You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 1, 2022

Thailand: Operationalising PDPA – Lawful Basis, Sensitive Personal Data, and Data Processing Safeguards

OneTrust DataGuidance

Background

Thailand’s Personal Data Protection Act 2019 (‘PDPA’) is the country’s first unified data privacy legislation for personal data protection. Coming at a time when people around the world are increasingly aware of the risks and negative consequences of their personal data being compromised, the PDPA seeks to align with international standards, such as the General Data Protection Regulation (Regulation (EU) 2016/679) (‘GDPR’).

Prior to the enactment of the PDPA, privacy rights were recognised in the Constitution of the Kingdom of Thailand. Beyond this, the handling of personal data was governed by specific regulations for a handful of sectors, such as telecommunications, financial institutions, securities, and life sciences.

The PDPA was announced in the Royal Gazette of the Kingdom of Thailand on 27 May 2019, with an exemption for the enforcement of its requirements in relation to the collection, use, disclosure, and transfer (‘process’ or ‘processing’) of personal data, as well as its provisions on data subjects rights. After some delays caused by the impact of the COVID-19 pandemic over the past two years, the PDPA finally came fully into force on 1 June 2022.

Unlike most legislation in Thailand, the PDPA has an extraterritorial aspect whereby data controllers and data processors outside Thailand may be subject to the PDPA if the processing activities they undertake fall under the criteria prescribed in the PDPA.

The basics

The PDPA defines personal data as any data pertaining to a living natural person that enables the identification of that person, whether directly or indirectly, such as phone number, address, email address, or anything else that might enable the data subject’s identification. The PDPA applies to personal data in any form, whether digital or otherwise.

The PDPA introduces two main roles relating to the handling of others’ personal data: the data controller and the data processor. A data controller is a person or entity with power to make decisions regarding the collection, use, and disclosure of personal data. A data processor is a person or entity that collects, uses, or discloses personal data on behalf of, or under the instructions of, the data controller. The data controller carries significant liability and obligations, while the data processor’s obligations and liabilities are very limited in comparison. The data processor only needs to process personal data in accordance with instructions from the data controller, while the data controller has to establish a lawful basis for the processing of personal data (e.g. request consent from the data subject) and notify the relevant data subjects about the processing.

Lawful basis

Similar to the EU’s GDPR, the key obligation for the processing of personal data under the PDPA is the lawful basis requirement. Under the PDPA, the data controller must obtain consent for the processing of personal data from the data controller, unless the processing activity can rely on other lawful bases, such as when the personal information is for educational, research, or statistics collection purposes (provided appropriate personal data protection measures are in place), or when it helps to prevent danger to a person’s life, body, or health. Also, certain contractual obligations do not require further consent. For instance, an agreement to sell goods and deliver them to various locations or email addresses would not need consent for handling each separate delivery address or email.

In addition, there is an exemption covering the ‘legitimate interest’ of the data controller or a third party. When the data controller wishes to rely on legitimate interest for processing personal data, the data controller must balance its own or another party’s legitimate interest with the need to uphold the fundamental rights and freedoms of data subjects.

When the processing of personal data needs to rely on consent as a lawful basis, the consent must be requested in accordance with the conditions prescribed in the PDPA. The consent must be requested before or at the time of collection of personal data, in writing or electronic form, and using clear and pain language. Moreover, it cannot be deceptive or cause the data subject to misunderstand.

Sensitive personal data

The PDPA also provides more protection to certain types of sensitive personal data by placing more restrictions on the processing of such sensitive personal data, which includes personal data pertaining to race, ethnic origin, political opinions, disability, creed, religious or philosophical beliefs, sexual behaviour, and criminal records, as well as health data, trade union information, genetic data, and biometric data. This list is not fixed, as the regulator under the PDPA, the Personal Data Protection Committee (‘PDPC’), may further identify other types of sensitive personal data in the future.

To process sensitive personal data, the data controller must obtain explicit consent from the data subject, unless the processing activity can rely on other lawful bases. The exemptions for the explicit consent requirement or other lawful bases that the data controller could rely on are very limited; they are not the same as the exemptions for the consent requirement for general personal data. Examples of the explicit consent exemption include that the processing of sensitive personal data is:

  • conducted to prevent danger to a person’s life, body, or health;
  • necessary for the establishment, compliance, exercise, or defence of legal claims; or
  • necessary for compliance with a law to achieve the purposes with respect to specific matters, including labour protection.

Appropriate safeguards for processing data

The PDPA also prescribes obligations for the data controller to comply with, when processing personal data. Their first obligation is to ensure that, throughout its processing, the personal data remains correct, up-to-date, complete, and not misleading. In terms of security and maintenance, the data controller must implement suitable measures to prevent the loss, unauthorised access, alteration, or disclosure of personal data. These measures must be reviewed whenever necessary, such as after the implementation of technological developments. The data must be recorded in a form – either written or electronic – that can be inspected by the data subject or an authorised party. When the storage period expires, the personal data is no longer relevant or exceeds the scope of necessity, or the consent is withdrawn, the data controller is also responsible for seeing that the personal data is erased.

When a data controller discloses or shares personal data with other persons, it must also implement measures to prevent unauthorised use and disclosure. If the data controller engages a data processor to do this upon its instructions, a data processing agreement must also be in place to ensure that the data processor will comply with the PDPA and the data controller’s instructions.

Furthermore, when personal data is to be transferred overseas, the data controller must ensure that the destination country has adequate personal data protection standards. If these standards are not adequate, the data controller may need to apply additional safeguards to personal data when it is transferred to the foreign country.

