You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 1, 2025

Thailand’s Data Privacy Landscape in the First Half of 2025

Now halfway through 2025, Thailand continues to advance in the realm of data privacy, with the ambitious goal of achieving zero data breaches. The Personal Data Protection Committee (PDPC), an independent government body established by the Personal Data Protection Act (PDPA), is taking a more proactive approach, having published several rulings and orders to enhance data protection measures and clarify compliance expectations for businesses.

Here is a look back at Thailand’s data privacy developments in the first half of the year.

Strengthening Law Enforcement and New Guidance for Compliance

Enforcement of existing data protection laws and regulations has taken a step forward this year. Some of the specific initiatives include:

  • Increased enforcement by the PDPC. A key trend to watch from the first half of 2025 is the PDPC’s active enforcement of the PDPA as it intensifies oversight through compliance orders and public warnings against noncompliant organizations while ramping up efforts to prevent and halt the illegal trading of personal data by actively monitoring emerging societal issues.
  • Call center scams and cyber fraud control. Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud.
  • Orders from the Expert Committee. Several orders issued by the Expert Committee under the PDPA were announced in the first half of this year. These include directives for data controllers to take corrective actions to comply with the PDPA, as well as initiatives to raise awareness of data privacy within organizations, reflecting the regulator’s focus on promoting organizational awareness and compliance. A guideline report summarizing the Expert Committee’s decisions and orders was also published to serve as a reference for compliance.
  • Public issue monitoring. The PDPC has been taking a more proactive approach by staying current with high-profile data privacy issues that are top of mind for the public. This has involved actively monitoring and following up on cases such as data breaches or incidents that show early signs or suspicions of potential data breaches.
  • Supporting PDPA compliance through PDPC programs. The PDPC launched several initiatives to support PDPA compliance, including training programs for key roles and executive-level personnel. A particularly noteworthy initiative is the PDPC Regulator Checklist, introduced as part of the PDPC’s advisory and inspection activities, which outlines 10 key areas that organizations should focus on to ensure compliance with the PDPA.

Promoting the Data Economy

Authorities have also been putting infrastructure in place to support data-intensive economic activity, such as:

  • Facilitating cross-border data transfers: Thailand has supported initiatives aimed at simplifying and securing cross-border data flows, such as by hosting workshops to educate businesses on adopting the ASEAN Model Contractual Clauses for Cross Border Data Flows as mechanisms to enable secure cross-border data transfers among ASEAN member states. Beyond the ASEAN level, the PDPC participated in the Global CBPR Workshop 2025, with the key objective of presenting Thailand’s progress toward joining the Global Cross-Border Privacy Rules (CBPR) framework. This certification scheme is to facilitate easier data transfers across member countries.
  • Data-sharing laws: In the first half of the year, Thailand’s Electronic Transactions Development Agency took steps to align with international standards and best practices, such as the EU’s Data Act and Data Governance Act, by releasing draft principles for future legislation on data sharing. These draft principles aim to enhance data sharing practices while ensuring robust data protection standards. These draft principles reflect Thailand’s commitment to harmonizing its data protection framework with international standards.

Advancing Ecosystems and Technology Use

Adoption and implementation of technology, particularly in regard to regulatory compliance, was also a focus, as seen in the following developments:

  • Digital technology for data compliance: The Government Platform for PDPA Compliance was established through a collaboration between the Office of the PDPC and the Office of the National Digital Economy and Society Commission to promote the implementation of the PDPA through digital technology. This initiative has been approved by the cabinet, requiring all government agencies to adopt the platform.
  • AI adoption: The adoption of AI in Thailand’s business sector was actively encouraged in ETDA’s draft AI law, which was also released in the first half of this year. This draft outlines principles for data sandboxes and the reuse of personal data (including personal data obtained for other purposes if proper privacy safeguards are in place) for AI development in the public interest.

This progress that Thailand made in the first half of 2025 reflects the country’s dedication to enhancing data privacy and protection as part of a secure digital economy. As progress continues rapidly, organizations are encouraged to stay engaged, actively maintain PDPA compliance, and regularly update their data privacy practices. We are committed to keeping pace with the evolving privacy landscape in Thailand.

