You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 2, 2026

Thailand Insurance Industry: AI and Privacy Regulatory Updates

Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance.

What Has Changed: OIC and PDPC Alignment

The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers.

  • Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible.
  • Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors.
  • Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels.
  • DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on a large scale”—expressly including insurance—must appoint and register a data protection officer (DPO). The absence of a registered DPO or an outdated record of processing activities (ROPA) that fails to map agent-level data flows is now considered a high-risk compliance gap.

AI in Insurance: Draft PDPC Guidelines

The PDPC’s draft AI guidelines carry particular significance for insurers. The guidelines single out insurance risk assessments as an example of automated decision-making that produces legal effects or significantly affects data subjects. Organizations using AI-driven tools for underwriting, claims processing, or policy recommendations must implement a human-in-the-loop mechanism with actual authority to overturn AI decisions and must document processes for data subjects to request review. A data protection impact assessment (DPIA) is required for high-risk AI projects, including automated decision-making with legal effects and large-scale processing of sensitive data. Leakage of sensitive health or financial data through AI systems is categorized as high risk, requiring notification to both the PDPC and affected data subjects without delay.

Cross-Border Data Transfers

For multinational insurance groups, a binding corporate rules (BCRs) regulation became fully effective on February 17, 2026, providing a formal mechanism for intragroup cross-border transfers. Groups that already hold GDPR-approved BCRs may use a “fast-track” process by submitting their existing BCRs together with a Thailand addendum. Alternatively, Standard Contractual Clauses based on the ASEAN Model Contractual Clauses may be used for transfers to third-party reinsurers or service providers outside Thailand.

Practical Compliance Steps

Given the current regulatory landscape, insurers should consider the following immediate and near-term actions.

  • Governance and organization. Register a DPO with the PDPC if not already done, and ensure that the DPO has a direct reporting line to senior management with sufficient authority and resources to fulfill the role. Update the ROPA to comprehensively map all processing activities, including data flows through agents, brokers, and third-party administrators.
  • Consent architecture overhaul. Redesign application forms and digital onboarding flows so that marketing consent is presented as a separate, clearly labeled opt-in, entirely distinct from the consent required for the insurance contract itself. Ensure that refusal to consent to marketing does not affect the customer’s ability to obtain coverage.
  • Agent and vendor compliance program. Issue updated written instructions and security protocols to all insurance intermediaries classified as data processors. Review and strengthen data processing agreements with all third-party processors, including specific provisions for PDPA responsibilities, security standards, audit rights, breach notification obligations, and end-of-term data deletion or return. Implement a periodic audit cycle—rather than relying on static contractual commitments—to verify vendor compliance.
  • Privacy notice refresh. Prepare a concise summary privacy notice for distribution alongside insurance policies, covering all required elements under the OIC guidance. For digital tele-sales, implement prerecording disclosures informing customers that their voice or image data will be processed under the PDPA.
  • AI and automated decision-making readiness. Conduct DPIAs for all AI-driven underwriting, claims, and risk-assessment tools currently in use or under development. Establish a documented human-in-the-loop process for any automated decision that produces legal effects on policyholders, including a clear escalation path and a mechanism for data subjects to contest decisions.
  • Breach response preparedness. Ensure that internal incident response plans can meet the 72-hour notification deadline to the PDPC, with particular attention to AI-related data leakage scenarios.
  • Cross-border transfer mechanism. For multinational groups, evaluate whether BCR certification—including the fast-track route—or SCCs provide the most efficient path for data transfers to group entities or reinsurers abroad.

Outlook

Thailand’s insurance sector faces a significantly more demanding compliance environment as PDPA enforcement matures and OIC alignment tightens. The convergence of stricter consent rules, expanded liability for intermediary conduct, new AI governance expectations, and a workable cross-border transfer framework means that insurers must move from reactive compliance to proactive data governance. Organizations that address these areas systematically—beginning with DPO registration, ROPA updates, and consent architecture—will be best positioned to manage regulatory risk and maintain the trust of their policyholders.

