You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 2, 2026

Thailand Insurance Industry: AI and Privacy Regulatory Updates

Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance.

What Has Changed: OIC and PDPC Alignment

The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers.

  • Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible.
  • Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors.
  • Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels.
  • DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on a large scale”—expressly including insurance—must appoint and register a data protection officer (DPO). The absence of a registered DPO or an outdated record of processing activities (ROPA) that fails to map agent-level data flows is now considered a high-risk compliance gap.

AI in Insurance: Draft PDPC Guidelines

The PDPC’s draft AI guidelines carry particular significance for insurers. The guidelines single out insurance risk assessments as an example of automated decision-making that produces legal effects or significantly affects data subjects. Organizations using AI-driven tools for underwriting, claims processing, or policy recommendations must implement a human-in-the-loop mechanism with actual authority to overturn AI decisions and must document processes for data subjects to request review. A data protection impact assessment (DPIA) is required for high-risk AI projects, including automated decision-making with legal effects and large-scale processing of sensitive data. Leakage of sensitive health or financial data through AI systems is categorized as high risk, requiring notification to both the PDPC and affected data subjects without delay.

Cross-Border Data Transfers

For multinational insurance groups, a binding corporate rules (BCRs) regulation became fully effective on February 17, 2026, providing a formal mechanism for intragroup cross-border transfers. Groups that already hold GDPR-approved BCRs may use a “fast-track” process by submitting their existing BCRs together with a Thailand addendum. Alternatively, Standard Contractual Clauses based on the ASEAN Model Contractual Clauses may be used for transfers to third-party reinsurers or service providers outside Thailand.

Practical Compliance Steps

Given the current regulatory landscape, insurers should consider the following immediate and near-term actions.

  • Governance and organization. Register a DPO with the PDPC if not already done, and ensure that the DPO has a direct reporting line to senior management with sufficient authority and resources to fulfill the role. Update the ROPA to comprehensively map all processing activities, including data flows through agents, brokers, and third-party administrators.
  • Consent architecture overhaul. Redesign application forms and digital onboarding flows so that marketing consent is presented as a separate, clearly labeled opt-in, entirely distinct from the consent required for the insurance contract itself. Ensure that refusal to consent to marketing does not affect the customer’s ability to obtain coverage.
  • Agent and vendor compliance program. Issue updated written instructions and security protocols to all insurance intermediaries classified as data processors. Review and strengthen data processing agreements with all third-party processors, including specific provisions for PDPA responsibilities, security standards, audit rights, breach notification obligations, and end-of-term data deletion or return. Implement a periodic audit cycle—rather than relying on static contractual commitments—to verify vendor compliance.
  • Privacy notice refresh. Prepare a concise summary privacy notice for distribution alongside insurance policies, covering all required elements under the OIC guidance. For digital tele-sales, implement prerecording disclosures informing customers that their voice or image data will be processed under the PDPA.
  • AI and automated decision-making readiness. Conduct DPIAs for all AI-driven underwriting, claims, and risk-assessment tools currently in use or under development. Establish a documented human-in-the-loop process for any automated decision that produces legal effects on policyholders, including a clear escalation path and a mechanism for data subjects to contest decisions.
  • Breach response preparedness. Ensure that internal incident response plans can meet the 72-hour notification deadline to the PDPC, with particular attention to AI-related data leakage scenarios.
  • Cross-border transfer mechanism. For multinational groups, evaluate whether BCR certification—including the fast-track route—or SCCs provide the most efficient path for data transfers to group entities or reinsurers abroad.

Outlook

Thailand’s insurance sector faces a significantly more demanding compliance environment as PDPA enforcement matures and OIC alignment tightens. The convergence of stricter consent rules, expanded liability for intermediary conduct, new AI governance expectations, and a workable cross-border transfer framework means that insurers must move from reactive compliance to proactive data governance. Organizations that address these areas systematically—beginning with DPO registration, ROPA updates, and consent architecture—will be best positioned to manage regulatory risk and maintain the trust of their policyholders.

