You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 4, 2026

Thailand Proposes Significant Amendments to the Personal Data Protection Act

Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) could soon see some important changes, as a draft bill to amend the PDPA has been introduced in the House of Representatives. The draft amendment is currently in the public consultation phase, with comments accepted from July 16 to August 15, 2026. If enacted in its current form, the amendment would make three key changes: expanding the government exemption to cover anticorruption operations, introducing a statutory definition of “government agency,” and restructuring the lawful bases for personal data processing to align with international standards.

Background

The PDPA has encountered several enforcement challenges since its implementation, including three core problems identified by the bill’s sponsors: (1) the current exemptions for government agencies do not cover anticorruption and misconduct-prevention operations; (2) the PDPA lacks a clear statutory definition of “government agency,” causing legal uncertainty as to which entities are covered; and (3) the existing framework for lawful bases of data processing does not align with international standards—particularly the multiple-lawful-bases system in the EU’s General Data Protection Regulation (GDPR)—making compliance inflexible for both government and private sector entities.

Expanded Government Exemption

The current PDPA exempts government agencies performing duties related to national security (including fiscal security), public safety, anti-money laundering, forensic science, and cybersecurity. The proposed amendment adds “prevention and suppression of corruption and misconduct” to this list of exempted functions. This would allow anticorruption bodies—most notably the National Anti-Corruption Commission (NACC), which is identified as a directly affected party—to collect, use, and disclose personal data without being subject to PDPA requirements when carrying out their duties.

New Statutory Definition of “Government Agency”

Notably, while the current PDPA use the term “government agency” in several provisions, the term is not comprehensively defined, creating potential uncertainty as to its scope. The draft bill therefore inserts a new definition of “government agency” to cover central government agencies, regional government agencies, local government agencies, state enterprises, public organizations, Parliament, courts, independent constitutional organizations, the Office of the Attorney General, public higher-education institutions, and independent state agencies. The proposed definition seeks to clarify which entities are considered “government agencies” and covered by the act.

Restructured Lawful Bases for Data Processing

The most significant proposed change for both government and private-sector organizations is the restructuring of the PDPA’s section 24, which currently prohibits data controllers from collecting personal data without consent, subject to certain exceptions framed as carveouts.

The proposed amendment would restructure section 24 to adopt a multiple-lawful-bases model aligned with the GDPR, and add more clarity on the public-task basis. Under the new framework, personal data processing would be lawful when carried out under at least one of the following bases:

  • Archival/research/statistical: For historical or archival purposes in the public interest, or for research or statistics with appropriate safeguards, as prescribed by the PDPC board.
  • Public task/official authority: Necessary for performing a public-interest mission or exercising official authority, including government disclosure obligations under the Official Information Act or other laws.
  • Vital interests: To prevent or suppress danger to a person’s life, body, or health.
  • Contractual necessity: Necessary for performing a contract with the data subject or for pre-contractual steps at the data subject’s request.
  • Legitimate interests: Necessary for the legitimate interests of the data controller or a third party, unless overridden by the data subject’s fundamental rights.
  • Legal obligation: Necessary for compliance with a legal obligation of the data controller
  • Consent: The data subject has given consent.

The most critical structural shift is that consent is repositioned from the default requirement to one of seven coequal lawful bases.

Next Steps

All organizations should monitor the public consultation process, which is open until August 15, 2026. If enacted, the bill will take effect the day after its publication in the Government Gazette.

