You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2024

Thailand Prepares Criteria for Personal Data Deletion, Destruction, and De-identification

On June 14, 2024, the Personal Data Protection Committee (PDPC) released a draft notification under the Personal Data Protection Act 2019 (PDPA), setting out criteria for how data controllers must delete, destroy, and de-identify personal data.

According to the PDPA, a data subject can request that a data controller delete, destroy, or de-identify their personal data in any of the following circumstances:

  • The personal data is no longer necessary for the purposes for which it was collected, used, or disclosed.
  • The data subject has withdrawn their consent for the processing of the personal data, and no other lawful basis for processing remains.
  • The data subject has objected to the processing of their personal data on grounds of legitimate interests or official tasks, the data controller has no other compelling grounds to refuse the request, and the data is not needed for legal claims.
  • The data subject objects to the processing of their personal data for direct marketing purposes.
  • The processing of personal data is unlawful.

The draft stipulates that data controllers respond to a data subject’s request to delete, destroy, or de-identify personal data immediately, and within 60 days of receiving the request. If the data controller cannot fulfill the request immediately, they must take interim measures to ensure that the personal data is made difficult to collect, use, or disclose. This includes implementing measures such as preventing access to the data and applying appropriate security measures to protect the data from unauthorized use or disclosure.

De-identification or Anonymization of Personal Data

In certain circumstances, a data controller may opt to de-identify or anonymize personal data, rather than delete or destroy it. If doing so, the data controller must satisfy the following criteria:

  • There must be a structured process to remove or eliminate all direct identifiers linked to the data subject, such as names, identification numbers, personal email addresses, biometric data, and so on.
  • Additional measures must be implemented to ensure that this data cannot indirectly identify the data subject.  The risk of identifying the data subject must be sufficiently low in order to prevent the re-identification of personal data with the data subject. The data controller may consider pseudonymizing the data or carrying out any action toward the data, whether in whole or in part, that would result in the risk of a data subject being identified by indirect identifiers (such as date of birth, IP address, age, position, etc.) being reduced.

De-identification or anonymization is not permitted when a data subject exercises their right of erasure specifically because their personal data has been unlawfully processed by the data controller. In such cases, the data must be fully deleted or destroyed to comply with the data subject’s request.

The draft PDPC notification remains open for public feedback until June 28, 2024, and may undergo further revision before being issued and made legally binding.

For more details on this draft PDPC notification, or on any aspect of compliance with the PDPA, please contact Nopparat Lalitkomon at [email protected], Gvavalin Mahakunkitchareon at [email protected], or Wilin Somya at [email protected].

