You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 2, 2026

Thailand Insurance Industry: AI and Privacy Regulatory Updates

Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance.

What Has Changed: OIC and PDPC Alignment

The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers.

  • Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible.
  • Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors.
  • Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels.
  • DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on a large scale”—expressly including insurance—must appoint and register a data protection officer (DPO). The absence of a registered DPO or an outdated record of processing activities (ROPA) that fails to map agent-level data flows is now considered a high-risk compliance gap.

AI in Insurance: Draft PDPC Guidelines

The PDPC’s draft AI guidelines carry particular significance for insurers. The guidelines single out insurance risk assessments as an example of automated decision-making that produces legal effects or significantly affects data subjects. Organizations using AI-driven tools for underwriting, claims processing, or policy recommendations must implement a human-in-the-loop mechanism with actual authority to overturn AI decisions and must document processes for data subjects to request review. A data protection impact assessment (DPIA) is required for high-risk AI projects, including automated decision-making with legal effects and large-scale processing of sensitive data. Leakage of sensitive health or financial data through AI systems is categorized as high risk, requiring notification to both the PDPC and affected data subjects without delay.

Cross-Border Data Transfers

For multinational insurance groups, a binding corporate rules (BCRs) regulation became fully effective on February 17, 2026, providing a formal mechanism for intragroup cross-border transfers. Groups that already hold GDPR-approved BCRs may use a “fast-track” process by submitting their existing BCRs together with a Thailand addendum. Alternatively, Standard Contractual Clauses based on the ASEAN Model Contractual Clauses may be used for transfers to third-party reinsurers or service providers outside Thailand.

Practical Compliance Steps

Given the current regulatory landscape, insurers should consider the following immediate and near-term actions.

  • Governance and organization. Register a DPO with the PDPC if not already done, and ensure that the DPO has a direct reporting line to senior management with sufficient authority and resources to fulfill the role. Update the ROPA to comprehensively map all processing activities, including data flows through agents, brokers, and third-party administrators.
  • Consent architecture overhaul. Redesign application forms and digital onboarding flows so that marketing consent is presented as a separate, clearly labeled opt-in, entirely distinct from the consent required for the insurance contract itself. Ensure that refusal to consent to marketing does not affect the customer’s ability to obtain coverage.
  • Agent and vendor compliance program. Issue updated written instructions and security protocols to all insurance intermediaries classified as data processors. Review and strengthen data processing agreements with all third-party processors, including specific provisions for PDPA responsibilities, security standards, audit rights, breach notification obligations, and end-of-term data deletion or return. Implement a periodic audit cycle—rather than relying on static contractual commitments—to verify vendor compliance.
  • Privacy notice refresh. Prepare a concise summary privacy notice for distribution alongside insurance policies, covering all required elements under the OIC guidance. For digital tele-sales, implement prerecording disclosures informing customers that their voice or image data will be processed under the PDPA.
  • AI and automated decision-making readiness. Conduct DPIAs for all AI-driven underwriting, claims, and risk-assessment tools currently in use or under development. Establish a documented human-in-the-loop process for any automated decision that produces legal effects on policyholders, including a clear escalation path and a mechanism for data subjects to contest decisions.
  • Breach response preparedness. Ensure that internal incident response plans can meet the 72-hour notification deadline to the PDPC, with particular attention to AI-related data leakage scenarios.
  • Cross-border transfer mechanism. For multinational groups, evaluate whether BCR certification—including the fast-track route—or SCCs provide the most efficient path for data transfers to group entities or reinsurers abroad.

Outlook

Thailand’s insurance sector faces a significantly more demanding compliance environment as PDPA enforcement matures and OIC alignment tightens. The convergence of stricter consent rules, expanded liability for intermediary conduct, new AI governance expectations, and a workable cross-border transfer framework means that insurers must move from reactive compliance to proactive data governance. Organizations that address these areas systematically—beginning with DPO registration, ROPA updates, and consent architecture—will be best positioned to manage regulatory risk and maintain the trust of their policyholders.

