You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 1, 2022

Thailand: Operationalising PDPA – Lawful Basis, Sensitive Personal Data, and Data Processing Safeguards

OneTrust DataGuidance

Background

Thailand’s Personal Data Protection Act 2019 (‘PDPA’) is the country’s first unified data privacy legislation for personal data protection. Coming at a time when people around the world are increasingly aware of the risks and negative consequences of their personal data being compromised, the PDPA seeks to align with international standards, such as the General Data Protection Regulation (Regulation (EU) 2016/679) (‘GDPR’).

Prior to the enactment of the PDPA, privacy rights were recognised in the Constitution of the Kingdom of Thailand. Beyond this, the handling of personal data was governed by specific regulations for a handful of sectors, such as telecommunications, financial institutions, securities, and life sciences.

The PDPA was announced in the Royal Gazette of the Kingdom of Thailand on 27 May 2019, with an exemption for the enforcement of its requirements in relation to the collection, use, disclosure, and transfer (‘process’ or ‘processing’) of personal data, as well as its provisions on data subjects rights. After some delays caused by the impact of the COVID-19 pandemic over the past two years, the PDPA finally came fully into force on 1 June 2022.

Unlike most legislation in Thailand, the PDPA has an extraterritorial aspect whereby data controllers and data processors outside Thailand may be subject to the PDPA if the processing activities they undertake fall under the criteria prescribed in the PDPA.

The basics

The PDPA defines personal data as any data pertaining to a living natural person that enables the identification of that person, whether directly or indirectly, such as phone number, address, email address, or anything else that might enable the data subject’s identification. The PDPA applies to personal data in any form, whether digital or otherwise.

The PDPA introduces two main roles relating to the handling of others’ personal data: the data controller and the data processor. A data controller is a person or entity with power to make decisions regarding the collection, use, and disclosure of personal data. A data processor is a person or entity that collects, uses, or discloses personal data on behalf of, or under the instructions of, the data controller. The data controller carries significant liability and obligations, while the data processor’s obligations and liabilities are very limited in comparison. The data processor only needs to process personal data in accordance with instructions from the data controller, while the data controller has to establish a lawful basis for the processing of personal data (e.g. request consent from the data subject) and notify the relevant data subjects about the processing.

Lawful basis

Similar to the EU’s GDPR, the key obligation for the processing of personal data under the PDPA is the lawful basis requirement. Under the PDPA, the data controller must obtain consent for the processing of personal data from the data controller, unless the processing activity can rely on other lawful bases, such as when the personal information is for educational, research, or statistics collection purposes (provided appropriate personal data protection measures are in place), or when it helps to prevent danger to a person’s life, body, or health. Also, certain contractual obligations do not require further consent. For instance, an agreement to sell goods and deliver them to various locations or email addresses would not need consent for handling each separate delivery address or email.

In addition, there is an exemption covering the ‘legitimate interest’ of the data controller or a third party. When the data controller wishes to rely on legitimate interest for processing personal data, the data controller must balance its own or another party’s legitimate interest with the need to uphold the fundamental rights and freedoms of data subjects.

When the processing of personal data needs to rely on consent as a lawful basis, the consent must be requested in accordance with the conditions prescribed in the PDPA. The consent must be requested before or at the time of collection of personal data, in writing or electronic form, and using clear and pain language. Moreover, it cannot be deceptive or cause the data subject to misunderstand.

Sensitive personal data

The PDPA also provides more protection to certain types of sensitive personal data by placing more restrictions on the processing of such sensitive personal data, which includes personal data pertaining to race, ethnic origin, political opinions, disability, creed, religious or philosophical beliefs, sexual behaviour, and criminal records, as well as health data, trade union information, genetic data, and biometric data. This list is not fixed, as the regulator under the PDPA, the Personal Data Protection Committee (‘PDPC’), may further identify other types of sensitive personal data in the future.

To process sensitive personal data, the data controller must obtain explicit consent from the data subject, unless the processing activity can rely on other lawful bases. The exemptions for the explicit consent requirement or other lawful bases that the data controller could rely on are very limited; they are not the same as the exemptions for the consent requirement for general personal data. Examples of the explicit consent exemption include that the processing of sensitive personal data is:

  • conducted to prevent danger to a person’s life, body, or health;
  • necessary for the establishment, compliance, exercise, or defence of legal claims; or
  • necessary for compliance with a law to achieve the purposes with respect to specific matters, including labour protection.