RELATED INSIGHTS​ 

January 22, 2026
On January 20, 2026, Vietnam’s Ministry of Finance (MOF) issued Decision No. 96/QD-BTC to formally launch pilot administrative procedures for licensing crypto asset trading market services in Vietnam. The decision took immediate effect and implements the government’s pilot crypto asset market program under Resolution No. 05/2025/NQ-CP. Notably, competent authorities have now begun accepting license applications, marking the first time Vietnam has operationalized a licensing pathway for crypto trading market operators. Administrative Procedures and Applications The decision stipulates procedures for (i) granting, (ii) adjusting, and (iii) revoking licenses to provide services for organizing crypto asset trading markets. It provides detailed, step-by-step guidance for each procedure, including dossier composition, internal review stages, coordination mechanisms, and statutory timelines. These procedures apply specifically to entities seeking to organize and operate crypto asset trading markets within Vietnam’s pilot regulatory framework. The MOF is the authority responsible for reviewing and deciding on the above procedures, with the State Securities Commission acting as the receiving, coordinating, and procedural focal point. For licensing applications, the MOF will coordinate with multiple authorities, including the State Bank of Vietnam and the Ministry of Public Security, particularly in relation to anti-money laundering, cybersecurity, system safety, and risk control requirements. Applications may be submitted in person, by post, or electronically via the National Public Service Portal or the administrative procedure information system, in line with applicable regulations. Statutory processing timelines vary depending on the specific procedure and stage involved. For applications to obtain a license to organize a crypto asset trading market, the process is conducted in multiple phases: The MOF will issue an initial written response within 20 working days from receipt of a complete and valid initial dossier, following which, upon submission of the full set of required documents, the MOF will complete substantive review and issue the license
January 21, 2026
On January 16, 2026, Thailand’s Electronic Transactions Committee released for public comment a draft notification that would require social media platforms operating in Thailand to implement identity verification for all user accounts and advertisers, with enhanced scrutiny for high-risk advertising activities. If finalized in its current form, the Notification on Measures to Prevent Technology Crime for Social Media Service Providers would take effect 180 days after publication in the Government Gazette, fundamentally changing how platforms verify users and monetize advertising services. The public comment period is open through February 2, 2026. Mandatory User and Advertiser Identity Verification The draft establishes a universal requirement that all social media service providers implement identity verification measures for every user account. The draft imposes stricter verification obligations for advertisers than for general users. Before publishing any advertisement, platforms must verify the advertiser’s identity at a level sufficient to identify the advertiser, unless the advertiser has previously completed verification. Risk-Based Advertisement Verification The identification requirements for advertisers will be more stringent in the following cases: The advertiser has a history of user complaints or has previously violated the platform’s terms of service. The advertisement involves finance, investment, loans, sensitive personal data, or content flagged as potentially involving cybercrime. The advertisement specifically targets vulnerable groups, such as the elderly or other at-risk demographics. In such cases, platforms must conduct identity verification using government-issued identification documents and must confirm the accuracy, authenticity, and currency of these documents with the issuing government agencies. Alternatively, platforms may verify identity through an eligible digital identity verification and authentication system provider. Information Retention Platforms must retain specific information for each advertiser, including the name of the individual or juristic person and any representatives, government-issued identification documents such as ID cards, passports, or certificates of incorporation, and reachable contact information including
January 21, 2026
Spurred by global geopolitics and Canada’s Indo-Pacific Strategy, which aims to forge deeper ties with ASEAN, Canadian companies have been showing growing interest in Thailand and Southeast Asia in recent years. To understand the opportunities offered by the region, we sat down with Andrew Stoutley, a Toronto native and the chief operating officer of Tilleke & Gibbins, a leading Southeast Asian regional law firm with over 130 years of history in Thailand. Q: Why are Canadian companies looking at Thailand and Southeast Asia right now? A: Two reasons stand out. First, diversification has moved up the agenda. Many Canadian companies want options outside North America due to tariff volatility and policy uncertainty in the United States, as well as questions around the next Canada–United States–Mexico Agreement mandatory joint review. At the same time, the shift of global production from China to Southeast Asia is accelerating, driven by rising costs, geopolitics, and the need to avoid overreliance on a single market. As a result, Canadian companies are looking for a second production base or a regional hub, and Thailand and its neighbors are natural choices given their manufacturing depth, location, and established supply chains. Second, Canada’s own efforts in the region are gaining traction. The Indo-Pacific Strategy has led to more on-the-ground support, including larger trade missions, upgraded diplomatic posts, and new financing options. Export Development Canada (EDC) now has a presence in Bangkok, giving Canadian companies a direct line to financing and insurance in Thailand. There’s also steady progress on trade frameworks like the recently signed Canada–Indonesia Comprehensive Economic Partnership Agreement (which will come into effect pending domestic procedures), ongoing negotiations of a Canada–ASEAN FTA, and the exciting announcement about the launch of negotiations of a Canada–Thailand FTA. Together, these developments have the potential to make it much easier
January 13, 2026
On January 9, 2026, Thailand’s Securities and Exchange Commission (SEC) filed a criminal complaint with the Economic Crime Suppression Division (ECD) against five individuals for unauthorized operation of a digital-asset dealer business under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This precedent-setting case signals that the regulator is willing to pursue crypto enforcement against natural persons even in the absence of a licensed platform entity. Background and Implications The case follows the SEC’s October 2025 public warning about the use of iris-scanning technology in exchange for certain digital tokens. In its warning, the SEC cautioned that exchanging or trading these specific tokens with unlicensed service providers exposes users to heightened fraud, scam, and money laundering risks. Unlike prior regulatory enforcement matters, which involved platform-level administrative fines for operational or compliance failures, this case targets misconduct by individuals who may not be professional traders but openly advertised their willingness to buy these tokens from the public, opened individual over-the-counter (OTC) trade channels for these tokens, and facilitated off-exchange transactions in a manner resembling ordinary commercial dealing. This enforcement action establishes a clear precedent that natural persons engaging in public-facing digital-asset dealing may face criminal liability under Thai law, even without operating through a corporate or licensed platform structure. Outlook The alleged offenders may not settle this crime by payment of fines. Following the SEC’s referral, the ECD will undertake further investigation, after which prosecutors may review the case and proceed to court. The SEC has stated that it will cooperate fully with enforcement agencies throughout the criminal enforcement process.