Conclusion and outlook

Some of the PDPA’s many new requirements and rules for the processing of personal data will become more precise with further clarifications from the PDPC. This process may affect data controllers and data processors – both abroad and in Thailand – and bring new understandings of how best to comply with the law. Business operators in Thailand and outside the country therefore need to stay informed about the enforcement of the PDPA and be prepared to adjust their compliance strategies accordingly.

Despite the challenges of adjusting to new regulatory requirements, businesses will likely find that the PDPA enables them to conduct their personal data-related operations more smoothly and according to internationally accepted standards.

 

This article was first published by OneTrust DataGuidance as part four of their “Operationalising PDPA” series. To view the original and browse other articles in the series, please visit the OneTrust DataGuidance website.

RELATED INSIGHTS​ 

July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 21, 2026
Thailand’s Ministry of Digital Economy and Society (MDES) published a notification establishing an expedited court-ordered takedown mechanism for online content in cases of “urgent necessity.” The notification, which was issued on July 17, 2026, under the Computer Crime Act B.E. 2550 (2007), as amended, took effect the following day. It significantly expands the categories of content subject to rapid government-initiated removal. Content Categories Subject to Takedown The notification defines “urgent necessity” (section 20, paragraph 5, of the Computer Crime Act) as circumstances where any delay in suppressing computer data may impact national security, religion, the monarchy, good morals, social culture, or public order. In this regard, it establishes four broad categories of content: Computer Crime Act offenses. National security offenses. IP and other criminal offenses, where it is contrary to public order or good morals and a competent officer has requested its suppression. Content contrary to public order or good morals, a broad residual category encompassing 14 subcategories approved by the Computer Data Screening Committee. The fourth category is the most expansive. Its 14 subcategories include: Content defaming, mocking, satirizing, or devaluing the monarchy. Online gambling advertising or facilitation. Offering illegal firearms for sale. Offering baraku (hookah) products or e-cigarettes for sale. Offering cannabis inflorescences or processed cannabis products for sale. Advertising or soliciting prostitution. Content inciting violence, hatred, or social division. Unauthorized overseas employment advertising. Offering boiled kratom juice for sale. Online sale or advertising of alcoholic beverages. Content satirizing or degrading Buddhism. Money lending at interest rates exceeding legally prescribed limits. Advertising or disseminating information about surrogacy services. Forgery of documents, cards, or official documents. Enforcement Procedure In cases of urgent necessity, a competent official assigned by the MDES permanent secretary must file a petition with supporting evidence to the court with jurisdiction, requesting an order to
July 20, 2026
On July 16, 2026, Thailand’s Personal Data Protection Committee (PDPC) published a notification in the Government Gazette establishing detailed rules governing data subjects’ right of access under section 30 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notification will take effect 60 days after publication—mid-September 2026—giving data controllers a limited window to bring their processes into compliance. Scope The notification covers requests to access or obtain copies of personal data and requests for disclosure of the source of data collected without consent. Data subjects may exercise their rights directly or through authorized representatives. Key Requirements Important requirements set by the notification include the following: Required request channels. Controllers must provide at least two request channels: direct submission at the business location and registered mail. Electronic channels are optional but, if offered, may also be used for fulfilling requests. Request contents. Requests must be in writing or in electronic form and include the data subject’s name, the preferred access method, details of the data requested, and the requester’s signature. Controllers may request additional identifying information as needed. Identity and authority verification. Controllers may require official identity documents for verification. Authorized representatives must provide authorization documents and identity documents for both the data subject and the representative. Alternative verification methods (e.g., digital authentication) are permitted if they do not unreasonably obstruct data subjects’ rights. Review and response timelines. Controllers must review requests within 15 days. If the request is incomplete, the controller must notify the requester and allow at least 15 days to correct deficiencies. If not corrected, the request may be treated as abandoned. Once verified, controllers must fulfill requests within 30 days, extendable by another 30 days for large-volume or complex requests with notice to the requester. Methods for providing access or copies. Controllers may fulfill
July 16, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) published a series of draft guidance documents for public consultation on July 7, 2026. Issued under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), the drafts address a range of compliance issues and offer insight into the regulator’s current enforcement priorities. This article examines two of those drafts: one on lawful bases for processing personal data, and another on marketing and direct marketing. Together, they reflect the Office of the PDPC’s evolving expectations on lawful-basis selection, accountability, and the use of personal data in marketing. Organizations operating in Thailand should assess the practical implications now, before the guidance is finalized. Lawful Bases: A Structured Selection Process The draft guidance on lawful bases introduces a systematic five-step process for selecting an appropriate lawful basis for each processing activity. Organizations are expected to: Identify the processing activity involved. Assess the appropriate lawful basis. Evaluate whether the data is necessary for the processing. Conduct a legitimate interest assessment (LIA) where applicable. Ensure transparency through privacy notices. The guidance provides practical explanations and examples for each lawful basis under section 24 of the PDPA—including archiving, research, statistics, vital interests, contractual necessity, legal obligation, public task, legitimate interests, and consent—as well as the bases applicable to sensitive personal data under section 26. The aim is to promote more consistent and accurate lawful-basis selection across public- and private-sector organizations. A recurring theme throughout the guidance is that organizations should select the lawful basis that most accurately reflects the actual purpose and circumstances of the processing activity. The guidance cautions against treating consent as a default or catch-all basis where another lawful basis is more appropriate. For processing based on legitimate interests, organizations should conduct and document an LIA. Processing involving sensitive personal data may require