You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 2, 2026

Thailand Insurance Industry: AI and Privacy Regulatory Updates

Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance.

What Has Changed: OIC and PDPC Alignment

The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers.

  • Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible.
  • Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors.
  • Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels.
  • DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on a large scale”—expressly including insurance—must appoint and register a data protection officer (DPO). The absence of a registered DPO or an outdated record of processing activities (ROPA) that fails to map agent-level data flows is now considered a high-risk compliance gap.

AI in Insurance: Draft PDPC Guidelines

The PDPC’s draft AI guidelines carry particular significance for insurers. The guidelines single out insurance risk assessments as an example of automated decision-making that produces legal effects or significantly affects data subjects. Organizations using AI-driven tools for underwriting, claims processing, or policy recommendations must implement a human-in-the-loop mechanism with actual authority to overturn AI decisions and must document processes for data subjects to request review. A data protection impact assessment (DPIA) is required for high-risk AI projects, including automated decision-making with legal effects and large-scale processing of sensitive data. Leakage of sensitive health or financial data through AI systems is categorized as high risk, requiring notification to both the PDPC and affected data subjects without delay.

Cross-Border Data Transfers

For multinational insurance groups, a binding corporate rules (BCRs) regulation became fully effective on February 17, 2026, providing a formal mechanism for intragroup cross-border transfers. Groups that already hold GDPR-approved BCRs may use a “fast-track” process by submitting their existing BCRs together with a Thailand addendum. Alternatively, Standard Contractual Clauses based on the ASEAN Model Contractual Clauses may be used for transfers to third-party reinsurers or service providers outside Thailand.

Practical Compliance Steps

Given the current regulatory landscape, insurers should consider the following immediate and near-term actions.

  • Governance and organization. Register a DPO with the PDPC if not already done, and ensure that the DPO has a direct reporting line to senior management with sufficient authority and resources to fulfill the role. Update the ROPA to comprehensively map all processing activities, including data flows through agents, brokers, and third-party administrators.
  • Consent architecture overhaul. Redesign application forms and digital onboarding flows so that marketing consent is presented as a separate, clearly labeled opt-in, entirely distinct from the consent required for the insurance contract itself. Ensure that refusal to consent to marketing does not affect the customer’s ability to obtain coverage.
  • Agent and vendor compliance program. Issue updated written instructions and security protocols to all insurance intermediaries classified as data processors. Review and strengthen data processing agreements with all third-party processors, including specific provisions for PDPA responsibilities, security standards, audit rights, breach notification obligations, and end-of-term data deletion or return. Implement a periodic audit cycle—rather than relying on static contractual commitments—to verify vendor compliance.
  • Privacy notice refresh. Prepare a concise summary privacy notice for distribution alongside insurance policies, covering all required elements under the OIC guidance. For digital tele-sales, implement prerecording disclosures informing customers that their voice or image data will be processed under the PDPA.
  • AI and automated decision-making readiness. Conduct DPIAs for all AI-driven underwriting, claims, and risk-assessment tools currently in use or under development. Establish a documented human-in-the-loop process for any automated decision that produces legal effects on policyholders, including a clear escalation path and a mechanism for data subjects to contest decisions.
  • Breach response preparedness. Ensure that internal incident response plans can meet the 72-hour notification deadline to the PDPC, with particular attention to AI-related data leakage scenarios.
  • Cross-border transfer mechanism. For multinational groups, evaluate whether BCR certification—including the fast-track route—or SCCs provide the most efficient path for data transfers to group entities or reinsurers abroad.

Outlook

Thailand’s insurance sector faces a significantly more demanding compliance environment as PDPA enforcement matures and OIC alignment tightens. The convergence of stricter consent rules, expanded liability for intermediary conduct, new AI governance expectations, and a workable cross-border transfer framework means that insurers must move from reactive compliance to proactive data governance. Organizations that address these areas systematically—beginning with DPO registration, ROPA updates, and consent architecture—will be best positioned to manage regulatory risk and maintain the trust of their policyholders.

