You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 23, 2026

Thailand Seeks Feedback on Draft Data Protection Guidelines for AI

On February 17, 2026, Thailand’s Personal Data Protection Committee (PDPC) released its draft Guidelines on Personal Data Protection in the Development and Use of Artificial Intelligence. The draft guidelines, which translate data controller and data processor compliance obligations under the Personal Data Protection Act (PDPA) into measures tailored to AI development and deployment, are open for public comment until February 25, 2026.

At a public hearing session on the draft guidelines held on February 19, the PDPC emphasized that its approach to AI is not to hinder innovation but to develop practical guidance supporting safe deployment while ensuring data protection. Although the guidelines are not legally binding, they indicate the regulator’s expectations and the likely direction of interpretation and enforcement.

Scope of Application and Role of Stakeholders

The guidelines will apply to all data controllers and data processors in Thailand, and to overseas data controllers and data processors whose data processing falls within the extraterritorial scope of the PDPA.

The draft guidelines distinguish the roles of parties involved in AI deployment. Users of AI who determine the purpose of use and designate the input data, and retain outputs generated by the AI, are considered data controllers. In contrast, AI model providers or system integrators that process personal data under the instructions of the data controller are generally regarded as data processors. However, if an AI model provider utilizes user data for its own purposes, such as model fine-tuning or training, it may instead be classified as a data controller.

Key Obligations for AI Data Collection and Use

The basic principles of data processing under the PDPA must be maintained throughout the AI implementation lifecycle, from design to decommissioning, emphasizing accountability and privacy-by-design principles. The draft guidelines also stipulate the following:

  • Data processing agreements (DPAs) should include model training prohibitions, including the deletion of model weights and vector database
  • Data minimization, privacy-enhancing technologies, and privacy by default should be integrated as part of the system architecture design.
  • The collection of personal data should take into account identifiability of input data, data minimization, legitimate collection of data from other sources, transparency of the privacy notice, appropriate lawful basis, avoidance of blanket consent, and storage limitation and architecture patterns for data deletion.
  • Repurposing of data requires the data controller to re-notify the relevant data subjects, which can be done by updating the existing privacy notice and making it available to them.
  • Disclosure of personal data to AI service providers should be recorded in the record of processing activities (ROPA) to ensure traceability.

Data Protection Impact Assessments for High-Risk AI

Data protection impact assessments (DPIAs) for high-risk AI applications are necessary to identify, manage, and mitigate AI-specific risks that may affect the confidentiality, integrity, or availability of personal data processed within AI systems.

High-risk AI applications include, for example, automated decision-making with legal or similarly significant effects on individuals, large-scale processing of sensitive data for AI model training, systematic behavioral monitoring in public spaces, and generative AI capable of creating defamatory or misleading content about individuals.

Businesses must conduct DPIAs from the design phase, assessing necessity, proportionality, and AI-specific risks such as algorithmic bias, model inversion attacks, and limited explainability of outputs. These assessments should identify risk-mitigation measures, which may include the deployment of privacy-enhancing technologies, anonymization techniques, data encryption, and the implementation of human-in-the-loop controls for high-risk AI systems.

The draft guidelines also provide examples of sector-specific applications that may face heightened scrutiny. For instance, financial institutions using AI for credit scoring must ensure explainability and fairness, with human oversight required for adverse or rejection decisions. HR departments deploying AI for recruitment or performance evaluation must audit for algorithmic bias to prevent unlawful discrimination. In the healthcare sector, AI tools that support diagnosis must not be used as the sole basis for life-affecting medical decisions, and a physician must make the final determination.

Security Measures and Vendor Management

The draft guidelines prescribe layered security obligations, including organizational, physical, and technical measures.

Organizational measures should include access controls that follow the principle of least privilege, with developers restricted to anonymized data in testing environments and general users barred from accessing model weights or training datasets. Businesses must adopt acceptable use policies (AUPs) prohibiting employees from entering personal data into public generative AI platforms and must train staff on AI-specific risks like hallucinations and prompt-injection attacks. When procuring external AI services, businesses must conduct vendor due diligence and execute DPAs that explicitly prohibit vendors from using client data to train or improve their own models without authorization. Third-party and open-source models also introduce supply chain risks, including the possibility that models were trained on unlawfully collected data or contain embedded backdoors. Using an open-source AI model does not reduce legal responsibility; the deploying organization remains the data controller and must assess the model’s provenance and security.

Physical measures should also be implemented to cover both hardware and system architecture, such as restricting access to premises where computer networks and cloud infrastructure are hosted, and ensuring the separation of testing sandbox environments from primary production environments at both physical and network levels.

