You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 2, 2026

Thailand Insurance Industry: AI and Privacy Regulatory Updates

Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance.

What Has Changed: OIC and PDPC Alignment

The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers.

  • Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible.
  • Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors.
  • Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels.
  • DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on a large scale”—expressly including insurance—must appoint and register a data protection officer (DPO). The absence of a registered DPO or an outdated record of processing activities (ROPA) that fails to map agent-level data flows is now considered a high-risk compliance gap.

AI in Insurance: Draft PDPC Guidelines

The PDPC’s draft AI guidelines carry particular significance for insurers. The guidelines single out insurance risk assessments as an example of automated decision-making that produces legal effects or significantly affects data subjects. Organizations using AI-driven tools for underwriting, claims processing, or policy recommendations must implement a human-in-the-loop mechanism with actual authority to overturn AI decisions and must document processes for data subjects to request review. A data protection impact assessment (DPIA) is required for high-risk AI projects, including automated decision-making with legal effects and large-scale processing of sensitive data. Leakage of sensitive health or financial data through AI systems is categorized as high risk, requiring notification to both the PDPC and affected data subjects without delay.

Cross-Border Data Transfers

For multinational insurance groups, a binding corporate rules (BCRs) regulation became fully effective on February 17, 2026, providing a formal mechanism for intragroup cross-border transfers. Groups that already hold GDPR-approved BCRs may use a “fast-track” process by submitting their existing BCRs together with a Thailand addendum. Alternatively, Standard Contractual Clauses based on the ASEAN Model Contractual Clauses may be used for transfers to third-party reinsurers or service providers outside Thailand.

Practical Compliance Steps

Given the current regulatory landscape, insurers should consider the following immediate and near-term actions.

  • Governance and organization. Register a DPO with the PDPC if not already done, and ensure that the DPO has a direct reporting line to senior management with sufficient authority and resources to fulfill the role. Update the ROPA to comprehensively map all processing activities, including data flows through agents, brokers, and third-party administrators.
  • Consent architecture overhaul. Redesign application forms and digital onboarding flows so that marketing consent is presented as a separate, clearly labeled opt-in, entirely distinct from the consent required for the insurance contract itself. Ensure that refusal to consent to marketing does not affect the customer’s ability to obtain coverage.
  • Agent and vendor compliance program. Issue updated written instructions and security protocols to all insurance intermediaries classified as data processors. Review and strengthen data processing agreements with all third-party processors, including specific provisions for PDPA responsibilities, security standards, audit rights, breach notification obligations, and end-of-term data deletion or return. Implement a periodic audit cycle—rather than relying on static contractual commitments—to verify vendor compliance.
  • Privacy notice refresh. Prepare a concise summary privacy notice for distribution alongside insurance policies, covering all required elements under the OIC guidance. For digital tele-sales, implement prerecording disclosures informing customers that their voice or image data will be processed under the PDPA.
  • AI and automated decision-making readiness. Conduct DPIAs for all AI-driven underwriting, claims, and risk-assessment tools currently in use or under development. Establish a documented human-in-the-loop process for any automated decision that produces legal effects on policyholders, including a clear escalation path and a mechanism for data subjects to contest decisions.
  • Breach response preparedness. Ensure that internal incident response plans can meet the 72-hour notification deadline to the PDPC, with particular attention to AI-related data leakage scenarios.
  • Cross-border transfer mechanism. For multinational groups, evaluate whether BCR certification—including the fast-track route—or SCCs provide the most efficient path for data transfers to group entities or reinsurers abroad.

Outlook

Thailand’s insurance sector faces a significantly more demanding compliance environment as PDPA enforcement matures and OIC alignment tightens. The convergence of stricter consent rules, expanded liability for intermediary conduct, new AI governance expectations, and a workable cross-border transfer framework means that insurers must move from reactive compliance to proactive data governance. Organizations that address these areas systematically—beginning with DPO registration, ROPA updates, and consent architecture—will be best positioned to manage regulatory risk and maintain the trust of their policyholders.