RELATED INSIGHTS​ 

August 31, 2023
When your company suffers a data breach, taking prudent, careful action can limit and perhaps even rectify some of the damage. First of all, it is important to document everything, starting with the time the data breach was discovered. Secure the data systems and preserve all evidence so that investigators can determine what happened, and begin following the protocol that all companies handling personal data should have in place to guide their data breach response. It is also crucial to seek timely legal assistance to ensure that every aspect of the response is planned and carried out according to the law. While applicable legal advice for each situation can only be obtained by consulting a legal advisor, this guide gives an overview of what companies in Southeast Asian jurisdictions can expect if they suffer a data breach. This guide from Tilleke & Gibbins is a quick-reference resource covering key regulatory issues regarding data breach responses in Cambodia, Laos, Myanmar, Thailand, and Vietnam. The full guide can be downloaded through the button below.
August 23, 2023
Introduction The idea of the metaverse rose to prominence in the public discourse in 2021, most notably when Facebook renamed itself Meta and announced a new focus on launching a virtual, immersive world. The initial excitement around the metaverse has since faded, with worsening economic conditions having a particularly acute effect on companies in the technology sector. When Meta CEO Mark Zuckerberg announced in March 2023 that artificial intelligence (AI) was the company’s “single largest investment,” many took this as a sign of the company shifting focus away from the metaverse. However, there remains significant interest in the metaverse from both businesses and consumers. Zuckerberg himself reaffirmed Meta’s focus on the metaverse, highlighting how developments in AI will improve virtual reality (VR) and augmented reality (AR) technology. Meanwhile, Roblox, a metaverse gaming platform, announced that in Q1 2023, its number of daily active users had increased to 66 million. Most recently, the announcement by Apple of its new ‘Vision Pro’ AR headset is reported to have renewed interest in the metaverse among developers. A particular area of interest in the developing metaverse is digital fashion and retail. In its Metaverse Fashion Trends Report 2022, Roblox found that nearly three in four users aged 14 to 24 spend money on digital fashion items. Roblox itself has partnered with fashion brands Burberry, Gucci, Tommy Hilfiger, and others, to offer experiences and items for use on the platform. In March 2023, Decentraland, a metaverse platform with a decentralized governance structure, hosted the Metaverse Fashion Week, featuring brands such as Adidas, Coach, and DKNY. As businesses continue to invest and look for opportunities to expand into the metaverse, whether through traditional e-commerce or more innovative digital asset offerings, it is important that they consider the ways in which new and existing laws apply
August 22, 2023
On August 17, 2023, the Thai government rolled out a royal decree that provides certain exemptions to data controllers’ obligations under the Personal Data Protection Act B.E. 2562 (PDPA). The royal decree, which will come into effect after the lapse of 150 days from its publication in the Government Gazette, reflects the government’s ongoing quest to strike a balance between privacy, state interests, and the data protection regulatory burden on organizations. The royal decree seeks to clarify the circumstances in which data controllers—including business operators and state agencies—are exempt from certain PDPA requirements on the collection, use, and disclosure of personal data and data subject rights. In doing so, it establishes three foundational pillars in considering exemptions: Collection or requests for personal data are to be for the public interest pursuant to the purpose and scope prescribed by any law authorizing a state agency to carry out a certain action, without imposing an undue burden on the data controller responsible for disclosing the personal information. Data controllers can share personal data without the data subject’s consent if legally authorized state agencies request it and specify the statutory provisions granting authority to request the data. Data subjects and data controllers of requested personal data must have the right to submit complaints to the PDPA’s Expert Committee or seek its expertise for clarification or determination. Under the three foundational pillars, data controllers will be partially exempted from certain requirements under the PDPA when the following state agencies request personal data: The National Anti-Corruption Commission or other government entities with mandates aligned with anticorruption laws; The Revenue Department, Customs Department, Excise Department, or other governmental units operating under taxation laws; Local governmental bodies recognized by the Personal Data Protection Committee (PDPC), or any government unit with mandates as per the laws related
August 3, 2023
Tilleke & Gibbins’ insurance specialists in Cambodia, Laos, Myanmar, and Thailand have contributed to the Law and Jurisdiction in Insurance and Reinsurance Contracts – Asia Pacific guide produced by RPC. The guide addresses how governing law, jurisdiction, and arbitration clauses are used in insurance and reinsurance contracts. For each jurisdiction in the Asia Pacific region, the guide addresses the following topics: Governing law; Arbitration; Mediation; and Limitations and time bars on claims. The Law and Jurisdiction in Insurance and Reinsurance Contracts – Asia Pacific guide is available below.