You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 2, 2026

Thailand Insurance Industry: AI and Privacy Regulatory Updates

Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance.

What Has Changed: OIC and PDPC Alignment

The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers.

  • Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible.
  • Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors.
  • Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels.
  • DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on a large scale”—expressly including insurance—must appoint and register a data protection officer (DPO). The absence of a registered DPO or an outdated record of processing activities (ROPA) that fails to map agent-level data flows is now considered a high-risk compliance gap.

AI in Insurance: Draft PDPC Guidelines

The PDPC’s draft AI guidelines carry particular significance for insurers. The guidelines single out insurance risk assessments as an example of automated decision-making that produces legal effects or significantly affects data subjects. Organizations using AI-driven tools for underwriting, claims processing, or policy recommendations must implement a human-in-the-loop mechanism with actual authority to overturn AI decisions and must document processes for data subjects to request review. A data protection impact assessment (DPIA) is required for high-risk AI projects, including automated decision-making with legal effects and large-scale processing of sensitive data. Leakage of sensitive health or financial data through AI systems is categorized as high risk, requiring notification to both the PDPC and affected data subjects without delay.

Cross-Border Data Transfers

For multinational insurance groups, a binding corporate rules (BCRs) regulation became fully effective on February 17, 2026, providing a formal mechanism for intragroup cross-border transfers. Groups that already hold GDPR-approved BCRs may use a “fast-track” process by submitting their existing BCRs together with a Thailand addendum. Alternatively, Standard Contractual Clauses based on the ASEAN Model Contractual Clauses may be used for transfers to third-party reinsurers or service providers outside Thailand.

Practical Compliance Steps

Given the current regulatory landscape, insurers should consider the following immediate and near-term actions.

  • Governance and organization. Register a DPO with the PDPC if not already done, and ensure that the DPO has a direct reporting line to senior management with sufficient authority and resources to fulfill the role. Update the ROPA to comprehensively map all processing activities, including data flows through agents, brokers, and third-party administrators.
  • Consent architecture overhaul. Redesign application forms and digital onboarding flows so that marketing consent is presented as a separate, clearly labeled opt-in, entirely distinct from the consent required for the insurance contract itself. Ensure that refusal to consent to marketing does not affect the customer’s ability to obtain coverage.
  • Agent and vendor compliance program. Issue updated written instructions and security protocols to all insurance intermediaries classified as data processors. Review and strengthen data processing agreements with all third-party processors, including specific provisions for PDPA responsibilities, security standards, audit rights, breach notification obligations, and end-of-term data deletion or return. Implement a periodic audit cycle—rather than relying on static contractual commitments—to verify vendor compliance.
  • Privacy notice refresh. Prepare a concise summary privacy notice for distribution alongside insurance policies, covering all required elements under the OIC guidance. For digital tele-sales, implement prerecording disclosures informing customers that their voice or image data will be processed under the PDPA.
  • AI and automated decision-making readiness. Conduct DPIAs for all AI-driven underwriting, claims, and risk-assessment tools currently in use or under development. Establish a documented human-in-the-loop process for any automated decision that produces legal effects on policyholders, including a clear escalation path and a mechanism for data subjects to contest decisions.
  • Breach response preparedness. Ensure that internal incident response plans can meet the 72-hour notification deadline to the PDPC, with particular attention to AI-related data leakage scenarios.
  • Cross-border transfer mechanism. For multinational groups, evaluate whether BCR certification—including the fast-track route—or SCCs provide the most efficient path for data transfers to group entities or reinsurers abroad.

Outlook

Thailand’s insurance sector faces a significantly more demanding compliance environment as PDPA enforcement matures and OIC alignment tightens. The convergence of stricter consent rules, expanded liability for intermediary conduct, new AI governance expectations, and a workable cross-border transfer framework means that insurers must move from reactive compliance to proactive data governance. Organizations that address these areas systematically—beginning with DPO registration, ROPA updates, and consent architecture—will be best positioned to manage regulatory risk and maintain the trust of their policyholders.