RELATED INSIGHTS​ 

December 11, 2024
Thailand has released a draft amended Electronic Transactions Act (ETA), which aims to overhaul the current version of the law from 2001 to correct its enforcement limitations and update the ETA to be consistent with current electronic transactions practice. The draft ETA is open for public comment until December 20, 2024. The draft ETA introduces a new supervisory scheme that (1) recognizes electronic transactions executed by both current and future technologies without having to enact regulations recognizing the technology, (2) replaces the licensing, registration, and notification scheme for electronic transaction service providers with a trust-mark scheme, and (3) introduces a new mechanism to regulate electronic transaction service providers. The major amendments under the draft ETA address: Relationship with other relevant laws. The draft ETA is designated as the primary law governing electronic transactions, whether between private parties or between private parties and the state. However, if specific laws—including those on electronic administrative procedures—prescribe methods for conducting particular electronic transactions, those laws will prevail. Definitions. The draft ETA revises some existing terms, such as “transaction,” which is now more clearly defined as “any act relating to civil or commercial activities, including administrative procedures, administrative contracts, and any other actions by government agencies or officials.” It also introduces new definitions, such as “biometric data,” “automated system,” and “electronic seal.” Electronic transaction reliability. The draft ETA now clearly provides that electronic transactions executed using a method or an electronic method stipulated by the Electronic Transactions Development Agency (ETDA) as reliable are themselves presumed to be “reliable.” In case of a challenge over the implementation of a certified method or certified service, the challenging party bears the burden of proof and related expenses. Electronic transferable instruments. The draft ETA adopts the UNCITRAL Model Law on Electronic Transferable Records (ETRs) in recognizing ETRs (e.g.,
December 10, 2024
Thailand’s Ministry of Finance (MOF) has issued a new notification easing foreign shareholding and board limits for life insurers. This long-awaited update aligns with the draft notification that was previewed in May 2024, and reflects the MOF’s intention to enhance the stability and competitiveness of life insurers. Life Insurer Qualifications Life insurers may apply for permission to exceed 49% foreign shareholding or have a majority of foreign directors if: The life insurer operates in a manner that could harm the insured or the public, and either (1) the OIC has directed the company to improve its status or adjust its capital, or (2) the company’s actions may have a significant impact on the insurance industry, causing significant compensation burdens and affecting the company’s capital adequacy ratio (CAR); The life insurer’s shareholders are unable to increase capital; and The life insurer is unable to attract Thai investors to increase the capital necessary to ensure stability and the long-term operation of the business. Foreign Shareholder Qualifications To qualify, foreign shareholders must: Either be an insurance company or have at least 10 years of relevant experience in the insurance industry; Demonstrate financial stability and possess a credit rating (or have a parent company with a credit rating) of at least “A” from a reputable credit rating agency; Present a clear and comprehensive business plan to develop and promote the company’s efficiency and competitiveness in the industry; and Be able to make an investment that increases the company’s capital by at least THB 2 billion to maintain stability with a CAR of at least 250%. For more details on the MOF’s notification regarding criteria on foreign shareholding limits for life insurance companies, or on any issue concerning insurance regulations in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Witchupong Chittchang at [email protected], Ajaree
December 6, 2024
Thailand’s Office of Insurance Commission (OIC) recently announced two Notifications regarding Timeframe Standards for Service Level Agreements, for both life and non-life insurance companies. Under these notifications, every insurance company is required to set out clear and specific timeframes in its service level agreement (SLA) for at least the following activities: Providing information about life and non-life insurance and offering insurance policies; Underwriting and providing after-sales services; Paying compensation under the insurance policy; and Handling complaints. The timeframes described in the SLA must not exceed those specified in the insurance policy or by the relevant laws, and the SLA (which must be published on the insurer’s website) must be continually updated to reflect any changes in the timeframes. Insurance companies are required to disclose the standard timeframes for SLAs on their website by January 1, 2025, and notify the OIC through the channels and methods specified by the OIC. For more details on the OIC’s notifications on SLA timeframe standards, or on any aspect of insurance regulations in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Witchupong Chittchang at [email protected], Ajaree Trachukul at [email protected], Thammapas Chanpanich at [email protected], or Sireethorn Wijan at [email protected].
December 4, 2024
On October 28, 2024, Indonesia officially amended its existing Patent Law when the president ratified Law Number 65 of 2024. This comprehensive update—the third such amendment in the history of Indonesia’s Patent Law—introduces several key changes that will significantly impact patent protection and application processes in Indonesia. Key highlights and changes are outlined below. Definition of Invention The new law broadens the definition of “invention” to explicitly include systems, methods, and uses. Additionally, the law introduces formal definitions for traditional knowledge and genetic resources. Patentability Criteria Notable changes include: Computer programs are now excluded, with an exception for computer-implemented inventions. Theories and methods in science and mathematics are added to the list of excluded inventions. Previous restrictions on new uses of existing products are removed. Grace Periods The grace periods for some patent-related actions have been adjusted: The grace period for disclosures has been extended to 12 months (from 6 months previously), providing inventors with more flexibility in filing patent applications after initial disclosure. A newly introduced item is the grace period for a conventional patent application claiming priority rights, which is 4 months after the 12-month filing deadline under the Paris Convention. The grace period for annuity payments is 6 months (from 12 months previously) with a fine for late payments of 100% of the annual fee payable. Patent Holder Rights and Obligations Patent holders can now grant permissions to enforce patents. There is a new requirement for patent holders to submit annual statements on patent implementation in Indonesia. Compulsory Licensing Significant changes to compulsory licensing include: Establishment of licenses based on the principle of expediency. Limitations on license scope and transferability. Prioritization of domestic market needs. New provisions for technical improvements and economic significance. Government Patent Exploitation The new law contains specific provisions for the government’s implementation