You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 5, 2020

Thailand’s Personal Data Protection Act: A Guide to the Partial Compliance Extension

In May 2020, the Thai Cabinet approved a royal decree granting a one-year exemption from certain provisions of the Personal Data Protection Act 2019 (PDPA), which had been scheduled to take full effect on May 27, 2020. The new decree has extended the effective date for a number of the law’s provisions to May 31, 2021.

Key Elements of the Extension

Under the decree, certain critical provisions of the PDPA are not enforceable against exempted businesses (see list below) during the extension period, including the following:

  • General requirements and obligations on data controllers. Specifically, the postponed enforcement covers consent requirements, notification requirements, establishment of lawful basis, requirements on the collection of personal data from other sources, and processing of minors’ personal data. The enforcement of a second list of requirements is also postponed, including observance of data subjects’ rights and data erasure or destruction requirements, the implementation of appropriate internal security measures to prevent unauthorized access (section 37 (1)), provision of data breach notifications, appointment of data protection officers (DPOs), filing complaints, and penalties.
  • The grandfather provision (section 95) is also within the scope of the extension. This means that personal data collected or processed during the extension period will not be subject to the requirements enumerated in the second list above when they come into force in 2021. Furthermore, this data can be retained and used after the extension period has lapsed, provided that doing so is within the original purposes stated for collecting and processing the personal data. It is especially important to note that the scope of the grandfather provision does not include disclosure of personal data or processing of personal data outside of the original purposes stated.

However, as required by section 4, data controllers must still implement a minimum level of security protection measures for personal data in accordance with the standards to be prescribed by the Ministry of Digital Economy and Society, expected later this year.

It should also be noted that the requirement for the regulator to issue supplemental notifications and regulations is not within the scope of the extension. The Personal Data Protection Commission (PDPC) is therefore expected to continue issuing these supplemental measures during the extension period.

Exempted Businesses

The list of exempted businesses, below, covers a wide range of sectors and industries, and applies regardless of location:

  • Agriculture
  • Industrial businesses
  • Commerce
  • Medical and public health businesses
  • Energy, steam, water, waste disposal, and related businesses
  • Construction
  • Repair and maintenance
  • Transportation, logistics, and warehousing
  • Tourism
  • Communication, telecommunications, computers, and digital enterprises
  • Financial, banking, and insurance enterprises
  • Real estate
  • Professional practice
  • Administration and support
  • Science and technology, academia, social welfare, and arts
  • Education
  • Entertainment and recreation
  • Security
  • Household operations and SMEs that cannot be classified
  • Government agencies
  • Foreign government agencies and international organizations
  • Foundations, associations, and religious and nonprofit organizations

What to Do Now

In addition to staying up to date on the issuance and implementation of supplemental notifications and regulations under the PDPA over the coming year, businesses should make use of the additional time to prepare for compliance. A sample framework for doing so is provided below.

Step 1: Identify the personal data currently possessed by the company

Estimated timeframe: 1–3 months

In this stage, it is important to understand the PDPA’s requirements and conduct self-assessments to identify an entity’s current and anticipated personal data processing activities. To identify the main processing activities, companies should answer the five Ws:

  • Who are the relevant data subjects and the responsible personnel?
  • What types of personal data are collected and processed, and what are the sources?
  • When is the personal data collected and updated, and how long is it retained?
  • Where is the physical and digital data stored and transferred to (i.e. within Thailand or overseas)?
  • Why is the personal data being collected or processed?

This should be a reported in an internal assessment to aid widespread understanding of the practice—especially the original purpose for collecting or processing the personal data—within the organization.

Gaps and mitigation measures should also be identified, including:

  • processing activities that require consent as the lawful basis;
  • processing activities that can rely on another lawful basis (e.g. “legitimate interest”);
  • relevant retention periods pertaining to the various types of personal data; and
  • list of data processors, the scope of their data processing activities, and relevant personal data pertaining to the activities.