Appropriate safeguards for processing data

The PDPA also prescribes obligations for the data controller to comply with, when processing personal data. Their first obligation is to ensure that, throughout its processing, the personal data remains correct, up-to-date, complete, and not misleading. In terms of security and maintenance, the data controller must implement suitable measures to prevent the loss, unauthorised access, alteration, or disclosure of personal data. These measures must be reviewed whenever necessary, such as after the implementation of technological developments. The data must be recorded in a form – either written or electronic – that can be inspected by the data subject or an authorised party. When the storage period expires, the personal data is no longer relevant or exceeds the scope of necessity, or the consent is withdrawn, the data controller is also responsible for seeing that the personal data is erased.

When a data controller discloses or shares personal data with other persons, it must also implement measures to prevent unauthorised use and disclosure. If the data controller engages a data processor to do this upon its instructions, a data processing agreement must also be in place to ensure that the data processor will comply with the PDPA and the data controller’s instructions.

Furthermore, when personal data is to be transferred overseas, the data controller must ensure that the destination country has adequate personal data protection standards. If these standards are not adequate, the data controller may need to apply additional safeguards to personal data when it is transferred to the foreign country.

Conclusion and outlook

Some of the PDPA’s many new requirements and rules for the processing of personal data will become more precise with further clarifications from the PDPC. This process may affect data controllers and data processors – both abroad and in Thailand – and bring new understandings of how best to comply with the law. Business operators in Thailand and outside the country therefore need to stay informed about the enforcement of the PDPA and be prepared to adjust their compliance strategies accordingly.

Despite the challenges of adjusting to new regulatory requirements, businesses will likely find that the PDPA enables them to conduct their personal data-related operations more smoothly and according to internationally accepted standards.

 

This article was first published by OneTrust DataGuidance as part four of their “Operationalising PDPA” series. To view the original and browse other articles in the series, please visit the OneTrust DataGuidance website.

