Law note · Thailand
Personal Data Protection Act, breach notification
cite Personal Data Protection Act B.E. 2562 (2019), Section 37(4)
stage IN FORCE in force since 2022-06-01
kind Breach notification
binds private bodies
reviewed 2026-08-29
What it requires
- An app that experiences a personal data breach affecting an individual in Thailand must notify the Personal Data Protection Committee's Office without delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to pose a risk to the affected individuals; where the breach is likely to cause high risk, the app must also notify each affected individual without delay.
When LexLint raises it
processes_biometricsprocesses_voicecrawls_web
What we found
The Data Controller must notify the Office of any personal data breach without delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the affected individuals. Where the breach is likely to cause high risk, the Data Controller must also notify the data subject without delay, together with remedial measures.
This section number is inferred from a cross-reference in the retention clause rather than confirmed against its own article heading directly.