Step 2: Close the gaps and monitoring for new subordinate regulations

Estimated Timeframe: 2-4 months for closing gaps, monitoring ongoing until May 31, 2021

In this stage, organizations should monitor the issuance and development of new subordinate legislation—including through public hearings—to ensure that they are aware of their compliance obligations. At the same time, it will be necessary to focus also on closing the gaps identified in Step 1 by implementing the necessary mitigation measures and putting measures in place to ensure operational compliance. This may include preparing the following:

Privacy policies for relevant data subjects. Where consent is identified as the lawful basis, consent forms must be prepared for the relevant data subjects (e.g. individual customers, employees, etc.).

  • A data processing agreement (or addendum) template to be arranged, proposed, and countersigned by the relevant data processors.
  • A record of processing activities.
  • A record of internal assessments where legitimate interest is to be relied upon as the lawful basis (noting that these should be carried out in consideration of organizational conflicts of interest).
  • Plans for a DPO or DPO team, depending on the size of the operation and quantity of personal data involved, and in accordance with the DPO qualifications prescribed by the PDPC.
  • A custom internal training program, addressing current gaps and relevant parties in the context of the new legal requirements.
  • Internal rules forbidding collection of personal data without justification or lawful basis, or that is not necessary for business operations. Any personal data of this type that is currently being processed should also be deleted at this time.

When the subordinate laws on data subject rights become publicly available, it will be necessary to examine the requirements and set up a process for managing requests to uphold data subject rights, as well as data controller and processor obligations under the PDPA.

Achieving Compliance on Schedule

By following these steps, organizations can ensure that they will be fully compliant when the extension period ends on May 31, 2021. The estimated timeframes of the various steps listed above can give an idea of how long each step will take, but the actual schedules should be determined based on the level of PDPA readiness within the organization, the scale of implementation, and any future developments of the subordinate legislation under the PDPA. Companies should work closely with local legal counsel to ensure that their compliance measures are on track, and will be effective when the law comes into force.

Tilleke & Gibbins will continue to monitor the development of the PDPA and provide updates as they emerge. If you have questions about the PDPA, or any other aspect of data compliance in Thailand, please do not hesitate to contact any member of the PDPA team, including Athistha (Nop) Chitranukroh at [email protected] or Nopparat Lalitkomon at [email protected].

