Thailand
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Thailand does not make you keep personal data inside the country, but data cannot leave until you have picked and documented a legal route. The regulator never published a list of approved destination countries, so consent and written safeguards do all the work. A foreign company selling into Thailand needs a named representative living there. Getting it wrong can mean fines, double damages, and in the worst cases jail.
Eight questions about Thailand
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Thailand's rules apply to my company?
Yes. The privacy law reaches a company with no office in Thailand if it offers goods or services to people who are in Thailand, or if it tracks what those people do. Payment is irrelevant — a free service counts. There is no revenue or headcount floor to fall below. A foreign company caught this way must appoint, in writing, a representative who is physically in Thailand and who can be held answerable with no cap on liability.
Personal Data Protection Act B.E. 2562 (2019), section 5: the Act applies to any controller or processor located in Thailand wherever the processing happens, and to a controller or processor outside Thailand where the activity is (1) offering goods or services to data subjects in Thailand, whether or not payment is made, or (2) monitoring the behaviour of data subjects that takes place in Thailand. Section 37(5) requires a controller caught by the second paragraph of section 5 to appoint a written representative located in the Kingdom, authorised to act on the controller's behalf 'without any limitation of liability'. Section 38 carves out only two groups: state agencies designated by the Committee, and controllers whose business does not involve sensitive data and does not involve personal data at the scale the Committee prescribes under section 41(2). Separately, the Royal Decree on Digital Platform Services deems a foreign platform to be serving Thai users if it displays in Thai, uses a .th or .ไทย domain, accepts Thai baht, or specifies Thai governing law; those operators must notify the Electronic Transactions Development Agency before starting and appoint a written point of contact located in Thailand.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 5, 37(5) and 38
mdes.go.th
“ในกรณีที่ผู้ควบคุมข้อมูลส่วนบุคคลหรือผู้ประมวลผลข้อมูลส่วนบุคคลอยู่นอกราชอาณาจักร พระราชบัญญัตินี้ให้ใช้บังคับแก่การเก็บรวบรวม ใช้ หรือเปิดเผยข้อมูลส่วนบุคคลของเจ้าของข้อมูลส่วนบุคคลซึ่งอยู่ในราชอาณาจักร”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development Agency (official English translation)Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022), sections 5, 8 and 11
etda.or.th
“the operator shall appoint, in writing, a point of contact to perform duties to coordinate with the Agency in the Kingdom. The point of contact performing such duties must be located within the Kingdom”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyDigital platform law library: the Royal Decree, Electronic Transactions Commission notifications and ETDA notifications 1/2566 to 7/2568
etda.or.th
Link checked 18 August 2026
Can I store my users' data outside Thailand?
Yes, in most cases. Thailand does not make companies keep a copy of personal data inside the country. But data cannot simply leave: you must first have a legal route, and the regulator has never published a list of approved destination countries, so the 'this country is safe enough' route is unusable in practice. Everyone falls back on informed consent, contract necessity, approved group-wide rules, or their own written safeguards. Several industries add a second gate on top, described below.
Section 28 of the Personal Data Protection Act says the destination country or international organisation must have an adequate personal data protection standard, judged against criteria the Personal Data Protection Committee publishes under section 16(5). Six exceptions let you transfer anyway: compliance with law; consent where the person has been told the destination's protection is not adequate; necessity for a contract with the person or pre-contract steps; a contract made with someone else for the person's benefit; protection of life, body or health where consent cannot be given; and necessary performance of an important public-interest mission. Section 29 adds two more routes that bypass section 28 entirely: (a) an intra-group personal data protection policy — binding corporate rules — reviewed and certified by the Office, and (b) 'appropriate safeguards' that make the data subject's rights enforceable and provide effective legal remedies, in accordance with rules the Committee publishes. SECTOR OVERRIDES. (1) Banking and payments: the Payment Systems Act B.E. 2560 (2017) section 24 gives the Bank of Thailand express power to set binding rules on a regulated payment operator's use of outsourced service providers and on the retention and disclosure of users' personal data; section 25 requires operators to keep records, accounts and evidence on the Bank's terms so it can inspect them. In practice this converts an offshore cloud or offshore processing decision into a supervisory conversation with the Bank. Rating: data can leave with the right paperwork. (2) Government: state bodies are steered onto domestic government data-centre and cloud arrangements under the Act on Government Administration and Service Delivery in Digital Format B.E. 2562 (2019) and Cabinet-level digital-government policy. Rating: data can leave with the right paperwork, in practice close to onshore-by-default. (3) Telecommunications and any 'service provider': the Computer Crime Act obliges retention of computer traffic data for at least 90 days in a form officials can obtain, which is a practical pull toward onshore or dual-held logs even though it is not written as a residency rule. (4) Banking plus telecoms together: the technological-crime emergency decree forces both to disclose and exchange customer account and transaction data through a central system operated under the Ministry of Digital Economy and Society — that data flows inward, not outward. (5) Health, insurance, securities and mapping: we looked for hard localisation rules and did not find one we could verify from a government source during this run; see the 'unconfirmed' list rather than treating that as a finding of no rule.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 28 and 29
mdes.go.th
“ในกรณีที่ผู้ควบคุมข้อมูลส่วนบุคคลส่งหรือโอนข้อมูลส่วนบุคคลไปยังต่างประเทศ ประเทศปลายทางหรือองค์การระหว่างประเทศที่รับข้อมูลส่วนบุคคลต้องมีมาตรฐานการคุ้มครองข้อมูลส่วนบุคคลที่เพียงพอ”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Payment Systems Act B.E. 2560 (2017), sections 24(6), 24(7) and 25 — Bank of Thailand power over outsourcing and over retention and disclosure of users' personal data
mdes.go.th
Link checked 18 August 2026
- Official sourceBank of ThailandPayment Systems Act B.E. 2560 (2017) — official English translation
bot.or.th
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Act on Government Administration and Service Delivery in Digital Format B.E. 2562 (2019), section 12 — data governance duties on state agencies
mdes.go.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023), Government Gazette Vol. 140 Part 18 Kor, 16 March 2023
etda.or.th
“มาตรา ๔ ... ให้สถาบันการเงินและผู้ประกอบธุรกิจ มีหน้าที่เปิดเผยหรือแลกเปลี่ยนข้อมูลเกี่ยวกับบัญชีและธุรกรรมของลูกค้า”
Link checked 18 August 2026
What do I need in place before data leaves Thailand?
