You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 2, 2026

Thailand Insurance Industry: AI and Privacy Regulatory Updates

Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance.

What Has Changed: OIC and PDPC Alignment

The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers.

  • Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible.
  • Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors.
  • Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels.
  • DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on a large scale”—expressly including insurance—must appoint and register a data protection officer (DPO). The absence of a registered DPO or an outdated record of processing activities (ROPA) that fails to map agent-level data flows is now considered a high-risk compliance gap.

AI in Insurance: Draft PDPC Guidelines

The PDPC’s draft AI guidelines carry particular significance for insurers. The guidelines single out insurance risk assessments as an example of automated decision-making that produces legal effects or significantly affects data subjects. Organizations using AI-driven tools for underwriting, claims processing, or policy recommendations must implement a human-in-the-loop mechanism with actual authority to overturn AI decisions and must document processes for data subjects to request review. A data protection impact assessment (DPIA) is required for high-risk AI projects, including automated decision-making with legal effects and large-scale processing of sensitive data. Leakage of sensitive health or financial data through AI systems is categorized as high risk, requiring notification to both the PDPC and affected data subjects without delay.

Cross-Border Data Transfers

For multinational insurance groups, a binding corporate rules (BCRs) regulation became fully effective on February 17, 2026, providing a formal mechanism for intragroup cross-border transfers. Groups that already hold GDPR-approved BCRs may use a “fast-track” process by submitting their existing BCRs together with a Thailand addendum. Alternatively, Standard Contractual Clauses based on the ASEAN Model Contractual Clauses may be used for transfers to third-party reinsurers or service providers outside Thailand.

Practical Compliance Steps

Given the current regulatory landscape, insurers should consider the following immediate and near-term actions.

  • Governance and organization. Register a DPO with the PDPC if not already done, and ensure that the DPO has a direct reporting line to senior management with sufficient authority and resources to fulfill the role. Update the ROPA to comprehensively map all processing activities, including data flows through agents, brokers, and third-party administrators.
  • Consent architecture overhaul. Redesign application forms and digital onboarding flows so that marketing consent is presented as a separate, clearly labeled opt-in, entirely distinct from the consent required for the insurance contract itself. Ensure that refusal to consent to marketing does not affect the customer’s ability to obtain coverage.
  • Agent and vendor compliance program. Issue updated written instructions and security protocols to all insurance intermediaries classified as data processors. Review and strengthen data processing agreements with all third-party processors, including specific provisions for PDPA responsibilities, security standards, audit rights, breach notification obligations, and end-of-term data deletion or return. Implement a periodic audit cycle—rather than relying on static contractual commitments—to verify vendor compliance.
  • Privacy notice refresh. Prepare a concise summary privacy notice for distribution alongside insurance policies, covering all required elements under the OIC guidance. For digital tele-sales, implement prerecording disclosures informing customers that their voice or image data will be processed under the PDPA.
  • AI and automated decision-making readiness. Conduct DPIAs for all AI-driven underwriting, claims, and risk-assessment tools currently in use or under development. Establish a documented human-in-the-loop process for any automated decision that produces legal effects on policyholders, including a clear escalation path and a mechanism for data subjects to contest decisions.
  • Breach response preparedness. Ensure that internal incident response plans can meet the 72-hour notification deadline to the PDPC, with particular attention to AI-related data leakage scenarios.
  • Cross-border transfer mechanism. For multinational groups, evaluate whether BCR certification—including the fast-track route—or SCCs provide the most efficient path for data transfers to group entities or reinsurers abroad.

Outlook

Thailand’s insurance sector faces a significantly more demanding compliance environment as PDPA enforcement matures and OIC alignment tightens. The convergence of stricter consent rules, expanded liability for intermediary conduct, new AI governance expectations, and a workable cross-border transfer framework means that insurers must move from reactive compliance to proactive data governance. Organizations that address these areas systematically—beginning with DPO registration, ROPA updates, and consent architecture—will be best positioned to manage regulatory risk and maintain the trust of their policyholders.

