You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 1, 2025

Thailand’s Data Privacy Landscape in the First Half of 2025

Now halfway through 2025, Thailand continues to advance in the realm of data privacy, with the ambitious goal of achieving zero data breaches. The Personal Data Protection Committee (PDPC), an independent government body established by the Personal Data Protection Act (PDPA), is taking a more proactive approach, having published several rulings and orders to enhance data protection measures and clarify compliance expectations for businesses.

Here is a look back at Thailand’s data privacy developments in the first half of the year.

Strengthening Law Enforcement and New Guidance for Compliance

Enforcement of existing data protection laws and regulations has taken a step forward this year. Some of the specific initiatives include:

  • Increased enforcement by the PDPC. A key trend to watch from the first half of 2025 is the PDPC’s active enforcement of the PDPA as it intensifies oversight through compliance orders and public warnings against noncompliant organizations while ramping up efforts to prevent and halt the illegal trading of personal data by actively monitoring emerging societal issues.
  • Call center scams and cyber fraud control. Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud.
  • Orders from the Expert Committee. Several orders issued by the Expert Committee under the PDPA were announced in the first half of this year. These include directives for data controllers to take corrective actions to comply with the PDPA, as well as initiatives to raise awareness of data privacy within organizations, reflecting the regulator’s focus on promoting organizational awareness and compliance. A guideline report summarizing the Expert Committee’s decisions and orders was also published to serve as a reference for compliance.
  • Public issue monitoring. The PDPC has been taking a more proactive approach by staying current with high-profile data privacy issues that are top of mind for the public. This has involved actively monitoring and following up on cases such as data breaches or incidents that show early signs or suspicions of potential data breaches.
  • Supporting PDPA compliance through PDPC programs. The PDPC launched several initiatives to support PDPA compliance, including training programs for key roles and executive-level personnel. A particularly noteworthy initiative is the PDPC Regulator Checklist, introduced as part of the PDPC’s advisory and inspection activities, which outlines 10 key areas that organizations should focus on to ensure compliance with the PDPA.

Promoting the Data Economy

Authorities have also been putting infrastructure in place to support data-intensive economic activity, such as:

  • Facilitating cross-border data transfers: Thailand has supported initiatives aimed at simplifying and securing cross-border data flows, such as by hosting workshops to educate businesses on adopting the ASEAN Model Contractual Clauses for Cross Border Data Flows as mechanisms to enable secure cross-border data transfers among ASEAN member states. Beyond the ASEAN level, the PDPC participated in the Global CBPR Workshop 2025, with the key objective of presenting Thailand’s progress toward joining the Global Cross-Border Privacy Rules (CBPR) framework. This certification scheme is to facilitate easier data transfers across member countries.
  • Data-sharing laws: In the first half of the year, Thailand’s Electronic Transactions Development Agency took steps to align with international standards and best practices, such as the EU’s Data Act and Data Governance Act, by releasing draft principles for future legislation on data sharing. These draft principles aim to enhance data sharing practices while ensuring robust data protection standards. These draft principles reflect Thailand’s commitment to harmonizing its data protection framework with international standards.

Advancing Ecosystems and Technology Use

Adoption and implementation of technology, particularly in regard to regulatory compliance, was also a focus, as seen in the following developments:

  • Digital technology for data compliance: The Government Platform for PDPA Compliance was established through a collaboration between the Office of the PDPC and the Office of the National Digital Economy and Society Commission to promote the implementation of the PDPA through digital technology. This initiative has been approved by the cabinet, requiring all government agencies to adopt the platform.
  • AI adoption: The adoption of AI in Thailand’s business sector was actively encouraged in ETDA’s draft AI law, which was also released in the first half of this year. This draft outlines principles for data sandboxes and the reuse of personal data (including personal data obtained for other purposes if proper privacy safeguards are in place) for AI development in the public interest.

This progress that Thailand made in the first half of 2025 reflects the country’s dedication to enhancing data privacy and protection as part of a secure digital economy. As progress continues rapidly, organizations are encouraged to stay engaged, actively maintain PDPA compliance, and regularly update their data privacy practices. We are committed to keeping pace with the evolving privacy landscape in Thailand.

