Law note · Thailand

Personal Data Protection Act, cross-border transfer

cite Personal Data Protection Act B.E. 2562 (2019), Section 28 stage IN FORCE in force since 2022-06-01 kind Cross border transfer binds private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal data of an individual in Thailand to a recipient in another country must ensure the destination has an adequate data protection standard, following the Committee's prescribed rules, unless a statutory exception such as informed consent to an inadequate destination applies.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

Section 28 requires that where a Data Controller sends or transfers personal data to a foreign country, the destination country or international organization must have an adequate data protection standard and the transfer must follow rules the Personal Data Protection Committee prescribes, subject to exceptions including legal compliance, informed consent where the data subject is told the destination's standard is inadequate, and contract necessity. This is an adequacy-based restriction; no data-localization mandate was found.

← Back to the example  ·  Lint your app →