You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 3, 2025

Thailand’s PDPC Hosts Event to Promote Data Protection Awareness

On January 28, 2025, the Office of the Personal Data Protection Committee (PDPC) hosted Data Privacy Day 2025, bringing together over 1,000 participants from both the public and private sectors. The event underscored the importance of personal data protection and aimed to raise nationwide awareness while fostering a culture of compliance. During the event, the PDPC reaffirmed its commitment to strengthening Thailand’s data protection framework to align with international standards. The initiative also emphasized the collective goal of achieving zero data breaches.

During the first session of the event, Mr. Prasert Jantararuangtong, deputy prime minister and minister of digital economy and society, delivered a speech highlighting the role of personal data protection in fostering Thailand’s digital economy. He emphasized that strong data protection measures enhance business credibility, build consumer trust, and attract foreign investment. He also addressed the PDPC’s “zero data breach” policy and the ongoing issue of data leaks, which have been exploited by call-center scam operations to deceive the public and cause financial harm.

Additionally, Mr. Prasert announced that the Thai cabinet has approved a draft amendment to the Emergency Decree on Cyber Crime Prevention and Suppression B.E. 2566 (2023), commonly referred to as the “Cyber Crime Decree.” The draft will now proceed to the Council of State for review before its official enactment. Key provisions of the amendment include holding financial institutions, telecom providers, and social media platforms accountable for technology-related crimes; requiring compensation for victims; and enforcing stricter security measures. Cyber offenses, including personal data trading, face harsher penalties of up to THB 5 million in fines or five years of imprisonment. Authorities are also empowered to suspend suspicious SIM cards for committing illegal activities and expedite monetary refunds for victims without court approval.

In the second session, the Office of the PDPC presented its 2024 Privacy Maturity Model and Privacy Index report, summarizing key findings and developments in Thailand’s personal data protection landscape.

Privacy Maturity Model

The Privacy Maturity Model consists of assessment criteria designed to evaluate the readiness of government agencies and private entities in implementing personal data protection measures. The Privacy Maturity Model provides online self-assessment questionnaires for organizations to assess their compliance levels under the PDPA.

The model classifies organizations into five maturity levels based on compliance status and implementation of personal data protection measures:

  • Initial (Level 1) – Minimal compliance, with key legal requirements not yet fully implemented.
  • Managed (Level 2) – A structured approach to data protection is in place, but gaps remain in meeting full legal requirements.
  • Defined (Level 3) – Full compliance with legal requirements has been achieved in a systematic manner.
  • Measured (Level 4) – Ongoing performance monitoring and assessment have been implemented to enhance effectiveness.
  • Optimizing (Level 5) – Data protection practices are continuously refined and improved based on evaluation metrics.

The Privacy Maturity Model assesses organizations across 10 areas: oversight, policies and procedures, training and awareness, individuals’ rights, transparency, ROPA and lawful basis, contracts and data sharing, risk management, data security, and breach response and monitoring. The assessment aligns with the PDPA, covering both legal requirements and best practices.

Overall, the first-year Privacy Maturity Model assessment recorded an average score of 2.72 out of 5. In 2024, 142 entities participated in the assessment, including 69 government agencies and 31 private sector organizations, spanning various industries. The financial, investment, and insurance industries achieved the highest scores, with 47% of participating organizations scoring above the average. Across all categories, the highest-scoring areas were (1) Policies and Procedures (e.g., implementation of privacy policies), (2) Training and Awareness, and (3) Oversight. Conversely, the lowest-scoring areas were (1) contracts and data sharing (e.g., lack of safeguards for B2B and cross-border data sharing), (2) breach response and monitoring (e.g., absence of data breach handling policies or breach notification procedures), and (3) individuals’ rights (e.g., lack of identity verification before processing data subject requests).

Privacy Index

The key difference between the Privacy Index and the Privacy Maturity Model is that while the Privacy Maturity Model is an internal assessment based solely on self-assessment and internal data, the Privacy Index incorporates external data for a more comprehensive evaluation. The Privacy Index assigns scores on a scale of 0 to 100 and evaluates organizations using two types of data sources:

  • Primary data – Information obtained from questionnaires or evidence submitted by the organization.
  • Secondary data – Information collected from external sources, including reported data breaches, complaints filed with the PDPC, or publicly available information.

Overall, the average Privacy Index score was 51.03, with private-sector organizations scoring an average of 63.12, while the financial, investment, and insurance industries achieved the highest scores. The results suggest that organizations generally demonstrate a moderate level of personal data protection, complying with legal requirements to some extent. However, organizations should strive for more comprehensive compliance, with greater emphasis on preparing and maintaining ROPAs to identify potential risks and vulnerabilities and on enhancing data security measures based on these findings.

Outlook

The PDPC’s Data Privacy Day 2025 event highlighted the importance of personal data protection and set a clear direction for Thailand’s digital future. The implementation of the Privacy Maturity Model and Privacy Index provides organizations with valuable tools to assess and improve their data protection practices. As Thailand continues to strengthen its data protection framework, the collective efforts of the public and private sectors to put in place strong safeguards and procedures will help the country achieve the goal of zero data breaches.