There is no permission slip to apply for and no banned-country list. You pick a route and document it before the data moves. The routes are: the destination is judged to have good enough protection; one of six statutory exceptions such as informed consent; group-wide rules certified by the regulator; or your own written safeguards that a person in Thailand could actually enforce. The 'good enough country' route is dead on arrival because the regulator has published no approved list, so in practice the safeguards route and consent do all the work.
The model is best described as case-by-case self-assessment with a residual regulator decision. Section 28 paragraph two says that where there is a question about whether a destination's standard is adequate, the matter is put to the Personal Data Protection Committee to decide, and the decision may be revisited on new evidence. There is no prior-approval requirement for an ordinary transfer, no filing, and no registry. The only pre-approval mechanism is the binding corporate rules route in section 29 paragraph one, where the Office reviews and certifies an intra-group policy. Section 29 paragraph three is the workhorse: where there is no Committee decision on the destination and no certified group policy, the controller or processor may transfer if it has put in place appropriate safeguards under rules and methods the Committee publishes. IMPORTANT GAP: the Committee has issued subordinate notifications fleshing out sections 28 and 29, but we could not open the regulator's own website during this run because it is behind a bot-challenge, and we could not locate a government-hosted copy of those notifications. Treat their detail — not their existence — as unverified here; see 'unconfirmed'. Penalties for getting the route wrong are graded: up to three million baht for ordinary personal data, up to five million baht where sensitive data is involved.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 28, 29, 83, 84 and 87
mdes.go.th
“มาตรา ๘๗ ผู้ประมวลผลข้อมูลส่วนบุคคลผู้ใดส่งหรือโอนข้อมูลส่วนบุคคลตามมาตรา ๒๖ ... ต้องระวางโทษปรับทางปกครองไม่เกินห้าล้านบาท”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommitteeOffice of the Personal Data Protection Committee — official website
pdpc.or.th
Link checked 18 August 2026
Who enforces the rules in Thailand, and what can they do?
The Office of the Personal Data Protection Committee, usually shortened to PDPC, sits under the Ministry of Digital Economy and Society. It is real and staffed: it has a serving Secretary-General, it runs walk-in complaint centres in five provinces and opened another in Ubon Ratchathani on 17 August 2026, and it is executing Cabinet-level instructions on data breaches. Complaints are decided by an Expert Committee that can order you to stop, order you to fix things, and impose fines itself. Other regulators run their own lanes: the cyber-security agency for critical infrastructure, the central bank for payments, and the electronic transactions agency for digital platforms.
Enforcement rating: active, on the following observable evidence verified on 18 August 2026. The Ministry's own newsroom of 17 August 2026 names Pol. Col. Surapong Plengkham as Secretary-General of the Office of the Personal Data Protection Committee, records that the Office already runs public service centres in five provinces and is expanding to eight during 2026 across all five regions, and records a Cabinet resolution of 11 August 2026 approving a government-wide approach to preventing personal data leakage from leaked login credentials using multi-factor authentication. That is an agency with a chair, a budget, a field presence and a policy mandate, not a paper body. Under sections 72 and 90 of the Act, the Expert Committee handles complaints, may attempt mediation, may order rectification or prohibition, and may impose administrative fines directly, taking into account the seriousness of the conduct and the size of the business; unpaid fines are enforced under the administrative procedure law. HONEST LIMIT: we could not reach the regulator's own website during this run because it sits behind a bot challenge, so we could not count or quote individual enforcement decisions. The 'active' rating rests on institutional evidence, not on a verified decision list.