RELATED INSIGHTS​ 

January 9, 2026
Vietnam has taken a decisive step into the global artificial intelligence regulatory landscape with the promulgation of the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law), adopted on December 10, 2025, and effective from March 1, 2026. As one of the earliest comprehensive, standalone AI statutes in Southeast Asia, the AI Law signals Vietnam’s ambition to position itself as both an innovation-friendly and governance-conscious AI market. In doing so, the legislature has also streamlined Vietnam’s AI regulatory architecture. The AI Law repeals most AI-related provisions previously embedded in the Law on Digital Technology Industry No. 71/2025/QH15, consolidating AI governance under a single, unified legal framework. This structural move underscores an intent to provide greater regulatory clarity and coherence for businesses operating across the AI value chain. Against this backdrop, the key question for AI developers, providers, deployers, and governance teams is how the new risk-based framework will shape compliance expectations, operational decisions, and governance design in practice. This article examines the new AI Law through that practical lens, focusing on what it means for AI businesses operating in or into Vietnam. Scope of Application The AI Law applies broadly to Vietnamese organizations and individuals, as well as foreign entities that participate in AI-related activities within Vietnam. The law expressly excludes AI activities conducted solely for national defense, security, and cryptography purposes. A defining feature of the AI Law is that it regulates by role, not by industry. It distinguishes between: Developers, who design, build, train, test, or fine-tune AI models and have direct control over the technical methods, training data, or model parameters; Providers, who place AI systems on the market or put them into use under their own names; Deployers, who use AI systems under their control in professional, commercial, or service-provision activities; Users, who interact with AI
January 9, 2026
Thailand continues to advance its legal and regulatory framework for the technology sector, with several key laws undergoing review and proposed amendments. These developments reflect Thailand’s broader efforts to ensure that its regulatory landscape keeps pace with rapid technological change and aligns more closely with international standards and best practices. The following are key legal developments and proposed legislative reforms in 2026 that are expected to impact businesses operating in the technology sector and the broader Thai business landscape. Data Privacy and Cybersecurity Personal Data Protection Act B.E. 2562 (2019) Following the full enforcement of Thailand’s Personal Data Protection Act (PDPA) in June 2022, businesses and practitioners have identified practical implementation challenges and interpretative issues. These challenges were reflected in an effectiveness assessment conducted by the Personal Data Protection Committee (PDPC) in late 2024. The PDPC published a set of principles for public consultation to identify issues and directions for potential amendments to the PDPA. Key issues: Emerging issues include clarifying the definitions of “data controller,” “data processor,” and “criminal record”; revisiting the scope of sensitive personal data to better reflect Thailand’s context; proposing amendments to the hierarchy of legal bases to avoid misconceptions of consent as the default legal basis; and clarifying the required level of expressiveness for explicit consent, as well as rules for collecting personal data from other sources. Current status: The first round of public consultation has concluded. Next steps: The proposed amendments are proceeding to a revised draft following the consultation outcomes. Cybersecurity Act B.E. 2562 (2019) Thailand is moving forward with proposed amendments to enhance the effectiveness of its national cybersecurity framework, as evolving digital technologies bring new risks such as misinformation, system intrusions, and attacks on critical infrastructure, making cybersecurity a national priority. Key issues: The amendments aim to clarify and strengthen
January 8, 2026
Thailand’s Digital Government Development Agency (DGA) has proposed new standards that would require government agencies to select cloud services exclusively from a preapproved shortlist of providers. The draft Digital Government Standards re: Cloud Service Provider Standards aims to strengthen procurement confidence and reduce risks associated with selecting cloud service providers that do not meet the required standards. A public hearing period on these standards concluded on December 27, 2025. The DGA will now review submitted comments and consider revising the standards accordingly. Shortlisted Cloud Service Provider Tiers The draft standards establish three tiers of cloud service providers based on their assessed service capability levels, core qualifications, and certifications. The DGA sets qualification requirements for each tier, and it is at the discretion of each agency to select the tier of cloud service provider that best suits its operational needs, as follows: Tier 1 cloud service providers are suitable for providing services involving disclosable official data. Tier 2 cloud service providers are suitable for handling official data and protected data, such as personal data, which requires a high-security public cloud (e.g., virtual private cloud). Tier 3 cloud service providers are suitable for providing services to agencies with specific regulatory and security requirements that handle highly protected data, such as the national security system. These providers must offer sovereign or hybrid cloud as stipulated by the Ministry of Digital Economy and Society. All tiers of cloud service providers must be legal entities incorporated under Thai law and can be authorized distributors of offshore cloud service providers. However, each tier will be subject to different requirements, including infrastructure obligations. Government agencies are encouraged to select a cloud service provider appropriate for their intended use. For example, if a government agency intends to procure cloud services for operating applications that process personal data,
January 8, 2026
Thailand has enacted comprehensive sexual harassment legislation that significantly expands criminal penalties and creates new compliance obligations for online platform operators. The Act Amending the Penal Code (No. 30) B.E. 2568 (2025), enacted on December 29, 2025, and taking effect the following day, introduces a comprehensive definition of sexual harassment, establishes new criminal offenses with graduated penalties, and imposes content removal obligations on social media platforms and computer system service providers. The amendment, which establishes a comprehensive framework for addressing sexual harassment in both physical and digital environments, significantly expands legal exposure for online service operators. It also grants courts authority to order takedowns of violating data accessible to the public. Definition of Sexual Harassment The law introduces “sexual harassment” as a distinct statutory concept covering physical conduct, verbal conduct, sounds, gestures, expressions, postures, communications, surveillance, stalking, and acts committed through computer systems or electronic devices. Conduct qualifies as sexual harassment when it is sexual in nature and likely to cause the victim distress, annoyance, embarrassment, humiliation, fear, or a sense of sexual insecurity. Criminal Offenses and Penalties The amended Penal Code establishes graduated penalties based on the severity and context of the harassment—including enhanced penalties for public or online conduct. For instance: Basic sexual harassment is punishable by imprisonment for up to one year, a fine of up to THB 20,000, or both. Continuous or repeated harassment that prevents normal life escalates penalties to imprisonment for up to two years, a fine of up to THB 40,000, or both. Critically for online operators, harassment committed in public places, in the presence of the public, or through computer systems accessible to the general public triggers imprisonment for up to three years, a fine of up to THB 60,000, or both. Acts of harassment committed by supervisors, employers, or others