You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 5, 2020

Thailand’s Personal Data Protection Act: A Guide to the Partial Compliance Extension

In May 2020, the Thai Cabinet approved a royal decree granting a one-year exemption from certain provisions of the Personal Data Protection Act 2019 (PDPA), which had been scheduled to take full effect on May 27, 2020. The new decree has extended the effective date for a number of the law’s provisions to May 31, 2021.

Key Elements of the Extension

Under the decree, certain critical provisions of the PDPA are not enforceable against exempted businesses (see list below) during the extension period, including the following:

  • General requirements and obligations on data controllers. Specifically, the postponed enforcement covers consent requirements, notification requirements, establishment of lawful basis, requirements on the collection of personal data from other sources, and processing of minors’ personal data. The enforcement of a second list of requirements is also postponed, including observance of data subjects’ rights and data erasure or destruction requirements, the implementation of appropriate internal security measures to prevent unauthorized access (section 37 (1)), provision of data breach notifications, appointment of data protection officers (DPOs), filing complaints, and penalties.
  • The grandfather provision (section 95) is also within the scope of the extension. This means that personal data collected or processed during the extension period will not be subject to the requirements enumerated in the second list above when they come into force in 2021. Furthermore, this data can be retained and used after the extension period has lapsed, provided that doing so is within the original purposes stated for collecting and processing the personal data. It is especially important to note that the scope of the grandfather provision does not include disclosure of personal data or processing of personal data outside of the original purposes stated.

However, as required by section 4, data controllers must still implement a minimum level of security protection measures for personal data in accordance with the standards to be prescribed by the Ministry of Digital Economy and Society, expected later this year.

It should also be noted that the requirement for the regulator to issue supplemental notifications and regulations is not within the scope of the extension. The Personal Data Protection Commission (PDPC) is therefore expected to continue issuing these supplemental measures during the extension period.

Exempted Businesses

The list of exempted businesses, below, covers a wide range of sectors and industries, and applies regardless of location:

  • Agriculture
  • Industrial businesses
  • Commerce
  • Medical and public health businesses
  • Energy, steam, water, waste disposal, and related businesses
  • Construction
  • Repair and maintenance
  • Transportation, logistics, and warehousing
  • Tourism
  • Communication, telecommunications, computers, and digital enterprises
  • Financial, banking, and insurance enterprises
  • Real estate
  • Professional practice
  • Administration and support
  • Science and technology, academia, social welfare, and arts
  • Education
  • Entertainment and recreation
  • Security
  • Household operations and SMEs that cannot be classified
  • Government agencies
  • Foreign government agencies and international organizations
  • Foundations, associations, and religious and nonprofit organizations

What to Do Now

In addition to staying up to date on the issuance and implementation of supplemental notifications and regulations under the PDPA over the coming year, businesses should make use of the additional time to prepare for compliance. A sample framework for doing so is provided below.

Step 1: Identify the personal data currently possessed by the company

Estimated timeframe: 1–3 months

In this stage, it is important to understand the PDPA’s requirements and conduct self-assessments to identify an entity’s current and anticipated personal data processing activities. To identify the main processing activities, companies should answer the five Ws:

  • Who are the relevant data subjects and the responsible personnel?
  • What types of personal data are collected and processed, and what are the sources?
  • When is the personal data collected and updated, and how long is it retained?
  • Where is the physical and digital data stored and transferred to (i.e. within Thailand or overseas)?
  • Why is the personal data being collected or processed?

This should be a reported in an internal assessment to aid widespread understanding of the practice—especially the original purpose for collecting or processing the personal data—within the organization.

Gaps and mitigation measures should also be identified, including:

  • processing activities that require consent as the lawful basis;
  • processing activities that can rely on another lawful basis (e.g. “legitimate interest”);
  • relevant retention periods pertaining to the various types of personal data; and
  • list of data processors, the scope of their data processing activities, and relevant personal data pertaining to the activities.

Step 2: Close the gaps and monitoring for new subordinate regulations

Estimated Timeframe: 2-4 months for closing gaps, monitoring ongoing until May 31, 2021

In this stage, organizations should monitor the issuance and development of new subordinate legislation—including through public hearings—to ensure that they are aware of their compliance obligations. At the same time, it will be necessary to focus also on closing the gaps identified in Step 1 by implementing the necessary mitigation measures and putting measures in place to ensure operational compliance. This may include preparing the following:

Privacy policies for relevant data subjects. Where consent is identified as the lawful basis, consent forms must be prepared for the relevant data subjects (e.g. individual customers, employees, etc.).

