You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 28, 2026

Thailand’s New Draft Guidance on Data Protection Officers

Data protection officers (DPOs) have become a fixture of Thailand’s privacy compliance landscape since the Personal Data Protection Act B.E. 2562 (2019) (PDPA) took full effect and the Office of the Personal Data Protection Committee (PDPC) began requiring certain organizations to appoint them.

On July 7, 2026, the Office of the PDPC presented draft guidance on DPOs as part of a public consultation on a series of draft personal data protection manuals and recommendations. The draft offers the clearest indication yet of how the regulator expects the DPO role to work in practice, addressing recurring implementation issues under the PDPA—including when an organization must appoint a DPO, how the DPO should operate independently, how to manage conflicts of interest, and how data subjects and regulators should be able to contact the DPO. Because it remains in draft, organizations have an opportunity to weigh the practical implications now before the guidance is finalized.

When a DPO Must Be Appointed

The draft guidance clarifies the triggers for mandatory DPO appointment, including:

  • Regular and systematic monitoring of personal data or systems on a large scale, such as tracking, analyzing, or predicting behavior, attitudes, or individual characteristics.
  • Core activities involving large-scale processing of sensitive personal data, such as health data, biometric data, or criminal records.
  • Certain foreign-organization representative arrangements.
  • Public-sector coverage under relevant notifications identifying government entities that must appoint a DPO.

Processing involving 100,000 or more data subjects may be considered large-scale.

The guidance also contemplates voluntary DPO appointment for organizations that wish to raise their privacy governance standards, and such organizations should still comply with the standards applicable to DPOs under the law.

Independence and Reporting Lines

The draft guidance identifies lack of DPO independence as a core risk because an ineffective or constrained DPO may be unable to raise deficiencies to senior management. Organizations are expected to support the DPO with adequate time, budget, personnel, tools, access to information, and the ability to report directly to the highest level of management. The DPO should be protected from punishment for identifying organizational deficiencies or objecting to non-compliant practices. Where management does not follow the DPO’s recommendation, the DPO should document the reasons in writing.

Conflict of Interest

The draft guidance cautions against appointing individuals who determine the purposes and means of processing as DPO, including the chief executive officer, chief operating officer, chief financial officer, head of marketing, or head of human resources. It draws a distinction between general IT support personnel, who may serve as DPO, and senior IT leaders who decide what systems to use or what data to centralize, whose appointment may create a conflict. For organizations with limited personnel, the draft allows some flexibility but recommends assigning monitoring functions to another department to preserve neutrality.

Structuring Options for the DPO Role

The draft guidance recognizes several possible DPO structures:

  • In-house DPO. Appropriate for medium or large organizations with complex internal systems; organizations should avoid appointing someone who decides how personal data is used.
  • Outsourced DPO. Appropriate where specialist expertise or limited internal resources exist; organizations should define access rights, response responsibilities, and internal coordination arrangements.
  • Group DPO. May be appointed for companies within the same corporate group; the DPO must be easily contactable by each company and understand each business’s context.
  • Voluntary DPO. Organizations appointing a DPO voluntarily should still comply with the standards applicable to DPOs under the law.

DPO Operational Role and Accountability Framework

The DPO should be involved from the system design or new project planning stage to support privacy by design. The DPO serves as a key accountability mechanism, providing advice, monitoring compliance, coordinating with relevant stakeholders, and maintaining confidentiality, while responsibility for compliance remains with the organization. The organization should support the DPO with adequate resources, independence, access to necessary information, and direct reporting to senior management. Where breach notification is required, the notification should include the DPO’s name, contact location, and contact method, along with information on the breach, potential impacts, and measures taken or to be taken to prevent, stop, correct, or remediate the breach.

Outlook

Organizations should map their processing activities, confirm whether any DPO appointment trigger applies, and review reporting lines, job descriptions, and governance documents to ensure DPO independence, adequate resources, and senior management access. Any current or proposed DPO role should be assessed for conflicts of interest.

Organizations using an outsourced or group DPO should document access rights, scope of work, escalation processes, and data-subject response arrangements. Privacy notices and public contact points should be updated, and the DPO should be integrated into DPIAs, product reviews, ROPA governance, training, and breach response.

The draft guidance shows that DPO governance is increasingly becoming an operational compliance issue in Thailand. Organizations should not treat DPO appointment as a formality but should note the draft guidance’s emphasis on functional independence, contactability, conflict management, and documented escalation when the organization declines to follow the DPO’s advice. Reviewing DPO arrangements against these expectations now—while the guidance is still open for consultation—will leave organizations better positioned once it is finalized.

RELATED INSIGHTS​ 

August 6, 2025
Thailand’s Digital Government Development Agency (DGA) has released drafts of two pivotal documents to guide Thai government agencies in adopting cloud technology and classifying data for cloud usage. These draft guidelines, open for public hearing through August 12, 2025, are part of the national “Go Cloud First” policy, which aims to accelerate digital transformation, improve efficiency, and ensure robust data security across the public sector. The new standards will have significant implications for both government agencies and cloud service providers operating in Thailand. Highlights of the draft guidelines are presented below. Government Cloud Usage Guidelines Cloud-first transformation: All government agencies are directed to prioritize cloud solutions for new IT projects, in line with the cabinet’s “Go Cloud First” policy. Cloud model selection: Agencies must assess their needs and select the most appropriate cloud deployment model—public, private, hybrid, or community cloud—based on the sensitivity of the data and operational requirements. Service types: The guidelines provide criteria for choosing between Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS), emphasizing the importance of using standard, non-customized services where possible. Cost management: Agencies are required to plan and separate cloud-related expenses, ensuring transparency and efficient budget allocation. Cloud migration: The guidelines outline the steps for migrating to the cloud and highlight the role of cloud service providers in facilitating the process, including supporting innovation and enabling smooth exit strategies. Procurement compliance: All cloud procurement must comply with public sector procurement laws and regulations. Only providers meeting government-mandated standards can be selected. Security and shared responsibility: The guidelines clarify the division of security responsibilities between cloud providers and government agencies. While providers manage infrastructure security, agencies remain responsible for data, application, and access controls. Legal framework: Agencies must comply with the Digital Government Administration Act, Cybersecurity
August 1, 2025
Thailand’s Personal Data Protection Committee (PDPC) announced to the press on August 1, 2025, that it had issued eight new administrative fines under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) in five cases of noncompliance by public and private entities. The enforcement actions reflect a growing commitment by the PDPC to penalize noncompliance across all sectors, regardless of organizational type or size. The total amount imposed to date was approximately THB 21.5 million (approx. USD 654,690), underscoring the financial risks tied to PDPA violations. The five cases—one involving a state agency and the remainder in the private sector—are summarized below. Case 1: State Agency Providing Online Services to the Public The order in this case stemmed from a cyberattack on a state agency’s web app, resulting in personal data of 200,000 data subjects being leaked to and sold on the dark web. The software developer was also found to have implemented no privacy by design, lacked an access control system, had no data breach prevention measures, and failed to conduct risk assessments or review existing security measures. Key noncompliance identified: Lack of appropriate security measures Weak password protection No risk assessment or ongoing review of security measures No data processing agreement with software developer that acted as data processor The state agency and the developer were each fined THB 153,120 (approx. USD 4,670). Case 2: Private Hospital This case involved a hospital that engaged an individual contractor to destroy patient medical record documents. However, the contractor stored the documents at their own premises, failed to follow the required destruction protocols, and ultimately used the medical records to wrap sweets, resulting in the leak of over 1,000 records during the destruction process. The contractor also failed to notify the hospital of the data breach. Although there was a
August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with
August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention