You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 5, 2020

Thailand’s Personal Data Protection Act: A Guide to the Partial Compliance Extension

In May 2020, the Thai Cabinet approved a royal decree granting a one-year exemption from certain provisions of the Personal Data Protection Act 2019 (PDPA), which had been scheduled to take full effect on May 27, 2020. The new decree has extended the effective date for a number of the law’s provisions to May 31, 2021.

Key Elements of the Extension

Under the decree, certain critical provisions of the PDPA are not enforceable against exempted businesses (see list below) during the extension period, including the following:

  • General requirements and obligations on data controllers. Specifically, the postponed enforcement covers consent requirements, notification requirements, establishment of lawful basis, requirements on the collection of personal data from other sources, and processing of minors’ personal data. The enforcement of a second list of requirements is also postponed, including observance of data subjects’ rights and data erasure or destruction requirements, the implementation of appropriate internal security measures to prevent unauthorized access (section 37 (1)), provision of data breach notifications, appointment of data protection officers (DPOs), filing complaints, and penalties.
  • The grandfather provision (section 95) is also within the scope of the extension. This means that personal data collected or processed during the extension period will not be subject to the requirements enumerated in the second list above when they come into force in 2021. Furthermore, this data can be retained and used after the extension period has lapsed, provided that doing so is within the original purposes stated for collecting and processing the personal data. It is especially important to note that the scope of the grandfather provision does not include disclosure of personal data or processing of personal data outside of the original purposes stated.

However, as required by section 4, data controllers must still implement a minimum level of security protection measures for personal data in accordance with the standards to be prescribed by the Ministry of Digital Economy and Society, expected later this year.

It should also be noted that the requirement for the regulator to issue supplemental notifications and regulations is not within the scope of the extension. The Personal Data Protection Commission (PDPC) is therefore expected to continue issuing these supplemental measures during the extension period.

Exempted Businesses

The list of exempted businesses, below, covers a wide range of sectors and industries, and applies regardless of location:

  • Agriculture
  • Industrial businesses
  • Commerce
  • Medical and public health businesses
  • Energy, steam, water, waste disposal, and related businesses
  • Construction
  • Repair and maintenance
  • Transportation, logistics, and warehousing
  • Tourism
  • Communication, telecommunications, computers, and digital enterprises
  • Financial, banking, and insurance enterprises
  • Real estate
  • Professional practice
  • Administration and support
  • Science and technology, academia, social welfare, and arts
  • Education
  • Entertainment and recreation
  • Security
  • Household operations and SMEs that cannot be classified
  • Government agencies
  • Foreign government agencies and international organizations
  • Foundations, associations, and religious and nonprofit organizations

What to Do Now

In addition to staying up to date on the issuance and implementation of supplemental notifications and regulations under the PDPA over the coming year, businesses should make use of the additional time to prepare for compliance. A sample framework for doing so is provided below.

Step 1: Identify the personal data currently possessed by the company

Estimated timeframe: 1–3 months

In this stage, it is important to understand the PDPA’s requirements and conduct self-assessments to identify an entity’s current and anticipated personal data processing activities. To identify the main processing activities, companies should answer the five Ws:

  • Who are the relevant data subjects and the responsible personnel?
  • What types of personal data are collected and processed, and what are the sources?
  • When is the personal data collected and updated, and how long is it retained?
  • Where is the physical and digital data stored and transferred to (i.e. within Thailand or overseas)?
  • Why is the personal data being collected or processed?

This should be a reported in an internal assessment to aid widespread understanding of the practice—especially the original purpose for collecting or processing the personal data—within the organization.

Gaps and mitigation measures should also be identified, including:

  • processing activities that require consent as the lawful basis;
  • processing activities that can rely on another lawful basis (e.g. “legitimate interest”);
  • relevant retention periods pertaining to the various types of personal data; and
  • list of data processors, the scope of their data processing activities, and relevant personal data pertaining to the activities.

Step 2: Close the gaps and monitoring for new subordinate regulations

Estimated Timeframe: 2-4 months for closing gaps, monitoring ongoing until May 31, 2021

In this stage, organizations should monitor the issuance and development of new subordinate legislation—including through public hearings—to ensure that they are aware of their compliance obligations. At the same time, it will be necessary to focus also on closing the gaps identified in Step 1 by implementing the necessary mitigation measures and putting measures in place to ensure operational compliance. This may include preparing the following:

Privacy policies for relevant data subjects. Where consent is identified as the lawful basis, consent forms must be prepared for the relevant data subjects (e.g. individual customers, employees, etc.).

  • A data processing agreement (or addendum) template to be arranged, proposed, and countersigned by the relevant data processors.
  • A record of processing activities.
  • A record of internal assessments where legitimate interest is to be relied upon as the lawful basis (noting that these should be carried out in consideration of organizational conflicts of interest).
  • Plans for a DPO or DPO team, depending on the size of the operation and quantity of personal data involved, and in accordance with the DPO qualifications prescribed by the PDPC.
  • A custom internal training program, addressing current gaps and relevant parties in the context of the new legal requirements.
  • Internal rules forbidding collection of personal data without justification or lawful basis, or that is not necessary for business operations. Any personal data of this type that is currently being processed should also be deleted at this time.