  • A data processing agreement (or addendum) template to be arranged, proposed, and countersigned by the relevant data processors.
  • A record of processing activities.
  • A record of internal assessments where legitimate interest is to be relied upon as the lawful basis (noting that these should be carried out in consideration of organizational conflicts of interest).
  • Plans for a DPO or DPO team, depending on the size of the operation and quantity of personal data involved, and in accordance with the DPO qualifications prescribed by the PDPC.
  • A custom internal training program, addressing current gaps and relevant parties in the context of the new legal requirements.
  • Internal rules forbidding collection of personal data without justification or lawful basis, or that is not necessary for business operations. Any personal data of this type that is currently being processed should also be deleted at this time.

When the subordinate laws on data subject rights become publicly available, it will be necessary to examine the requirements and set up a process for managing requests to uphold data subject rights, as well as data controller and processor obligations under the PDPA.

Achieving Compliance on Schedule

By following these steps, organizations can ensure that they will be fully compliant when the extension period ends on May 31, 2021. The estimated timeframes of the various steps listed above can give an idea of how long each step will take, but the actual schedules should be determined based on the level of PDPA readiness within the organization, the scale of implementation, and any future developments of the subordinate legislation under the PDPA. Companies should work closely with local legal counsel to ensure that their compliance measures are on track, and will be effective when the law comes into force.

Tilleke & Gibbins will continue to monitor the development of the PDPA and provide updates as they emerge. If you have questions about the PDPA, or any other aspect of data compliance in Thailand, please do not hesitate to contact any member of the PDPA team, including Athistha (Nop) Chitranukroh at [email protected] or Nopparat Lalitkomon at [email protected].