Technical measures should include AI-specific safeguards that reflect the complexity and sensitivity of the data involved, such as input sanitization and data minimization, data encryption and anonymization, and the implementation of audit trails specifically designed for AI systems. These audit trails should cover interaction logs and metadata, including model versions, system prompts, and input data, as these are necessary to support digital forensic investigations. API rate limiting, proactive penetration testing, and input and output guardrails must also be implemented.

Data Subject Rights and Breach Notification

Businesses must design AI systems to support data subjects’ rights, taking into account technical feasibility to ensure effective protection of these rights, as listed below:

  • Right of access and data portability: Preparation for responding to access and data portability requests must include identity verification before granting the request, as well as systems capable of tracing which personal data was used in training or generated as output. This requires purpose-built audit trails to ensure that accurate copies of the data can be provided upon request.
  • Right of erasure: This right extends beyond deleting data from active databases. Businesses must also remove personal data from caches, and must fine-tune datasets, and, where technically feasible, trained models. If removing data from a model is not technically feasible or would require disproportionate resources, the data controller should implement alternative safeguards to protect the data subject’s rights.
  • Right to object: Systems must be able to segregate and immediately stop the processing of personal data when an objection is raised.
  • Right to rectification: Human intervention should be activated when there is any objection to the output, particularly if the trained model contains inaccurate data, and appropriate measures should be implemented to adjust the training process accordingly.

AI-related breach scenarios also require tailored response protocols. Prompt-injection attacks or data leakage through model inference may constitute reportable breaches if they result in unauthorized exposure of personal data. Businesses should assess breach severity by considering the sensitivity and volume of data involved and whether the exposure is contained internally or made public. Agreements with AI vendors should establish joint incident response procedures and require vendors to provide logs and forensic support within defined timeframes.

Next Steps

Businesses deploying AI in their operations should monitor the development and final issuance of the guidelines and any subsequent regulatory clarifications. Despite the guidelines’ nonbinding nature, organizations deploying AI will find it difficult to avoid aligning with these expectations, as regulators are likely to assess compliance against them.

Gap analysis of internal AI governance and preparation of AUPs may be necessary. The integration of AI into business operations will require clear and demonstrable compliance with data protection requirements. At the same time, staff training and robust contractual safeguards with third parties should be put in place to ensure enforceability, coordination, and effective risk management when AI-related issues arise.