When the subordinate laws on data subject rights become publicly available, it will be necessary to examine the requirements and set up a process for managing requests to uphold data subject rights, as well as data controller and processor obligations under the PDPA.

Achieving Compliance on Schedule

By following these steps, organizations can ensure that they will be fully compliant when the extension period ends on May 31, 2021. The estimated timeframes of the various steps listed above can give an idea of how long each step will take, but the actual schedules should be determined based on the level of PDPA readiness within the organization, the scale of implementation, and any future developments of the subordinate legislation under the PDPA. Companies should work closely with local legal counsel to ensure that their compliance measures are on track, and will be effective when the law comes into force.

Tilleke & Gibbins will continue to monitor the development of the PDPA and provide updates as they emerge. If you have questions about the PDPA, or any other aspect of data compliance in Thailand, please do not hesitate to contact any member of the PDPA team, including Athistha (Nop) Chitranukroh at [email protected] or Nopparat Lalitkomon at [email protected].

RELATED INSIGHTS​ 

January 16, 2025
On January 13, 2025, Thailand’s cabinet approved in principle the draft Entertainment Complex Act, as proposed by the Ministry of Finance. This landmark legislative proposal, which would allow casinos as part of larger “entertainment complexes,” will now proceed through further parliamentary review and approval. Key provisions of the draft act are described below. Corporate structure: Entertainment complexes must be operated by Thai-registered limited companies or public limited companies with a minimum paid-up capital of THB 10 billion. Directors of the licensed entity must be individuals and have the qualifications and none of the prohibited characteristics specified in the draft act. The draft act does not impose restrictions on foreign-majority ownership structures; however, it is worth monitoring whether any amendments addressing this matter are introduced during the legislative process. Operating conditions: Each entertainment complex must be located in an area designated under a royal decree. It must also include at least four types of entertainment businesses listed in the annex to the draft act (e.g., shopping mall, hotel, sports stadium, amusement park), along with a casino. The allocation of casino space must comply with regulations to be specified at a later date. Licensing conditions: Licenses will be valid for 30 years, renewable in increments of up to 10 years. The license issuance fee is THB 5 billion, the annual fee is THB 1 billion, and the renewal fee is THB 5 billion. The Entertainment Complex Policy Committee, chaired by the prime minister, will review and approve applications. Online gambling restrictions: Licensees are prohibited from offering gambling through internet-connected systems or electronic devices that allow access from outside the casino premises. Labor requirements: Thai and foreign employee ratios must adhere to prescribed regulations. Land privileges: Lease agreements for land use are limited to 50 years. Renewal is permitted for up to
January 13, 2025
The State Bank of Vietnam’s Circular No. 50/2024/TT-NHNN regulating safety and security for the provision of online services in the banking sector (“Circular 50”), issued on October 31, 2024, took effect on January 1, 2025, with delayed effectiveness for certain provisions on (i) network, communication, and security systems, online banking application software, and mobile banking application software (July 1, 2025); (ii) transaction confirmation for payment transactions conducted via the straight-through processing method (January 1, 2026); and (iii) authentication forms and reporting obligations (July 1, 2026). The cybersecurity situation in Vietnam is complicated, and the banking and finance sector has been one of the top targets of high-tech criminals. Circular 50 seeks to enhance user protection by expanding the technical requirements to more services in the banking sector as well as standardizing how transactions are authenticated. Expanded Scope of Services Covered Previous regulations on safety and security of online services in the banking sector only covered banking services and intermediary payment services. Circular 50 expands the scope to include other services of credit institutions and foreign bank branches such as credit information services, foreign exchange services, securities depository services, and services related to factoring and letters of credit, which now need to comply with technical requirements and standards for online services such as firewalls and DMZ network barriers. Risk-Based Approach to Authentication Circular 50 sets out standards for payment transactions and card transactions by: Classifying various online transactions based on the type of client, the purpose of the transfer, the value of the specific transaction, and the total value of certain transactions during the day; and Applying various types of authentication for the corresponding types of online transactions, e.g., using passwords or PINs for small-value online transactions, and using OTPs (through SMS, voice, or email), biometric matching, or e-signatures for
January 10, 2025
On January 8, 2025, Thailand’s Office of the Personal Data Protection Committee published two notifications in the Government Gazette—one for data controllers and the other for data processors—concerning exemptions for data controllers and data processors from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019). The notification for data processors took effect on January 9, 2025, the day after its publication. The notification for data controllers will take effect on April 8, 2025. The content of these notifications is identical to that in the draft versions of the notifications previously released for public consultation in October 2024. For more information on the ROPA exemptions for data controllers and data processors, or on any aspect of personal data protection in Thailand, please contact Nopparat Lalitkomon at [email protected] or Wilin Somya at [email protected].
January 9, 2025
On January 1, 2025, Myanmar’s State Administration Council enacted Cybersecurity Law No. 1/2025, which aims to regulate various aspects of digital security and online activities. The law has not yet been implemented and will come into force on a date specified by the Myanmar president, who will also provide an official adoption and compliance timeline for individuals and organizations impacted by the new regulations. Below are some of the key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The