You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 9, 2024

Thailand Releases Master Plan for Personal Data Protection

On April 29, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) issued the master plan for personal data protection, which outlines the PDPC’s strategies for developing and enhancing the data protection framework in Thailand from 2024 to 2027. A draft of this four-year plan had previously been released for a public hearing on November 27, 2023.

Overview

The master plan sets out the long-term direction for the protection of personal data in Thailand, analyzing the current landscape, challenges, and obstacles encountered since the full enactment of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). It aims to align with Thailand’s National Security Policy and Plan for 2024–2027 and focuses on key sectors in its initial two years. These sectors are:

  • Public security and key government services;
  • Retail and e-commerce;
  • Information and communication technology and telecommunications;
  • Finance, investment, and insurance;
  • Public health;
  • Tourism; and
  • Education.

Objectives

The master plan’s goals include increasing organizational compliance with the PDPA, reducing data breaches, updating the PDPA to reflect current circumstances, introducing various PDPC e-services, and enhancing Thailand’s global competitiveness in data privacy and personal data protection. It sets targets and indicators of the plan’s success, such as achieving a 100% PDPA compliance rate across all sectors in Thailand and raising Thailand’s digital competitiveness to at least 30th in the World Digital Competitiveness Rankings from the IMD World Competitiveness Center.

Strategic Initiatives

To achieve these objectives, the master plan introduces four strategic initiatives:

  • Effective and balanced PDPA enforcement: Develop standards, principles, criteria, tools, indicators, and data privacy governance, including law enhancements. A recent example of this is the PDPC’s launch of the Personal Data Protection Surveillance Centre (PDPC Eagle Eye) to monitor data breaches.
  • Knowledge and trust enhancement: Build human capacity and trust by enhancing knowledge through initiatives like the forthcoming data protection officer (DPO) course that is certified by the PDPC.
  • Digital economy and society promotion: Enhance collaboration across the private and public sectors, both domestically and internationally, to increase personal data protection capabilities and create a sustainable regulatory network.
  • R&D and technology adoption: Support research and technology adoption to enhance competitive capabilities, including implementation of a data protection sandbox and the hosting of an international data protection summit.

The recently released master plan not only provides systematic strategies for the PDPC but also shows the PDPC’s proactive approach to data protection. Private entities can ensure their compliance with the PDPA by upholding the required data privacy standards and staying alert for upcoming moves from the PDPC.

For more information on the PDPC’s master plan, or on any aspect of personal data protection in Thailand, please contact Tilleke & Gibbins’ data privacy team at [email protected], [email protected], or [email protected].