Sources
- Official sourceMinistry of Digital Economy and SocietyDeputy Minister opens the southern Isan PDPA Center, 17 August 2026 — names the Secretary-General of the Personal Data Protection Committee Office and records the Cabinet resolution of 11 August 2026 on multi-factor authentication
mdes.go.th
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 72 and 90 — powers of the Expert Committee to order and to fine
mdes.go.th
“มาตรา ๙๐ คณะกรรมการผู้เชี่ยวชาญมีอำนาจสั่งลงโทษปรับทางปกครอง”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Cybersecurity Act B.E. 2562 (2019), section 57 — reporting line to the National Cyber Security Agency and the sector regulator
mdes.go.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyDigital platform law library: the Royal Decree, Electronic Transactions Commission notifications and ETDA notifications 1/2566 to 7/2568
etda.or.th
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommitteeOffice of the Personal Data Protection Committee — official website
pdpc.or.th
Link checked 18 August 2026
How long do I have to keep the data?
Thailand pushes in both directions at once. The floor: anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days, and an official can order that stretched to as much as two years. The ceiling: the privacy law makes you build a system that actually deletes personal data once your stated retention period runs out or the data is no longer needed. When the two collide, the keep-it duty wins, because the delete duty has a written carve-out for complying with law and for defending legal claims.
FLOOR. Computer-Related Crime Act B.E. 2550 (2007), section 26: a service provider must keep computer traffic data for at least ninety days from the date the data enters the computer system, and where necessary a competent official may order a particular provider to keep traffic data for longer than ninety days but not exceeding two years. Failure carries a fine of up to five hundred thousand baht (about 15,000 US dollars). 'Service provider' is defined broadly enough to catch businesses that merely provide internet access to others, which is why hotels, co-working spaces and offices with guest wi-fi get caught. CEILING. Personal Data Protection Act section 37(3): the controller must put in place an examination system to erase or destroy personal data when the retention period ends, when the data is no longer relevant or is beyond what the purpose requires, when the person asks, or when consent is withdrawn — with exceptions for freedom of expression, the public-interest and research grounds in sections 24(1), 24(4) and 26(5), for establishing, exercising or defending legal claims, and for compliance with law. Section 39 separately requires the record of processing activities to state the retention period for each category. NOT VERIFIED THIS RUN: the general commercial floors — five years of accounting records under the Accounting Act and five years of tax documents under the Revenue Code — are widely relied on in Thailand but we did not open a government copy of either during this run; see 'unconfirmed'.
Sources
- Official sourceMinistry of Digital Economy and Society (Office of the Council of State consolidated text)Computer-Related Crime Act B.E. 2550 (2007) as amended, section 26 — ninety-day traffic data retention, extendable to two years by order
mdes.go.th
“มาตรา ๒๖ ผู้ให้บริการต้องเก็บรักษาข้อมูลจราจรทางคอมพิวเตอร์ไว้ไม่น้อยกว่าเก้าสิบวันนับแต่วันที่ข้อมูลนั้นเข้าสู่ระบบคอมพิวเตอร์ แต่ในกรณีจำเป็น พนักงานเจ้าหน้าที่จะสั่งให้...เกินเก้าสิบวันแต่ไม่เกินสองปี”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 37(3) and 39 — duty to erase and duty to record retention periods
mdes.go.th
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks, not one. First: tell the privacy regulator about a personal data breach without delay and within 72 hours of becoming aware, unless the breach carries no risk to people; if the risk to people is high you must also tell the affected individuals, with advice on what to do, without delay. Second: if you run critical information infrastructure, a significant cyber threat must be reported to the national cyber-security agency and to your own sector regulator, and silence without good reason is itself an offence. Third: if you are a bank or a telecoms operator and you suspect technology crime, you must push customer account and transaction data into a shared government-run system immediately.
Clock 1 — Personal Data Protection Act section 37(4): notify the Office without delay and where feasible within seventy-two hours of becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of persons; where there is a high risk, also notify the data subject together with remedial measures without delay. The detail of the notification and its exceptions is set by Committee notification. Clock 2 — Cybersecurity Act B.E. 2562 (2019) section 57: on a significant cyber threat to a critical information infrastructure organisation's systems, that organisation must report to the Office of the National Cyber Security Committee and to its regulating or supervising body and must carry out the response measures; failing to report without reasonable cause is punishable by a fine of up to two hundred thousand baht (about 6,000 US dollars). Clock 3 — Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023) section 4, as amended in 2025: where there is reasonable suspicion of technological crime, financial institutions and business operators have a duty to disclose or exchange customer account and transaction data among themselves through a disclosure or exchange system operated under the Ministry of Digital Economy and Society. The three regimes have different triggers, different addressees and different deadlines, and an incident can start all three at once.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), section 37(4) — 72-hour breach notification
mdes.go.th
“แจ้งเหตุการละเมิดข้อมูลส่วนบุคคลแก่สำนักงานโดยไม่ชักช้าภายในเจ็ดสิบสองชั่วโมงนับแต่ทราบเหตุเท่าที่จะสามารถกระทำได้”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Cybersecurity Act B.E. 2562 (2019), section 57 and the related penalty provision
mdes.go.th
“มาตรา ๕๗ เมื่อมีเหตุภัยคุกคามทางไซเบอร์เกิดขึ้นอย่างมีนัยสำคัญต่อระบบของหน่วยงานโครงสร้างพื้นฐานสำคัญทางสารสนเทศ ให้...รายงานต่อสำนักงานและหน่วยงานควบคุมหรือกำกับดูแล”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023), Government Gazette Vol. 140 Part 18 Kor, 16 March 2023
etda.or.th
“มาตรา ๔ ... ให้สถาบันการเงินและผู้ประกอบธุรกิจ มีหน้าที่เปิดเผยหรือแลกเปลี่ยนข้อมูลเกี่ยวกับบัญชีและธุรกรรมของลูกค้า”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes (No. 2) B.E. 2568 (2025), Government Gazette Vol. 142 Part 27 Kor, 12 April 2025
etda.or.th
Link checked 18 August 2026
What trips people up in Thailand?
