Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
What it requires →
The Data Controller must notify the Office of any personal data breach without delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the affected individuals. Where the breach is likely to cause high risk, the Data Controller must also notify the data subject without delay, together with remedial measures.
This section number is inferred from a cross-reference in the retention clause rather than confirmed against its own article heading directly.
Comprehensive regime
What it requires →
The Personal Data Protection Act (PDPA) is Thailand's comprehensive personal-data statute, published in the Government Gazette 27 May 2019 and, after enforcement of most operative provisions was twice postponed, fully enforceable since 1 June 2022. Lawful basis is consent by default under Section 24, a General Data Protection Regulation (GDPR)-style model, with heightened requirements for sensitive categories under Section 26. The Personal Data Protection Committee and its Office enforce the Act.
The primary source read for this document is a Ministry of Digital Economy and Society (MDES) mirror of the Act, adopted after the Personal Data Protection Committee's own pdpc.or.th page presented a Cloudflare challenge that crawler infrastructure correctly treated as a stop rather than solving.
Cross border transfer
What it requires →
Section 28 requires that where a Data Controller sends or transfers personal data to a foreign country, the destination country or international organization must have an adequate data protection standard and the transfer must follow rules the Personal Data Protection Committee prescribes, subject to exceptions including legal compliance, informed consent where the data subject is told the destination's standard is inadequate, and contract necessity. This is an adequacy-based restriction; no data-localization mandate was found.
Enforcement supervision
What it requires →
The Personal Data Protection Committee and its Office enforce the Act with administrative fines that vary by provision violated: up to Baht 5,000,000 for Section 26 sensitive-category, Section 27 use or disclosure, and Section 28/29 cross-border transfer violations (Section 84 and Section 87), up to Baht 1,000,000 for data processor non-compliance (Section 85), and up to Baht 3,000,000 under Section 86.
Separately, Section 77 creates civil liability for a Data Controller or Data Processor whose PDPA operation causes damage, subject to narrow defenses of force majeure, the data subject's own act, or compliance with an official order, and Section 78 lets the court additionally order punitive damages up to twice the actual compensation awarded. This is a genuine private right of action with punitive-damages exposure, distinct from the administrative fine regime.
Sensitive categories
What it requires →
Section 26 prohibits collecting personal data on race, ethnic origin, political opinions, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, or biometric data, or any data that may affect the data subject in the same manner, without the data subject's explicit consent, subject to enumerated exceptions such as vital interest and substantial public interest.
Biometric data is defined as data arising from technical processing of a person's physical or behavioral characteristics used to identify them, with facial recognition, iris recognition, and fingerprint recognition data given as express statutory examples. A voiceprint is not named as an express example, but the same-manner catch-all and the general physical-or-behavioral-dominance definition plausibly reach it; no provision was found excluding voice.