You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 9, 2026

Thailand’s Public Consultation on Proposed PDPA Guidelines: Key Updates

As part of its ongoing public consultation process for the development of new practical guidelines under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), Thailand’s Personal Data Protection Committee (PDPC) held a two‑day public hearing on April 1–2, 2026. The hearing followed an online questionnaire and stakeholder engagement activities conducted in March 2026 and reflects the PDPC’s continued efforts to develop guidance that aligns international regulatory standards with Thai operational realities.

The public hearing provided a forum for participants from both the public and private sectors to exchange views with the PDPC on the proposed guidance so that it responds to the needs of the business community while supporting effective and balanced enforcement of the PDPA. The PDPC emphasized that the consultation process is part of a wider policy objective to build trust in the convenient, secure, and internationally aligned exchange of data.

Structure of the Consultation Process

According to the PDPC, the initiative to develop the draft PDPA guidelines is being implemented through three core phases:

  • Review of international best practices. The PDPC has conducted a comparative review of data protection guidance and regulatory approaches in jurisdictions with internationally recognized standards, including Singapore, the United Kingdom, the European Union (EU), and Japan. These materials are intended to serve as a reference point for developing practical recommendations across key subject areas under the PDPA.
  • Identification of practical issues and challenges. To ensure that the guidelines respond to real‑world compliance challenges in Thailand, the PDPC has gathered views from a broad range of stakeholders across the public sector, the private sector, and the general public. This phase included focus group discussions and questionnaires aimed at identifying areas to provide organizations with greater clarity and consistency on regulatory expectations.
  • Preparation of draft guidelines. Insights from the comparative study and stakeholder feedback are being consolidated to prepare draft guidance covering six core thematic areas (see the following section), intended to reflect both international standards and the practical realities of PDPA implementation in Thailand. The input gathered will be used to inform a draft set of guidelines.

Overview of Draft Guidelines

The consultation process has now advanced beyond open‑ended issue identification, with the PDPC presenting substantive draft guidelines that provide clearer insight into the regulatory focus of the six core thematic areas:

  • Lawful basis for processing personal data. The draft guidelines clarify the importance of lawful basis and lay out how organizations should identify, assess, and document lawful bases for the collection, use, and disclosure of personal data. They emphasize necessity, proportionality, and accountability and address both general and sensitive personal data, supported by practical examples, checklists, and FAQs.
  • Security measures and personal data breach notification. To address this area, the draft guidelines set out a structured framework for security measures, covering technical, administrative, and physical measures, as well as consideration for conducting data protection impact assessments (DPIAs) and managing risks arising from third parties and data transfers. They further provide detailed operational guidance on identifying and assessing personal data breaches, determining notification obligations, incident response procedures, documentation, and timelines for notifying the Office of the PDPC and affected data subjects.
  • Data protection officers (DPOs). The draft guidance clarifies when an organization is required to appoint a DPO and sets out expectations regarding the DPO’s role, professional qualifications, independence, reporting lines, and avoidance of conflicts of interest. It also includes checklists for key compliance concerns, such as the appointment process, the DPO’s position within the organization, and accessibility to data subjects and the Office of the PDPC.
  • Marketing and direct marketing. These guidelines also set out relevant data protection principles for the use of personal data for marketing and direct marketing purposes, such as purpose limitation, data minimization, lawful bases for processing, and applicable data subject rights. They categorize different types of marketing activities (including direct marketing, online tracking, profiling, and platform‑based targeting), provide practical organizational procedures on transparency, opt‑out mechanisms, and consent withdrawal, and provide illustrative case studies and FAQs on common marketing scenarios.
  • Records of processing activities (ROPAs). The draft ROPA guidelines position ROPAs as a core accountability and compliance tool, highlighting mandatory content, the roles of controllers and processors, and a structured approach to preparation, review, and updating ROPAs. This includes practical examples (e.g., HR, customer management, IT vendors, CCTV), templates, and a questionnaire for gathering information within the organization for filling in the ROPA.
  • Use of CCTV and access control systems. The guidelines address personal data processing involving CCTV and related surveillance technologies in housing estates and condominiums, with the objective of promoting PDPA‑compliant, industry‑consistent practices. Also covered are common risk areas, such as visitor management, biometrics, license plate recognition, and resident portals, as well as practical guidance and FAQs for typical operational scenarios.

Regulatory Signals

The April 1–2 public hearing indicates that the PDPC is moving into a more mature, internationally informed phase of PDPA guidance development while remaining attentive to domestic operational challenges. Although the forthcoming guidelines will not have the force of law, they are expected to influence regulatory expectations, compliance assessments, and enforcement decisions.

Organizations should therefore anticipate greater clarity but not a relaxation of PDPA obligations, and may wish to begin reviewing current compliance frameworks, particularly in higher‑risk processing areas, internal documentation practices, and governance arrangements, in preparation for the final guidance.