RELATED INSIGHTS​ 

April 10, 2025
After making revisions to the initial draft notification released in November 2024, Thailand’s Electronic Transactions Development Agency (ETDA) has released an updated draft Notification on Additional Obligations for Digital Platform Service Operators of Online Marketplaces for Goods with Specific Characteristics under Section 18(2) of the Royal Decree on the Operation of Digital Platform Service Businesses Subject to Prior Notification B.E. 2565 (2022) B.E. … . A focus group session was also held to gather feedback from business operators. Below is a summary of key provisions in the new draft. Unchanged Items Some key concerns that remain unchanged from the previous version of the draft notification include the following: Offshore business operators running online marketplaces that act as intermediaries for the sale or exchange of goods and provide facility services for the sale of goods (referred to as “specific marketplace operators” in the draft) are required to establish a local entity in Thailand. However, the criteria for determining which operators are specific marketplace operators are still under discussion due to feedback from business operators. Specific marketplace operators must submit a compliance report to the ETDA along with their annual report each year. Specific marketplace operators must verify that “business users” (e.g., merchants) provide complete details about goods in accordance with product standardization requirements. Removed Obligations The updated draft notification has removed specific marketplace operators’ obligations to: Conduct Identity Assurance Level 2 (IAL2) verification of business users before onboarding them on their platforms. Submit a registry of business users’ information to the ETDA. Retain business users’ information for a specified retention period. Implement measures to filter reviews of products subject to specific standards. Revisions Key revisions made to the draft notification include the following: The effective date has been extended to 120 days after the notification’s publication in the Government Gazette,
March 18, 2025
On February 6, 2025, the prime minister of Vietnam, Pham Minh Chinh, chaired an online meeting to review the progress of Vietnam’s digital transformation agenda. The meeting assessed achievements under the National Digital Transformation Program and Project 06 on the development and application of population data, electronic identification, and authentication for national digital transformation for the period 2022-2025, with a vision to 2030, approved by the prime minister in 2022. The meeting also outlined key legislative and regulatory priorities for 2025, as set forth in Notice No. 56/TB-BPCP issued by the Government Office on February 23, 2025 (Notice 56). One of the central focuses of the 2025 digital transformation agenda is the development and issuance of laws and regulations governing digital technology, data management, and cybersecurity. Below are the key legal developments provided in Notice 56 that stakeholders should anticipate in the coming months. 1. Law on Digital Technology Industry The Ministry of Information and Communications (MIC) has been tasked with finalizing the draft Law on Digital Technology Industry (DTI Law) for submission to the National Assembly at its 9th session in May 2025. This law is expected to establish a comprehensive legal framework for the digital technology sector, addressing regulatory gaps in emerging fields such as artificial intelligence (AI), Internet of Things (IoT), cloud computing, big data and platform services to promote innovation, ensure data security, and support the growth of the digital economy in Vietnam. Concurrently, the MIC will expedite the issuance of guiding decrees to ensure the swift implementation of the DTI Law once enacted. 2. Law on Personal Data Protection and regulations guiding implementation of Data Law The Ministry of Public Security (MPS) is making efforts to finalize the long-anticipated Law on Personal Data Protection (PDPL)—data protection is currently governed by Decree No. 13/2023/ND-CP on
March 17, 2025
Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to Data Protection and Cybersecurity Regulation in Southeast Asia, a wide-ranging guide published by Drew Network Asia (DNA). The resource provides a comprehensive overview of data protection and cybersecurity laws across the region, offering practical insight into compliance requirements and regulatory developments affecting organizations that handle personal data or operate digital services in Southeast Asia. The guide begins with a regional overview, including the broader ASEAN context and cooperation initiatives. Jurisdiction-specific chapters follow a consistent structure—covering data privacy and governance obligations, security requirements and breach notification, outsourcing and cross-border data transfers, and broader accountability and compliance measures. This format allows readers to compare regulatory approaches across markets such as Brunei, Indonesia, Malaysia, the Philippines, Singapore, and others. In addition to the country chapters, the publication addresses cybersecurity and privacy engineering challenges, providing guidance for organizations and outlining obligations applicable to data controllers, processors, and intermediaries. A dedicated section on data breach management across ASEAN examines notification requirements, response considerations, and practical steps for managing incidents in a regional or global context. The guide is intended to serve as a practical reference, and the authors note that specific legal requirements may vary depending on sector, processing activity, or evolving legislation. Readers seeking more detailed advice can contact the practitioners listed in each chapter. The full guide is available for download using the button below or directly from the DNA website.
March 13, 2025
Vietnam’s Ministry of Finance has released a draft Decree on Tax Administration for E-Commerce and Digital Platforms (“Draft Decree”), introducing significant tax compliance obligations that could reshape how digital platforms, and individuals and business households conducting business through the platforms, manage their tax responsibilities. Aimed at strengthening tax enforcement, the Draft Decree requires e-commerce and digital platforms to actively track and withhold taxes from business households and individual sellers, and remit payments to tax authorities. While it has not yet been promulgated, the Draft Decree is expected to take effect on April 1, 2025, leaving platforms with a limited window to prepare for compliance. Who Is Affected by the New Tax Rules? The Draft Decree significantly broadens the tax administration scope beyond traditional e-commerce platforms to cover a wide range of digital economy participants. Specifically, the Draft Decree places direct tax-related responsibilities on two major categories (collectively, “Regulated Operators”): E-commerce and digital platforms with payment functions (e.g., platforms that process buyer payments via e-wallets, bank transfers, cards, or cash-on-delivery); and Other digital-economy players that enable e-commerce transactions, including (i) intermediary service platforms connecting service providers with consumers, (ii) digital content platforms, (iii) online advertising providers, (iv) cloud computing and data storage providers, (v) social media platforms engaged in business activities (e.g., live-stream, in-app transactions), (vi) online education, gaming, and digital entertainment platforms generating revenue from digital transactions, (vii) Vietnam-based partners of foreign digital service providers facilitating local payments for overseas platforms, and (viii) intermediary payment service providers handling financial transactions for e-commerce activities. Under the Draft Decree, Regulated Operators will be required to track, report, and enforce tax compliance for both resident and nonresident individuals and households conducting business through their platforms (“Sellers”). What New Tax Obligations Do Platforms Face? Onshore platforms For the first time, Regulated Operators will