Five things that are not in the brochure. Children: Thailand needs a parent's consent for a child aged ten or under, and for older teenagers too unless the act is one the law lets a minor do alone — and a person is a minor in Thailand until twenty. Jail is on the table for misusing sensitive data. You owe compensation even if you were not careless, and a court can add up to double on top. A foreign company must put a named human in Thailand with unlimited authority. And the 90-day log rule catches ordinary businesses that just offer guest wi-fi.
TRAP 1 — children. Section 20 of the Personal Data Protection Act: where the data subject is a minor who has not reached majority by marriage and is not treated as of age under section 27 of the Civil and Commercial Code, consent must also be obtained from the person with parental power unless the act is one the minor may consent to alone under sections 22, 23 or 24 of that Code; and where the minor is not over ten years old, consent must be obtained from the person with parental power. Majority in Thailand is twenty, so the practical population needing a parental check is far wider than the thirteen-or-sixteen thresholds most global products are built for. The same rule applies to withdrawal of consent, notices, rights requests and complaints. TRAP 2 — criminal, not just administrative. Section 79: unlawfully disclosing sensitive data, or transferring it abroad in breach of section 28, in a way likely to cause another person damage, loss of reputation, insult, hatred or humiliation, is punishable by up to six months' imprisonment or a fine of up to five hundred thousand baht (about 15,000 US dollars) or both; if done to obtain an unlawful benefit for oneself or another, up to one year's imprisonment or a fine of up to one million baht (about 30,000 US dollars) or both. The offence is compoundable, which changes how it is negotiated in practice. TRAP 3 — strict liability plus punitive damages. Section 77: the controller or processor must compensate a data subject for damage caused by breaching the Act 'whether the act was intentional or negligent or not', with only two defences — force majeure or the subject's own act, and acting on the lawful order of an official. Section 78: the court may award punitive damages on top of actual damages, up to twice the actual amount. The claim is time-barred three years after the injured person knows of the damage and of who is responsible. TRAP 4 — the in-country representative. Section 37(5) requires a foreign controller caught by section 5 paragraph two to appoint, in writing, a representative located in Thailand, authorised to act 'without any limitation of liability'. Section 38's exemptions are narrow: designated state agencies, and businesses that do not handle sensitive data and are not large-scale on criteria the Committee sets. This is not a mailbox function. TRAP 5 — who counts as a 'service provider' for logs. The 90-day traffic data duty in section 26 of the Computer-Related Crime Act attaches to providers of computer service to other persons, not only to telecoms carriers, and carries a fine of up to five hundred thousand baht. Hotels, landlords, clinics and offices with guest networks are routinely inside it. TRAP 6 — digital platforms are reached by look-and-feel. Under the Royal Decree on Digital Platform Services, a platform run entirely from abroad is deemed to serve users in Thailand if it merely displays in Thai, or uses a .th or .ไทย domain, or accepts payment in Thai baht, or names Thai law as the governing law. Prior notification to the Electronic Transactions Development Agency then bites at revenue above 1.8 million baht a year for an individual (about 55,000 US dollars) or 50 million baht for a company (about 1.5 million US dollars), or above 5,000 average monthly users.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 20, 37(5), 77, 78 and 79
mdes.go.th
“ในกรณีที่ผู้เยาว์มีอายุไม่เกินสิบปี ให้ขอความยินยอมจากผู้ใช้อำนาจปกครองที่มีอำนาจกระทำการแทนผู้เยาว์”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (Office of the Council of State consolidated text)Computer-Related Crime Act B.E. 2550 (2007), section 26 and its penalty — fine of up to five hundred thousand baht
mdes.go.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development Agency (official English translation)Royal Decree on Digital Platform Services B.E. 2565 (2022), sections 5 and 8 — deeming rules and notification thresholds
etda.or.th
“a digital platform service with annual revenue from providing the digital platform service within the Kingdom exceeding one million and eight hundred thousand baht in case the operator is a natural person, or exceeding fifty million baht in case the operator is a juristic person”
Link checked 18 August 2026
What is changing soon in Thailand?
Nothing in the next twelve months looks like a new statute. What is moving is enforcement reach. The privacy regulator is opening walk-in centres in eight provinces during 2026 to cover all five regions, which means more complaints will actually get filed. The Cabinet decided on 11 August 2026 to require multi-factor login protection across government to stop leaked passwords turning into data breaches, and the ministry is pushing the same expectation across all twenty ministries. The bigger risk is not new law but switches the government already holds and can flip without warning.
