You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 28, 2026

Thailand’s New Draft Guidance on Data Protection Officers

Data protection officers (DPOs) have become a fixture of Thailand’s privacy compliance landscape since the Personal Data Protection Act B.E. 2562 (2019) (PDPA) took full effect and the Office of the Personal Data Protection Committee (PDPC) began requiring certain organizations to appoint them.

On July 7, 2026, the Office of the PDPC presented draft guidance on DPOs as part of a public consultation on a series of draft personal data protection manuals and recommendations. The draft offers the clearest indication yet of how the regulator expects the DPO role to work in practice, addressing recurring implementation issues under the PDPA—including when an organization must appoint a DPO, how the DPO should operate independently, how to manage conflicts of interest, and how data subjects and regulators should be able to contact the DPO. Because it remains in draft, organizations have an opportunity to weigh the practical implications now before the guidance is finalized.

When a DPO Must Be Appointed

The draft guidance clarifies the triggers for mandatory DPO appointment, including:

  • Regular and systematic monitoring of personal data or systems on a large scale, such as tracking, analyzing, or predicting behavior, attitudes, or individual characteristics.
  • Core activities involving large-scale processing of sensitive personal data, such as health data, biometric data, or criminal records.
  • Certain foreign-organization representative arrangements.
  • Public-sector coverage under relevant notifications identifying government entities that must appoint a DPO.

Processing involving 100,000 or more data subjects may be considered large-scale.

The guidance also contemplates voluntary DPO appointment for organizations that wish to raise their privacy governance standards, and such organizations should still comply with the standards applicable to DPOs under the law.

Independence and Reporting Lines

The draft guidance identifies lack of DPO independence as a core risk because an ineffective or constrained DPO may be unable to raise deficiencies to senior management. Organizations are expected to support the DPO with adequate time, budget, personnel, tools, access to information, and the ability to report directly to the highest level of management. The DPO should be protected from punishment for identifying organizational deficiencies or objecting to non-compliant practices. Where management does not follow the DPO’s recommendation, the DPO should document the reasons in writing.

Conflict of Interest

The draft guidance cautions against appointing individuals who determine the purposes and means of processing as DPO, including the chief executive officer, chief operating officer, chief financial officer, head of marketing, or head of human resources. It draws a distinction between general IT support personnel, who may serve as DPO, and senior IT leaders who decide what systems to use or what data to centralize, whose appointment may create a conflict. For organizations with limited personnel, the draft allows some flexibility but recommends assigning monitoring functions to another department to preserve neutrality.

Structuring Options for the DPO Role

The draft guidance recognizes several possible DPO structures:

  • In-house DPO. Appropriate for medium or large organizations with complex internal systems; organizations should avoid appointing someone who decides how personal data is used.
  • Outsourced DPO. Appropriate where specialist expertise or limited internal resources exist; organizations should define access rights, response responsibilities, and internal coordination arrangements.
  • Group DPO. May be appointed for companies within the same corporate group; the DPO must be easily contactable by each company and understand each business’s context.
  • Voluntary DPO. Organizations appointing a DPO voluntarily should still comply with the standards applicable to DPOs under the law.

DPO Operational Role and Accountability Framework

The DPO should be involved from the system design or new project planning stage to support privacy by design. The DPO serves as a key accountability mechanism, providing advice, monitoring compliance, coordinating with relevant stakeholders, and maintaining confidentiality, while responsibility for compliance remains with the organization. The organization should support the DPO with adequate resources, independence, access to necessary information, and direct reporting to senior management. Where breach notification is required, the notification should include the DPO’s name, contact location, and contact method, along with information on the breach, potential impacts, and measures taken or to be taken to prevent, stop, correct, or remediate the breach.

Outlook

Organizations should map their processing activities, confirm whether any DPO appointment trigger applies, and review reporting lines, job descriptions, and governance documents to ensure DPO independence, adequate resources, and senior management access. Any current or proposed DPO role should be assessed for conflicts of interest.

Organizations using an outsourced or group DPO should document access rights, scope of work, escalation processes, and data-subject response arrangements. Privacy notices and public contact points should be updated, and the DPO should be integrated into DPIAs, product reviews, ROPA governance, training, and breach response.

The draft guidance shows that DPO governance is increasingly becoming an operational compliance issue in Thailand. Organizations should not treat DPO appointment as a formality but should note the draft guidance’s emphasis on functional independence, contactability, conflict management, and documented escalation when the organization declines to follow the DPO’s advice. Reviewing DPO arrangements against these expectations now—while the guidance is still open for consultation—will leave organizations better positioned once it is finalized.

