You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 7, 2022

Thailand Opens Public Hearing Period on Measures for Cross-Border Transfer of Personal Data

Thailand’s Office of the Personal Data Protection Committee (PDPC) has opened a public hearing period on its draft notification regarding cross-border transfer of personal data. The public hearing is open through October 24. The notification, once issued, will supplement the principle of cross-border transfer of personal data outside of Thailand set out in the Personal Data Protection Act (PDPA).

The notification sets out the following key matters:

Definitions

  • “Transfer of personal data” means any sending or transferring of personal data by a transferor of personal data, either by way of a physical transfer or a remote transfer through a computer system or an internet network to the recipient of the personal data. It does not include sending personal data through an intermediary by transiting between computer systems or internet networks, or any storing or retaining of personal data, either permanently or temporarily, by a cloud computing service provider, whereby the personal data transferor and the personal data recipient (1) are not making the order, (2) are not involved with any data selection or the content of the personal data sent and received through the computer systems or internet networks, or (3) have the purpose of entering into an agreement or any juristic act.
  • “Binding corporate rules” means the agreed terms or policy on personal data protection made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data within a group of corporations or companies.
  • “Standard contractual clauses” means the contractual terms made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data.
  • “Code of conduct” means a code that sets out the obligations of a personal data transferor and a personal data recipient outside of Thailand.
  • “Certification” means an undertaking in relation to safeguarding personal data, in order to establish appropriate personal data safeguarding measures.

Binding Corporate Rules

For cross-border transfers within a group of corporations or companies, binding corporate rules (BCRs) can be established and submitted to the PDPC for approval. The BCRs must adhere to the following minimum standards:

  • The effectiveness and legally binding nature of the BCRs apply to each company or entity within the group, including the data recipient, data processor, and data transferor, and the members belonging to the group, as well as their employees, staff, or persons related to the transfer or receipt of personal data within the group.
  • The BCRs must comply with Thai laws on personal data protection.
  • The BCRs must contain certification of data subject rights under the PDPA and sub-regulations.
  • The BCRs must contain measures on personal data protection in relation to personnel, processes, and security measures in accordance with the required technology standards for personal data protection.

Appropriate Safeguards

In accordance with section 29, paragraph 3, of the PDPA, a personal data transferor may transfer personal data to a recipient outside of Thailand when procuring appropriate safeguard measures by way of “standard contractual clauses,” “code of conduct,” or “certification.” Such appropriate safeguards must at least ensure the enforceability of the data subject’s rights and effective legal remedial actions, as provided in the annexes of the notification.

The appropriate safeguards must at least have the following:

  • Effectiveness and legal enforceability.
  • Compliance with Thai laws on personal data protection.
  • Certification of data subject rights under the PDPA and sub-regulations.
  • Measures on personal data protection in relation to personnel, process, and security measures in accordance with the required technology standards for personal data protection.

The standard contractual clauses must be filed with the PDPC. The appropriate safeguard measures must be enforceable under Thai law, and they must provide data subject rights under Thai law. Such rights must also be enforceable and provide remedial rights for data subjects as stipulated under Thai law.

The notification also sets out standard contractual clauses for controller-to-controller and controller-to-processor international transfers. The clauses primarily stipulate the obligations of the transferor and the recipient, recognize the enforceability of the PDPA provisions on personal data protection, and ensure the ability of data subjects to exercise their rights (in the form of third-party rights).

For more information from Tilleke & Gibbins’ data privacy team regarding the draft notification, or any aspect of compliance with PDPA requirements, please contact Athistha (Nop) Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Gvavalin Mahakunkitchareon at [email protected], or Thammapas Chanpanich at [email protected].