RELATED INSIGHTS​ 

November 13, 2024
Thailand’s Electronic Transactions Committee has publicized a new draft notification detailing additional duties for specific marketplace digital platform service operators under Section 18(2) of the Royal Decree on Operation of Digital Platform Service Businesses Subject to Prior Notification B.E. 2565 (2022). The draft notification, which is open for public comments until November 30, 2024, aims to provide enhanced protection for users of “specific marketplace platforms” (defined below). Some key points of the draft notification are detailed below. Scope The draft notification applies to “marketplace digital platform services,” which refers to digital platform services that serve as an intermediary for buying or exchanging goods and provide services to facilitate sale transactions, such as providing communication systems (e.g., chat features), shopping carts, delivery arrangements, and supplemental payment processing facilitation. “Specific marketplace platforms” refers to Section 18(2) of the Royal Decree on Digital Platform Services, which covers digital platform services that pose risks to financial and commercial security, the reliability and credibility of data messaging systems, or potential harm to the public, and that have a high level of potential impact based on the criteria for assessing the impact of digital platform service operations. Key Obligations Registration. The draft notification requires the marketplace operators mentioned above to be registered as legal entities in Thailand. Terms and conditions. The draft notification details additional obligations relating to marketplace operators’ terms and conditions: In addition to existing obligations prescribed in the Royal Decree and the relevant subordinate laws, the draft notification emphasizes that the terms and conditions must be in Thai, clear, accessible, and understandable, and may include graphical elements to aid explanation. The terms and conditions must prescribe conditions relating to the sale of products subject to specific standards, such as those restricted under the Food Act, the Drugs Act, and the Industrial Product
November 11, 2024
The Vietnamese government has demonstrated a strong commitment to building a digital government, digital economy, and digital society through its recently issued national strategy on digital infrastructure. Under Decision No. 1132/QD-TTg dated October 19, 2024, on “Digital Infrastructure Strategy to 2025 with Orientation to 2030,” the government will create supportive conditions for both domestic and international businesses to invest in digital infrastructure with cybersecurity as a priority. Recognized as vital to the economy, this digital infrastructure will consist of four main components: (i) telecommunications and internet infrastructure, (ii) data infrastructure, (iii) physical-digital infrastructure, and (iv) digital utility infrastructure, including digital technology as a service. Key goals for 2025 include universal fiber optic access for households, 100% 5G coverage across all provinces and cities, deployment of at least two new international undersea fiber optic cables, establishment of AI data centers, development of green-standard data centers, and platforms for IoT, AI, big data, blockchain, and cybersecurity. By 2030, goals include fiber access with speeds of at least 1 Gbps, 5G coverage for 99% of the population, readiness for 6G trials, six additional international undersea fiber optic cables, development of a hyperscale data center, and positioning Vietnam as a digital hub. To achieve these goals, the government has outlined some core tasks, creating significant opportunities for both foreign and domestic investors: Developing telecommunications and internet infrastructure for widespread fiber optic and 5G access, while preparing for emerging technologies like 6G, Open RAN, satellite, and IpV6. Telecommunication enterprises will jointly invest in and share the use of international fiber optic cable routes to ensure efficient capacity utilization and optimize investment capital. Attracting foreign and domestic investment to establish hyperscale data centers and cloud computing services that meet global standards. Creating physical-digital infrastructure by integrating technology across key sectors such as transportation, energy, healthcare,
November 8, 2024
On October 31, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) opened a public consultation period on its draft notifications—one directed at data controllers and another at data processors—regarding exemptions from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft notification for data controllers aims to amend and revoke certain aspects of the first ROPA exemption notification issued in June 2022 and outlines the criteria for data controllers to be exempted from the obligation to prepare and maintain such records. Although it is officially titled “Notification of the Personal Data Protection Committee on Exemption from Record-Keeping Requirements for Small Business Data Controllers,” this draft notification applies to all types of exempted data controllers (see list below), and not only small businesses. The draft notification for data processors is new and does not replace any prior notification. The criteria under both draft notifications exempt certain data controllers and data processors from the obligation to maintain ROPAs, but exempted data controllers are not free from the obligation to retain information on the rejection of data subjects’ requests to exercise certain rights under the PDPA. While these criteria remain consistent with the June 2022 ROPA exemption notification, there are a few key takeaways from the notifications, as detailed below. Types of Exempted Parties The draft notification on data controllers adds condominium and housing estate juristic persons, as well as individuals, to the list of parties eligible for an exemption, while removing internet cafes from the list. The new draft notification for data processors mirrors the corresponding list in the draft notification for data controllers. The complete list of parties eligible for ROPA exemptions under the draft notifications is as follows: SMEs according to the law on
October 9, 2024
Thailand’s Anti-Money Laundering Office has released new guidelines on customer due diligence (CDD) for insurance companies to outline anti-money laundering and counter-terrorism financing measures based on the Anti-Money Laundering Act B.E. 2542 (1999). The previous guidelines were revoked and replaced by these guidelines. The guidelines include seven key measures: Anti-money laundering and counter-terrorism financing policy: Insurance companies must establish a policy in Thai that outlines the organization’s approach to assessing, managing, and mitigating risks related to money laundering, terrorism financing, and proliferation. Risk management framework: Insurance companies’ frameworks for risk management are to be divided into three stages: (1) internal risk management, (2) risk assessment before customer onboarding, and (3) ongoing customer risk management. CDD before engagement with customers: Insurance companies must implement a rigorous approval process to verify customers’ identities. Customer information review and transaction monitoring: Insurance companies must update customer information and the list of banned transactions to ensure compliance with current risk profiles. Enhanced CDD for high-risk clients: Insurance companies must apply a stricter level of verification and monitoring measures for high-risk clients, including reviews of financial transactions. Third-party reliance and subsidiary controls: Reliance on third parties is allowed only in processes for customer identification and verification of identity. Internal controls and policies for subsidiaries or affiliates must be updated regularly. Suspicious transaction reporting: Insurance companies must report any suspicious transactions, particularly whenever CDD is not available. For more details on the CDD guidelines, or on any aspect of insurance and anti-money laundering regulations in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Witchupong Chittchang at [email protected], Ajaree Trachukul at [email protected], or Sireethorn Wijan at [email protected].