You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 1, 2022

Thailand: Operationalising PDPA – Lawful Basis, Sensitive Personal Data, and Data Processing Safeguards

OneTrust DataGuidance

Background

Thailand’s Personal Data Protection Act 2019 (‘PDPA’) is the country’s first unified data privacy legislation for personal data protection. Coming at a time when people around the world are increasingly aware of the risks and negative consequences of their personal data being compromised, the PDPA seeks to align with international standards, such as the General Data Protection Regulation (Regulation (EU) 2016/679) (‘GDPR’).

Prior to the enactment of the PDPA, privacy rights were recognised in the Constitution of the Kingdom of Thailand. Beyond this, the handling of personal data was governed by specific regulations for a handful of sectors, such as telecommunications, financial institutions, securities, and life sciences.

The PDPA was announced in the Royal Gazette of the Kingdom of Thailand on 27 May 2019, with an exemption for the enforcement of its requirements in relation to the collection, use, disclosure, and transfer (‘process’ or ‘processing’) of personal data, as well as its provisions on data subjects rights. After some delays caused by the impact of the COVID-19 pandemic over the past two years, the PDPA finally came fully into force on 1 June 2022.

Unlike most legislation in Thailand, the PDPA has an extraterritorial aspect whereby data controllers and data processors outside Thailand may be subject to the PDPA if the processing activities they undertake fall under the criteria prescribed in the PDPA.

The basics

The PDPA defines personal data as any data pertaining to a living natural person that enables the identification of that person, whether directly or indirectly, such as phone number, address, email address, or anything else that might enable the data subject’s identification. The PDPA applies to personal data in any form, whether digital or otherwise.

The PDPA introduces two main roles relating to the handling of others’ personal data: the data controller and the data processor. A data controller is a person or entity with power to make decisions regarding the collection, use, and disclosure of personal data. A data processor is a person or entity that collects, uses, or discloses personal data on behalf of, or under the instructions of, the data controller. The data controller carries significant liability and obligations, while the data processor’s obligations and liabilities are very limited in comparison. The data processor only needs to process personal data in accordance with instructions from the data controller, while the data controller has to establish a lawful basis for the processing of personal data (e.g. request consent from the data subject) and notify the relevant data subjects about the processing.

Lawful basis

Similar to the EU’s GDPR, the key obligation for the processing of personal data under the PDPA is the lawful basis requirement. Under the PDPA, the data controller must obtain consent for the processing of personal data from the data controller, unless the processing activity can rely on other lawful bases, such as when the personal information is for educational, research, or statistics collection purposes (provided appropriate personal data protection measures are in place), or when it helps to prevent danger to a person’s life, body, or health. Also, certain contractual obligations do not require further consent. For instance, an agreement to sell goods and deliver them to various locations or email addresses would not need consent for handling each separate delivery address or email.

In addition, there is an exemption covering the ‘legitimate interest’ of the data controller or a third party. When the data controller wishes to rely on legitimate interest for processing personal data, the data controller must balance its own or another party’s legitimate interest with the need to uphold the fundamental rights and freedoms of data subjects.

When the processing of personal data needs to rely on consent as a lawful basis, the consent must be requested in accordance with the conditions prescribed in the PDPA. The consent must be requested before or at the time of collection of personal data, in writing or electronic form, and using clear and pain language. Moreover, it cannot be deceptive or cause the data subject to misunderstand.

Sensitive personal data

The PDPA also provides more protection to certain types of sensitive personal data by placing more restrictions on the processing of such sensitive personal data, which includes personal data pertaining to race, ethnic origin, political opinions, disability, creed, religious or philosophical beliefs, sexual behaviour, and criminal records, as well as health data, trade union information, genetic data, and biometric data. This list is not fixed, as the regulator under the PDPA, the Personal Data Protection Committee (‘PDPC’), may further identify other types of sensitive personal data in the future.

To process sensitive personal data, the data controller must obtain explicit consent from the data subject, unless the processing activity can rely on other lawful bases. The exemptions for the explicit consent requirement or other lawful bases that the data controller could rely on are very limited; they are not the same as the exemptions for the consent requirement for general personal data. Examples of the explicit consent exemption include that the processing of sensitive personal data is:

  • conducted to prevent danger to a person’s life, body, or health;
  • necessary for the establishment, compliance, exercise, or defence of legal claims; or
  • necessary for compliance with a law to achieve the purposes with respect to specific matters, including labour protection.

Appropriate safeguards for processing data

The PDPA also prescribes obligations for the data controller to comply with, when processing personal data. Their first obligation is to ensure that, throughout its processing, the personal data remains correct, up-to-date, complete, and not misleading. In terms of security and maintenance, the data controller must implement suitable measures to prevent the loss, unauthorised access, alteration, or disclosure of personal data. These measures must be reviewed whenever necessary, such as after the implementation of technological developments. The data must be recorded in a form – either written or electronic – that can be inspected by the data subject or an authorised party. When the storage period expires, the personal data is no longer relevant or exceeds the scope of necessity, or the consent is withdrawn, the data controller is also responsible for seeing that the personal data is erased.

When a data controller discloses or shares personal data with other persons, it must also implement measures to prevent unauthorised use and disclosure. If the data controller engages a data processor to do this upon its instructions, a data processing agreement must also be in place to ensure that the data processor will comply with the PDPA and the data controller’s instructions.

Furthermore, when personal data is to be transferred overseas, the data controller must ensure that the destination country has adequate personal data protection standards. If these standards are not adequate, the data controller may need to apply additional safeguards to personal data when it is transferred to the foreign country.

Conclusion and outlook

Some of the PDPA’s many new requirements and rules for the processing of personal data will become more precise with further clarifications from the PDPC. This process may affect data controllers and data processors – both abroad and in Thailand – and bring new understandings of how best to comply with the law. Business operators in Thailand and outside the country therefore need to stay informed about the enforcement of the PDPA and be prepared to adjust their compliance strategies accordingly.

Despite the challenges of adjusting to new regulatory requirements, businesses will likely find that the PDPA enables them to conduct their personal data-related operations more smoothly and according to internationally accepted standards.

 

This article was first published by OneTrust DataGuidance as part four of their “Operationalising PDPA” series. To view the original and browse other articles in the series, please visit the OneTrust DataGuidance website.

