Law note · Thailand

Personal Data Protection Act, breach notification

cite Personal Data Protection Act B.E. 2562 (2019), Section 37(4) stage IN FORCE in force since 2022-06-01 kind Breach notification binds private bodies reviewed 2026-08-29

What it requires

  • An app that experiences a personal data breach affecting an individual in Thailand must notify the Personal Data Protection Committee's Office without delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to pose a risk to the affected individuals; where the breach is likely to cause high risk, the app must also notify each affected individual without delay.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web

What we found

The Data Controller must notify the Office of any personal data breach without delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the affected individuals. Where the breach is likely to cause high risk, the Data Controller must also notify the data subject without delay, together with remedial measures.

This section number is inferred from a cross-reference in the retention clause rather than confirmed against its own article heading directly.

← Back to the example  ·  Lint your app →