RELATED INSIGHTS​ 

June 19, 2025
Thailand’s Electronic Transactions Development Agency (ETDA) has announced plans for increased enforcement of the Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022). The ETDA outlined a comprehensive enforcement framework and review process during an online meeting with digital platform service operators on June 11, 2025. The ETDA’s enhanced enforcement approach includes systematic reviews of notification submissions, formal correction orders, and potential criminal penalties for noncompliance. Digital platform operators should immediately assess their current notification status and prepare for increased regulatory scrutiny. Review and Amendment of Previously Submitted Notification Data The ETDA will begin reviewing operation notification forms and annual reports submitted by digital platform service operators to assess each platform’s risk level and develop tailored regulatory obligations. In this comprehensive review process, the ETDA will: Examine the accuracy and completeness of submitted notification data; Request additional information as needed by phone or email; and Issue formal orders as needed requiring operators to correct or complete missing information. Operators who fail to comply with ETDA orders may face suspension of operations, revocation of their notification receipt, and public disclosure of their noncompliant status on the ETDA’s website. The ETDA will conduct follow-up workshops in July 2025 for operators whose data remains unclear or incomplete. Enforcement Framework and Penalties The ETDA outlined a three-tiered enforcement framework with escalating consequences for different types of violations, as follows: Failure to notify before commencing operations: Operators who begin services without proper notification may face criminal penalties under the Electronic Transactions Act, including up to one year of imprisonment, fines of up to THB 100,000 (approx. USD 3,070), or both. Additional consequences include suspension of operations and potential liability for company directors. Failure to correct or comply with official orders: Noncompliance with ETDA correction
June 13, 2025
In today’s digital age, cyberattacks have become a real threat to organizations worldwide. These attacks can range from phishing and malware to ransomware and distributed denial of service (DDoS) attacks. As the frequency and sophistication of these attacks increase, so does the importance of cybersecurity compliance. In the corporate world, compliance refers to the process of ensuring that a company and its employees adhere to all relevant laws, regulations, standards, and ethical practices—but it should not stop there. Compliance should also encompass asset recovery and disciplinary measures, which can both help organizations address incidents effectively and promote good governance. Cyberattacks are malicious attempts to access or damage a computer system or network, often carried out for financial gain, for political activism, or simply to cause disruption. For instance, a successful attack might involve an attacker creating an email address that closely resembles a legitimate one, perhaps by changing only one or two characters. That email address is then inserted into an existing conversation thread, making it appear as if the user with this email address was already part of the discussion. This tactic can easily deceive a recipient into believing the email was sent from a trusted source, thereby leading them to click on malicious links, provide sensitive information, or even make payments in accordance with the attacker’s request or instructions. Phishing attacks like these are particularly dangerous and can have a serious impact on the ongoing business of a corporation because they exploit the trust and familiarity established in the original email chain. Effective Mitigation Approaches Mechanisms for addressing the aftermath of a crisis provide important recourse to affected organizations, but effective compliance mechanisms can minimize the risk of such crises ever occurring. Companies should therefore prioritize preventative measures and implementation of effective crisis management schemes. Various legal
May 28, 2025
Tilleke & Gibbins attorneys in Vietnam have contributed the 2025 edition of Doing Business in Vietnam, a comprehensive Q&A-style resource from Thomson Reuters Practical Law that provides essential insights for companies navigating business operations in Vietnam. The guide presents a detailed overview of the country’s legal framework and regulatory environment, reflecting recent updates in Vietnamese legislation and practice. This annually updated guide offers key information on the following areas: Legal system: Structure of the Vietnamese judiciary and the role of codified law. Foreign investment: Conditions for market access, licensing requirements, foreign ownership restrictions, and investment incentives. Business vehicles: Formation and operation of legal entities, including limited liability companies, joint-stock companies, and representative offices. Employment: Employment contracts, social insurance, labor rights, and procedures for hiring foreign nationals. Tax: Overview of corporate income tax, personal income tax, value-added tax, and other tax obligations. Intellectual property: Procedures for protecting and enforcing patents, trademarks, copyrights, and other IP rights. Data protection: Compliance requirements under Vietnam’s data privacy laws, including the Personal Data Protection Decree. Competition law: Antitrust rules and regulatory oversight under the Law on Competition. Anti-bribery and corruption: Legal framework and enforcement practices aimed at curbing corrupt activities. E-commerce and digital business: Regulations governing online platforms, digital content, and cross-border services. Marketing and advertising: Laws and guidelines on advertising standards and consumer protection. Product regulation and liability: Safety requirements, product liability issues, and roles of relevant authorities. Doing Business in Vietnam is part of Practical Law’s global series of legal guides designed to support international practitioners and businesses. To access the most recent edition of the Vietnam guide, visit the Practical Law website and sign up for a free trial.
May 28, 2025
Thailand’s Food and Drug Administration (FDA) has launched a strategic collaboration with leading e-commerce platforms Lazada and Shopee to strengthen regulatory oversight of health-related products sold online. This partnership is part of a broader initiative to enhance consumer protection, enforce compliance with Thai health regulations, and foster a safer digital marketplace for health products. As part of this initiative, the Thai FDA is urging all sellers—particularly cross-border vendors—to secure proper FDA registration for their products before market entry. The objective is to ensure that only legally authorized, safe, and quality-assured healthcare products are available to Thai consumers. In pursuit of this goal, the FDA has been working closely with Lazada and Shopee to implement proactive surveillance mechanisms aimed at identifying and removing noncompliant, substandard, or unregistered products. This collaboration has already yielded measurable results. Between September 2023 and 2024, Lazada supported regulatory enforcement by removing 9,454 noncompliant listings and delisting 30 vendors. In addition, 134 sellers were subjected to legal proceedings for regulatory violations. Shopee has taken a similarly rigorous stance, committing to the immediate removal of products found to be in breach of FDA regulations. The platform has also provided educational materials for merchants and implemented consumer complaint mechanisms to enhance accountability. Looking ahead, the Thai FDA plans to roll out a data integration system utilizing API technology, enabling seamless and secure exchange of regulatory data between the agency and e-commerce platforms. This system will be supported by comprehensive training for both Thai FDA officials and e-commerce staff, with a particular focus on the use of the Thai government’s Law Enforcement Request Portal, a secure communication channel for coordinating enforcement actions between government agencies and platform operators. Additionally, a joint product inspection framework is currently under development in partnership with Lazada and Shopee. This framework will incorporate strict