RELATED INSIGHTS​ 

November 7, 2025
Thailand and the United States signed a memorandum of understanding (MOU) titled “Cooperation to Diversify Global Critical Minerals Supply Chains and Promote Investments” on October 26, 2025, signaling a new strategic alignment aimed at developing Thailand’s mineral sector, particularly in rare earth elements (REEs). The MOU has implications for investments in technology, manufacturing, and other related sectors. This update outlines the key provisions of the MOU and the potential opportunities and legal navigating points for businesses. Objectives The primary driver of this agreement is the US initiative to diversify global supply chains for critical minerals and reduce reliance on current market leaders, particularly China. For Thailand, it represents a major opportunity to attract high-tech investment and develop its downstream processing industries. The cooperation is set to focus on five main areas: Technical knowledge: Exchange of technical expertise and international best practices to strengthen Thailand’s mining and processing sector. Joint cooperation: Establishing workshops, seminars, and scientific collaboration to boost innovation. Regulatory practice: Promoting good governance and streamlining regulatory and licensing procedures. Information sharing: Sharing data on potential projects and global market prices. Full-value chain: The MOU covers the entire mineral lifecycle, from exploration and extraction to processing, refining, and recycling. “First Opportunity to Invest” Clause The most debated provision within the MOU states that “participants expect to have the first opportunity to invest . . . in critical minerals assets that may be sold in Thailand.” Business implications: This clause is widely interpreted as granting US companies a first look or preferential access to investment opportunities in Thailand’s critical minerals sector. This could be a significant advantage for US-based or affiliated companies in mining, technology, and energy seeking to secure a foothold in a developing REE supply chain. Thai government position: Thai officials, including the prime minister, have publicly clarified
October 31, 2025
On September 29, 2025, Thailand’s Office of the Personal Data Protection Committee (PDPC Office) published its Regulations on the Review and Certification of Binding Corporate Rules B.E. 2568 (2025) (the Regulations). The Regulations provide clarity on the PDPC Office’s approach to reviewing and certifying binding corporate rules (BCRs) under Section 29 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA), and aim to facilitate international data transfers within a group of undertakings or enterprises (a “corporate group”). In conjunction with this development, the PDPC Office also approved BCRs for two companies operating in Thailand on September 30, 2025. This milestone represents the first concrete progress since the PDPC’s Notification on Criteria for the Protection of Personal Data Sent or Transferred to a Foreign Country pursuant to Section 29 of the PDPA B.E. 2566 (2023) came into effect in March 2024. Some key features of the Regulations are set out below. Categorization of BCRs BCRs are classified into two types: (1) BCRs for Controllers (BCR-C) and (2) BCRs for Processors (BCR-P). The category must be clearly specified when submitting the BCRs to the PDPC Office. Documentation Requirement The applicant must prepare and submit the application (a standard template may be provided by the PDPC Office in the future) along with supporting documents for review and certification in the Thai language. If the supporting documents are in a foreign language, a certified Thai translation should be provided. The translation must be notarized by a notary public or qualified person. Supporting documents may include, among others, a binding instrument such as an intra-group agreement, or a list of entities subject to the BCRs. Expedited Process Requirement Organizations with existing BCR approvals under the EU or UK GDPR, or from countries announced by the PDPC under Section 28, may apply through an
October 26, 2025
AI-generated songs are now making waves in Vietnam on platforms like TikTok, with tracks such as “Say mot doi vi em” quickly gaining popularity and sparking widespread attention. This phenomenon raises a host of legal and ethical questions: Who is the author of these songs? Can they be protected by copyright? Who is responsible if there is an infringement? These questions are becoming increasingly urgent as AI music becomes more mainstream in Vietnam. Copyright Protection for AI-Generated Music in Vietnam Under current Vietnamese law, copyright protection is reserved for works that bear the mark of human creativity. The 2022 amendments to Vietnam’s Intellectual Property Law reaffirm that only works created by humans are eligible for copyright. In practice, if a human meaningfully contributes to the creative process—by providing prompts, making selections, editing, or arranging—their contribution may be protected. However, if a song is generated entirely by AI without significant human input, it is unlikely to qualify for copyright protection. When an AI-generated song does not qualify for copyright protection, the question arises as to whether the person who writes the prompts, edits, or compiles the work can still be considered the owner of an asset under the Vietnamese Civil Code. According to Article 105 of the Civil Code 2015, assets include objects, money, valuable papers, and property rights. While AI-generated music that is not protected by copyright is not considered money or valuable papers, it may be regarded as an object (in the form of a digital file or recording) or as a property right if it can be possessed, used, transferred, or exploited for value. Use of AI-Generated Works Without Copyright Protection If a song is not protected by copyright, does that mean anyone can use it freely? Not necessarily. The absence of copyright does not mean the
October 3, 2025
On September 26, 2025, the Contract Committee under Thailand’s Consumer Protection Board issued a regulation that aims to standardize contracts and enhance consumer protection within the beauty and wellness industry. The Notification on Prescribing the Beauty Service Business as a Contract-Controlled Business B.E. 2568 (2025), which takes effect on January 24, 2026, requires business operators to use a prescribed standard contract in Thai and adhere to strict mandatory provisions and prohibitions. These regulations apply to operators across all in-person and online service channels, including via digital platforms. “Beauty services business” is defined as the provision of services under an agreement allowing consumers to receive a series of treatments, either over a set number of sessions or within a set period. This includes massage, spa, other methods for cleanliness, beauty, or care of facial or body skin, and weight control and body shaping—including services offered electronically. The law excludes surgery, liposuction, and medical treatments performed by licensed practitioners. The notification establishes the following key requirements: Mandatory contract and formatting. All contracts with consumers must use the standard contract form, in Thai, with clear, readable text (minimum font size of 2 millimeters, no more than 11 characters per inch), and include all essential terms from the annexed form. Contract execution. Contracts must be made in duplicate, with one copy given to the consumer at signing. For agreements concluded through electronic channels, the process must comply with the Electronic Transactions Act and use the same required terms. Digital platforms. Business operators who provide services facilitated through a digital platform as an intermediary are ultimately responsible for ensuring the consumer receives a compliant contract. Prohibited clauses. The law prohibits clauses that limit or exclude liability for damages to life, body, health, mind, or property resulting from breach of contract or a wrongful act;