RELATED INSIGHTS​ 

December 24, 2024
On November 30, 2024, the Data Law was officially promulgated after an accelerated preparation process that began in February 2024. The Data Law is set to take effect on July 1, 2025. Having extraterritorial effect, the Data Law will impact both local and foreign individuals and enterprises. As noted in our previous legal update, the Data Law governs digital data, the National Data Center, the National General Database, digital data products and services, digital data management, and the rights, obligations, and responsibilities of agencies, organizations, and individuals related to digital data activities. This legal update provides an overview of the Data Law, with a deep focus on the key provisions likely to impact businesses operating or offering services in Vietnam. New Data Definition and Classification The Data Law broadly defines “digital data” as data about objects, phenomena, and events, which can include one or a combination of audio, images, numbers, text, or symbols represented in digital format (hereinafter referred to as “data”). This definition is very broad and potentially covers any information recorded or represented in digital forms, including personal and nonpersonal data (such as business data, transactional data, trade secrets, etc.). Data is further categorized into different types that can be used by public bodies. However, the rights and obligations associated with each type of data are not clearly addressed. The data classification criteria include: The nature of data sharing (shared data, private data, open data); The importance of data (core data, important data, and other data); Any other criteria to meet the requirements of data administration, processing, and protection, as determined by the data owner. While the Data Law requires private organizations to categorize data based on its level of importance, it still grants these organizations the right to categorize data based on other criteria. Cross-Border Data
December 12, 2024
Vietnam is a world leader in blockchain adoption and growth, appearing near the top of most rankings of cryptocurrency ownership and blockchain investment. Although the country has taken a cautious approach toward cryptocurrency (banning the use of cryptocurrencies like Bitcoin as a means of payment, for example), the government actively supports blockchain technology and its applications in non-financial sectors. Recognizing blockchain as a core technology of the Fourth Industrial Revolution, as a part of Vietnam’s broader digital transformation agenda, the government issued Decision No. 1236/QD-TTg on October 22, 2024, providing the National Strategy for Blockchain Application and Development to 2025, with Orientation to 2030. Like the National Strategy on Digital Infrastructure, the National Strategy on Blockchain outlines a very ambitious vision to position Vietnam as a regional leader in blockchain technology. The strategy aims for Vietnam to master and apply blockchain across all socio-economic sectors, supporting the nation’s goal of becoming a stable and prosperous digital nation by 2030. The specific goals set for 2025 include developing Vietnam’s blockchain infrastructure and ensuring compliance with cybersecurity and data protection laws; advancing blockchain research through three national innovation centers; building and upgrading 10 facilities dedicated to blockchain research and workforce training; and expanding blockchain education by integrating it into university programs. The strategy also aims to establish at least one blockchain center, special zone, or area, as a pilot, to build a national blockchain network; and foster a blockchain ecosystem by promoting its application across sectors such as banking and finance, transportation, healthcare, education and training, commerce, logistics, postal services, industrial production, energy, tourism, agriculture, public services, and more. The goals for 2030 include strengthening Vietnam’s national blockchain infrastructure to support both domestic and international services, positioning Vietnam as a global and regional leader in blockchain research, application, and development. The
December 11, 2024
On November 30, 2024, the National Assembly of Vietnam issued a new Law on Data (“Data Law”), the first of its kind in the country. Initiated by a legislative proposal in February 2024, the Data Law underwent an accelerated preparation process and was officially promulgated just nine months later. It is worth noting that the Data Law is not the same as the Personal Data Protection Law, which is still in draft form and is expected to be submitted to the National Assembly in November 2025. The scope of application of the Data Law is broader, including not only personal data but also other types of data. The Data Law governs digital data, the National Data Center, the National General Database, digital data products and services, digital data management, and the rights, obligations, and responsibilities of agencies, organizations, and individuals related to digital data activities. Set to take effect on July 1, 2025, the Data Law is expected to have a significant impact on businesses involved in data-processing activities. Below are some key takeaways from this pivotal legislation. Cross-Border Data Transfer and Processing The Data Law recognizes and protects the freedom of cross-border data transfer and processing, as well as the legitimate rights and interests of relevant agencies, organizations, and individuals. The government is assigned the responsibility to provide detailed regulations on cross-border data transfer and processing activities, including the transfer of offshore data into Vietnam. National Data Center Resolution No. 175/NQ-CP issued by the Vietnamese government in October 2023 set out ambitious goals for a new National Data Center, which will integrate and manage human-related data from the national database, databases of ministries and central and local authorities, and other databases. The National Data Center is expected to be a core platform to provide data-related services, support policy
December 11, 2024
Thailand has released a draft amended Electronic Transactions Act (ETA), which aims to overhaul the current version of the law from 2001 to correct its enforcement limitations and update the ETA to be consistent with current electronic transactions practice. The draft ETA is open for public comment until December 20, 2024. The draft ETA introduces a new supervisory scheme that (1) recognizes electronic transactions executed by both current and future technologies without having to enact regulations recognizing the technology, (2) replaces the licensing, registration, and notification scheme for electronic transaction service providers with a trust-mark scheme, and (3) introduces a new mechanism to regulate electronic transaction service providers. The major amendments under the draft ETA address: Relationship with other relevant laws. The draft ETA is designated as the primary law governing electronic transactions, whether between private parties or between private parties and the state. However, if specific laws—including those on electronic administrative procedures—prescribe methods for conducting particular electronic transactions, those laws will prevail. Definitions. The draft ETA revises some existing terms, such as “transaction,” which is now more clearly defined as “any act relating to civil or commercial activities, including administrative procedures, administrative contracts, and any other actions by government agencies or officials.” It also introduces new definitions, such as “biometric data,” “automated system,” and “electronic seal.” Electronic transaction reliability. The draft ETA now clearly provides that electronic transactions executed using a method or an electronic method stipulated by the Electronic Transactions Development Agency (ETDA) as reliable are themselves presumed to be “reliable.” In case of a challenge over the implementation of a certified method or certified service, the challenging party bears the burden of proof and related expenses. Electronic transferable instruments. The draft ETA adopts the UNCITRAL Model Law on Electronic Transferable Records (ETRs) in recognizing ETRs (e.g.,