RELATED INSIGHTS​ 

September 24, 2026
Vietnam is implementing and developing a broad package of regulatory reforms that could reshape how IP, data, digital platforms, and product authenticity are regulated and enforced. Several of the key measures have been led by the Ministry of Public Security in its legislative and administrative capacity, as part of a broader government effort. The core reform package consists of four key legal instruments: proposed amendments to the Criminal Code, a proposed new Data Security Law, a draft Decree on Product Identification, Authentication and Traceability, and the newly enacted Decree No. 330/2026/ND-CP. These instruments include rules on criminal enforcement, data security, electronic identification, product identification and traceability, administrative violations, and cybersecurity sanctions. Combined, these measures will affect copyright enforcement, industrial property rights, trade secrets, AI training data, product provenance, online takedowns, valuation of counterfeit goods and electronic evidence. It is worth noting that, in addition to strengthening criminal penalties for IP crimes, Vietnam’s emerging regulatory framework increasingly treats infringement, data misuse, product authentication, and platform-enabled violations as interconnected regulatory and enforcement challenges. For rights holders and foreign investors, this could mean stronger tools against counterfeiting and online infringement, but also more compliance obligations around data, traceability, AI, platform controls and government-facing reporting. Expansion of Criminal IP Enforcement Proposed amendments to Article 225 of the Criminal Code would expand criminal copyright exposure beyond reproduction and distribution to cover large-scale commercial public performance and online communication of works, phonograms and video recordings. This is important because piracy is increasingly about streaming, unauthorized communication, and platform access models rather than physical copying. Aggravated copyright infringement could be subject to up to 10 years in prison for individuals and fines of up to VND 6 billion (about USD 228,300) for commercial legal entities. The amended Article 226 would expand criminal industrial property liability beyond
September 17, 2026
Thailand’s Office of the Consumer Protection Board (OCPB) has released for public comment a draft bill to amend the Consumer Protection Act B.E. 2522 (1979), the country’s foundational consumer protection legislation. The draft amendment aims to modernize the nearly five-decade-old framework to address the rapid growth of digital commerce, online advertising, influencer marketing, and new business models. The public consultation period is open until October 10, 2026. Expanded Definitions Covering Digital Commerce The draft significantly broadens several core definitions to capture modern commercial activities: “Consumer” is expanded to include natural persons and nonprofit juristic persons who purchase or receive services, including those solicited by businesses and end users who do not directly pay for the goods or services. “Business operator” now explicitly covers advertising business operators and hired advertising persons, such as influencers and content creators. “Advertising media” is expanded to include digital platforms, social media, and social media user accounts. “Label” now encompasses electronic labels—symbols, codes, or other electronic formats displaying product information. Influencer and Advertising Disclosure Requirements In addition to these expanded definitions, “hired advertising person for selling goods or services” is a new definition covering influencers, content creators, live streamers, affiliate marketers, and virtual online media operators who receive monetary compensation or other benefits for advertising goods or services. Hired advertising persons—including influencers and content creators—must disclose to consumers that content is advertising and reveal their relationship with the business owner. Disclosure is required when the business owner employs the advertiser, pays or provides other benefits for the advertisement, or provides free or discounted products or services. These requirements apply where consumers would not otherwise know that the business has a connection to the person presenting the content. Labeling Requirements for Importers The draft introduces a clearer labeling obligation for importers of label-controlled goods, who must
September 11, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has published a new five-year master plan that will bring significant regulatory changes to the broadcasting and digital media sectors, including formal licensing requirements for internet-based audiovisual services. The Master Plan for Broadcasting and Television, 3rd Edition (B.E. 2569–2573/2026–2030) was published in the Government Gazette on September 1, 2026, and will affect OTT platforms, internet-based audiovisual service providers, and traditional broadcasters. Licensing Reform The NBTC will develop new licensing frameworks ahead of existing digital television license expirations, which are slated to occur between 2028 and 2030. This creates both uncertainty and opportunity for incumbents and new market entrants. New licensing criteria will also be developed for audiovisual services delivered over the internet, meaning previously unregulated internet-based providers may face licensing, fee, and content obligations for the first time. The plan also calls for a new law to govern converged communications services. OTT Regulation and Content Oversight The plan explicitly acknowledges and aims to lessen the regulatory asymmetry between traditional broadcasters—which are subject to licensing, fees, and content regulation—and internet-based services that currently face fewer obligations. The NBTC intends to develop regulatory frameworks to bring internet-based audiovisual services, including OTT platforms, streaming services, and user-generated content platforms, under content, consumer protection, and licensing requirements. Consumer Protection and Digital Rights The NBTC will strengthen its oversight of broadcasting, television, and telecommunications operators to ensure compliance with consumer protection and personal data protection requirements. This includes updating relevant notifications and orders and more strictly enforcing rules against practices that unfairly exploit consumers. These measures may layer NBTC-specific requirements on top of Thailand’s existing Personal Data Protection Act obligations. Stricter enforcement against practices that exploit consumers is a priority, with particular scrutiny on advertising practices. The NBTC will modernize complaint resolution processes, meaning service providers should
September 7, 2026
On September 4, 2026, Thailand’s prime minister convened the first meeting of the Data Center Business Policy Committee. The committee endorsed a draft policy framework for the data center industry and tasked four subcommittees with developing the standards that would sit beneath it, shifting away from fragmented, agency-by-agency approvals toward a unified national strategy aiming to maximize economic value while managing environmental and infrastructure concerns. Proposed Scope and Pillars of the National Data Center Policy Framework The proposed framework would cover all types of data centers, including internal or captive facilities operated within a company or its affiliates, rather than only commercial third-party providers. If adopted in this form, companies running private data centers purely for internal purposes would also become subject to regulatory oversight. Minimum safety and operational standards would be established, with uniform enforcement across all categories. The committee endorsed a draft policy framework with four key pillars: Industrial classification: Data centers exceeding 2 MW would be classified as industrial operations, which may require factory licenses and environmental impact assessments under the Factory Act. Resource pricing: Utility rates would be structured to reflect both direct and indirect costs, supporting green energy and green data center standards. Centralized screening: A centralized review would evaluate project suitability and resource allocation. Operators may be required to submit proposals through periodic “pitching” rounds, where projects are competitively assessed on their potential economic and strategic benefits to Thailand. Digital ecosystem: The framework would prioritize data sovereignty, tax incentives, and conditions promoting domestic digital businesses, AI, and cloud infrastructure. Multidimensional Evaluation Criteria and Subcommittees Four subcommittees will be established to develop standards responsible for the following dimensions: Economic: Criteria for assessing the economic viability of data center projects, for use in prioritizing data centers based on infrastructure readiness, demand type (including AI factories),