RELATED INSIGHTS​ 

July 16, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) published a series of draft guidance documents for public consultation on July 7, 2026. Issued under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), the drafts address a range of compliance issues and offer insight into the regulator’s current enforcement priorities. This article examines two of those drafts: one on lawful bases for processing personal data, and another on marketing and direct marketing. Together, they reflect the Office of the PDPC’s evolving expectations on lawful-basis selection, accountability, and the use of personal data in marketing. Organizations operating in Thailand should assess the practical implications now, before the guidance is finalized. Lawful Bases: A Structured Selection Process The draft guidance on lawful bases introduces a systematic five-step process for selecting an appropriate lawful basis for each processing activity. Organizations are expected to: Identify the processing activity involved. Assess the appropriate lawful basis. Evaluate whether the data is necessary for the processing. Conduct a legitimate interest assessment (LIA) where applicable. Ensure transparency through privacy notices. The guidance provides practical explanations and examples for each lawful basis under section 24 of the PDPA—including archiving, research, statistics, vital interests, contractual necessity, legal obligation, public task, legitimate interests, and consent—as well as the bases applicable to sensitive personal data under section 26. The aim is to promote more consistent and accurate lawful-basis selection across public- and private-sector organizations. A recurring theme throughout the guidance is that organizations should select the lawful basis that most accurately reflects the actual purpose and circumstances of the processing activity. The guidance cautions against treating consent as a default or catch-all basis where another lawful basis is more appropriate. For processing based on legitimate interests, organizations should conduct and document an LIA. Processing involving sensitive personal data may require
July 14, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has published guidelines establishing a risk-based framework for the responsible use of artificial intelligence by telecom licensees. Released on July 2, 2026, the Guidelines on the Use of Artificial Intelligence for Telecommunications Services address governance structures, ethical principles, lifecycle management, and consumer protection obligations. Scope and Legal Context The nonbinding guidelines apply to holders of telecom business licenses under Thailand’s telecom licensing laws, but only with respect to the use of AI in providing licensed telecom services. Entities without such licenses are not directly subject to the guidelines, though they may be affected as third-party AI solution providers to licensees. The guidelines supplement and should be read alongside existing laws, including the Cybersecurity Act, the Personal Data Protection Act (PDPA), the Computer Crime Act, and the NBTC Notification regarding Measures to Protect Telecommunications Service Users’ Rights Regarding Personal Data, Privacy Rights, and Freedom of Telecommunications, as well as forthcoming AI governance legislation being drafted by the ETDA. AI Governance Structure Licensees are expected to establish committees, working groups, or designated officers at both policy and operational levels to set strategic direction for AI use, formulate governance policies and tools, and oversee risk management. Roles, responsibilities, and accountability should be clearly defined for all personnel across every stage of the AI lifecycle—including for third-party AI solution providers and outsourced service providers, whose obligations should be explicitly documented in service agreements. Core Principles The guidelines identify six core principles that licensees should adhere to when deploying AI: Compliance with laws, ethics, and international standards: AI should respect privacy, dignity, and human rights, and content filtering for inputs and outputs should be considered. For example, the AI should not be designed and developed to be used in generating false information, supporting illegal activities, or causing
July 10, 2026
Vietnam has taken a significant step in regulating its e-commerce sector with the issuance of a new decree guiding the country’s recently enacted Law on E-Commerce. Decree No. 248/2026/ND-CP, issued on June 30, 2026, and taking effect the following day, addresses mandatory platform policies, registration requirements for offshore platforms, additional obligations on platform operators, and market access conditions for foreign investors. Mandatory Policy Contents The decree sets out detailed guidance on the required contents of various platform policies, covering pricing, payment, display priority, livestream sales, delivery, returns, method of service provision, and service termination and refunds. Clarification of Obligations for Platform Operators The decree provides clarification of the obligations applicable to platform operators. Notably, intermediary e-commerce platform operators with online ordering functions must: Collect specific information to implement electronic identity verification of sellers; Cooperate with regulators by reporting online through the state e-commerce management system and by blocking, suspending, or removing content upon request of a competent authority; Maintain a mechanism to store contract data, including price, product or service information, and parties’ information, for at least three years from the date of contract conclusion; and If qualifying as a “large digital platform” under consumer protection law, maintain an online system for receiving and handling complaints and requests, and comply with enhanced content-removal requirements. Registration Requirements for Offshore Platforms Offshore e-commerce platforms, whether direct-sales, intermediary, social-network-based, or integrated, that conduct e-commerce activity in Vietnam must register with the Ministry of Industry and Trade if the platform: Allows Vietnamese-language selection; Uses a “.vn” domain; or Reaches 100,000 or more transactions with Vietnam-based buyers within a calendar year. Notably, the registration requirement now captures not only traditional intermediary platforms, but also direct-sales platforms. Foreign Investment Conditions Foreign investors holding a controlling interest in an intermediary e-commerce platform, a social media platform
July 8, 2026
On July 7, 2026, the Trade Competition Commission of Thailand (TCCT) issued a press release announcing the establishment of two new subcommittees designed to intensify oversight of digital platforms and modern trade businesses. The formation of the digital platform subcommittee marks a significant escalation in competition enforcement following the TCCT’s Guidelines on Multi-Sided Platforms and E-Commerce Businesses, which took effect on March 25, 2026. Platform operators, sellers, and related service providers should expect heightened regulatory scrutiny and potential investigations into practices already flagged under the March guidelines. Two Dedicated Enforcement Bodies The first new body is the digital platform subcommittee—formally the Subcommittee on Supervision, Monitoring, and Prevention of Trade Conduct in Digital Platform Business. It is tasked with driving intensive oversight of digital platform businesses. It will coordinate with government agencies, the private sector, business operators, and other relevant stakeholders to supervise and prevent trade conduct that may affect competition, and to promote free and fair competition in the digital platform sector. The subcommittee will be composed of TCCT members and representatives from the Department of Internal Trade. The second body—the Subcommittee on Determining Guidelines and Action Plans Concerning Competition Conditions in Modern Wholesale and Retail Business—will study, analyze, and monitor market structure in modern wholesale and retail businesses, compile databases to analyze retail business concentration, assess impacts on small-scale operators, and propose supervisory measures for the retail sector. TCCT members will serve on the subcommittee alongside experts from government and private organizations, including the Office of Industrial Economics, the Office of Small and Medium Enterprises Promotion, the Thai SME Federation, and the Thai SME Council. Operational Impact for Industry Participants These subcommittees provide the TCCT with a focused mechanism to investigate various trade practices deemed unfair, and the TCCT has authority under the Trade Competition Act to issue cease-and-desist