You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 24, 2024

Thailand: Ruling Clarifies “Lawful Basis” for Processing Certain Personal Data

In March 2024, a Thai court of first instance handed down a decision in a personal data protection case against an insurance company in Thailand. The landmark ruling has important implications for the disclosure of special categories of personal data.

The case concerned an individual, acting as the plaintiff, who filed a claim against an insurance company, as a data controller, and its representatives, for collecting, using, and disclosing the results of the plaintiff’s blood alcohol level test, along with a photo of the plaintiff taking the test, without explicit consent, resulting in his insurance claim being rejected. The company also disclosed the data to the insured party, who is the plaintiff’s family member, causing the plaintiff to suffer reputational damage, discrimination, humiliation, and ill treatment.

Since results of a blood alcohol level test are considered a special category of personal data pursuant to section 26 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA), the plaintiff filed the claim with the criminal court, requesting that the criminal penalties under the PDPA and the Penal Code be imposed on the defendants, and that the defendants delete or destroy the plaintiff’s personal data. The insurance company argued that it had disclosed the test results and the photograph to the plaintiff’s family member—as the insured under the insurance agreement—for the purpose of informing the insured of the rejection of the insurance claim.

Considering these facts and reasons, the criminal court ruled that the processing of this special category of personal data was necessary for the defense of the insurance company’s legal claims pursuant to section 26(4) of the PDPA, and therefore, explicit consent was not required. As a result, the criminal court dismissed the case.

Key Takeaways

While this case was dismissed, it indicates that explicit consent is not the only legal basis for processing a special category of personal data, and data controllers are able to process personal data as long as there is a lawful purpose and an appropriate legal basis to achieve that purpose. This case also suggests that data subjects are now becoming more aware of their rights in regard to privacy and personal data, which could increase the likelihood of more cases being brought before the courts.

As this ruling was made by the court of first instance, it might be appealed.

For more information on the interpretation of the PDPA, or on any aspect of data compliance in Thailand, please contact Nop Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Gvavalin Mahakunkitchareon at [email protected], or Wilin Somya at [email protected].

RELATED INSIGHTS​ 

August 1, 2025
Thailand’s Personal Data Protection Committee (PDPC) announced to the press on August 1, 2025, that it had issued eight new administrative fines under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) in five cases of noncompliance by public and private entities. The enforcement actions reflect a growing commitment by the PDPC to penalize noncompliance across all sectors, regardless of organizational type or size. The total amount imposed to date was approximately THB 21.5 million (approx. USD 654,690), underscoring the financial risks tied to PDPA violations. The five cases—one involving a state agency and the remainder in the private sector—are summarized below. Case 1: State Agency Providing Online Services to the Public The order in this case stemmed from a cyberattack on a state agency’s web app, resulting in personal data of 200,000 data subjects being leaked to and sold on the dark web. The software developer was also found to have implemented no privacy by design, lacked an access control system, had no data breach prevention measures, and failed to conduct risk assessments or review existing security measures. Key noncompliance identified: Lack of appropriate security measures Weak password protection No risk assessment or ongoing review of security measures No data processing agreement with software developer that acted as data processor The state agency and the developer were each fined THB 153,120 (approx. USD 4,670). Case 2: Private Hospital This case involved a hospital that engaged an individual contractor to destroy patient medical record documents. However, the contractor stored the documents at their own premises, failed to follow the required destruction protocols, and ultimately used the medical records to wrap sweets, resulting in the leak of over 1,000 records during the destruction process. The contractor also failed to notify the hospital of the data breach. Although there was a
August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with
August 1, 2025
Tilleke & Gibbins has contributed the Vietnam chapter to Corporate Governance 2025, part of the International Comparative Legal Guides (ICLG) series published by Global Legal Group. This respected guide offers comprehensive, jurisdiction-specific overviews of corporate governance laws and practices around the world. Each jurisdictional chapter follows a clear Q&A format, providing practical insights into critical issues such as: Sources of corporate governance regulation Shareholders’ rights, powers, and responsibilities Structure and duties of management bodies Stakeholder involvement in governance Transparency and reporting requirements ESG and sustainability-related obligations Cybersecurity and technology-related disclosures The Vietnam chapter was authored by Tram Ngoc Bich Nguyen, Truc Thi Thanh Tran, Dung Thi Phuong Le, and Quang Minh Vu, members of Tilleke & Gibbins’ corporate and commercial team in Ho Chi Minh City. The authors provide detailed analysis of Vietnam’s corporate governance framework, including recent developments such as the 2025 amendments to the Law on Enterprises requiring disclosure of ultimate beneficial ownership and the increasing emphasis on sustainable business practices and responsible corporate conduct. The chapter also discusses practical considerations for foreign investors in Vietnam, such as overlapping signing authorities between key company officers, enforcement of shareholders’ agreements, and disclosure obligations related to ownership and management roles. The complete Vietnam chapter is available as a PDF below. The Vietnam chapter—and the full Corporate Governance 2025 guide—are also freely available on the ICLG website.
August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention