You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 9, 2026

Thailand’s Public Consultation on Proposed PDPA Guidelines: Key Updates

As part of its ongoing public consultation process for the development of new practical guidelines under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), Thailand’s Personal Data Protection Committee (PDPC) held a two‑day public hearing on April 1–2, 2026. The hearing followed an online questionnaire and stakeholder engagement activities conducted in March 2026 and reflects the PDPC’s continued efforts to develop guidance that aligns international regulatory standards with Thai operational realities.

The public hearing provided a forum for participants from both the public and private sectors to exchange views with the PDPC on the proposed guidance so that it responds to the needs of the business community while supporting effective and balanced enforcement of the PDPA. The PDPC emphasized that the consultation process is part of a wider policy objective to build trust in the convenient, secure, and internationally aligned exchange of data.

Structure of the Consultation Process

According to the PDPC, the initiative to develop the draft PDPA guidelines is being implemented through three core phases:

  • Review of international best practices. The PDPC has conducted a comparative review of data protection guidance and regulatory approaches in jurisdictions with internationally recognized standards, including Singapore, the United Kingdom, the European Union (EU), and Japan. These materials are intended to serve as a reference point for developing practical recommendations across key subject areas under the PDPA.
  • Identification of practical issues and challenges. To ensure that the guidelines respond to real‑world compliance challenges in Thailand, the PDPC has gathered views from a broad range of stakeholders across the public sector, the private sector, and the general public. This phase included focus group discussions and questionnaires aimed at identifying areas to provide organizations with greater clarity and consistency on regulatory expectations.
  • Preparation of draft guidelines. Insights from the comparative study and stakeholder feedback are being consolidated to prepare draft guidance covering six core thematic areas (see the following section), intended to reflect both international standards and the practical realities of PDPA implementation in Thailand. The input gathered will be used to inform a draft set of guidelines.

Overview of Draft Guidelines

The consultation process has now advanced beyond open‑ended issue identification, with the PDPC presenting substantive draft guidelines that provide clearer insight into the regulatory focus of the six core thematic areas:

  • Lawful basis for processing personal data. The draft guidelines clarify the importance of lawful basis and lay out how organizations should identify, assess, and document lawful bases for the collection, use, and disclosure of personal data. They emphasize necessity, proportionality, and accountability and address both general and sensitive personal data, supported by practical examples, checklists, and FAQs.
  • Security measures and personal data breach notification. To address this area, the draft guidelines set out a structured framework for security measures, covering technical, administrative, and physical measures, as well as consideration for conducting data protection impact assessments (DPIAs) and managing risks arising from third parties and data transfers. They further provide detailed operational guidance on identifying and assessing personal data breaches, determining notification obligations, incident response procedures, documentation, and timelines for notifying the Office of the PDPC and affected data subjects.
  • Data protection officers (DPOs). The draft guidance clarifies when an organization is required to appoint a DPO and sets out expectations regarding the DPO’s role, professional qualifications, independence, reporting lines, and avoidance of conflicts of interest. It also includes checklists for key compliance concerns, such as the appointment process, the DPO’s position within the organization, and accessibility to data subjects and the Office of the PDPC.
  • Marketing and direct marketing. These guidelines also set out relevant data protection principles for the use of personal data for marketing and direct marketing purposes, such as purpose limitation, data minimization, lawful bases for processing, and applicable data subject rights. They categorize different types of marketing activities (including direct marketing, online tracking, profiling, and platform‑based targeting), provide practical organizational procedures on transparency, opt‑out mechanisms, and consent withdrawal, and provide illustrative case studies and FAQs on common marketing scenarios.
  • Records of processing activities (ROPAs). The draft ROPA guidelines position ROPAs as a core accountability and compliance tool, highlighting mandatory content, the roles of controllers and processors, and a structured approach to preparation, review, and updating ROPAs. This includes practical examples (e.g., HR, customer management, IT vendors, CCTV), templates, and a questionnaire for gathering information within the organization for filling in the ROPA.
  • Use of CCTV and access control systems. The guidelines address personal data processing involving CCTV and related surveillance technologies in housing estates and condominiums, with the objective of promoting PDPA‑compliant, industry‑consistent practices. Also covered are common risk areas, such as visitor management, biometrics, license plate recognition, and resident portals, as well as practical guidance and FAQs for typical operational scenarios.

Regulatory Signals

The April 1–2 public hearing indicates that the PDPC is moving into a more mature, internationally informed phase of PDPA guidance development while remaining attentive to domestic operational challenges. Although the forthcoming guidelines will not have the force of law, they are expected to influence regulatory expectations, compliance assessments, and enforcement decisions.

Organizations should therefore anticipate greater clarity but not a relaxation of PDPA obligations, and may wish to begin reviewing current compliance frameworks, particularly in higher‑risk processing areas, internal documentation practices, and governance arrangements, in preparation for the final guidance.