RELATED INSIGHTS​ 

July 11, 2025
Vietnam’s recent embrace of “regulatory sandboxes” reflects a deliberate policy choice to balance the need for robust oversight with an equally pressing imperative to catalyze innovation. A sandbox is a controlled, time-bound framework in which businesses may pilot emerging technologies, products, or business models under relaxed or tailor-made regulatory requirements, thereby allowing regulators to observe risks in real time while innovators validate commercial viability without bearing the full weight of the traditional compliance regime. By issuing sandbox regulations, the government of Vietnam is signaling its commitment to accelerating digital transformation, attracting investment, and developing a knowledge-based economy, all while safeguarding financial stability, consumer protection, and national security. This strategy is embodied in a suite of instruments that together establish sector-specific sandboxes: Decree No. 94/2025/ND-CP on the Regulatory Sandbox in the Banking Sector (Fintech Sandbox Decree), effective July 1, 2025. Law on Digital Technology Industry (DTI Law), effective January 1, 2026, and Law on Science, Technology and Innovation (STI Law), effective October 1, 2025. Resolution No. 222/2025/QH15 on International Financial Centers (IFC Resolution), effective September 1, 2025. In addition, a draft resolution on the pilot implementation of the crypto-asset market (Draft Crypto Pilot Resolution) is expected to introduce a dedicated sandbox for crypto-asset service providers later this year, further underscoring Vietnam’s holistic, forward-looking approach to regulating emerging technologies. Below is a brief summary of all the regulatory sandboxes, who they are open for, and what businesses are attracted. Fintech Sandbox Decree Under the Fintech Sandbox Decree, besides credit institutions and foreign bank branches, fintech companies operating in Vietnam can apply for a Certificate of Sandbox Participation issued by the State Bank of Vietnam to operate any of the following services in Vietnam: Credit scoring: A solution applicable to information technology systems of credit institutions, branches of foreign banks, and fintech
July 11, 2025
On June 10, 2025, Thailand’s Supreme Administrative Court accepted for consideration a pivotal lawsuit concerning the regulatory obligations of administrative agencies over internet-based television broadcasting services, commonly referred to as over-the-top (OTT) services. This court’s decision in the case may set important precedents for how OTT platforms are regulated, especially regarding consumer protections and advertising practices. Background A user of an OTT television application initiated legal action against the National Broadcasting and Telecommunications Commission (NBTC) and related officials, alleging that the lack of clear regulatory criteria and oversight allowed OTT operators to broadcast general television content while compelling users to view advertisements before and during programming. The plaintiff argued this constituted consumer exploitation and claimed that the responsible authorities neglected or delayed their statutory duties under the Act on the Organization to Assign Radio Frequencies and Regulate Broadcasting, Television, and Telecommunications Services B.E. 2553 (2010). Initially, the Central Administrative Court declined to accept the lawsuit. However, on appeal, the Supreme Administrative Court determined that the claim fell within its jurisdiction, noting that OTT television services—defined under section 4 of the governing act—are subject to the same regulatory framework as traditional television services, regardless of the transmission method (frequency, cable, internet, or other system). Implications for OTT Services The key implications for OTT services concern the following issues: Regulatory oversight: The court recognized that OTT television services are explicitly covered under Thailand’s broadcast regulatory regime. Regulatory agencies may be compelled to establish clear operational rules and oversight mechanisms for OTT providers. Consumer protections: The plaintiff’s claim that excessive or unavoidable in-program advertising constitutes consumer exploitation was acknowledged as a matter of public interest. This may prompt stricter advertising standards for OTT platforms. Licensing requirements: The case raises the prospect that OTT operators may be required to obtain licenses from the
July 10, 2025
For companies and individuals doing business in Vietnam, a common question is whether electronic signatures (e-signatures) are legally recognized under Vietnamese law. This matter is governed by Law No. 20/2023/QH15 on Electronic Transactions issued on June 22, 2023 (ETL 2023) and its guiding legal documents such as Decree No. 23/2025/ND-CP dated February 21, 2025, and Circular 06/2024/TT-BTTTT dated July 1, 2024 (Circular 06). Recognition of Validity of E-signatures in Vietnam As a general principle, the ETL 2023 confirms that an e-signature cannot be denied legal validity solely due to its electronic form. The law categorizes e-signatures into three types: Type 1: Specialized e-signatures for organizations Type 2: Public digital signatures for individuals and organizations Type 3: Specialized digital signatures for government agencies Among these types, only secure specialized e-signatures (a secure e-signature of type 1) and digital signatures (type 2) are explicitly granted the same legal validity as handwritten (wet) signatures. This distinction is particularly important in legal disputes and for transactions with government agencies. (For more details, please refer to our previous article.) Domestic e-signatures A domestic organization can choose to use secure specialized e-signatures (type 1) and/or digital signatures (type 2) while a Vietnam-based individual can choose digital signatures (type 2) for their transactions—particularly for those involving government agencies and transactions of high value and complexity which require stronger legal protection. Specialized e-signatures (type 1) can be created by the organizations themselves, and additionally must be “secure” to be explicitly recognized as having the same legal validity as handwritten signatures. For clarity, “secure” specialized e-signatures are those certified (granted a safety certificate) by the Ministry of Science and Technology (MST). (This was formerly the responsibility of the Ministry of Information and Communications, which was merged with MST under Vietnam’s 2025 administrative restructuring.) Digital signatures (type 2) are
July 9, 2025
On June 16, 2025, the National Assembly of Vietnam adopted Law No. 75/2025/QH15 amending and supplementing a number of articles of the 2012 Advertising Law, with an effective date of January 1, 2026. The amended Advertising Law was enacted to further refine the legal framework for advertising activities in the modern era. Online Advertising Under the amended Advertising Law, “online advertising” is defined to encompass not only advertising on electronic newspapers and electronic information pages (as provided under the 2012 Advertising Law) but also advertising on other electronic venues, including social media, online applications, and digital platforms with internet connection. The amended Advertising Law also imposes new requirements for online advertising, including: Identification signs: Advertisements must have clear identifiable signs in numbers, letters, symbols, images, or sounds to distinguish them from non-advertising content. Control features: For advertisements not in fixed areas, there must be easily recognizable features and icons that allow recipients to turn off the advertisement, notify the service provider of violating advertising content, and refuse to view inappropriate advertising content. Linked content: Content in the links embedded in advertisements must comply with the law. Advertising service providers and publishers must have measures to check and monitor the linked content. Advertising on social media: Organizations and enterprises providing social media services must offer users features to distinguish advertising content from other content. Signage for sponsored content: When advertising, users of social media services must use signs to differentiate advertising or sponsored content from other content they provide. In response to the above requirements for online advertising, the amended Advertising Law sets out obligations of advertisers, advertising service providers, advertising publishers, and advertising conveyors in relation to online advertising. Among these, it is notably the responsibility of individuals and organizations engaging in online advertising to prevent and remove violating