You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 2, 2026

Thailand Insurance Industry: AI and Privacy Regulatory Updates

Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance.

What Has Changed: OIC and PDPC Alignment

The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers.

  • Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible.
  • Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors.
  • Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels.
  • DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on a large scale”—expressly including insurance—must appoint and register a data protection officer (DPO). The absence of a registered DPO or an outdated record of processing activities (ROPA) that fails to map agent-level data flows is now considered a high-risk compliance gap.

AI in Insurance: Draft PDPC Guidelines

The PDPC’s draft AI guidelines carry particular significance for insurers. The guidelines single out insurance risk assessments as an example of automated decision-making that produces legal effects or significantly affects data subjects. Organizations using AI-driven tools for underwriting, claims processing, or policy recommendations must implement a human-in-the-loop mechanism with actual authority to overturn AI decisions and must document processes for data subjects to request review. A data protection impact assessment (DPIA) is required for high-risk AI projects, including automated decision-making with legal effects and large-scale processing of sensitive data. Leakage of sensitive health or financial data through AI systems is categorized as high risk, requiring notification to both the PDPC and affected data subjects without delay.

Cross-Border Data Transfers

For multinational insurance groups, a binding corporate rules (BCRs) regulation became fully effective on February 17, 2026, providing a formal mechanism for intragroup cross-border transfers. Groups that already hold GDPR-approved BCRs may use a “fast-track” process by submitting their existing BCRs together with a Thailand addendum. Alternatively, Standard Contractual Clauses based on the ASEAN Model Contractual Clauses may be used for transfers to third-party reinsurers or service providers outside Thailand.

Practical Compliance Steps

Given the current regulatory landscape, insurers should consider the following immediate and near-term actions.

  • Governance and organization. Register a DPO with the PDPC if not already done, and ensure that the DPO has a direct reporting line to senior management with sufficient authority and resources to fulfill the role. Update the ROPA to comprehensively map all processing activities, including data flows through agents, brokers, and third-party administrators.
  • Consent architecture overhaul. Redesign application forms and digital onboarding flows so that marketing consent is presented as a separate, clearly labeled opt-in, entirely distinct from the consent required for the insurance contract itself. Ensure that refusal to consent to marketing does not affect the customer’s ability to obtain coverage.
  • Agent and vendor compliance program. Issue updated written instructions and security protocols to all insurance intermediaries classified as data processors. Review and strengthen data processing agreements with all third-party processors, including specific provisions for PDPA responsibilities, security standards, audit rights, breach notification obligations, and end-of-term data deletion or return. Implement a periodic audit cycle—rather than relying on static contractual commitments—to verify vendor compliance.
  • Privacy notice refresh. Prepare a concise summary privacy notice for distribution alongside insurance policies, covering all required elements under the OIC guidance. For digital tele-sales, implement prerecording disclosures informing customers that their voice or image data will be processed under the PDPA.
  • AI and automated decision-making readiness. Conduct DPIAs for all AI-driven underwriting, claims, and risk-assessment tools currently in use or under development. Establish a documented human-in-the-loop process for any automated decision that produces legal effects on policyholders, including a clear escalation path and a mechanism for data subjects to contest decisions.
  • Breach response preparedness. Ensure that internal incident response plans can meet the 72-hour notification deadline to the PDPC, with particular attention to AI-related data leakage scenarios.
  • Cross-border transfer mechanism. For multinational groups, evaluate whether BCR certification—including the fast-track route—or SCCs provide the most efficient path for data transfers to group entities or reinsurers abroad.

Outlook

Thailand’s insurance sector faces a significantly more demanding compliance environment as PDPA enforcement matures and OIC alignment tightens. The convergence of stricter consent rules, expanded liability for intermediary conduct, new AI governance expectations, and a workable cross-border transfer framework means that insurers must move from reactive compliance to proactive data governance. Organizations that address these areas systematically—beginning with DPO registration, ROPA updates, and consent architecture—will be best positioned to manage regulatory risk and maintain the trust of their policyholders.