RELATED INSIGHTS​ 

July 31, 2023
On July 13, 2023, Thailand’s Personal Data Protection Committee (PDPC) published a draft notification on the requirements for appointment of a data protection officer (DPO). Under the Personal Data Protection Act B.E. 2562 (PDPA), data controllers or data processors must appoint a DPO if: The data controller or data processor is a state agency as prescribed by the PDPC (the list of state agencies was published in the Government Gazette on July 18, 2023); The activities of the data controller or data processor in relation to the processing of the personal data require “regular monitoring of the personal data or the system,” by reason of “having large-scale personal data” as prescribed by the PDPC; or The core activity of the data controller or data processor is related to the processing of special categories of personal data (e.g., health-related data, biometric data, etc.). The draft notification’s criteria for determining whether a processing activity (1) requires regular monitoring of the personal data or the system, and (2) involves large-scale personal data are outlined below. General Principles When determining whether processing of personal data requires regular monitoring due to having large-scale personal data, it is likely that only the “core activity” of the data controller or data processor is to be taken into consideration. The term “core activity” denotes an essential and integral activity directly related to the primary operations of the data controller or data processor and does not include any supplementary business activities. Regular Monitoring of Personal Data or Systems According to the draft notification, activities related to processing personal data require regular monitoring of the personal data or the system if: The core part of the data controller’s or data processor’s activities consists of tracking, monitoring, analyzing, or predicting the behavior, attitude, or profile of individuals; and These activities
July 31, 2023
Vietnam’s Decree No. 72/2013/ND-CP, as amended by Decree 27/2018/ND-CP (referred to collectively as “Decree 72”) regulates internet services and online information, and plays a crucial role in governing significant services such as social networks, online games, and aggregated information websites, as well as key matters like domain names and online information security. Given the rapid pace of development in these areas, Decree 72—having been in effect for nearly a decade—is in need of an update. The Ministry of Information and Communications (MIC) had initially intended to draft an amendment to Decree 72 in 2021. However, the magnitude of required changes made it impractical to retain the form of an amending decree, leading the MIC to shift its focus toward replacing Decree 72 entirely. As a result, a new draft decree to replace Decree 72 (the “Draft Decree”) was released by the MIC for public consultation from July 17 to September 15, 2023. The Draft Decree is comprehensive, with six chapters, 87 articles, and an appendix of 56 forms. The following are some of the main issues covered by the new Draft Decree. 1. Social Network Services Classification and licensing/notification Social network services include onshore and offshore social network services. Onshore social network services refer to those provided by organizations or enterprises with legal status in Vietnam, and are divided into “high-visitor” or “low-visitor” categories based on number of regular visitors. The high-visitor category includes social networks with total visits of 10,000 or more per month for six consecutive months or with more than 1,000 regular members in a month. High-visitor onshore social network service providers must obtain a license to provide social network services. Low-visitor onshore social network service providers only need to notify the MIC’s Authority of Broadcasting and Electronic Information (ABEI) and receive the ABEI’s written notification
July 28, 2023
Myanmar’s Ministry of Commerce (MOC) issued three notifications related to e-commerce on July 21, 2023, classifying online retail businesses as essential services, requiring them to register with the relevant authorities, and setting the criteria for their registration. Under Notification No. 49/2023 the MOC authorized the Department of Trade (DOT) to issue notifications, orders, and directives relating to online retail businesses. This was followed by Notification No. 50/2023, which classifies online retail businesses as essential services under the Essential Supplies and Services Law and requires them to register with the DOT within six months of the issuance of the notification (i.e., by January 21, 2024). Failure to register within the specified period will be punishable by imprisonment for six months to three years and a fine of up to MMK 500,000 (approx. USD 238). Finally, under Notification No. 51/2023, the MOC set out the criteria and requirements for the registration of online retail businesses by entities, business institutions, and individuals, as well as the duties and liabilities of sellers and consumers. Pursuant to this notification, registration should be completed via the DOT’s online system, fees must be paid digitally, and electronic registration certificates will be issued. Certificates are initially valid for two years, and can be renewed. The MOC will provide information at a later time on the prescribed forms, certificate format, registration and online fees, and online registration portal. In applying for registration, an entity or business institution established under the Myanmar Companies Law, Special Company Act, Co-operative Society Law, or any other existing Myanmar laws must have a website with its own domain name or an online channel with an exact address that is used for online sales and a registered business address within Myanmar. Individual applicants must be at least 18 years old, reside in Myanmar, and
July 26, 2023
Thailand’s Electronic Transactions Development Agency (ETDA) held a briefing session on July 20, 2023, laying out the changes and new requirements in draft sublaws under the Royal Decree on Digital Platform Services. These sublaws are expected to be announced in August 2023. The key changes and new requirements are listed below. The ETDA has drafted guidelines on the methods for identifying active users to give digital platform service operators a better understanding of the calculation methods. The definition of “users” for calculating annual monthly active users (AMAUs) has been reduced in scope to cover only users in Thailand. E-marketplace digital platform services that will suspend or terminate operations for specific users must inform the affected users and provide a period for them to challenge the suspension or termination. Digital platform service operators cannot use the requirements to identify their active users as a legal basis for processing users’ personal data, especially for profiling and tracking activities. The sublaws on announcement of terms and conditions (T&Cs) and changes to T&Cs, once issued, will take effect on January 3, 2024, while the other sublaws will take effect immediately (i.e., August 21, 2023). This shows that the ETDA has acknowledged the private sector’s feedback that the requirements on T&Cs will take more time for operators to comply with. The requirements for changing T&Cs have been adjusted. Under the current draft, the required advance notification period can be exempted if a change in the T&Cs is for the purpose of, for example, rolling out new products or services and improving the platform. Required submissions under the Royal Decree for Digital Platform Services and its sublaws will be made through the ETDA’s online portal. There will likely be no extensions granted for compliance with the Royal Decree for Digital Platform Services and its sublaws