You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 2, 2026

Thailand Insurance Industry: AI and Privacy Regulatory Updates

Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance.

What Has Changed: OIC and PDPC Alignment

The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers.

  • Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible.
  • Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors.
  • Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels.
  • DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on a large scale”—expressly including insurance—must appoint and register a data protection officer (DPO). The absence of a registered DPO or an outdated record of processing activities (ROPA) that fails to map agent-level data flows is now considered a high-risk compliance gap.

AI in Insurance: Draft PDPC Guidelines

The PDPC’s draft AI guidelines carry particular significance for insurers. The guidelines single out insurance risk assessments as an example of automated decision-making that produces legal effects or significantly affects data subjects. Organizations using AI-driven tools for underwriting, claims processing, or policy recommendations must implement a human-in-the-loop mechanism with actual authority to overturn AI decisions and must document processes for data subjects to request review. A data protection impact assessment (DPIA) is required for high-risk AI projects, including automated decision-making with legal effects and large-scale processing of sensitive data. Leakage of sensitive health or financial data through AI systems is categorized as high risk, requiring notification to both the PDPC and affected data subjects without delay.

Cross-Border Data Transfers

For multinational insurance groups, a binding corporate rules (BCRs) regulation became fully effective on February 17, 2026, providing a formal mechanism for intragroup cross-border transfers. Groups that already hold GDPR-approved BCRs may use a “fast-track” process by submitting their existing BCRs together with a Thailand addendum. Alternatively, Standard Contractual Clauses based on the ASEAN Model Contractual Clauses may be used for transfers to third-party reinsurers or service providers outside Thailand.

Practical Compliance Steps

Given the current regulatory landscape, insurers should consider the following immediate and near-term actions.

  • Governance and organization. Register a DPO with the PDPC if not already done, and ensure that the DPO has a direct reporting line to senior management with sufficient authority and resources to fulfill the role. Update the ROPA to comprehensively map all processing activities, including data flows through agents, brokers, and third-party administrators.
  • Consent architecture overhaul. Redesign application forms and digital onboarding flows so that marketing consent is presented as a separate, clearly labeled opt-in, entirely distinct from the consent required for the insurance contract itself. Ensure that refusal to consent to marketing does not affect the customer’s ability to obtain coverage.
  • Agent and vendor compliance program. Issue updated written instructions and security protocols to all insurance intermediaries classified as data processors. Review and strengthen data processing agreements with all third-party processors, including specific provisions for PDPA responsibilities, security standards, audit rights, breach notification obligations, and end-of-term data deletion or return. Implement a periodic audit cycle—rather than relying on static contractual commitments—to verify vendor compliance.
  • Privacy notice refresh. Prepare a concise summary privacy notice for distribution alongside insurance policies, covering all required elements under the OIC guidance. For digital tele-sales, implement prerecording disclosures informing customers that their voice or image data will be processed under the PDPA.
  • AI and automated decision-making readiness. Conduct DPIAs for all AI-driven underwriting, claims, and risk-assessment tools currently in use or under development. Establish a documented human-in-the-loop process for any automated decision that produces legal effects on policyholders, including a clear escalation path and a mechanism for data subjects to contest decisions.
  • Breach response preparedness. Ensure that internal incident response plans can meet the 72-hour notification deadline to the PDPC, with particular attention to AI-related data leakage scenarios.
  • Cross-border transfer mechanism. For multinational groups, evaluate whether BCR certification—including the fast-track route—or SCCs provide the most efficient path for data transfers to group entities or reinsurers abroad.

Outlook

Thailand’s insurance sector faces a significantly more demanding compliance environment as PDPA enforcement matures and OIC alignment tightens. The convergence of stricter consent rules, expanded liability for intermediary conduct, new AI governance expectations, and a workable cross-border transfer framework means that insurers must move from reactive compliance to proactive data governance. Organizations that address these areas systematically—beginning with DPO registration, ROPA updates, and consent architecture—will be best positioned to manage regulatory risk and maintain the trust of their policyholders.