RELATED INSIGHTS​ 

December 8, 2023
In a significant development on December 5, 2023, the Central Bank of Myanmar (CBM) issued Letter No. FE-1/2937 granting authorized dealer licensed banks (ADLBs) the authority to freely transact in foreign currency trades, buying and selling at the market exchange rate for Myanmar kyat (MMK) as proposed by buyers and sellers through online trading platforms. Offshore remittances, however, must comply with the remittance criteria set by the Foreign Exchange Supervisory Committee. The online trading platform Refinitiv, initiated in June 2022 under the CBM’s guidance, facilitates the buying and selling of foreign currency between ADLBs and between banks and customers. The initiative was implemented in accordance with CBM Letter No. FE-1/789, dated June 21, 2023. The platform’s inception saw the exchange rate set at over MMK 2,900 per USD 1. Then, in August 2023, the CBM ordered banks and traders to limit foreign exchange transactions to an approved online trading platform, again with the exchange rate fixed at MMK 2,900 per USD 1. Transactions outside of online trading platforms continue to be governed by the exchange rate set by the CBM of 2,100 MMK per USD 1. Conversion Rules for Exporters On December 6, 2023, the CBM issued Notification No. 26/2023 lowering the percentage of Myanmar companies’ export earnings in foreign currency subject to mandatory conversion into MMK from 50% to 35% at the current official exchange rate set by the CBM at USD 1 to MMK 2,100. This mandatory conversion must follow the requirements for mandatory conversion of foreign currency, which remain in effect. For more details on foreign exchange developments, or on any aspect of financial regulations in Myanmar, please contact Tilleke & Gibbins at [email protected].
November 27, 2023
The emergence of generative artificial intelligence (AI) has transformed the landscape for innovators and creators. As many legal practitioners have pointed out, it’s imperative for both developers of AI and artists using generative AI to understand the intricacies of intellectual property (IP) strategies so they can navigate this evolving terrain successfully. This article lays out some essential considerations relating to the major types of IP for both developers and creators in the realm of generative AI. IP Strategies for Developers of Generative AI Developers of generative AI technologies play a pivotal role in the innovation landscape. There are three overarching IP-related issues to consider: protecting their own intellectual property, mitigating the risk of violating other people’s IP rights, and IP commercialization. Key aspects of these concerns, along with suggested approaches for developers, are outlined below. Protecting IP Copyrights. One of the primary considerations for AI developers is the protection of AI-generated works, such as art and source code. The good news is that in most countries, these creations enjoy copyright protection without the need for registration. As a result, the works are automatically protected from the moment of creation. However, it’s crucial to maintain comprehensive records of your work to establish your ownership. Trademarks. Trademarks are vital for AI developers looking to establish and protect their brand. Pay close attention to Nice classifications, particularly class 9 (for software), class 35 (for business management and online marketing), and class 42 (for software design and development). Registering trademarks in these classes can provide robust protection for your brand and products. Patents. For truly innovative AI algorithms, techniques, or processes, consider the option of patenting. Patents offer strong protection, but they require a thorough application process and the documentation of your innovation, including evidence that the invention is novel, non-obvious, and practically
November 27, 2023
Thailand’s Electronic Transaction Development Agency (ETDA) has released two new subordinate regulations under the Royal Decree on Digital Platform Services: one detailing the assessment of digital platform services (DPSs) that will be deemed “high-risk” and subject to additional obligations, and another setting guidelines on user verification and authentication for all DPSs. The two subordinate regulations are summarized below. Impact Assessment of DPS Operations Under the Royal Decree on Digital Platform Services, DPS operations that have the risk of seriously impacting financial and commercial security, reliability and credibility of data message systems, or the general public are subject to additional obligations. The first subordinate regulation mentioned above (officially titled Notification of the Electronic Transactions Commission Re: Criteria for Impact Assessment on Operation of Digital Platform Services) outlines the criteria for the ETDA to determine which DPSs are “high-risk.” DPSs falling under this designation include: DPSs whose total value of transactions conducted through the platform in Thailand exceeds THB 100 million (approx. USD 2.8 million) per year; DPSs whose operators have not registered their entities with the Department of Business Development (DBD)—notably overseas operators—and that have 100 or more merchants or business users in Thailand or total users in Thailand between 5 and 10 percent of the country’s population (i.e., approx. 3.3–6.1 million users, calculated using official 2022 figures); DPSs that allow their users to freely post certain messages, or do certain acts, that may affect the public in certain cases, such as: (1) unlawful messages or acts; (2) messages or acts that may affect a child’s rights or people’s fundamental rights; and (3) messages or acts that may negatively affect political opinions of Thai citizens (whether before or after an election) or statements or actions likely to negatively affect other individuals due to gender differences or sexual violence. After considering
November 23, 2023
On November 14, 2023, Thailand’s Personal Data Protection Committee (PDPC) published a draft notification on collection of personal data regarding criminal records. The draft notification aims to provide clarifications and prescribe further criteria for processing criminal record data under the Personal Data Protection Act (PDPA), which generally requires the processing of criminal records to be carried out under the control of the relevant official authority under the law or under a data protection measure implemented according to rules prescribed by the PDPC. After its eventual passage, the draft notification will have important implications for businesses’ recruitment and human resources activities in relation to individuals with criminal records. Key aspects of the draft notification include the following: “Personal data regarding a criminal record” and “criminal record data” denote personal data related to the investigations of criminal offenses, criminal prosecution, or criminal punishment that is official information or certified by the relevant supervisory authority, regardless of whether that action is connected to a final judgment. Under the draft notification, data controllers may process criminal record data for the purpose of a recruitment process, checking the qualifications of personnel, and considering the suitability of a person for a position if the processing activities are required by law or when a data controller obtains explicit consent from the data subject. Furthermore, the necessity of processing the criminal record data must be announced at the beginning of the recruitment process. Data controllers’ requests for explicit consent to collect a data subject’s criminal record data must also notify the data subject of the consequences of not providing consent or withdrawing consent. The draft notification sets the allowable retention period for criminal record data at a maximum of six months from the end of the processing activities specified above. After the retention period ends, the criminal