Law note · Thailand
Personal Data Protection Act, comprehensive regime
What it requires
- An app that collects, uses, or discloses the personal data of an individual in Thailand must obtain consent by default before processing, unless a Section 24 statutory exception applies.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
What we found
The Personal Data Protection Act (PDPA) is Thailand's comprehensive personal-data statute, published in the Government Gazette 27 May 2019 and, after enforcement of most operative provisions was twice postponed, fully enforceable since 1 June 2022. Lawful basis is consent by default under Section 24, a General Data Protection Regulation (GDPR)-style model, with heightened requirements for sensitive categories under Section 26. The Personal Data Protection Committee and its Office enforce the Act.
The primary source read for this document is a Ministry of Digital Economy and Society (MDES) mirror of the Act, adopted after the Personal Data Protection Committee's own pdpc.or.th page presented a Cloudflare challenge that crawler infrastructure correctly treated as a stop rather than solving.
Primary source
unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)
Government Gazette Vol. 136, Special Issue 69 Kor is the official citation