You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 2, 2026

Thailand Insurance Industry: AI and Privacy Regulatory Updates

Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance.

What Has Changed: OIC and PDPC Alignment

The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers.

  • Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible.
  • Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors.
  • Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels.
  • DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on a large scale”—expressly including insurance—must appoint and register a data protection officer (DPO). The absence of a registered DPO or an outdated record of processing activities (ROPA) that fails to map agent-level data flows is now considered a high-risk compliance gap.

AI in Insurance: Draft PDPC Guidelines

The PDPC’s draft AI guidelines carry particular significance for insurers. The guidelines single out insurance risk assessments as an example of automated decision-making that produces legal effects or significantly affects data subjects. Organizations using AI-driven tools for underwriting, claims processing, or policy recommendations must implement a human-in-the-loop mechanism with actual authority to overturn AI decisions and must document processes for data subjects to request review. A data protection impact assessment (DPIA) is required for high-risk AI projects, including automated decision-making with legal effects and large-scale processing of sensitive data. Leakage of sensitive health or financial data through AI systems is categorized as high risk, requiring notification to both the PDPC and affected data subjects without delay.

Cross-Border Data Transfers

For multinational insurance groups, a binding corporate rules (BCRs) regulation became fully effective on February 17, 2026, providing a formal mechanism for intragroup cross-border transfers. Groups that already hold GDPR-approved BCRs may use a “fast-track” process by submitting their existing BCRs together with a Thailand addendum. Alternatively, Standard Contractual Clauses based on the ASEAN Model Contractual Clauses may be used for transfers to third-party reinsurers or service providers outside Thailand.

Practical Compliance Steps

Given the current regulatory landscape, insurers should consider the following immediate and near-term actions.

  • Governance and organization. Register a DPO with the PDPC if not already done, and ensure that the DPO has a direct reporting line to senior management with sufficient authority and resources to fulfill the role. Update the ROPA to comprehensively map all processing activities, including data flows through agents, brokers, and third-party administrators.
  • Consent architecture overhaul. Redesign application forms and digital onboarding flows so that marketing consent is presented as a separate, clearly labeled opt-in, entirely distinct from the consent required for the insurance contract itself. Ensure that refusal to consent to marketing does not affect the customer’s ability to obtain coverage.
  • Agent and vendor compliance program. Issue updated written instructions and security protocols to all insurance intermediaries classified as data processors. Review and strengthen data processing agreements with all third-party processors, including specific provisions for PDPA responsibilities, security standards, audit rights, breach notification obligations, and end-of-term data deletion or return. Implement a periodic audit cycle—rather than relying on static contractual commitments—to verify vendor compliance.
  • Privacy notice refresh. Prepare a concise summary privacy notice for distribution alongside insurance policies, covering all required elements under the OIC guidance. For digital tele-sales, implement prerecording disclosures informing customers that their voice or image data will be processed under the PDPA.
  • AI and automated decision-making readiness. Conduct DPIAs for all AI-driven underwriting, claims, and risk-assessment tools currently in use or under development. Establish a documented human-in-the-loop process for any automated decision that produces legal effects on policyholders, including a clear escalation path and a mechanism for data subjects to contest decisions.
  • Breach response preparedness. Ensure that internal incident response plans can meet the 72-hour notification deadline to the PDPC, with particular attention to AI-related data leakage scenarios.
  • Cross-border transfer mechanism. For multinational groups, evaluate whether BCR certification—including the fast-track route—or SCCs provide the most efficient path for data transfers to group entities or reinsurers abroad.

Outlook

Thailand’s insurance sector faces a significantly more demanding compliance environment as PDPA enforcement matures and OIC alignment tightens. The convergence of stricter consent rules, expanded liability for intermediary conduct, new AI governance expectations, and a workable cross-border transfer framework means that insurers must move from reactive compliance to proactive data governance. Organizations that address these areas systematically—beginning with DPO registration, ROPA updates, and consent architecture—will be best positioned to manage regulatory risk and maintain the trust of their policyholders.