LANDING IN THE NEXT TWELVE MONTHS. (1) Expansion of the Personal Data Protection Committee Office's regional PDPA Centers from five provinces to eight during 2026, covering all five regions, announced by the Deputy Minister on 17 August 2026 with the Office's Secretary-General present. (2) Implementation of the Cabinet resolution of 11 August 2026 on preventing personal data leakage arising from leaked authentication credentials, using multi-factor authentication, together with the Minister's stated plan to raise personal data protection and cyber-risk measures across all twenty ministries. DORMANT SWITCHES — powers already in hand that can change the picture with no consultation. (a) Section 28 read with section 16(5): the Committee sets the criteria for judging whether a destination country's protection is adequate, and decides contested cases. A single decision that a widely used destination is not adequate would invalidate transfers that rely on adequacy overnight; conversely the criteria could be relaxed the same way. (b) Section 26 of the Computer-Related Crime Act: a competent official may order any named service provider to keep traffic data for longer than ninety days, up to two years, case by case, with no rule-making needed. (c) The Royal Decree on Digital Platform Services lets the Electronic Transactions Commission and the Agency add named platforms to the heavier duty tiers by notification; notifications 4/2568, 6/2568 and 7/2568 have already been used to name marketplace platforms, and 2/2568 to name ride-hailing platforms, so the mechanism is live and in regular use. (d) The technological-crime regime is an emergency decree, which the executive can amend without going through Parliament first — it already was, in April 2025 — so bank and telecoms data-sharing duties can be widened quickly. (e) Sections 38 and 41 let the Committee define, by notification, which businesses are 'large scale' and therefore must appoint a data protection officer and a representative; moving that line moves thousands of companies in or out of scope. WE COULD NOT VERIFY: whether any bill amending the Personal Data Protection Act is before Parliament, and whether Thailand has taken any further step toward the Global Cross-Border Privacy Rules system. See 'unconfirmed'.
Sources
- Official sourceMinistry of Digital Economy and SocietyDeputy Minister opens the southern Isan PDPA Center, 17 August 2026 — names the Secretary-General of the Personal Data Protection Committee Office and records the Cabinet resolution of 11 August 2026 on multi-factor authentication
mdes.go.th
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 16(5), 28, 38 and 41 — the standing powers behind the dormant switches
mdes.go.th
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (Office of the Council of State consolidated text)Computer-Related Crime Act B.E. 2550 (2007), section 26 — official power to extend log retention to two years
mdes.go.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyDigital platform law library: the Royal Decree, Electronic Transactions Commission notifications and ETDA notifications 1/2566 to 7/2568
etda.or.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes (No. 2) B.E. 2568 (2025), Government Gazette Vol. 142 Part 27 Kor, 12 April 2025
etda.or.th
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
3 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
4 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules3 rules
พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. ๒๕๖๒ (Personal Data Protection Act B.E. 2562)
Act of parliament · Government Gazette Vol. 136, Part 69 Kor, page 52, 27 May 2019
Thailand's general privacy law. It reaches foreign companies that sell to or monitor people in Thailand, requires a representative inside Thailand, allows data to leave only through a named route, gives people 72-hour breach notice, and backs it with administrative fines, criminal liability and double damages.
Enforced by Office of the Personal Data Protection Committee
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Standard contract clauses, Explicit consent, Needed for a contract, Someone's life is at risk, Important public interest
What it makes you do
- Put a transfer safeguard in placeSections 28 and 29. No approved-country list has been published, so the adequacy route is unusable in practice and controllers rely on consent, contract necessity, certified group rules or their own appropriate safeguards.
- Report breaches to the regulator — within 72 hoursSection 37(4). Without delay and where feasible within 72 hours of becoming aware, unless the breach is unlikely to risk people's rights and freedoms.
- Tell affected peopleSection 37(4). Required without delay, together with remedial guidance, where the breach carries a high risk to people.
- Appoint a local representativeSection 37(5). A foreign controller must appoint a written representative located in Thailand, authorised without any limitation of liability. Narrow exemptions in section 38.
- Keep records of processingSections 39 and 40(3). Records of processing must state the retention period for each category; small businesses may be relieved by Committee notification unless they handle sensitive data or process other than occasionally.
- Delete data after a periodSection 37(3). A system must exist that actually erases or destroys data once the retention period ends or the data is no longer needed.
- Get a parent's consent for childrenSection 20. Parental consent always required at age ten or under, and for older minors unless the Civil and Commercial Code lets the minor act alone. Majority in Thailand is twenty.
- Written vendor contractSection 40 paragraph two. A controller must have a written arrangement controlling its processor.
- Secure the dataSection 37(1). Security measures must meet the minimum standard the Committee publishes and must be reviewed as technology changes.
What it costs if you get it wrong
- Fixed maximum fine: 5,000,000 baht — about $155 thousandSection 84: mishandling sensitive data, or sending sensitive data abroad outside sections 28 or 29. Section 83 caps ordinary transfer and processing breaches at 3,000,000 baht; section 82 caps record and notice failures at 1,000,000 baht.
- Criminal liability: 1 year imprisonment and/or 1,000,000 baht — about $30 thousandSection 79: unlawful disclosure or transfer of sensitive data likely to cause damage or humiliation; the higher tier applies where done for unlawful benefit. Compoundable offence.
- Claims by individuals: actual damages plus up to 2x punitiveSections 77 and 78: liability regardless of intent or negligence, with punitive damages up to twice actual damages; three-year limitation.
