You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 7, 2022

Thailand Opens Public Hearing Period on Measures for Cross-Border Transfer of Personal Data

Thailand’s Office of the Personal Data Protection Committee (PDPC) has opened a public hearing period on its draft notification regarding cross-border transfer of personal data. The public hearing is open through October 24. The notification, once issued, will supplement the principle of cross-border transfer of personal data outside of Thailand set out in the Personal Data Protection Act (PDPA).

The notification sets out the following key matters:

Definitions

  • “Transfer of personal data” means any sending or transferring of personal data by a transferor of personal data, either by way of a physical transfer or a remote transfer through a computer system or an internet network to the recipient of the personal data. It does not include sending personal data through an intermediary by transiting between computer systems or internet networks, or any storing or retaining of personal data, either permanently or temporarily, by a cloud computing service provider, whereby the personal data transferor and the personal data recipient (1) are not making the order, (2) are not involved with any data selection or the content of the personal data sent and received through the computer systems or internet networks, or (3) have the purpose of entering into an agreement or any juristic act.
  • “Binding corporate rules” means the agreed terms or policy on personal data protection made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data within a group of corporations or companies.
  • “Standard contractual clauses” means the contractual terms made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data.
  • “Code of conduct” means a code that sets out the obligations of a personal data transferor and a personal data recipient outside of Thailand.
  • “Certification” means an undertaking in relation to safeguarding personal data, in order to establish appropriate personal data safeguarding measures.

Binding Corporate Rules

For cross-border transfers within a group of corporations or companies, binding corporate rules (BCRs) can be established and submitted to the PDPC for approval. The BCRs must adhere to the following minimum standards:

  • The effectiveness and legally binding nature of the BCRs apply to each company or entity within the group, including the data recipient, data processor, and data transferor, and the members belonging to the group, as well as their employees, staff, or persons related to the transfer or receipt of personal data within the group.
  • The BCRs must comply with Thai laws on personal data protection.
  • The BCRs must contain certification of data subject rights under the PDPA and sub-regulations.
  • The BCRs must contain measures on personal data protection in relation to personnel, processes, and security measures in accordance with the required technology standards for personal data protection.

Appropriate Safeguards

In accordance with section 29, paragraph 3, of the PDPA, a personal data transferor may transfer personal data to a recipient outside of Thailand when procuring appropriate safeguard measures by way of “standard contractual clauses,” “code of conduct,” or “certification.” Such appropriate safeguards must at least ensure the enforceability of the data subject’s rights and effective legal remedial actions, as provided in the annexes of the notification.

The appropriate safeguards must at least have the following:

  • Effectiveness and legal enforceability.
  • Compliance with Thai laws on personal data protection.
  • Certification of data subject rights under the PDPA and sub-regulations.
  • Measures on personal data protection in relation to personnel, process, and security measures in accordance with the required technology standards for personal data protection.

The standard contractual clauses must be filed with the PDPC. The appropriate safeguard measures must be enforceable under Thai law, and they must provide data subject rights under Thai law. Such rights must also be enforceable and provide remedial rights for data subjects as stipulated under Thai law.

The notification also sets out standard contractual clauses for controller-to-controller and controller-to-processor international transfers. The clauses primarily stipulate the obligations of the transferor and the recipient, recognize the enforceability of the PDPA provisions on personal data protection, and ensure the ability of data subjects to exercise their rights (in the form of third-party rights).

For more information from Tilleke & Gibbins’ data privacy team regarding the draft notification, or any aspect of compliance with PDPA requirements, please contact Athistha (Nop) Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Gvavalin Mahakunkitchareon at [email protected], or Thammapas Chanpanich at [email protected].

