You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 24, 2019

Thailand’s Personal Data Protection Act – Requirements for Employers

Taylor Vinters – International Employment Law Update

If an employer collects employees’ personal information, the employer must comply with the Personal Data Protection Act (PDPA).

Thailand’s PDPA, which was enacted earlier this year, contains significant new requirements for employers that collect employees’ (called “data subjects” in the PDPA) personal information. Most sections of the PDPA will become effective on May 27, 2020, so employers should be aware of their duties and liabilities.

Important PDPA requirements that relate to employers include the following:

  • Employees’ personal information can be collected only to the limited extent necessary for the employer’s lawful purpose.
  • Employers cannot collect employees’ personal information from any source apart from the employees themselves.
  • Employers must prevent employees’ personal information from being disclosed, lost, or altered.
  • Employers must delete employees’ personal information after a certain time period.
  • Employers must receive consent from employees to collect, use, or disclose the employees’ personal information.
  • Employers must inform a special government-run Personal Data Committee if an employees’ personal information is leaked.

Employers who violate the PDPA could face civil or criminal liability, as well as administrative fines, depending on the claim and breach.

Civil Liability

If an offender is found to be civilly liable (e.g. an employee sues the employer for damages arising from a breach of the PDPA), the court can order the offender to pay punitive damages capped at twice the actual damages.

Criminal Liability

The PDPA also contains criminal liability for certain offences. Penalties are set at a maximum of six months’ imprisonment, a fine of up to THB 1 million (approximately EUR 30,000), or both. If the offender is a corporate entity, and the offence is committed because of an order or act by a director, manager, or any associated persons responsible for the act, those individuals would face criminal liability and be subject to the above penalties. Moreover, a person who has a duty to order or perform any act but fails to carry out his or her duty, resulting in the company committing an offence, is also criminally liable and subject to the above penalties.

Administrative liability

Companies can also face administrative fines for violation of the PDPA, which range from THB 500,000 to THB 5 million (approximately EUR 15,000 to EUR 150,000).

Comment

If an employer collects, uses, or discloses employees’ personal information, then the employer should be aware of the PDPA’s requirements. Otherwise, the employer can face criminal, civil, or administrative penalties.

RELATED INSIGHTS​ 

May 10, 2021
Attorneys from Tilleke & Gibbins’ offices in Myanmar, Thailand, and Vietnam have contributed chapters on labor law in these jurisdictions to the Global Employment Law Guide, published by Lex Mundi. The guide provides answers to key employment-related legal questions in 57 jurisdictions around the world, with all entries provided by member firms in the global Lex Mundi legal network. Each chapter contains in-depth information on the jurisdiction’s legal framework governing employment relationships, including coverage of the following topics: Employment categories and contract types Employee rights and protections Employment termination Leave and social benefits Restrictive covenants COVID-19 vaccination mandates and post-pandemic workplace reopening Readers can browse the contributions, generate country-specific reports, and compare attorney-client privilege in multiple jurisdictions. For more information, please visit the Lex Mundi website.
March 2, 2021
Maintaining positive employee relations is a top concern for virtually all companies. Many companies in Thailand—especially those located in the country’s industrial estates—have labor unions, while others rely on other non-union pathways for attending to the concerns of employees. In all of these cases, the union or collective group of employees also chooses members of the “employee committee” that is charged with fostering good relations and open communications with the employer through regular meetings dedicated to discussion of workplace matters. Companies with a workforce of 50 or more employees need to understand the roles of the employee committee and the specific rights accorded to the committee members, which are different from the rights of the other employees. Besides the obvious benefits that this understanding has for relations with their employees, it is also important if an employer takes disciplinary action against employee committee members, as violation of a committee member’s rights could result in the employer facing criminal penalties. The legal basis for these employee committees is the Labor Relations Act B.E. 2518 (LRA), which stipulates that in any workplace with at least 50 employees, the employees or their labor union of the business establishment is entitled to establish an employee committee. Members are elected (or, in the case of a labor union, appointed) to three-year terms on the committee, with the total number of committee members depending on the size of the workforce, as shown in the table. Membership Requirements Among partially unionized workforces, labor unions are generally given precedence when it comes to control of the committee. If a labor union whose members account for more than 20% of the total employees in a workplace, the union gets to appoint the majority of the employee committee members (e.g., four out of a seven-person committee, five of a
February 23, 2021
As many are already aware, following the change of government in Myanmar on February 1, 2021, a draft Cyber Security Law was proposed which attracted widespread criticism. However, less attention has been paid to significant amendments to two existing laws, some of which have a similar effect to parts of the draft Cyber Security Law. In other words, while the draft Cyber Security Law has not progressed further and is under public scrutiny, significant elements of it have found their way into law in Myanmar by other routes. Because these amendments are already law, it is very important that individuals and businesses in Myanmar understand their implications. Amendments to the Law Protecting the Privacy and Security of Citizens The Law Protecting the Privacy and Security of Citizens (2017), or the “Privacy Law,” was amended on February 13, 2021, less than two weeks after the military government came into power. These amendments chiefly address the power of the government to conduct searches, seizures, and arrests; to extend detention without judicial oversight; and to carry out broad surveillance and investigation activities that could intrude on individual privacy. The amendments accomplish this by suspending various sections of the Privacy Law for as long as the State Administration Council (the military body now governing Myanmar) is in power. The suspended sections include the following: Section 5: Search, seizure, and arrest without civilian observation The relevant part of Section 5 of the Privacy Law states, “The responsible authorities shall … when acting in accordance with existing law, not enter into a person’s residence or a room used as a residence, or a building, compound or building in a compound, for the purpose of search, seizure, or arrest, unless accompanied by minimum of two witnesses who should comprise Ward or Village Tract Administrators…”. The suspension