personal data:

  • The National Anti-Corruption Commission or other government entities with mandates aligned with anticorruption laws;
  • The Revenue Department, Customs Department, Excise Department, or other governmental units operating under taxation laws;
  • Local governmental bodies recognized by the Personal Data Protection Committee (PDPC), or any government unit with mandates as per the laws related to land and building taxation;
  • The Secretariat of the Cabinet, executing responsibilities as defined by the laws concerning the royal prerogatives of the monarch; and
  • State agencies acting in line with laws concerning significant public interests.

The exemption further extends to the collection, use, and disclosure of personal data by data controllers for international legal matters, covering deportation, extradition, and combating transnational organized crime.

Even with certain provisions exempted, the core duties of data controllers in ensuring data security and accuracy of personal data remain. Data controllers are still obligated to implement security standards meeting the criteria to be set forth by the PDPC within 120 days of publication of the royal decree in the Government Gazette. In certain circumstances, data controllers must also promptly act on a state agency’s instruction to correct and update data subjects’ personal data.

For more details on any aspect of compliance with Thailand’s data protection laws and regulations, please contact Tilleke & Gibbins data privacy specialists Nopparat Lalitkomon at [email protected] or Gvavalin Mahakunkitchareon at [email protected].

RELATED INSIGHTS​ 

April 28, 2025
In recent years, Vietnam has positioned itself among the leading countries in the world in terms of digital asset ownership and trading volume. This rapid adoption reflects the country’s growing digital economy and the increasing engagement of individuals and businesses in blockchain-based financial activities. Central to this growth are Resolution No. 57-NQ/TW of the Politburo dated December 22, 2024, on breakthroughs in science, technology, innovation, and national digital transformation with a vision to 2045 (“Resolution 57”) and Resolution No. 03/NQ-CP of the Government dated January 9, 2025, promulgating the Action Plan to Implement Resolution 57 (“Resolution 03”), which outline a flexible and innovative policy framework that embraces pilot programs for emerging technologies to lay the groundwork for Vietnam’s legislative framework concerning cryptocurrency and blockchain technologies. Regulatory clarity in terms of digital assets and blockchain technologies is now more critical than ever for businesses and investors. In light of this, Vietnam is currently in the process of introducing three key legal instruments, with drafts of the Law on Digital Technology Industry (“Draft DTI Law”), Resolution of the National Assembly on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Financial Center Resolution”), and Resolution of the Government on the Pilot Implementation of Crypto Asset Markets in Vietnam (“Draft Crypto Pilot Resolution”) nearing promulgation. Current Regulatory Direction and Schedule Vietnam’s regulatory framework for crypto assets and blockchain has been in a developmental stage since 2017, focusing on directions, plans, and schedules rather than established regulations. In February 2024, under Decision No. 194/QD-TTg of the Prime Minister, the Ministry of Finance (MOF) was assigned to draft a legal framework to either prohibit or regulate virtual assets and service providers by May 2025, signaling a clearer regulatory direction. In March 2025, Directive No. 05/CT-TTg of the Prime Minister directed the MOF
April 18, 2025
On April 12, 2025, Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes in the Government Gazette, with the regulation taking effect the following day. Drafts of the amendment had been shared in recent months, and the final amendment of the decree contains some additional key revisions, such as narrowing the business operators subject to the decree’s requirements, reducing operators’ obligations, and establishing collaboration between relevant stakeholders to tackle technology crime. These key revisions to the amendment are detailed below. Business operators subject to the decree: The business operators covered under the decree now include only payment service providers under the Payment System Act and digital asset operators under the Royal Decree on Digital Asset Businesses. Digital platform services under the Royal Decree on Digital Platform Service Businesses That Are Subject to Prior Notification are no longer within the scope of the decree. Definition of technology crime: The final version of the amendment removed the expanded definition of technology crime that had been included in a previous draft, leaving the decree’s existing definition unchanged. Telecommunications provider obligations: Mobile and telecommunications service providers now have an obligation to monitor and screen for content that may be related to technology crime and suspend SIM cards when instructed to do so by the National Broadcasting and Telecommunications Commission (NBTC). Transaction and account suspension: The amendment removes the decree’s complex transaction suspension procedures and leaves room for business-specific regulators (e.g., Bank of Thailand, Securities and Exchange Commission, NBTC) to impose various technology crime suspension requirements on business operators under their supervision. The newly established Center for Prevention and Suppression of Technology Crimes can also notify financial institutions and business operators of names or digital asset wallet addresses that may be related to technology crime,
April 18, 2025
On April 12, 2025, Thailand issued an amended digital asset regulation that covers offshore digital asset businesses providing services on a cross-border basis to Thai users. These businesses will now be subject to the licensing requirements of the Royal Decree on Digital Asset Business Operations B.E. 2561 (2018), which is supervised by Thailand’s Securities and Exchange Commission (SEC). A digital asset business will be deemed as providing services in Thailand—and therefore subject to requirements under the Royal Decree on Digital Asset Business Operations—if the business does any of the following: Displays content in Thai, either fully or partially; Is registered under a “.th,” or “.ไทย” domain, contains any name relating to Thailand, or uses a domain written in Thai characters; Allows or requires payments in Thai baht (THB) or receives payments through Thai bank accounts or e-wallets; Chooses Thai law to govern transactions or Thai courts to litigate any dispute; Pays online search engines to attract users in Thailand to its services; Has an office, establishment, or personnel in Thailand to support or assist users within the country; or Meets any other criteria specified by the SEC. To operate legally in Thailand, offshore operators meeting any of the above criteria will be required to incorporate a local company in Thailand in order to apply for a digital asset business license with the SEC.
April 11, 2025
Vietnam’s draft Personal Data Protection Law (PDPL) continues to evolve, with significant implications for businesses operating in the region. The latest draft, released to the public in March 2025, contains several noteworthy changes from the previous draft that businesses with operations in Vietnam should be aware of when developing their data protection strategies and compliance frameworks. The draft PDPL will be submitted to the vote of the National Assembly in May 2025 with a tentative entry into force on January 1, 2026. Key Changes in the Latest Draft PDPL 1. Redefined Categories of Personal Data The draft PDPL has made important revisions to personal data classifications: Basic personal data: An individual’s image is no longer classified as basic personal data. Sensitive personal data: Bank account information has been removed from this classification (and is now considered basic personal data), but two new categories have been added: (i) salary, allowances, and other income sources, and (ii) information on land users and information on land containing such information. Organizations should review their data classification schemes and update protection measures accordingly, particularly for salary and compensation information. 2. Data Encryption Requirements The draft PDPL explicitly states that encrypted data remains classified as personal data. Additionally, it mandates that sensitive personal data must be encrypted when stored, transmitted, received, or shared in cyberspace. Organizations and individuals can freely opt for one or more encryption solutions and encryption/decryption processes suitable for their personal data management and administration activities. 3. Biometric Data Processing The latest draft PDPL adds new protection requirements for biometric data. Organizations processing biometric data (such as fingerprints) must: Implement physical security measures for devices storing and transmitting biometric data. Use strong encryption methods during transmission and storage. Restrict access to biometric data. Have early-detection monitoring systems to detect violations of biometric