RELATED INSIGHTS​ 

November 24, 2021
Attorneys from Tilleke & Gibbins have provided the latest update to the Thailand contribution to Doing Business in…, a Q&A-style guide published by Thomson Reuters Practical Law that presents an overview of the legal framework for doing business in 63 jurisdictions worldwide. The Thailand chapter of the guide outlines Thailand’s legal system and key laws applicable to foreign companies doing business in the country. The chapter specifically covers the following main topics: Legal system: Thailand’s court system and codified legal system. Foreign investment: Lists of reserved business activities, restrictions on doing business with certain jurisdictions, exchange controls and currency regulations, and grants and incentives available to investors. Business vehicles: Ordinary partnerships, registered ordinary partnerships, limited partnerships, private limited companies, and public companies. Environment: Main laws and regulations, factory operation. Employment: Laws, employment contract requirements, work permits, and termination and redundancy. Tax: Taxes on employment, tax and nontax resident employees and businesses, corporate income tax, value added tax, special business tax, municipal tax, stamp duty, dividends, interest, intellectual property royalties. Competition: Important aspects of Thailand’s regulatory regime surrounding competition, centered around the updated Trade Competition Act. Antibribery and corruption: Laws, compliance requirements, regulatory authority. Intellectual property: Patents, trademarks, registered and unregistered designs, and copyright. Marketing agreements and advertising: Regulation of marketing agreements, Thailand’s Consumer Protection Act, direct marketing, role of the Consumer Protection Board and Food and Drug Administration. E-commerce: E-commerce laws and regulations, marketing and sales via online platforms. Data protection: An outline of Thailand’s Personal Data Protection Act. Product liability: Procedures and regulations for product liability and product safety, including the Unsafe Goods Liability Act and the Consumer Case Procedure Act. Product liability: Key regulatory authorities for trade competition, environmental issues, and financial services. To browse, download, or print the Thailand chapter, please visit the Practical Law website.
October 25, 2021
Michael Ramirez, a counsel in Tilleke & Gibbins’ dispute resolution group in Bangkok, has updated the firm’s contribution to the Global Attorney-Client Privilege Guide, published by Lex Mundi. The newly expanded guide provides information on what constitutes attorney-client privilege in over 70 countries around the world. The Thailand section of the guide contains in-depth information on the function and applications of attorney-client privilege in Thailand (or, as explained in the guide, an equivalent concept enshrined in Thai law), including coverage of the following topics: Privilege in corporations Common interest doctrine Litigation funding Crime-fraud exception Work product doctrine/litigation privilege Other privileges including mediation, accountant-client and settlement negotiation The interactive guide features expert contributions by Lex Mundi member firms from jurisdictions worldwide. Readers can browse the contributions, generate country-specific reports, and compare attorney-client privilege in multiple jurisdictions. For more information, please visit the Lex Mundi website.
October 19, 2021
On September 9, 2021, Laos announced a new pilot program to allow the mining and trading of cryptocurrency. Notification No. 1158, issued by the Prime Minister’s Office, provides for an electricity sale-purchase agreement with six companies involved in the pilot program. Under the notification, the six companies authorized by the prime minister to mine and trade cryptocurrency in Laos will pay a capped fee for energy they use in data processing or mining cryptocurrency. This effectively establishes a sandbox in which these six companies may mine and trade cryptocurrency—including on international cryptocurrency exchanges. The Ministry of Technology and Communications (MTC) is in charge of coordinating the program, together with the Ministry of Finance, the Bank of the Lao PDR, the Ministry of Planning and Investment, the Ministry of Energy and Mines, the Ministry of Public Security, and Électricité du Laos. The MTC is also charged with drafting the rules of the pilot program and setting the conditions on which the participating companies can mine, sell, and purchase cryptocurrency in Laos. One of the six selected companies will also act as a coordinator for the other companies and report to the government on any benefits of cryptocurrency observed during the pilot program. The next step is for the MTC to compile data analysis from each of the other government agencies and submit the conclusions to a meeting of the prime minister and the deputy prime ministers before the pilot program is implemented. The pilot program was originally scheduled to start in September, but there has not yet been any update on the implementation of the program, which nonetheless is expected to start in the near future.
October 19, 2021
In September 2021, the Bank of Thailand (BOT) issued its Guidelines on Data Governance to provide financial institutions with recommendations on how to ensure that their data governance will be in compliance with accepted international principles. While there are no penalties for noncompliance, financial institutions should view the recommendations as minimum standard expectations for their data governance in Thailand. The BOT guidelines set forth five main data governance principles: Data Governance Policy Financial institutions should set forth their data governance policy in writing in accordance with their business size, business operations, business complexity, and data risk. The policy should cover all types of data, including data related to services from third parties or business partners, as well as provide information on the data governance structure, data lifecycle management, protection of data security and data privacy, and incident management. Financial institutions should inform their employees and other relevant parties of the policy to ensure their compliance. In addition, the data governance policy must be approved by the designated board or committee of the financial institution, and be reviewed and revised in response to significant changes. Data Governance Structure Financial institutions should establish a data governance structure with three lines of defense, supervised by an oversight committee. The first line of defense comprises data management personnel, a data approver, and data users; the second comprises a risk management unit and a compliance unit; and the third is an audit unit. While the chosen data governance structure can be tailored to the characteristics of the institution, the structure should cover all of these roles and duties, and must not contravene the principle of checks and balances. The data governance structure should also be supported by sufficient personnel and equipment, as well as a clear plan—reviewed and revised as necessary—for building awareness at