RELATED INSIGHTS​ 

July 14, 2023
The Bank of Thailand (BOT) has issued new notifications amending regulations for payment businesses that fall under the Payment Systems Act B.E. 2560 (2017) to promote transparency and good governance in the payment industry. Notification No. SorKorChor 2/2566 (“Notification 2”) increases the required qualifications for applicants seeking a license to provide payment services designated as being under the BOT’s supervision, and Notification No. SorKorChor 4/2566 (“Notification 4”) stipulates additional duties and exemptions for certain types of business operators. The notifications were published in the Government Gazette on July 7, 2023, and came into effect the following day. Additional Qualifications Notification 2 expands the list of prohibited characteristics for business operators applying for a license or registration to engage in a designated payment service, and their directors. For example, applicants must not have been ordered to suspend or cease their operations, and their registration or license to engage in financial business or operate a designated payment system or service must not have been revoked. The notification defines “financial business” as including financial institutions, credit card business, personal loan business, securities business, and so on. In addition, applicants’ directors and management must not have prohibited characteristics, such as being involved in the management of a financial business or designated payment system or service that was ordered to suspend or cease its operations. The applicable registration or license also must not have been revoked. Reporting Requirements During the application process, Notification 2 requires applicants to disclose information on shareholders and related parties (including spouses) who hold an aggregate 10 percent or more of the total paid-up shares. Notification 4 imposes this same reporting duty regarding shareholders and related parties but applies it to licensed operators in an ongoing manner. Existing payment service operators must make their first report of this information to
July 12, 2023
On June 30, 2023, Vietnam’s Ministry of Information and Communications (MIC) issued Circular No. 06/2003/TT-BTTTT to provide implementing guidelines for Decree 71 on editing, ratings, and warnings for video on demand (VOD) sports and entertainment content provided over radio and TV services. Circular 06 will take effect on August 15, 2023. Because Decree 71 allows VOD providers to self-edit and self-rate this type of content, it is important for them to know how the process is regulated in order to fully comply before providing VOD sports and entertainment programs to Vietnamese users. Under Circular 06, radio and TV service providers are required to display ratings and warnings on their programs, following the principles set out in the circular. These service providers must also compile dossiers in a stipulated form on the editing, ratings, and warnings of their programs for reporting to the authority and inspection. The main contents of Circular 06 are as follows. 1. Content Editing The main principles for editing VOD sports and entertainment programs include: Protection of children and other vulnerable people from inappropriate or potentially harmful content. Removal of all illegal/prohibited content, as well as content related to controversial issues or issues not recognized by Vietnamese law. Removal of content or dialogue that disparages the origins of others or makes fun of others’ physical weaknesses, and content that is contrary to Vietnamese culture, morality and fine customs and traditions; Removal of programs if it is discovered during the editing process that in the program or at the venue of the event, there are images or activities violating the prohibitions of the law, violating Vietnamese fine customs and traditions, or containing sensitive political elements. In addition to compliance with the above-mentioned principles, sports and entertainment programs related to health, education, and online gaming must additionally meet
July 11, 2023
Can computer programs resolve legal disputes? For decades, the answer from much of the legal community has been no. However, developments in artificial intelligence (AI), and in particular natural language processing and machine learning, have led to renewed discussions of this possibility. Increasingly, tools are being developed to assist parties with litigation outcome prediction and judges with litigation outcome determination. However, while some argue that the use of AI in legal disputes can reduce the length of proceedings, cut costs, and improve access to justice, others raise concerns that “black box” AI systems could reduce transparency, entrench bias, and harm the development of the law. Litigation Outcome Prediction The use of computers to predict the outcome of legal cases is not new. As early as the 1980s, researchers developed outcome prediction tools, often in the form of decision-tree algorithms. However, developments in AI have allowed the creation of more sophisticated prediction models. In 2017, a model built by Katz et al. predicted US Supreme Court decisions with an accuracy of 70.2%, while in 2019, a model built by Medvedeva et al. predicted decisions of the European Court of Human Rights with an accuracy of 75%. In various studies, AI tools have been able to predict case outcomes more accurately than expert lawyers. Companies such as Solomonic and Lex Machina, owned by LexisNexis, now provide commercial litigation prediction and analytics tools. Outcome prediction tools can be used by parties and their legal representatives to craft arguments and facilitate settlement negotiations, or by third-party litigation financers to assess the risk of providing funding. More broadly, outcome prediction may be used by the likes of insurance companies to help calculate claim payouts. However, those using such tools must take care to ensure that they do not breach any professional or legal obligations.
July 10, 2023
One of the more positive outcomes of the COVID-19 pandemic is that telemedicine has become remarkably important as an interactive system between patients and healthcare professionals. Thailand, which ranks near the top as a world medical hub, is a highly favored destination in Asia for expat workers. Currently, the Thai market has both Thai-based and foreign-based platforms with information about healthcare providers and telemedicine readily available. “Doctor Locator,” “Weed Map,” and “Find a Teeth Aligner Dentist” are examples of online platforms connecting patients with medical and telemedicine services. These digital platforms provide information about the location of specialized clinics, cannabis dispensaries, pharmacy stores, and orthodontic practitioners in Thailand. These platforms act as intermediaries between medical care businesses and consumers. As actual medical services are not offered or provided, these digital platforms do not have to be regulated under the Medical Facility Act of Thailand. However, healthcare digital platform services that act as an intermediary or conduit managing information used to connect medical clinics or cannabis dispensaries with patients or customers via a computer network are now regulated under the soon-to-be-implemented Royal Decree on Digital Platforms, regardless of whether payment is actually made via the platform. The regulatory authority for this is the Electronic Transactions Development Agency (ETDA). Under this royal decree, digital platform providers that intend to operate a digital platform service must notify the ETDA prior to initiating operations. The extent of the details to be included in the notification to the ETDA will be more comprehensive if the digital platform: has annual revenue (before expenses) for digital platform services within Thailand exceeding THB 1.8 million (approx. USD 51,200) for an individual operator or THB 50 million (approx. USD 1.42 million) for a corporate or entity operator; or has more than 5,000 users (on average) per month. Apart