RELATED INSIGHTS​ 

January 6, 2025
On December 24, 2024, the government of Vietnam issued Decree No. 163/2024/ND-CP, providing guidelines for implementing the new Telecommunications Law that took effect on July 1, 2024 (“Decree 163”). This new decree replaces Decree No. 25/2011/ND-CP and its amendments (“Decree 25”) and took effect immediately upon issuance, with regulations on data center services, cloud computing services, and basic telecom services over the internet (“over-the-top” or OTT telecom services) having an official effective date of January 1, 2025. Decree 163 introduces substantial changes across the telecom sector, covering various aspects including service provision, licensing, standards and technical regulations, quality, passive infrastructure planning, dispute resolution, and more. Hence, it is necessary for enterprises to conduct a compliance review to identify gaps between the new decree and their business models, and take necessary steps to ensure lawful business operations in Vietnam. Below are some highlights of Decree 163. Expanded Scope of Services For basic telecom services, Decree 163 has introduced machine-to-machine (M2M) communication and classified it as a basic telecom service. This establishes a regulatory framework for IoT device communication, previously unregulated in Decree 25. For value-added telecom services, in light of the new Telecommunications Law, Decree 163 provides more detailed regulations for new telecom services such as data center services, cloud computing services, and OTT telecom services, which were not addressed in Decree 25. Regulation of Three New Telecom Services Expanding on the Telecommunications Law’s definitions of data center services, cloud computing services, and OTT telecom services, Decree 163 applies a light-touch management approach to regulate these three new services, as follows: Offshore providers: Cross-border service providers are exempt from signing commercial agreements with licensed local telecom companies. They only need to notify the Vietnam Telecommunications Authority (VNTA) using the prescribed procedures and forms before offering services. Onshore providers: The foreign
December 24, 2024
On November 30, 2024, the Data Law was officially promulgated after an accelerated preparation process that began in February 2024. The Data Law is set to take effect on July 1, 2025. Having extraterritorial effect, the Data Law will impact both local and foreign individuals and enterprises. As noted in our previous legal update, the Data Law governs digital data, the National Data Center, the National General Database, digital data products and services, digital data management, and the rights, obligations, and responsibilities of agencies, organizations, and individuals related to digital data activities. This legal update provides an overview of the Data Law, with a deep focus on the key provisions likely to impact businesses operating or offering services in Vietnam. New Data Definition and Classification The Data Law broadly defines “digital data” as data about objects, phenomena, and events, which can include one or a combination of audio, images, numbers, text, or symbols represented in digital format (hereinafter referred to as “data”). This definition is very broad and potentially covers any information recorded or represented in digital forms, including personal and nonpersonal data (such as business data, transactional data, trade secrets, etc.). Data is further categorized into different types that can be used by public bodies. However, the rights and obligations associated with each type of data are not clearly addressed. The data classification criteria include: The nature of data sharing (shared data, private data, open data); The importance of data (core data, important data, and other data); Any other criteria to meet the requirements of data administration, processing, and protection, as determined by the data owner. While the Data Law requires private organizations to categorize data based on its level of importance, it still grants these organizations the right to categorize data based on other criteria. Cross-Border Data
December 12, 2024
Vietnam is a world leader in blockchain adoption and growth, appearing near the top of most rankings of cryptocurrency ownership and blockchain investment. Although the country has taken a cautious approach toward cryptocurrency (banning the use of cryptocurrencies like Bitcoin as a means of payment, for example), the government actively supports blockchain technology and its applications in non-financial sectors. Recognizing blockchain as a core technology of the Fourth Industrial Revolution, as a part of Vietnam’s broader digital transformation agenda, the government issued Decision No. 1236/QD-TTg on October 22, 2024, providing the National Strategy for Blockchain Application and Development to 2025, with Orientation to 2030. Like the National Strategy on Digital Infrastructure, the National Strategy on Blockchain outlines a very ambitious vision to position Vietnam as a regional leader in blockchain technology. The strategy aims for Vietnam to master and apply blockchain across all socio-economic sectors, supporting the nation’s goal of becoming a stable and prosperous digital nation by 2030. The specific goals set for 2025 include developing Vietnam’s blockchain infrastructure and ensuring compliance with cybersecurity and data protection laws; advancing blockchain research through three national innovation centers; building and upgrading 10 facilities dedicated to blockchain research and workforce training; and expanding blockchain education by integrating it into university programs. The strategy also aims to establish at least one blockchain center, special zone, or area, as a pilot, to build a national blockchain network; and foster a blockchain ecosystem by promoting its application across sectors such as banking and finance, transportation, healthcare, education and training, commerce, logistics, postal services, industrial production, energy, tourism, agriculture, public services, and more. The goals for 2030 include strengthening Vietnam’s national blockchain infrastructure to support both domestic and international services, positioning Vietnam as a global and regional leader in blockchain research, application, and development. The
December 11, 2024
On November 30, 2024, the National Assembly of Vietnam issued a new Law on Data (“Data Law”), the first of its kind in the country. Initiated by a legislative proposal in February 2024, the Data Law underwent an accelerated preparation process and was officially promulgated just nine months later. It is worth noting that the Data Law is not the same as the Personal Data Protection Law, which is still in draft form and is expected to be submitted to the National Assembly in November 2025. The scope of application of the Data Law is broader, including not only personal data but also other types of data. The Data Law governs digital data, the National Data Center, the National General Database, digital data products and services, digital data management, and the rights, obligations, and responsibilities of agencies, organizations, and individuals related to digital data activities. Set to take effect on July 1, 2025, the Data Law is expected to have a significant impact on businesses involved in data-processing activities. Below are some key takeaways from this pivotal legislation. Cross-Border Data Transfer and Processing The Data Law recognizes and protects the freedom of cross-border data transfer and processing, as well as the legitimate rights and interests of relevant agencies, organizations, and individuals. The government is assigned the responsibility to provide detailed regulations on cross-border data transfer and processing activities, including the transfer of offshore data into Vietnam. National Data Center Resolution No. 175/NQ-CP issued by the Vietnamese government in October 2023 set out ambitious goals for a new National Data Center, which will integrate and manage human-related data from the national database, databases of ministries and central and local authorities, and other databases. The National Data Center is expected to be a core platform to provide data-related services, support policy