- Order to stop: prohibition and rectification ordersSection 72: the Expert Committee may order a controller or processor to fix conduct or to stop conduct causing damage.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019) — full Government Gazette text
mdes.go.th
“มาตรา ๓๗ ... (๔) แจ้งเหตุการละเมิดข้อมูลส่วนบุคคลแก่สำนักงานโดยไม่ชักช้าภายในเจ็ดสิบสองชั่วโมง”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommitteeOffice of the Personal Data Protection Committee — official website
pdpc.or.th
Link checked 18 August 2026
พระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. ๒๕๕๐ (Computer-Related Crime Act B.E. 2550), section 26
Act of parliament · Computer-Related Crime Act B.E. 2550 (2007) as amended by Act (No. 2) B.E. 2560 (2017), section 26
Anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days, and an official can order that stretched to two years for a named provider. The duty catches ordinary businesses with guest wi-fi, not just telecoms carriers.
Enforced by Ministry of Digital Economy and Society
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep logs — 3 monthsAt least ninety days from the moment the data enters the computer system. A competent official may order a named provider to keep it longer, up to two years.
What it costs if you get it wrong
- Fixed maximum fine: 500,000 baht — about $15 thousandA service provider that fails to comply with section 26.
Sources
- Official sourceMinistry of Digital Economy and Society (Office of the Council of State consolidated text)Computer-Related Crime Act B.E. 2550 (2007), section 26, consolidated text published by the Ministry of Digital Economy and Society
mdes.go.th
Link checked 18 August 2026
พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์ พ.ศ. ๒๕๖๒ (Cybersecurity Act B.E. 2562)
Act of parliament · Government Gazette Vol. 136, Part 69 Kor, page 20, 27 May 2019
Organisations designated as critical information infrastructure must report significant cyber threats both to the national cyber-security agency and to their own sector regulator, and staying quiet without good reason is itself punishable.
Enforced by National Cyber Security Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidentsSection 57. A critical information infrastructure organisation must report a significant cyber threat to the National Cyber Security Agency and to its own regulating or supervising body, and must carry out the prescribed response.
- Hold a security certificateCritical information infrastructure organisations are subject to the standards and assessment regime set by the national cyber-security committee.
What it costs if you get it wrong
- Fixed maximum fine: 200,000 baht — about $6 thousandFailure to report under section 57 without reasonable cause.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Cybersecurity Act B.E. 2562 (2019), section 57 and its penalty provision
mdes.go.th
Link checked 18 August 2026
Industry rules4 rules
พระราชบัญญัติระบบการชำระเงิน พ.ศ. ๒๕๖๐ (Payment Systems Act B.E. 2560)
Act of parliament · Government Gazette Vol. 134, Part 110 Kor, page 1, 18 October 2017; sections 24 and 25 · Payments
Payments is not a hard residency wall but it is a permission gate. The Payment Systems Act gives the Bank of Thailand express power to set rules on a payment operator's outsourcing and on how it keeps and discloses users' personal data, and to require records to be held for inspection.
Enforced by Bank of Thailand
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Written vendor contractSection 24(6). The Bank of Thailand may prescribe binding criteria on a regulated operator's use of outside service providers, which is the hook for cloud and offshore processing arrangements.
- Keep data for a minimum periodSection 24(7) and section 25. The Bank may prescribe how users' personal data is retained and disclosed, and operators must keep data, accounts, documents and evidence about the business for inspection on the Bank's terms.
- Independent auditSection 25 exists so the Bank can inspect; an offshore arrangement that impairs inspection is the supervisory problem, not the transfer itself.
What it costs if you get it wrong
- Loss of your licenceOperating or continuing to operate a regulated payment service in breach of Bank of Thailand criteria.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Payment Systems Act B.E. 2560 (2017), sections 24 and 25 — Thai Government Gazette text
mdes.go.th
“มาตรา ๒๔ ให้ ธปท. มีอำนาจประกาศกำหนดหลักเกณฑ์ ... (๖) การใช้บริการจากบุคคลภายนอก (๗) การเก็บรักษาและการเปิดเผยข้อมูลส่วนบุคคลของผู้ใช้บริการ”
Link checked 18 August 2026
- Official sourceBank of ThailandPayment Systems Act B.E. 2560 (2017) — official English translation
bot.or.th
Link checked 18 August 2026
- Official sourceBank of ThailandLaws and announcements index, including the Bank of Thailand's notification and circular database
bot.or.th
Link checked 18 August 2026
พระราชกำหนดมาตรการป้องกันและปราบปรามอาชญากรรมทางเทคโนโลยี พ.ศ. ๒๕๖๖ (Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566), as amended by (No. 2) B.E. 2568
Act of parliament · Government Gazette Vol. 140, Part 18 Kor, page 1, 16 March 2023; amended Vol. 142, Part 27 Kor, page 5, 12 April 2025 · Banking
Banks, payment operators and telecoms companies must hand customer account and transaction data into a central government-run exchange whenever technology crime is suspected. It is an inward data-sharing mandate that overrides normal confidentiality, and it was widened by emergency decree in April 2025 without going through Parliament first.
Enforced by Ministry of Digital Economy and Society
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Report cyber incidentsSection 4. Where there is reasonable suspicion of technological crime, financial institutions and business operators must disclose or exchange customer account and transaction data among themselves through a system operated under the Ministry of Digital Economy and Society.
