Law / Thailand

Thailand

privacy

Thailand's comprehensive private-sector data-protection law is the Personal Data Protection Act B.E. 2562 (2019), published in the Government Gazette 27 May 2019 and fully enforceable since 1 June 2022.

Lawful basis is consent by default under Section 24, General Data Protection Regulation (GDPR)-style, with an explicit consent standard for sensitive categories under Section 26, which names biometric data directly and gives facial recognition data as an express statutory example; a voiceprint is not separately named but falls within the same catch-all covering any data that may affect the data subject in the same manner.

Cross-border transfer requires the destination to have an adequate data protection standard (Section 28), and breach notification to the regulator's Office is required within 72 hours where feasible (Section 37(4)). Thailand arms a private plaintiff: Section 78 lets a court award punitive damages up to twice actual compensation, on top of the civil liability Section 77 creates, alongside administrative fines that reach Baht 5,000,000 for the most serious violations.

Several dimensions, including the Act's data-subject rights chapter and the publicly-available-data question, were not independently read this research pass and are not represented in this document.

12 instruments named 5 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Personal Data Protection Act, breach notification

cite Personal Data Protection Act B.E. 2562 (2019), Section 37(4) stage IN FORCE in force since 2022-06-01 binds private bodies source unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)
What it requires

The Data Controller must notify the Office of any personal data breach without delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the affected individuals. Where the breach is likely to cause high risk, the Data Controller must also notify the data subject without delay, together with remedial measures.

This section number is inferred from a cross-reference in the retention clause rather than confirmed against its own article heading directly.

Comprehensive regime

Personal Data Protection Act, comprehensive regime

cite Personal Data Protection Act B.E. 2562 (2019), Government Gazette Vol. 136, Special Issue 69 Kor, fully enforceable 2022-06-01 stage IN FORCE in force since 2022-06-01 binds private bodies source unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)
What it requires

The Personal Data Protection Act (PDPA) is Thailand's comprehensive personal-data statute, published in the Government Gazette 27 May 2019 and, after enforcement of most operative provisions was twice postponed, fully enforceable since 1 June 2022. Lawful basis is consent by default under Section 24, a General Data Protection Regulation (GDPR)-style model, with heightened requirements for sensitive categories under Section 26. The Personal Data Protection Committee and its Office enforce the Act.

The primary source read for this document is a Ministry of Digital Economy and Society (MDES) mirror of the Act, adopted after the Personal Data Protection Committee's own pdpc.or.th page presented a Cloudflare challenge that crawler infrastructure correctly treated as a stop rather than solving.

Cross border transfer

Personal Data Protection Act, cross-border transfer

cite Personal Data Protection Act B.E. 2562 (2019), Section 28 stage IN FORCE in force since 2022-06-01 binds private bodies source unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)
What it requires

Section 28 requires that where a Data Controller sends or transfers personal data to a foreign country, the destination country or international organization must have an adequate data protection standard and the transfer must follow rules the Personal Data Protection Committee prescribes, subject to exceptions including legal compliance, informed consent where the data subject is told the destination's standard is inadequate, and contract necessity. This is an adequacy-based restriction; no data-localization mandate was found.

Enforcement supervision

Personal Data Protection Act, enforcement and private right of action

cite Personal Data Protection Act B.E. 2562 (2019), Sections 77, 78, 84-88 stage IN FORCE in force since 2022-06-01 binds private bodies source unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)
What it requires

The Personal Data Protection Committee and its Office enforce the Act with administrative fines that vary by provision violated: up to Baht 5,000,000 for Section 26 sensitive-category, Section 27 use or disclosure, and Section 28/29 cross-border transfer violations (Section 84 and Section 87), up to Baht 1,000,000 for data processor non-compliance (Section 85), and up to Baht 3,000,000 under Section 86.

Separately, Section 77 creates civil liability for a Data Controller or Data Processor whose PDPA operation causes damage, subject to narrow defenses of force majeure, the data subject's own act, or compliance with an official order, and Section 78 lets the court additionally order punitive damages up to twice the actual compensation awarded. This is a genuine private right of action with punitive-damages exposure, distinct from the administrative fine regime.

Sensitive categories

Personal Data Protection Act, sensitive and biometric categories

cite Personal Data Protection Act B.E. 2562 (2019), Section 26 stage IN FORCE in force since 2022-06-01 binds private bodies source unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)
What it requires

Section 26 prohibits collecting personal data on race, ethnic origin, political opinions, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, or biometric data, or any data that may affect the data subject in the same manner, without the data subject's explicit consent, subject to enumerated exceptions such as vital interest and substantial public interest.

Biometric data is defined as data arising from technical processing of a person's physical or behavioral characteristics used to identify them, with facial recognition, iris recognition, and fingerprint recognition data given as express statutory examples. A voiceprint is not named as an express example, but the same-manner catch-all and the general physical-or-behavioral-dominance definition plausibly reach it; no provision was found excluding voice.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.