RELATED INSIGHTS​ 

March 27, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has publicly indicated that it is preparing a new regulatory framework for data center operators that may introduce foreign-ownership restrictions. In particular, the NBTC is considering reclassifying data center operations from a type 1 telecommunications business license to a type 3 license. If implemented, this change would subject data center operators to a significantly more stringent regulatory regime, especially in relation to foreign ownership and control. The NBTC has indicated that it intends to propose a draft framework to the NBTC board. This would be followed by a public hearing process, with a view to implementing the new rules within 2026. Under the Telecommunications Business Act B.E. 2544 (2001), as amended, telecommunications businesses operating under type 3 licenses are subject to foreign ownership restrictions, including a requirement that less than 50% of the total issued shares be held by foreign shareholders. In addition, type 3 licensees are subject to foreign dominance restrictions, which prohibit arrangements that allow foreigners to dominate the business. These foreign dominance restrictions are broad in scope and may capture various forms of direct and indirect control or influence. This includes circumstances in which a foreign national is able to influence or control the formulation of policy, management, or business operations, or the appointment of directors or senior executives. At this stage, the exact scope of the proposed rules remains unclear. Businesses with existing or planned data center operations in Thailand should therefore monitor upcoming NBTC developments in this regard and prepare for the expected public hearing process.
March 27, 2026
Vietnam’s emerging governance framework for artificial intelligence (AI) is developing through a multi-layered structure comprising three components: Policy instruments setting national priorities for AI development; Regulatory framework governing development, provision, deployment and use of AI; and Technical standards and voluntary guidelines. Policy level. At policy level, the foundation for a strategic framework for AI development and governance was laid in 2021 by the National Strategy for Research, Development and Application of AI until 2030, aimed at strengthening the national AI ecosystem and positioning Vietnam as a regional AI innovation hub. Subsequently, resolution No.57-NQ/TW (2024) identified AI as a key driver of science, technology, innovation and national digital transformation. AI was also designated as a strategic technology under decision No.1131/QD-TTg (2025) listing priority technologies across sectors. Regulatory framework. At the legislative level, the new Law on Artificial Intelligence took effect on 1 March 2026, establishing the core regulatory framework governing development, provision, deployment and use of AI systems. Controlled testing for emerging AI technologies is implemented under the Law on Science, Technology and Innovation. The AI Law is expected to be further operationalised through implementing instruments, most notably a draft decree guiding the AI Law, and draft decision of the prime minister identifying high-risk AI systems (both published in February 2026). A decision establishing priority datasets for AI development is also anticipated. Compliance obligations may also arise under sectoral regulatory regimes, including data protection, cybersecurity, banking, consumer protection, e-commerce and intellectual property, particularly where AI systems are used in automated decision-making or data-driven services. Technical standards and non-binding guidelines. Vietnam’s AI governance framework is also supported by technical standards and voluntary guidelines. A key instrument is decision No.1290/QD-BKHCN (2024), providing guidelines for responsible research and development of AI systems, and represents Vietnam’s first national AI ethics code. The Ministry of Science and Technology
March 27, 2026
In response to the rapid advancement of artificial intelligence (AI) and evolving global digital trends, Thailand has undertaken significant efforts to establish a comprehensive national policy framework aimed at fostering an AI ecosystem. This framework seeks to promote the responsible development and deployment of AI technology to enhance Thailand’s economic competitiveness and improve quality of life, with targeted implementation by 2027. In furtherance of this national AI policy, regulatory authorities have initiated efforts to develop and refine the applicable legal framework, including the drafting of Thailand’s first unified AI legislation. Pending the composing and enactment of such comprehensive legislation, sector-specific regulators have proactively issued guidelines applicable to regulated entities within their respective jurisdictions, including financial institutions, banks, insurance companies, securities and derivatives business operators, and digital asset service providers. Concurrently, cross-sectoral regulatory bodies, notably the Personal Data Protection Committee (PDPC) and the National Cyber Security Agency (NCSA), have promulgated guidelines applicable to all business operators within their regulatory purview. While unified AI legislation has not been enacted, the design, development and use of AI in Thailand in various industries is still subject to existing sector-specific legislation. National AI policy The Thai cabinet approved the Thailand National AI Strategy and Action Plan (2022-2027) in July 2022, aiming to establish an AI development and application ecosystem by 2027. The strategy is built around five pillars: Preparing social, ethical, legal and regulatory readiness for AI; Developing national infrastructure; Increasing human capability and AI education; Driving AI technology and innovation; and Promoting AI adoption in public and private sectors. The above-mentioned national AI committee, under the National Digital Economy and Society Committee (NDESC), was established in August 2022, chaired by the prime minister. Comprehensive legislation Following the national AI strategy, the government has been developing comprehensive AI legislation to govern and promote AI
March 20, 2026
Thailand’s Board of Investment (BOI) now requires data center projects to demonstrate measurable benefits for local workforce development, R&D, SME capability, and domestic supply chains to qualify for corporate income tax (CIT) exemptions. BOI Notification No. Por. 3/2569, issued on February 6, 2026, updates the requirements for projects seeking promotion under BOI category 8.2.1 (data centers). All data center projects must now submit and implement plans covering development of Thai human resources and domestic supply chain support before benefiting from any CIT exemption. Human Resources Development Plan The BOI seeks to promote local talent development beyond basic training. Plans must include the following elements: Training for data center design, construction, and operations targeting vocational students, engineering and ICT undergraduates and postgraduates, and energy and building personnel in Thailand. Joint curricula with Thai universities and technical institutes. Collaborative R&D with Thai nationals or institutions in areas including AI, resource allocation, high-performance computing, and data center hardware and systems. Thai SME upskilling in electrical and energy systems and IT services. Domestic Supply Chain Support Plan Plans must demonstrate knowledge transfer in design, construction, cooling, security, and power and water management. Projects must also include usage or installation of domestically manufactured equipment or engage specialist domestic entities. Criteria for BOI Evaluation The BOI will assess data center operators’ eligibility for CIT incentives based on two criteria: Scale requirement: Training and joint-curriculum initiatives must reach a total participants equal to at least 10 times the project headcount and run for the duration of the CIT incentive. If this threshold is not met, the applicant must also implement continuous R&D or SME skills-development plans throughout the incentive period. Substantiality test: Supply-chain plans must be substantive, meet industry standards, and show measurable development of the domestic digital and data center supply base. To ensure compliance,