RELATED INSIGHTS​ 

December 4, 2024
On October 28, 2024, Indonesia officially amended its existing Patent Law when the president ratified Law Number 65 of 2024. This comprehensive update—the third such amendment in the history of Indonesia’s Patent Law—introduces several key changes that will significantly impact patent protection and application processes in Indonesia. Key highlights and changes are outlined below. Definition of Invention The new law broadens the definition of “invention” to explicitly include systems, methods, and uses. Additionally, the law introduces formal definitions for traditional knowledge and genetic resources. Patentability Criteria Notable changes include: Computer programs are now excluded, with an exception for computer-implemented inventions. Theories and methods in science and mathematics are added to the list of excluded inventions. Previous restrictions on new uses of existing products are removed. Grace Periods The grace periods for some patent-related actions have been adjusted: The grace period for disclosures has been extended to 12 months (from 6 months previously), providing inventors with more flexibility in filing patent applications after initial disclosure. A newly introduced item is the grace period for a conventional patent application claiming priority rights, which is 4 months after the 12-month filing deadline under the Paris Convention. The grace period for annuity payments is 6 months (from 12 months previously) with a fine for late payments of 100% of the annual fee payable. Patent Holder Rights and Obligations Patent holders can now grant permissions to enforce patents. There is a new requirement for patent holders to submit annual statements on patent implementation in Indonesia. Compulsory Licensing Significant changes to compulsory licensing include: Establishment of licenses based on the principle of expediency. Limitations on license scope and transferability. Prioritization of domestic market needs. New provisions for technical improvements and economic significance. Government Patent Exploitation The new law contains specific provisions for the government’s implementation
December 4, 2024
Thailand Legal Basics, a valuable primer for foreign investors, explores all aspects of living and doing business in Thailand. Written by specialists at Tilleke & Gibbins in Bangkok, it is the only comprehensive English-language guide to the Thai legal system with a focus on the concerns of foreign business and investment.
November 25, 2024
Thailand has released the set of principles that will form the official draft Platform Economy Act (PEA) for a public hearing period that runs until December 15, 2024. The PEA is likely to be positioned as a general or overarching law for digital intermediary services and digital platform service businesses. In January 2024, an early, unofficial version of the proposed law had been circulated among a limited group of operators in certain industries to get comments for the working group charged with the PEA’s development. Now, however, the proposed principles that will underpin the official draft PEA have been released publicly to gather comments, feedback, and suggestions from any interested stakeholders. The principles of the draft PEA cover two main areas: user protection and fair competition. The key details in these two areas are outlined below. User Protection The main regulator supervising the law’s user protection elements will be the Electronic Transactions Development Agency (ETDA). The draft PEA is expected to impose user protection obligations on service providers based on their nature, size, and risk level. The principles set out a three-tiered classification system for service providers that will be covered under the draft PEA, as detailed below, ordered from fewest obligations to most: Intermediary Service Provider: This describes a service provider acting as an intermediary between a sender and recipient of information on a computer network, the internet, or a telecommunications network. Service providers likely to fall under this category include cloud service providers and web hosting providers. Intermediary service providers may be further categorized into the following subtypes: Mere conduit service providers; Caching service providers; Hosting service providers; and Other service providers as prescribed in ministerial regulations. Online Platform: This refers to an intermediary service provider offering data storage services that connect various types of users to
November 15, 2024
Vietnam’s new Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (“Decree 147”), which will come into effect on December 25, 2024, replacing Decree No. 72/2013/ND-CP (“Decree 72”), introduces several changes to the regime for domain name dispute resolution. The new decree aims to clarify the legal framework and address some longstanding inconsistencies between Vietnam’s laws on intellectual property and information technology. The main changes related to domain name dispute resolution under Decree 147 are summarized below. Removal of Prescriptive Actions Decree 147 no longer lists specific actions for resolving domain name disputes. Decree 72 had outlined three methods: negotiation/mediation, arbitration, and court. However, IP practitioners had long criticized this approach, arguing it conflicted with the IP Law, which additionally allows administrative action. By omitting these methods, the new decree implies an acceptance of administrative action as provided in the IP Law. However, Decree 147 remains silent on establishing a dispute resolution forum aligned with the CPTPP’s requirement for a UDRP-like model. Currently, Vietnam’s available forums do not fully conform to the UDRP framework. An anticipated circular may provide further guidance on this aspect. Deactivation of Domain Names Decree 72 does not have any provision on the deactivation of a domain name. However, Decree 147 has stipulated some situations where domain names will be deactivated, such as when there is a request from an authority, or when it is discovered that incorrect information was used for registration. Clearer Criteria for Dispute Resolution Article 16 of Decree 147 sets out three clear criteria that must be met for domain name dispute resolution to proceed: (i) confusing similarity with the plaintiff’s trademark, trade name, or personal name; (ii) the defendant’s lack of legitimate rights or interests in the domain name; and (iii) bad faith. Previously,