You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 4, 2026

Thailand Proposes Significant Amendments to the Personal Data Protection Act

Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) could soon see some important changes, as a draft bill to amend the PDPA has been introduced in the House of Representatives. The draft amendment is currently in the public consultation phase, with comments accepted from July 16 to August 15, 2026. If enacted in its current form, the amendment would make three key changes: expanding the government exemption to cover anticorruption operations, introducing a statutory definition of “government agency,” and restructuring the lawful bases for personal data processing to align with international standards.

Background

The PDPA has encountered several enforcement challenges since its implementation, including three core problems identified by the bill’s sponsors: (1) the current exemptions for government agencies do not cover anticorruption and misconduct-prevention operations; (2) the PDPA lacks a clear statutory definition of “government agency,” causing legal uncertainty as to which entities are covered; and (3) the existing framework for lawful bases of data processing does not align with international standards—particularly the multiple-lawful-bases system in the EU’s General Data Protection Regulation (GDPR)—making compliance inflexible for both government and private sector entities.

Expanded Government Exemption

The current PDPA exempts government agencies performing duties related to national security (including fiscal security), public safety, anti-money laundering, forensic science, and cybersecurity. The proposed amendment adds “prevention and suppression of corruption and misconduct” to this list of exempted functions. This would allow anticorruption bodies—most notably the National Anti-Corruption Commission (NACC), which is identified as a directly affected party—to collect, use, and disclose personal data without being subject to PDPA requirements when carrying out their duties.

New Statutory Definition of “Government Agency”

Notably, while the current PDPA use the term “government agency” in several provisions, the term is not comprehensively defined, creating potential uncertainty as to its scope. The draft bill therefore inserts a new definition of “government agency” to cover central government agencies, regional government agencies, local government agencies, state enterprises, public organizations, Parliament, courts, independent constitutional organizations, the Office of the Attorney General, public higher-education institutions, and independent state agencies. The proposed definition seeks to clarify which entities are considered “government agencies” and covered by the act.

Restructured Lawful Bases for Data Processing

The most significant proposed change for both government and private-sector organizations is the restructuring of the PDPA’s section 24, which currently prohibits data controllers from collecting personal data without consent, subject to certain exceptions framed as carveouts.

The proposed amendment would restructure section 24 to adopt a multiple-lawful-bases model aligned with the GDPR, and add more clarity on the public-task basis. Under the new framework, personal data processing would be lawful when carried out under at least one of the following bases:

  • Archival/research/statistical: For historical or archival purposes in the public interest, or for research or statistics with appropriate safeguards, as prescribed by the PDPC board.
  • Public task/official authority: Necessary for performing a public-interest mission or exercising official authority, including government disclosure obligations under the Official Information Act or other laws.
  • Vital interests: To prevent or suppress danger to a person’s life, body, or health.
  • Contractual necessity: Necessary for performing a contract with the data subject or for pre-contractual steps at the data subject’s request.
  • Legitimate interests: Necessary for the legitimate interests of the data controller or a third party, unless overridden by the data subject’s fundamental rights.
  • Legal obligation: Necessary for compliance with a legal obligation of the data controller
  • Consent: The data subject has given consent.

The most critical structural shift is that consent is repositioned from the default requirement to one of seven coequal lawful bases.

Next Steps

All organizations should monitor the public consultation process, which is open until August 15, 2026. If enacted, the bill will take effect the day after its publication in the Government Gazette.