- Do not hand data to foreign authorities on demandThe duty runs inward: banking secrecy and ordinary privacy objections do not excuse non-disclosure into the government-operated exchange.
What it costs if you get it wrong
- Criminal liabilityThe Decree carries criminal provisions, including for mule accounts and SIM cards; we did not verify the exact tariffs from the gazette text during this run.
Sources
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023), Government Gazette Vol. 140 Part 18 Kor, 16 March 2023
etda.or.th
“มาตรา ๔ ... ให้สถาบันการเงินและผู้ประกอบธุรกิจ มีหน้าที่เปิดเผยหรือแลกเปลี่ยนข้อมูลเกี่ยวกับบัญชีและธุรกรรมของลูกค้า”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes (No. 2) B.E. 2568 (2025), Government Gazette Vol. 142 Part 27 Kor, 12 April 2025
etda.or.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyDigital platform law library: the Royal Decree, Electronic Transactions Commission notifications and ETDA notifications 1/2566 to 7/2568
etda.or.th
Link checked 18 August 2026
พระราชกฤษฎีกาการประกอบธุรกิจบริการแพลตฟอร์มดิจิทัลที่ต้องแจ้งให้ทราบ พ.ศ. ๒๕๖๕ (Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565)
Directly binding regulation · Government Gazette Vol. 139, Part 78 Kor, page 17, 23 December 2022 · E-commerce
A platform run entirely from abroad is treated as serving Thai users if it merely shows Thai text, uses a Thai domain, takes Thai baht, or picks Thai law. Above modest revenue or 5,000 monthly users it must notify the electronic transactions agency before launch and keep a named contact person inside Thailand.
Enforced by Electronic Transactions Development Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notify — applies at: Annual Thai revenue above 1,800,000 baht for an individual operator or above 50,000,000 baht for a company, or more than 5,000 average monthly active users in ThailandSection 8. Prior notification to the Electronic Transactions Development Agency before starting; annual re-notification and change notifications thereafter.
- Appoint a local representativeSection 11. A written point of contact must be appointed and must be located in Thailand. The Decree says this does not by itself require establishing a business in Thailand.
- Tell people what you doTerms and conditions must be published to users, and changes notified, under Electronic Transactions Commission notifications.
- Keep records of processingAnnual reporting of operating information to the Agency.
What it costs if you get it wrong
- Order to stopOperating a notifiable digital platform service without notification, or failing to comply with the heavier duties imposed on named marketplace and ride-hailing platforms.
Sources
- Official sourceElectronic Transactions Development Agency (official English translation)Royal Decree on Digital Platform Services B.E. 2565 (2022), sections 5, 8 and 11 — official English translation published by the regulator
etda.or.th
“The digital platform is displayed, in whole or in part, in the Thai language ... shall be deemed to have provided services to users located within the Kingdom”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyDigital platform law library: the Royal Decree, Electronic Transactions Commission notifications and ETDA notifications 1/2566 to 7/2568
etda.or.th
Link checked 18 August 2026
พระราชบัญญัติการบริหารงานและการให้บริการภาครัฐผ่านระบบดิจิทัล พ.ศ. ๒๕๖๒ (Act on Government Administration and Service Delivery in Digital Format B.E. 2562)
Act of parliament · Government Gazette Vol. 136, Part 67 Kor, page 57, 22 May 2019; section 12 · Government
Thai state bodies run under their own data-governance statute rather than ordinary commercial rules, and are steered onto domestic government cloud and data-centre arrangements. From August 2026 the Cabinet has also required multi-factor login protection across government to stop credential leaks becoming data breaches.
Enforced by Ministry of Digital Economy and Society
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep records of processingSection 12. Every state agency must operate agency-level data governance and act in accordance with it, so that government data can be integrated and shared.
- Secure the dataCabinet resolution of 11 August 2026 approved a government-wide approach to preventing personal data leakage from leaked authentication credentials, using multi-factor authentication.
- Prove the data stays under local controlIn practice government workloads are steered onto domestic government data-centre and cloud arrangements; we could not verify the current cloud policy text from a government source during this run.
What it costs if you get it wrong
- Order to stopAdministrative direction rather than fines; non-compliance is handled through the digital-government governance chain.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Act on Government Administration and Service Delivery in Digital Format B.E. 2562 (2019), section 12
mdes.go.th
“มาตรา ๑๒ ... ให้หน่วยงานของรัฐจัดทำธรรมาภิบาลข้อมูลภาครัฐในระดับหน่วยงาน”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and SocietyDeputy Minister opens the southern Isan PDPA Center, 17 August 2026 — names the Secretary-General of the Personal Data Protection Committee Office and records the Cabinet resolution of 11 August 2026 on multi-factor authentication
mdes.go.th
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The text, dates and exact requirements of the Personal Data Protection Committee's subordinate notifications on cross-border transfer under sections 28 and 29
The regulator's own website at pdpc.or.th is behind a Cloudflare bot challenge and returned 403 to every attempt on 18 August 2026, including through a text-rendering proxy. No government-hosted mirror of these notifications could be located. The statutory framework in sections 28 and 29 is verified from the Government Gazette text; the implementing detail is not.
