You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 9, 2024

Thailand Releases Master Plan for Personal Data Protection

On April 29, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) issued the master plan for personal data protection, which outlines the PDPC’s strategies for developing and enhancing the data protection framework in Thailand from 2024 to 2027. A draft of this four-year plan had previously been released for a public hearing on November 27, 2023.

Overview

The master plan sets out the long-term direction for the protection of personal data in Thailand, analyzing the current landscape, challenges, and obstacles encountered since the full enactment of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). It aims to align with Thailand’s National Security Policy and Plan for 2024–2027 and focuses on key sectors in its initial two years. These sectors are:

  • Public security and key government services;
  • Retail and e-commerce;
  • Information and communication technology and telecommunications;
  • Finance, investment, and insurance;
  • Public health;
  • Tourism; and
  • Education.

Objectives

The master plan’s goals include increasing organizational compliance with the PDPA, reducing data breaches, updating the PDPA to reflect current circumstances, introducing various PDPC e-services, and enhancing Thailand’s global competitiveness in data privacy and personal data protection. It sets targets and indicators of the plan’s success, such as achieving a 100% PDPA compliance rate across all sectors in Thailand and raising Thailand’s digital competitiveness to at least 30th in the World Digital Competitiveness Rankings from the IMD World Competitiveness Center.

Strategic Initiatives

To achieve these objectives, the master plan introduces four strategic initiatives:

  • Effective and balanced PDPA enforcement: Develop standards, principles, criteria, tools, indicators, and data privacy governance, including law enhancements. A recent example of this is the PDPC’s launch of the Personal Data Protection Surveillance Centre (PDPC Eagle Eye) to monitor data breaches.
  • Knowledge and trust enhancement: Build human capacity and trust by enhancing knowledge through initiatives like the forthcoming data protection officer (DPO) course that is certified by the PDPC.
  • Digital economy and society promotion: Enhance collaboration across the private and public sectors, both domestically and internationally, to increase personal data protection capabilities and create a sustainable regulatory network.
  • R&D and technology adoption: Support research and technology adoption to enhance competitive capabilities, including implementation of a data protection sandbox and the hosting of an international data protection summit.

The recently released master plan not only provides systematic strategies for the PDPC but also shows the PDPC’s proactive approach to data protection. Private entities can ensure their compliance with the PDPA by upholding the required data privacy standards and staying alert for upcoming moves from the PDPC.

For more information on the PDPC’s master plan, or on any aspect of personal data protection in Thailand, please contact Tilleke & Gibbins’ data privacy team at [email protected], [email protected], or [email protected].

RELATED INSIGHTS​ 

August 5, 2024
On June 28, 2024, Thailand’s Board of Investment (BOI) updated its list of promoted activities to include data hosting, which is listed as “Activity 8.2.4 Data Hosting Services.” Qualifying data hosting services are eligible for a corporate income tax exemption (capped) for eight years, along with other tax and nontax incentives, such as import duty exemption on imported machinery to be used in the project, the right for foreigners to own land, and work permit and visa facilitation for expats, among others. To be eligible for these BOI incentives, projects must: Provide services for leasing host servers for data storage (data hosting); Have at least two data centers located in Thailand that meet or exceed the ISO/IEC 27001 data center standards; and Have an investment amount (excluding cost of land and working capital) of at least THB 5 billion. Apart from the above specific criteria, projects also need to comply with the general BOI criteria, such as a debt-to-equity ratio no higher than 3:1, submission of a feasibility study report, and use of new machinery, among others. For more details on BOI incentives for software and data center activities, or on any aspect of investment promotion in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], or Napassorn Lertussavavivat at [email protected].
July 19, 2024
Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to How the Use of Artificial Intelligence Is Regulated in Southeast Asia, a comparative resource published by Drew Network Asia (DNA). The guide provides an accessible introduction to artificial intelligence (AI) and examines how ASEAN member states are approaching governance, regulation, and responsible deployment of AI technologies. The publication begins by outlining core AI concepts and summarizing the ASEAN Guide on AI Governance and Ethics, which reflects the region’s collective approach to promoting innovation while addressing risks. It then presents a comparative overview of nine ASEAN jurisdictions, highlighting emerging national strategies, regulatory developments, and institutional frameworks. Each country chapter responds to a consistent set of ten practical questions. These cover whether a national AI strategy has been issued; the extent to which dedicated AI laws or sectoral regulations apply; the existence of relevant judicial decisions; available guidelines and government support schemes; regulators responsible for AI oversight; approaches to liability, copyright, and data protection; and key considerations for organizations deploying AI technologies. By consolidating developments across the region, the guide serves as a useful reference for businesses exploring AI-related opportunities or compliance obligations in Southeast Asia. As regulatory approaches continue to evolve, readers seeking jurisdiction-specific advice are encouraged to contact the practitioners listed in each chapter. The full guide is available for download using the button below or directly from the DNA website.
July 10, 2024
The need for privacy and security has grown in tandem with the rapid proliferation of internet-enabled technologies. This is a major concern for consumers and individuals, and governments are increasingly mindful of online threats to their national security and their citizens. All of this represents an imposing challenge for companies—especially now that technology has enabled them to operate with relative ease across jurisdictions throughout the world.
July 5, 2024
The landscape of intellectual property (IP) has transformed alongside advancements in technology, transitioning from traditional methods to modern online approaches. A growing number of IP infringers are moving their illegal activities to the online sphere, particularly through the sale of counterfeit goods on their websites, social media, or e-commerce platforms. In response to these shifting pressures, Thailand implemented the Computer-Related Crime Act B.E. 2550 (CCA) on July 18, 2007, and amended it in 2017, aiming to enhance the effectiveness of combating online infringement by empowering government officials to request that the court block computer data (called “website-blocking”) that infringes upon other parties’ intellectual property rights, as per section 20(3) of the CCA. From 2018 to May 2024, Thailand’s Criminal Court and Central Intellectual Property and International Trade Court have issued 53 orders to block more than 1,779 infringing URLs. One significant recent development is the Criminal Court’s establishment of the Technology Crime Division, which has been operating since April 1, 2024. Its purpose is to address criminal offenses that occur through electronic means, which should then be handled in an effective and prompt manner by judges who have expertise on technological crimes. In addition, several current measures to combat technology crime, including section 20(3) of the CCA, require court orders for the prevention of electronic criminal offenses or online infringement. The Technology Crime Division has the jurisdiction to consider and grant these orders, which will help expedite the approval process and ensure review by specialized judges. Scope of the Technology Crime Division The announcement of the establishment of the Technology Crime Division within the Criminal Court was published in the Government Gazette on March 18, 2024, with operations commencing on April 1, 2024. The Technology Crime Division is empowered to: Consider and adjudicate technology crime cases, except cases falling