RELATED INSIGHTS​ 

September 24, 2024
On September 24, 2024, the government of Vietnam issued the first draft of a new Law on Personal Data Protection (“Draft PDPL”). As foreshadowed in our previous legal update, the Ministry of Public Security has been very active in developing this draft law. With this draft, they promise to continue their considerable efforts to establish a robust personal data protection culture in Vietnam, as the Draft PDPL indicates a tentative entry into force on January 1, 2026. With a tentative adoption by the National Assembly in May 2025, the Draft PDPL does not include any transition period, save for micro-enterprises, SMEs, and startups, which are only exempted from appointing a data protection department in their first two years of existence, while the timeline to comply with other obligations under the PDPL remains the same as for other enterprises. The Draft PDPL includes 68 articles, divided into seven chapters, making it more extensive than last year’s Decree No. 13/2023/ND-CP on Personal Data Protection (“PDPD”), and expressly addresses personal data protection in many fields, including marketing services, behavioral advertising, big-data processing, AI, cloud computing, labor monitoring and recruitment, financial and credit information, health and insurance, and others. It remains unclear how the PDPL will interact with the PDPD (whether it will replace its predecessor or coexist with it), although the Draft PDPL provides that it will prevail over any laws that have provisions on personal data protection that differ from the provisions of the PDPL. Among the important new developments of the Draft PDPL when compared to the PDPD, we note: Consent remains the main legal basis for processing, with limited exceptions (still not including “legitimate interest”). However, consent for cross-border transfer is further regulated under the Draft PDPL, including for intra-group sharing. Data processing impact assessment dossiers for controllers and
September 24, 2024
In recent years, Thailand has witnessed significant developments in its personal finance sector, particularly in alternative lending options. This article explores two key concepts in the Thai financial landscape: nano finance and personal loans. These alternative lending models, regulated by the Bank of Thailand (BOT), aim to provide more accessible financial services to individuals and small entrepreneurs who might have limited access to traditional funding sources. Nano Finance: Empowering Small Entrepreneurs The nano finance scheme under the BOT’s supervision is designed to provide funding to small entrepreneurs who might have limited access to traditional financial resources. One of the key features of this scheme is the ability of licensed nano finance providers to use alternative data in assessing loan applicants’ ability to repay (information-based lending). To implement this approach, nano finance providers must have an internal policy on credit approval that supports: Identifying scope and processes for utilizing alternative factors or technologies in determining debt repayment capacity, credit line limits for each loan applicant and total credit limits, and acceptable debt repayment targets; Having resources and personnel with sufficient knowledge, capability, experience, and expertise to operate efficiently and effectively, as well as clear checks and balances; Establishing guidelines for selecting and analyzing factors or financial models to evaluate or predict loan applicants’ ability and willingness to repay; Having an internal sandbox to test key success factors of the selected factors or models; and Having a process for monitoring and reviewing the application of the selected factors or models in assessing debt repayment capability. This approach allows nano finance providers to make more informed lending decisions based on a broader range of data, potentially increasing access to finance for small entrepreneurs who may not have traditional credit histories or collateral. Personal Loans The personal loan scheme under BOT supervision aims
September 20, 2024
On September 12, 2024, the Bank of Thailand (BOT) Notification Re: Virtual Bank Supervision Criteria took effect. According to this notification, virtual banks must adhere to standards for traditional commercial banks, along with additional requirements tailored to address virtual banks’ digital nature and corporate structure. Specific Requirements The concepts of supervision remain unchanged from the consultation paper titled “Criteria for Supervising Virtual Banks”. Some of the key additional provisions and details on supervision criteria relate to the following: Financial business groups: The notification identifies virtual banks as financial businesses, subject to the BOT’s regulations on financial business group supervision. If a virtual bank is a part of another financial institution’s financial business group, the virtual bank must be under a solo consolidated group. After the “initial phase” (see below), other financial institutions and companies within the financial business group are prohibited from extending credit to or engaging in transactions similar to lending activities with the virtual bank. Capital fund requirements: If other financial institutions’ investment in a virtual bank increases the capital fund in the financial system beyond a safe level and this poses a risk to other financial institutions, the BOT may order the relevant financial institution to maintain capital funds as the BOT deems appropriate. Service channels and outsourcing: Virtual banks must provide services solely through digital channels, except when necessary. For example, with the BOT’s approval, a virtual bank may use other commercial bank electronic branches via an ATM pool system, use a banking agent to serve customer needs for cash, or occasionally provide on-site services. Initial Phase The “initial phase” runs from the date that the virtual bank commences its operations until it receives the BOT’s approval to become fully operational. During this period, certain BOT supervisory requirements are relaxed as follows: Governance: Virtual banks in the initial phase may request
August 29, 2024
Thailand’s Securities and Exchange Commission (SEC) has revised its regulations on digital asset operators and exchanges to impose stricter governance standards on digital asset business operators and to align digital asset exchange rules with international standards. The new regulations are laid out in SEC Notification No. GorThor. 23/2567 on the Criteria, Conditions, and Procedures for Operating a Digital Asset Business (No. 24) and SEC Notification No. GorLorThor. 24/2567 on Determination of Prohibited Qualifications for Directors and Executives of Digital Asset Business Operators (No. 5). These were published in the Government Gazette on August 16, 2024, with most of the provisions taking effect on the same date. Governance for Digital Asset Businesses The heightened standards for digital asset business operators aim to ensure efficient business supervision and appropriate response to operational risks. The new requirements mainly address: Board of directors composition. Large-sized digital asset business operators (i.e., those with at least 10,000 customers and holding customer assets of at least THB 500 million) who do not provide digital asset custodian services must have at least five directors, at least two of whom must be independent directors. In addition, the business operators must establish an audit committee, with at least two members being independent directors, to create an appropriate “check and balance” mechanism within the organizational structure. Current digital asset business operators must comply with the requirements within 180 days of the notification’s effective date. Qualifications of authorized directors and managers. Authorized directors and managers are now required to (1) either have at least one year of working experience in the digital asset field or have participated in a digital asset course from an SEC-approved list, and (2) participate in a good corporate governance course recognized by the SEC. Current authorized directors and managers who have not previously completed a good