The date the main operative chapters of the Personal Data Protection Act actually began to bite, recorded here as 1 June 2022
The Act's own section 2 delays Chapters 2, 3, 5, 6 and 7 and sections 95 and 96 by one year from publication, and that delay was then extended twice by royal decree. We verified section 2 from the Government Gazette text but could not open a government copy of the postponement royal decrees during this run, so the 1 June 2022 date is carried forward without a verified backlink.
Whether the Personal Data Protection Committee has published any list or decision naming countries with an adequate protection standard
We found no such list, but we could not read the regulator's site, so this is 'not found, checked 18 August 2026' and not a finding that no list exists. The record assumes the adequacy route is unusable in practice; if a list has been published, the transfer picture is materially more permissive.
The number, size and subject matter of enforcement decisions and administrative fines issued by the Personal Data Protection Committee to date
Decisions are published on the regulator's own site, which we could not open. The 'active' enforcement rating rests on institutional evidence — a named Secretary-General, regional service centres, Cabinet-level tasking — rather than on a verified decision count.
Whether the Bank of Thailand's current notifications require prior approval for offshore outsourcing or offshore cloud by financial institutions and payment operators
The statutory power is verified from sections 24 and 25 of the Payment Systems Act, but the Bank's notification database renders only with JavaScript and its document URLs could not be resolved during this run. The rule is therefore recorded as a permission gate with medium confidence rather than as a specific approval requirement.
Whether securities firms, insurers or telecoms licensees are subject to any data localisation or offshore-storage restriction
The Securities and Exchange Commission, the Office of Insurance Commission and the National Broadcasting and Telecommunications Commission all sit behind bot challenges or JavaScript-only law libraries. We could not read a single one of their notifications on 18 August 2026. Absence from this record is a gap in our access, not evidence of absence in law.
Whether Thailand has a restriction on surveying, mapping or geospatial data leaving the country
The national geo-informatics and survey bodies (gistda.or.th, rtsd.mi.th) did not resolve from this environment. No conclusion either way was reached.
Whether health records are subject to any storage or transfer restriction beyond the general privacy law
The National Health Commission Office site reset the connection and the Ministry of Public Health site returned 403. The confidentiality rule in the National Health Act is well known but was not verified from a government source this run, so no health rule is asserted.
The current text of Thailand's government cloud policy, including whether it mandates domestic hosting for classified government workloads
The Digital Government Development Agency site (dga.or.th) is behind a bot challenge. The record relies on the Act on Government Administration and Service Delivery in Digital Format, which is verified, and describes the cloud steer as practice rather than as a verified legal mandate.
The five-year retention floors for accounting records and tax documents
These are the two floors most commonly cited in Thai practice, but we did not open a government copy of the Accounting Act or the Revenue Code during this run and therefore do not assert them as verified.
Whether any bill amending the Personal Data Protection Act is currently before Parliament, and Thailand's current status in the Global Cross-Border Privacy Rules system
The parliamentary bill tracker and the regulator's international pages could not be searched. Web search quota for this session was exhausted before Thailand-specific searching began, so discovery relied entirely on direct fetching of government sites.
Exact criminal penalty tariffs under the technological-crime emergency decree
The gazette PDF is embedded with a legacy Thai font that extracts as mojibake beyond the first page, so only the enabling provision in section 4 and the gazette dates could be read reliably.
The Thai baht to US dollar conversions used throughout this record
Converted at roughly 32 baht to the dollar for reader orientation. No live rate was checked. Treat every dollar figure as an approximation, not a legal threshold.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Thailand versus Argentina
- Thailand versus Armenia
- Thailand versus Australia
- Thailand versus Austria
- Thailand versus Azerbaijan
- Thailand versus Brazil
- Thailand versus Bulgaria
- Thailand versus Cambodia
- Thailand versus Canada
- Thailand versus China
- Thailand versus Croatia
- Thailand versus Cyprus
- Thailand versus Estonia
- Thailand versus France
- Thailand versus Georgia
- Thailand versus Germany
- Thailand versus Greece
- Thailand versus Hong Kong SAR
- Thailand versus Hungary
- Thailand versus Iceland
- Thailand versus India
- Thailand versus Indonesia
- Thailand versus Ireland
- Thailand versus Israel
- Thailand versus Italy
- Thailand versus Japan
- Thailand versus Latvia
- Thailand versus Lithuania
- Thailand versus Luxembourg
- Thailand versus Malta
- Thailand versus Mexico
- Thailand versus Mongolia
- Thailand versus Nepal
- Thailand versus Netherlands
- Thailand versus Poland
- Thailand versus Russia
- Thailand versus Saudi Arabia
- Thailand versus Serbia
- Thailand versus Singapore
- Thailand versus Slovakia
- Thailand versus Slovenia
- Thailand versus South Korea
- Thailand versus Spain
- Thailand versus Sri Lanka
- Thailand versus Sweden
- Thailand versus Switzerland
- Thailand versus Taiwan
- Thailand versus Turkey
- Thailand versus Ukraine
- Thailand versus United Arab Emirates
- Thailand versus United Kingdom
- Thailand versus United States
- Thailand versus Uzbekistan