RELATED INSIGHTS​ 

February 17, 2025
Thailand’s draft Emergency Decree on Technology Crimes Suppression, which we covered in a client alert in January 2025 primarily addressed to telecom operators and financial institutions, is expected to have significant implications for a wide range of business operators.  The draft emergency decree has already been approved by the cabinet but may undergo further developments as it continues in the legislative process. In this article, we will highlight the material impacts of the draft emergency decree on overseas and local fintech operators. Expanded Definition of “Technology Crimes” The definition of “technology crimes” now includes the following acts of forgery or alteration: Forging or altering the identity of individuals and biometric characteristics by utilizing computer or communication systems or other electronic means to commit offenses. Forging or altering symbols, trademarks, or seals of groups (e.g., foundations, community enterprises) or juristic persons, including acts by juristic persons using individuals or juristic persons as nominal directors or shareholders, regardless of whether such individuals or legal juristic persons reside in Thailand. Forging or altering digital or online platforms, regardless of the platform’s location or legal status. Individuals who conspire, utilize, assist, or support the commission of these offenses will face the same penalties as the principal offender. Business Operator Definition The scope of “business operators” is now expanded to cover various fintech and digital asset operators beyond those under the Payment Systems Act (PSA). The draft emergency decree now includes the following operators, whether they are legally authorized or not: Business operators under the PSA and business operators who operate “as if” they are payment system operators Business operators under the Royal Decree on Digital Asset Businesses or business operators who operate “as if” they are digital asset business operators. Foreign exchange business operators. Disclosure and Exchange of Information Business operators must disclose
February 7, 2025
Vietnam’s political system is currently undergoing a significant reorganization to streamline government operations and improve efficiency. In this regard, Plan 141/KH-BCDTKNQ18, issued on December 6, 2024, provided guidelines on the restructuring of existing ministries, ministerial-level agencies, and government-affiliated agencies. Accordingly, the number of ministries is being reduced from 18 to 14 through mergers and consolidations and the establishment of a new Ministry of Ethnic and Religious Affairs. The number of ministerial-level agencies is being reduced to three, and government-affiliated agencies to five. Similar streamlining is happening at provincial levels. The newly consolidated state agencies will assume all functions, rights, and responsibilities of the merged entities, and will continue handling all ongoing matters previously handled by the former agencies. Some examples of these changes include the following: The Ministry of Science and Technology (MOST) will oversee telecommunications, IT applications, cybersecurity, e-transactions, and national digital transformation, which had previously been managed by the Ministry of Information and Communications (MIC). MOST will also be responsible for issuing licenses related to these areas, such as licenses for G1 online game services and telecommunication services. The Ministry of Culture, Sports, and Tourism will assume the responsibility of press management, previously under the MIC. The Ministry of Finance will assume state management functions related to investment, previously handled by the Ministry of Planning and Investment. Provincial Departments of Finance will issue Investment Registration Certificates and Enterprise Registration Certificates, a responsibility previously held by the Departments of Planning and Investment. The Ministry of Home Affairs will oversee labor and employment matters. Provincial Departments of Home Affairs will be authorized to issue work permits and will be the designated authorities for companies to register their internal labor regulations. Advantages for Businesses The restructuring aims to simplify regulations and expedite licensing processes. By reducing the number of agencies
February 6, 2025
The Thai government has proposed amendments to the Gambling Act B.E. 2478 (1935), aiming to address the growing influence of online gambling activities and strengthen regulatory oversight. These amendments, if enacted, would introduce significant changes, particularly concerning online gambling operators, participants, and related advertising activities. The draft amendment is currently in the public hearing process, which is scheduled to conclude on February 14, 2025. Key highlights of the proposed amendments are discussed below. Online Gambling In the proposed amendment, “online gambling” refers to gambling via a computer system or electronic system either through the internet or through remote communication. Organizing, participating in, or engaging in any type of online gambling is prohibited unless authorized by the competent authority. This opens the door for the authorization of casino-style online gambling in Thailand. However, the proposed amendment also imposes strict penalties on both operators and gamblers engaging in unauthorized online gambling: Anyone who organizes unauthorized online gambling is subject to imprisonment for 7–12 years. This penalty also applies to those responsible for managing electronic systems or tools used to facilitate gambling, as well as anyone involved in advertising, promoting, or deceiving others, either directly or indirectly, to engage in online gambling without proper authorization. Any person who engages in unauthorized online gambling is subject to imprisonment for 1–3 years. Dealers, supervisors of gambling or gambling activities, runners conveying wagers or other betting information, and owners of premises who knowingly permit such unauthorized activities are subject to imprisonment for 5–7 years. Penalties for Unauthorized Offline Gambling Operators The proposed amendment revokes the previous penalties under the Gambling Act and proposes stronger penalties. Both the original penalties and the proposed replacements depend on the type of gambling activity under the law, which classifies gambling activities into two types—list A and list B. List
February 3, 2025
On January 28, 2025, the Office of the Personal Data Protection Committee (PDPC) hosted Data Privacy Day 2025, bringing together over 1,000 participants from both the public and private sectors. The event underscored the importance of personal data protection and aimed to raise nationwide awareness while fostering a culture of compliance. During the event, the PDPC reaffirmed its commitment to strengthening Thailand’s data protection framework to align with international standards. The initiative also emphasized the collective goal of achieving zero data breaches. During the first session of the event, Mr. Prasert Jantararuangtong, deputy prime minister and minister of digital economy and society, delivered a speech highlighting the role of personal data protection in fostering Thailand’s digital economy. He emphasized that strong data protection measures enhance business credibility, build consumer trust, and attract foreign investment. He also addressed the PDPC’s “zero data breach” policy and the ongoing issue of data leaks, which have been exploited by call-center scam operations to deceive the public and cause financial harm. Additionally, Mr. Prasert announced that the Thai cabinet has approved a draft amendment to the Emergency Decree on Cyber Crime Prevention and Suppression B.E. 2566 (2023), commonly referred to as the “Cyber Crime Decree.” The draft will now proceed to the Council of State for review before its official enactment. Key provisions of the amendment include holding financial institutions, telecom providers, and social media platforms accountable for technology-related crimes; requiring compensation for victims; and enforcing stricter security measures. Cyber offenses, including personal data trading, face harsher penalties of up to THB 5 million in fines or five years of imprisonment. Authorities are also empowered to suspend suspicious SIM cards for committing illegal activities and expedite monetary refunds for victims without court approval. In the second session, the Office of the PDPC presented its