RELATED INSIGHTS​ 

August 25, 2025
Artificial intelligence (AI), semiconductors, and digital assets are considered critical drivers of Vietnam’s future economic growth and are fundamental to the nation’s digital transformation targets. These sectors form the core of Vietnam’s strategy to build a robust, globally competitive digital economy. This strategic direction gained substantial momentum with the issuance of the Law on Digital Technology Industry (DTI Law) on June 14, 2025. The DTI Law was designed to attract investment, stimulate innovation, cultivate high-quality human resources, and ensure the responsible, secure, and sustainable growth of digital technologies like AI and digital assets, harmonizing Vietnam’s digital industry with international standards while safeguarding public interests and national security. Several key provisions of the DTI Law took effect on July 1, 2025, and the law will become fully effective on January 1, 2026. The government is delegated to provide further necessary guidelines and details for implementation of the law. Artificial Intelligence (AI): Principle-Driven and Risk-Based Regulations Under the DTI Law, there are seven core principles guiding the development, provision, and use of AI which are applicable to AI developers, providers and deployers. These principles favor values-based governance over purely technical prescriptions, and include the following: Taking a human-centered approach that upholds ethical values, inclusivity, flexibility, equality, and non-discrimination. Ensuring transparency, accountability, and explainability, with AI systems remaining under human control. Maintaining cybersecurity and system safety. Adherence to data protection and privacy regulations. Having the ability to control AI algorithms and models. Effective risk management throughout the entire lifecycle of AI systems. Compliance with consumer protection laws and other relevant legal frameworks. AI system management follows a risk-based approach, with the law categorizing systems into high-risk, high-impact, and other groups. High-risk AI systems are those that, in certain applications, may pose significant threats or harm to individuals or the public interest while
August 21, 2025
On August 19, 2025, the Trade Competition Commission of Thailand (TCCT) released its draft Guidelines on the Consideration of Unfair Trade Practices and Conduct Constituting Monopoly, Reducing Competition, or Restricting Competition in Multi-Sided Platform Businesses in the Category of Digital Platforms for the Sale of Goods or Services (E-commerce). A public comment period on the guidelines is open until September 18. The draft provides the first detailed framework for how the TCCT will interpret and enforce the substantive provisions under the Trade Competition Act against digital platforms, which have a unique network effect and require complex competition analysis. This development will profoundly impact the operations of e-commerce platforms, sellers, and associated service providers in Thailand. The guidelines primarily target e-commerce digital platform business operators, which are defined as follows: E-commerce digital platform: A medium facilitating the sale, purchase, or exchange of goods or services, including any operations to create transactions or interactions between business operators via an electronic transaction system, regardless of whether service fees are charged. E-commerce digital platform business operator: A service provider of a digital platform for the sale of goods or services who acts as an intermediary facilitating the sale of goods or services, including any operations to create transactions or interactions through an electronic transaction system by receiving orders for goods or services transacted via an electronic system, whether in the form of an e-marketplace, a social marketplace, or any other form that connects purchase orders for goods or services with business operators through an electronic system. Prohibited Conduct The guidelines classify potentially anticompetitive conduct and unfair trade practices into two categories: price-related and non-price-related conduct. 1. Price-related conduct The TCCT is targeting pricing strategies that can harm competition. Key prohibited behaviors include: Price below cost: Setting prices below the average total cost without
August 21, 2025
On August 18, 2025, Thailand’s Securities and Exchange Commission (SEC), in collaboration with the Ministry of Finance, the Anti-Money Laundering Office, and the Ministry of Tourism and Sports, announced the launch of TouristDigiPay. The initiative, implemented under the SEC’s Regulatory Sandbox, allows foreign tourists to convert digital assets into Thai baht for use in everyday transactions in Thailand. Foreign tourists who opt to participate in TouristDigiPay must open two accounts once they are in Thailand: An account with a licensed digital asset operator to sell or exchange digital assets for Thai baht; and A tourist wallet account with a licensed e-money operator regulated by the Bank of Thailand. Funds from digital asset sales will be transferred into the tourist wallet, enabling tourists to make payments at participating merchants that accept e-money. Key Regulatory Requirements The TouristDigiPay project will operate for a period of up to 18 months, with the following conditions: Only licensed digital asset brokers, dealers, and exchanges integrated with licensed e-money operators are eligible to participate. Operators must implement anti-money laundering (AML) protocols that are proportionate to the assessed risk level. These include: Conducting know-your-customer and customer-due-diligence (KYC/CDD) checks on all users. For monthly transactions exceeding THB 50,000 per person, verifying the source of the digital assets and assessing AML risk using internationally recognized blockchain forensic tools or equivalent procedures. Suspending or rejecting services if digital assets are transferred from wallets flagged for AML concerns. Ensuring that conversion between digital assets and fiat includes safeguards such as matching account names and returning digital assets only to the original wallet. The following transaction limits apply to participants in the TouristDigiPay initiative: Payments to small vendors are capped at THB 50,000 per month. Payments to vendors who have completed the know-your-merchant (KYM) process are capped at THB 500,000 per