RELATED INSIGHTS​ 

March 19, 2026
Thailand’s Electronic Transactions Development Agency (ETDA), which describes itself as a “co-creation regulator” working collaboratively with industry rather than imposing top-down rules, has unveiled its regulatory roadmap for digital platform businesses under the Royal Decree on Digital Platform Service Businesses B.E. 2565 (2022). The 2026 regulatory approach is guided by three core principles—“practicable, verifiable, shared responsibility”—aimed at elevating digital services to be safe, transparent, and fair. These principles inform ETDA’s 2026 priorities, which focus on three key dimensions: product and service standards on platforms, fair competition and fee transparency, and online fraud prevention. Product and Service Standards ETDA’s 2026 agenda addresses product and service standards across several platform categories: Online marketplace platforms. The Notification on Additional Measures for Online Marketplace Platforms under Section 18(2) came into force on December 31, 2025, designating 21 marketplace platforms that must verify products and merchants. Among other obligations, covered platforms must remove or suspend substandard products under the “notice and take down” principle. The ETDA has collaborated with the Food and Drug Administration and the Thai Industrial Standards Institute to develop inspection manuals and coordinate compliance procedures. Social commerce. The ETDA is preparing a new notification under Section 18(2) specifically targeting social commerce platforms with sales support functions, aiming to align regulation with evolving digital market conditions. Ride sharing. Since the postponement of the deadline to comply with the ETDA’s notification on ride-sharing platforms to March 31, 2026, the ETDA has supported drivers in registering with the Department of Land Transport through the Driver Verify registration system, which has already issued certifications to approximately 27,900 riders. The ETDA is also examining structural issues relating to appropriate insurance packages, motorcycle engine capacity expansion, and fair leasing fees and contract transfer costs in coordination with the Department of Land Transport, the Office of Insurance Commission,
March 19, 2026
Thailand’s Personal Data Protection Committee (PDPC) has launched a public consultation period to gather input for a forthcoming set of guidelines under the country’s Personal Data Protection Act (PDPA). This initiative follows the PDPC’s issuance of guidelines on consent and notification requirements in September 2022. The main consultation period, using an online questionnaire to gather feedback, runs until March 23, 2026. In addition, an interview-style online session for private-sector participants was held on March 17, and a two-day in-person event will be held on April 1–2—this is already fully booked and  walk-ins will not be accepted, but the session will be livestreamed on the PDPC’s Facebook page. The PDPC will use the public feedback to design draft guidelines that accurately reflect the operational realities of both public and private organizations, after which the guidelines will be shared with the public. Consultation Scope The PDPC has identified six priority areas for which upcoming guidance may be issued: Legal bases for processing: The online questionnaire assesses respondents’ understanding of consent requirements and seeks views on priority issues, such as explanations of the legal bases and considerations for selecting an appropriate legal basis depending on the nature of the processing activity. Security measures and data breach notification: The questionnaire examines respondents’ understanding of data breach reporting and security measure obligations. Topics proposed for inclusion in the guidelines include data breach prevention measures, incident response plans, risk assessment methods, and reporting procedures. Data protection officers: Respondents are invited to share their expectations regarding the DPO’s role and their experiences in contacting a DPO. The survey also asks respondents to identify priority issues, such as response timeframes for data subject requests and complaint procedures. Marketing and direct marketing: The online questionnaire seeks input on preferred topics for guidance, including individuals’ rights to refuse marketing
March 17, 2026
Thailand’s Office of Insurance Commission (OIC) has introduced comprehensive group-wide supervision requirements for insurers operating within corporate groups. Published on February 26, 2026, in two separate notifications in the Government Gazette, the new rules establish parallel frameworks for life and non-life insurance companies. Both notifications take effect on July 1, 2026, and impose significant new requirements on insurance business groups. Affected insurers should begin reviewing their group structures, governance frameworks, and risk management systems now to ensure timely compliance. The notifications aim to ensure that group-level operations are orderly, stable, and reliable, and prevent the accumulation of systemic risk that could undermine public confidence in the insurance sector. Both notifications share a substantially parallel structure and require insurers to assess and manage the financial position, risk exposure, reliability, and corporate governance of their entire insurance business group on a comprehensive and ongoing basis. The regulations introduce definitions for several key terms. An “insurance business group” encompasses the insurer together with its ultimate parent company, parent companies, subsidiaries, and related companies. The “head of the insurance business group” is the entity responsible for overseeing group-wide supervision, operations, and governance. An “ultimate parent company” is one that exercises control without itself being controlled by another entity. Key Requirements The notifications establish the following core obligations for insurers: Group structure and shareholding reporting: Insurers must report the organizational chart and shareholding structure of their insurance business group—covering the ultimate parent company, parent companies, subsidiaries, and related entities—to the OIC registrar by June of each year, and whenever material changes occur. The regulations prescribe specific thresholds for determining when shareholding proportions constitute control. Corporate governance standards: Board members, executives, and authorized persons of the ultimate parent company or parent company must not be disqualified (e.g., bankrupt individuals, persons convicted of property-related fraud, or
March 16, 2026
Thailand’s Securities and Exchange Commission (SEC) has broadened the definition of institutional investors, expanded the types of qualifying investments, and updated financial qualification thresholds for various investor categories through a revised notification on the definitions of institutional investors, ultra-high net worth investors, and high net worth investors. The amended framework, which came into force on March 1, 2026, adds digital asset business operators, investment planners, and investment consultants to the roster of entities recognized as institutional investors, and broadens the definition of investment to account for digital tokens. Expanded Definition of Institutional Investors Under the SEC’s revised notification, the category of institutional investors now expressly includes digital asset business operators licensed under the Royal Decree on Digital Asset Businesses B.E. 2561 (2018). This addition recognizes the growing role of digital asset platforms and service providers in Thailand’s investment ecosystem and aligns the regulatory treatment of digital markets with that of traditional markets. The definition of institutional investors now also encompasses investment planners and investment consultants approved by the SEC. Previously, only SEC-approved investment analysts held this status; the expansion covers a broader scope of professionals who possess comparable expertise and experience in evaluating investment opportunities. Broadened Investment Definition The revised framework now defines investment to mean direct or indirect investment in a wider range of assets beyond deposits. Specifically, the definition covers: Securities under the Securities and Exchange Act Derivatives under the Derivatives Act Investment tokens offered to the public Government-issued digital tokens (G-tokens) as specified in a separate SEC notification This expansion ensures that financial status assessments reflect the full spectrum of an investor’s holdings, including emerging digital assets. Updated Financial Qualification Thresholds The amended SEC notification also provides updated qualification thresholds for angel investors, ultra-high net worth investors, and high net worth investors. While the core criteria