RELATED INSIGHTS​ 

April 1, 2025
The collapse of a building under construction in Bangkok on March 28, 2025, following a powerful earthquake in Myanmar has sparked widespread public concern about the potential financial impact on local insurers and insurance implications. The construction site was insured under a contractors’ all risks (CAR) policy, and initial reports and market speculation suggest that the event could cause serious financial strain for the domestic insurance industry. Nevertheless, local insurers connected to the site of the collapse may face limited exposure for two main reasons: Reinsurance significantly mitigates local insurers’ exposure. According to market sources, 95% of the CAR coverage for the construction site was reinsured by foreign reinsurers. This is standard risk-management practice for large-scale infrastructure and construction projects, allowing local insurers to participate in underwriting while transferring most of the liability offshore. As a result, the direct financial impact on domestic insurers is expected to be minimal, subject to the reinsurance contracts and any potential claims disputes. Potential exclusions may apply. The Thai General Insurance Association has issued an interim public advisory noting that coverage under the CAR policy may be limited or excluded altogether, pending a full investigation. CAR policies often contain exclusions for certain events, depending on how the policy is worded and the actual cause of the incident. A thorough factual and forensic investigation will be necessary to determine the true cause and assess policy applicability. For further information or assistance in reviewing CAR or project insurance coverage in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Witchupong Chittchang at [email protected], or Ajaree Trachukul at [email protected].
March 18, 2025
On February 6, 2025, the prime minister of Vietnam, Pham Minh Chinh, chaired an online meeting to review the progress of Vietnam’s digital transformation agenda. The meeting assessed achievements under the National Digital Transformation Program and Project 06 on the development and application of population data, electronic identification, and authentication for national digital transformation for the period 2022-2025, with a vision to 2030, approved by the prime minister in 2022. The meeting also outlined key legislative and regulatory priorities for 2025, as set forth in Notice No. 56/TB-BPCP issued by the Government Office on February 23, 2025 (Notice 56). One of the central focuses of the 2025 digital transformation agenda is the development and issuance of laws and regulations governing digital technology, data management, and cybersecurity. Below are the key legal developments provided in Notice 56 that stakeholders should anticipate in the coming months. 1. Law on Digital Technology Industry The Ministry of Information and Communications (MIC) has been tasked with finalizing the draft Law on Digital Technology Industry (DTI Law) for submission to the National Assembly at its 9th session in May 2025. This law is expected to establish a comprehensive legal framework for the digital technology sector, addressing regulatory gaps in emerging fields such as artificial intelligence (AI), Internet of Things (IoT), cloud computing, big data and platform services to promote innovation, ensure data security, and support the growth of the digital economy in Vietnam. Concurrently, the MIC will expedite the issuance of guiding decrees to ensure the swift implementation of the DTI Law once enacted. 2. Law on Personal Data Protection and regulations guiding implementation of Data Law The Ministry of Public Security (MPS) is making efforts to finalize the long-anticipated Law on Personal Data Protection (PDPL)—data protection is currently governed by Decree No. 13/2023/ND-CP on
March 17, 2025
Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to Data Protection and Cybersecurity Regulation in Southeast Asia, a wide-ranging guide published by Drew Network Asia (DNA). The resource provides a comprehensive overview of data protection and cybersecurity laws across the region, offering practical insight into compliance requirements and regulatory developments affecting organizations that handle personal data or operate digital services in Southeast Asia. The guide begins with a regional overview, including the broader ASEAN context and cooperation initiatives. Jurisdiction-specific chapters follow a consistent structure—covering data privacy and governance obligations, security requirements and breach notification, outsourcing and cross-border data transfers, and broader accountability and compliance measures. This format allows readers to compare regulatory approaches across markets such as Brunei, Indonesia, Malaysia, the Philippines, Singapore, and others. In addition to the country chapters, the publication addresses cybersecurity and privacy engineering challenges, providing guidance for organizations and outlining obligations applicable to data controllers, processors, and intermediaries. A dedicated section on data breach management across ASEAN examines notification requirements, response considerations, and practical steps for managing incidents in a regional or global context. The guide is intended to serve as a practical reference, and the authors note that specific legal requirements may vary depending on sector, processing activity, or evolving legislation. Readers seeking more detailed advice can contact the practitioners listed in each chapter. The full guide is available for download using the button below or directly from the DNA website.
March 13, 2025
Vietnam’s Ministry of Finance has released a draft Decree on Tax Administration for E-Commerce and Digital Platforms (“Draft Decree”), introducing significant tax compliance obligations that could reshape how digital platforms, and individuals and business households conducting business through the platforms, manage their tax responsibilities. Aimed at strengthening tax enforcement, the Draft Decree requires e-commerce and digital platforms to actively track and withhold taxes from business households and individual sellers, and remit payments to tax authorities. While it has not yet been promulgated, the Draft Decree is expected to take effect on April 1, 2025, leaving platforms with a limited window to prepare for compliance. Who Is Affected by the New Tax Rules? The Draft Decree significantly broadens the tax administration scope beyond traditional e-commerce platforms to cover a wide range of digital economy participants. Specifically, the Draft Decree places direct tax-related responsibilities on two major categories (collectively, “Regulated Operators”): E-commerce and digital platforms with payment functions (e.g., platforms that process buyer payments via e-wallets, bank transfers, cards, or cash-on-delivery); and Other digital-economy players that enable e-commerce transactions, including (i) intermediary service platforms connecting service providers with consumers, (ii) digital content platforms, (iii) online advertising providers, (iv) cloud computing and data storage providers, (v) social media platforms engaged in business activities (e.g., live-stream, in-app transactions), (vi) online education, gaming, and digital entertainment platforms generating revenue from digital transactions, (vii) Vietnam-based partners of foreign digital service providers facilitating local payments for overseas platforms, and (viii) intermediary payment service providers handling financial transactions for e-commerce activities. Under the Draft Decree, Regulated Operators will be required to track, report, and enforce tax compliance for both resident and nonresident individuals and households conducting business through their platforms (“Sellers”). What New Tax Obligations Do Platforms Face? Onshore platforms For the first time, Regulated Operators will