RELATED INSIGHTS​ 

January 23, 2025
Thailand’s Ministry of Digital Economy and Society, through the Digital Economy Promotion Agency (DEPA), recently held a focus group hearing on the draft Gaming Industry Promotion Act. This legislation seeks to strike a balance by promoting the growth of the online game industry while safeguarding society, with a particular focus on protecting youth from potential negative impacts and enhancing a positive gaming environment. From the public releases, the draft act is expected to address several key aspects, including: Registration requirements for key industry players, such as developers and platform providers. It is also worth monitoring whether these requirements will also apply to offshore entities offering services to users in Thailand. Governance measures, such as game rating systems and measures to address online gambling and violence in games. Incentives, such as the establishment of a fund to support the gaming industry, and tax incentives to promote Thai gaming businesses. DEPA plans to incorporate feedback from the focus group hearing to refine the Draft Act. The legislation is expected to be submitted to the cabinet for approval by April 2025, with enactment expected by the end of 2025. As this draft law is still at an early stage, amendments may be introduced during the legislative process. Businesses and stakeholders in the gaming industry are encouraged to monitor the matter closely and assess how the developing legislation may impact their operations.
January 22, 2025
Tasked with implementing the Politburo’s policy outlined in Notice No. 47-TB/TW dated November 15, 2024, the prime minister of Vietnam issued Decision No. 1718/QD-TTg on December 31, 2024, appointing himself as the head of a steering committee dedicated to the establishment of an international financial center in Ho Chi Minh City and a regional financial center in Da Nang by 2025. The Ministry of Planning and Investment has subsequently drafted an outline for the National Assembly’s Resolution on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Resolution”). This Draft Resolution introduces two key policy groups: (i) policies governing the quantity, location, structure, organization, functions, and responsibilities of the financial centers; and (ii) policies applicable to various areas and matters within the financial centers. Notably, under the Draft Resolution, fintech has been identified as a key sector, with a specific focus on the implementation of a “controlled sandbox” policy for business models involving virtual assets and cryptocurrencies. Under this framework, transactions related to virtual assets and cryptocurrencies will be permitted from July 1, 2026, subject to licensing, management, impact assessment, and risk oversight by the financial centers’ Management and Operations Committee. Scope of Application and Key Principles The Draft Resolution applies to a wide range of stakeholders, including investors, regulatory agencies, organizations, and individuals involved in the establishment, organization, and operation of regional and international financial centers in Vietnam. These financial centers will have clearly defined geographical boundaries and specific locations, which will be further specified and detailed by the People’s Committees of Ho Chi Minh City and Da Nang. Companies successfully registered as members of these financial centers will benefit from special investor-friendly policy principles, which may differ from the general legal and regulatory framework applicable in other parts of Vietnam. Most notably, the state will
January 21, 2025
Vietnam’s Ministry of Information and Communications has released the latest version of its draft Law on the Digital Technology Industry (DTI Law), marking a significant step toward comprehensive regulation of digital technologies and notably addressing artificial intelligence (AI). The draft law was deliberated in the National Assembly on January 6, 2025, and is expected to be adopted in May 2025. Once in effect, the law will modernize Vietnam’s existing information technology regulatory framework. Background Vietnam has been steadily building its regulatory framework for AI since January 2021, when the prime minister issued Decision No. 127/QD-TTg on the National Strategy for Research, Development, and Application of Artificial Intelligence until 2030. While various ministries have been tasked with issuing guidance documents and technical standards, Vietnam still lacks a comprehensive legal framework specifically addressing AI and digital technologies. The draft DTI Law aims to fill this gap by providing a structured approach to regulating the digital technology industry. Scope and Definitions The draft DTI Law establishes a broad framework governing digital technology industry activities, initiatives for developing the digital technology sector, and rights and obligations of organizations and individuals in the industry. The draft law also proposes the creation of various incentives, primarily in the form of tax benefits, for encouraging foreign direct investment, talent acquisition and development, and industry growth. The draft law introduces several important definitions, particularly around AI, which is defined as digital technology that simulates human intelligence to generate content, forecasts, suggestions, and decisions based on human-determined goals. The draft distinguishes between different categories of AI systems: High-risk AI systems: Those posing risks to health, safety, rights, and legitimate interests. High-impact AI systems: Distinguished by their broad scope, large user base, and significant computational resources for training. Standard AI systems: Basic systems that apply AI for automated analysis
January 20, 2025
Thailand’s official draft Platform Economy Act (PEA) was released on January 15, 2025, for public comment until February 15, 2025. The draft PEA is positioned as a general or overarching law for digital intermediary services and digital platform service businesses. The official release of the draft came after the sharing of the set of principles that would form the basis for the official draft PEA in November 2024. The draft PEA incorporates those principles and adds more detailed provisions. Especially notable is that the draft PEA requires all intermediary service providers and online platform operators—both Thai and foreign—to appoint a point of contact to liaise with the Electronic Transactions Development Agency (ETDA) if they have any users in Thailand. However, the draft PEA does not mandate establishment of a local entity in Thailand. Types of Intermediary Services The draft PEA sets out a three-tiered classification system for different types of service providers, ordered from fewest obligations to most: Intermediary services. Intermediary services are further divided into three subcategories: mere conduit, caching, and hosting. Each type of intermediary service has different safe harbor provisions, which define their scope and limitations. Online platform services. Online platform services are defined as involving “the provision of intermediary services in the hosting category that involve facilitating the matching of various types of users to enable transactions or interactions, whether or not a fee is charged. Additionally, such services may include other provisions to facilitate these transactions or interactions.” Key obligations for online platform providers include: Informing users of their rights and duties under relevant laws Implementing a notice-and-action mechanism Disclosing advertising information Publishing T&Cs, including details such as service fees, algorithms, and complaint management mechanisms. Very large online platform services. Very large online platform services (VLOPs) have extra duties beyond regular online platform services,