RELATED INSIGHTS​ 

January 22, 2026
On January 20, 2026, Vietnam’s Ministry of Finance (MOF) issued Decision No. 96/QD-BTC to formally launch pilot administrative procedures for licensing crypto asset trading market services in Vietnam. The decision took immediate effect and implements the government’s pilot crypto asset market program under Resolution No. 05/2025/NQ-CP. Notably, competent authorities have now begun accepting license applications, marking the first time Vietnam has operationalized a licensing pathway for crypto trading market operators. Administrative Procedures and Applications The decision stipulates procedures for (i) granting, (ii) adjusting, and (iii) revoking licenses to provide services for organizing crypto asset trading markets. It provides detailed, step-by-step guidance for each procedure, including dossier composition, internal review stages, coordination mechanisms, and statutory timelines. These procedures apply specifically to entities seeking to organize and operate crypto asset trading markets within Vietnam’s pilot regulatory framework. The MOF is the authority responsible for reviewing and deciding on the above procedures, with the State Securities Commission acting as the receiving, coordinating, and procedural focal point. For licensing applications, the MOF will coordinate with multiple authorities, including the State Bank of Vietnam and the Ministry of Public Security, particularly in relation to anti-money laundering, cybersecurity, system safety, and risk control requirements. Applications may be submitted in person, by post, or electronically via the National Public Service Portal or the administrative procedure information system, in line with applicable regulations. Statutory processing timelines vary depending on the specific procedure and stage involved. For applications to obtain a license to organize a crypto asset trading market, the process is conducted in multiple phases: The MOF will issue an initial written response within 20 working days from receipt of a complete and valid initial dossier, following which, upon submission of the full set of required documents, the MOF will complete substantive review and issue the license
January 21, 2026
On January 16, 2026, Thailand’s Electronic Transactions Committee released for public comment a draft notification that would require social media platforms operating in Thailand to implement identity verification for all user accounts and advertisers, with enhanced scrutiny for high-risk advertising activities. If finalized in its current form, the Notification on Measures to Prevent Technology Crime for Social Media Service Providers would take effect 180 days after publication in the Government Gazette, fundamentally changing how platforms verify users and monetize advertising services. The public comment period is open through February 2, 2026. Mandatory User and Advertiser Identity Verification The draft establishes a universal requirement that all social media service providers implement identity verification measures for every user account. The draft imposes stricter verification obligations for advertisers than for general users. Before publishing any advertisement, platforms must verify the advertiser’s identity at a level sufficient to identify the advertiser, unless the advertiser has previously completed verification. Risk-Based Advertisement Verification The identification requirements for advertisers will be more stringent in the following cases: The advertiser has a history of user complaints or has previously violated the platform’s terms of service. The advertisement involves finance, investment, loans, sensitive personal data, or content flagged as potentially involving cybercrime. The advertisement specifically targets vulnerable groups, such as the elderly or other at-risk demographics. In such cases, platforms must conduct identity verification using government-issued identification documents and must confirm the accuracy, authenticity, and currency of these documents with the issuing government agencies. Alternatively, platforms may verify identity through an eligible digital identity verification and authentication system provider. Information Retention Platforms must retain specific information for each advertiser, including the name of the individual or juristic person and any representatives, government-issued identification documents such as ID cards, passports, or certificates of incorporation, and reachable contact information including
January 21, 2026
Spurred by global geopolitics and Canada’s Indo-Pacific Strategy, which aims to forge deeper ties with ASEAN, Canadian companies have been showing growing interest in Thailand and Southeast Asia in recent years. To understand the opportunities offered by the region, we sat down with Andrew Stoutley, a Toronto native and the chief operating officer of Tilleke & Gibbins, a leading Southeast Asian regional law firm with over 130 years of history in Thailand. Q: Why are Canadian companies looking at Thailand and Southeast Asia right now? A: Two reasons stand out. First, diversification has moved up the agenda. Many Canadian companies want options outside North America due to tariff volatility and policy uncertainty in the United States, as well as questions around the next Canada–United States–Mexico Agreement mandatory joint review. At the same time, the shift of global production from China to Southeast Asia is accelerating, driven by rising costs, geopolitics, and the need to avoid overreliance on a single market. As a result, Canadian companies are looking for a second production base or a regional hub, and Thailand and its neighbors are natural choices given their manufacturing depth, location, and established supply chains. Second, Canada’s own efforts in the region are gaining traction. The Indo-Pacific Strategy has led to more on-the-ground support, including larger trade missions, upgraded diplomatic posts, and new financing options. Export Development Canada (EDC) now has a presence in Bangkok, giving Canadian companies a direct line to financing and insurance in Thailand. There’s also steady progress on trade frameworks like the recently signed Canada–Indonesia Comprehensive Economic Partnership Agreement (which will come into effect pending domestic procedures), ongoing negotiations of a Canada–ASEAN FTA, and the exciting announcement about the launch of negotiations of a Canada–Thailand FTA. Together, these developments have the potential to make it much easier
January 13, 2026
On January 9, 2026, Thailand’s Securities and Exchange Commission (SEC) filed a criminal complaint with the Economic Crime Suppression Division (ECD) against five individuals for unauthorized operation of a digital-asset dealer business under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This precedent-setting case signals that the regulator is willing to pursue crypto enforcement against natural persons even in the absence of a licensed platform entity. Background and Implications The case follows the SEC’s October 2025 public warning about the use of iris-scanning technology in exchange for certain digital tokens. In its warning, the SEC cautioned that exchanging or trading these specific tokens with unlicensed service providers exposes users to heightened fraud, scam, and money laundering risks. Unlike prior regulatory enforcement matters, which involved platform-level administrative fines for operational or compliance failures, this case targets misconduct by individuals who may not be professional traders but openly advertised their willingness to buy these tokens from the public, opened individual over-the-counter (OTC) trade channels for these tokens, and facilitated off-exchange transactions in a manner resembling ordinary commercial dealing. This enforcement action establishes a clear precedent that natural persons engaging in public-facing digital-asset dealing may face criminal liability under Thai law, even without operating through a corporate or licensed platform structure. Outlook The alleged offenders may not settle this crime by payment of fines. Following the SEC’s referral, the ECD will undertake further investigation, after which prosecutors may review the case and proceed to court. The SEC has stated that it will cooperate fully with enforcement agencies throughout the criminal enforcement process.