RELATED INSIGHTS​ 

January 22, 2026
On December 10, 2025, Vietnam’s National Assembly enacted Law No. 139/2025/QH15 amending the Law on Insurance Business. The amendment, effective from January 1, 2026, introduces various changes in an effort to lift restrictions and hurdles for insurance businesses. Key points that may impact the activities of stakeholders in Vietnam’s insurance market are highlighted below. Management Personnel Qualifications To broaden the talent pool while ensuring competency standards, the amended law opens up the positions of director or general director to more candidates. Previously, candidates were required to hold either (i) a university degree or higher in insurance or (ii) a university degree in another discipline and an insurance certificate issued by a qualified insurance training institution. Now, candidates holding a university degree or higher in economics, finance, banking, law, business administration, accounting, or auditing, with at least one insurance‑related module, are also accepted. These changes are expected to mitigate the ongoing challenges faced by insurers in recruiting suitably qualified candidates for key executive positions, while still maintaining appropriate professional standards. Fewer Registrations for Insurance Businesses As part of the legislature’s broader initiative to reduce administrative burdens across all business sectors, the amended Law on Insurance Business relaxes registration requirements for the insurance industry, notably: Insurance enterprises and foreign non‑life insurance branches are no longer required to register and obtain prior approval from the Ministry of Finance (MOF) for their methodologies and bases for calculating premiums for motor vehicle insurance products (excluding compulsory civil liability insurance for motor vehicle owners). Instead, insurance enterprises are now only required to notify the MOF before applying or amending these methodologies. While life insurers must continue to register with the MOF their principles for separating owners’ equity from insurance premium funds, non‑life insurance enterprises and foreign non‑life insurance branches are now only required to notify
January 22, 2026
On January 20, 2026, Vietnam’s Ministry of Finance (MOF) issued Decision No. 96/QD-BTC to formally launch pilot administrative procedures for licensing crypto asset trading market services in Vietnam. The decision took immediate effect and implements the government’s pilot crypto asset market program under Resolution No. 05/2025/NQ-CP. Notably, competent authorities have now begun accepting license applications, marking the first time Vietnam has operationalized a licensing pathway for crypto trading market operators. Administrative Procedures and Applications The decision stipulates procedures for (i) granting, (ii) adjusting, and (iii) revoking licenses to provide services for organizing crypto asset trading markets. It provides detailed, step-by-step guidance for each procedure, including dossier composition, internal review stages, coordination mechanisms, and statutory timelines. These procedures apply specifically to entities seeking to organize and operate crypto asset trading markets within Vietnam’s pilot regulatory framework. The MOF is the authority responsible for reviewing and deciding on the above procedures, with the State Securities Commission acting as the receiving, coordinating, and procedural focal point. For licensing applications, the MOF will coordinate with multiple authorities, including the State Bank of Vietnam and the Ministry of Public Security, particularly in relation to anti-money laundering, cybersecurity, system safety, and risk control requirements. Applications may be submitted in person, by post, or electronically via the National Public Service Portal or the administrative procedure information system, in line with applicable regulations. Statutory processing timelines vary depending on the specific procedure and stage involved. For applications to obtain a license to organize a crypto asset trading market, the process is conducted in multiple phases: The MOF will issue an initial written response within 20 working days from receipt of a complete and valid initial dossier, following which, upon submission of the full set of required documents, the MOF will complete substantive review and issue the license
January 21, 2026
On January 16, 2026, Thailand’s Electronic Transactions Committee released for public comment a draft notification that would require social media platforms operating in Thailand to implement identity verification for all user accounts and advertisers, with enhanced scrutiny for high-risk advertising activities. If finalized in its current form, the Notification on Measures to Prevent Technology Crime for Social Media Service Providers would take effect 180 days after publication in the Government Gazette, fundamentally changing how platforms verify users and monetize advertising services. The public comment period is open through February 2, 2026. Mandatory User and Advertiser Identity Verification The draft establishes a universal requirement that all social media service providers implement identity verification measures for every user account. The draft imposes stricter verification obligations for advertisers than for general users. Before publishing any advertisement, platforms must verify the advertiser’s identity at a level sufficient to identify the advertiser, unless the advertiser has previously completed verification. Risk-Based Advertisement Verification The identification requirements for advertisers will be more stringent in the following cases: The advertiser has a history of user complaints or has previously violated the platform’s terms of service. The advertisement involves finance, investment, loans, sensitive personal data, or content flagged as potentially involving cybercrime. The advertisement specifically targets vulnerable groups, such as the elderly or other at-risk demographics. In such cases, platforms must conduct identity verification using government-issued identification documents and must confirm the accuracy, authenticity, and currency of these documents with the issuing government agencies. Alternatively, platforms may verify identity through an eligible digital identity verification and authentication system provider. Information Retention Platforms must retain specific information for each advertiser, including the name of the individual or juristic person and any representatives, government-issued identification documents such as ID cards, passports, or certificates of incorporation, and reachable contact information including
January 21, 2026
Spurred by global geopolitics and Canada’s Indo-Pacific Strategy, which aims to forge deeper ties with ASEAN, Canadian companies have been showing growing interest in Thailand and Southeast Asia in recent years. To understand the opportunities offered by the region, we sat down with Andrew Stoutley, a Toronto native and the chief operating officer of Tilleke & Gibbins, a leading Southeast Asian regional law firm with over 130 years of history in Thailand. Q: Why are Canadian companies looking at Thailand and Southeast Asia right now? A: Two reasons stand out. First, diversification has moved up the agenda. Many Canadian companies want options outside North America due to tariff volatility and policy uncertainty in the United States, as well as questions around the next Canada–United States–Mexico Agreement mandatory joint review. At the same time, the shift of global production from China to Southeast Asia is accelerating, driven by rising costs, geopolitics, and the need to avoid overreliance on a single market. As a result, Canadian companies are looking for a second production base or a regional hub, and Thailand and its neighbors are natural choices given their manufacturing depth, location, and established supply chains. Second, Canada’s own efforts in the region are gaining traction. The Indo-Pacific Strategy has led to more on-the-ground support, including larger trade missions, upgraded diplomatic posts, and new financing options. Export Development Canada (EDC) now has a presence in Bangkok, giving Canadian companies a direct line to financing and insurance in Thailand. There’s also steady progress on trade frameworks like the recently signed Canada–Indonesia Comprehensive Economic Partnership Agreement (which will come into effect pending domestic procedures), ongoing negotiations of a Canada–ASEAN FTA, and the exciting announcement about the launch of negotiations of a Canada–Thailand FTA. Together, these developments have the potential to make it much easier