Skip to the content
Global Data RulesData governance rules, country by country

Thailand

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Thailand does not make you keep personal data inside the country, but data cannot leave until you have picked and documented a legal route. The regulator never published a list of approved destination countries, so consent and written safeguards do all the work. A foreign company selling into Thailand needs a named representative living there. Getting it wrong can mean fines, double damages, and in the worst cases jail.

Eight questions about Thailand

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Thailand's rules apply to my company?

Yes. The privacy law reaches a company with no office in Thailand if it offers goods or services to people who are in Thailand, or if it tracks what those people do. Payment is irrelevant — a free service counts. There is no revenue or headcount floor to fall below. A foreign company caught this way must appoint, in writing, a representative who is physically in Thailand and who can be held answerable with no cap on liability.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside Thailand?

Yes, in most cases. Thailand does not make companies keep a copy of personal data inside the country. But data cannot simply leave: you must first have a legal route, and the regulator has never published a list of approved destination countries, so the 'this country is safe enough' route is unusable in practice. Everyone falls back on informed consent, contract necessity, approved group-wide rules, or their own written safeguards. Several industries add a second gate on top, described below.

High confidenceYes, with paperworkApproval each timeOfficial 'this country is safe' decisionApproved group rulesStandard contract clauses

What do I need in place before data leaves Thailand?

There is no permission slip to apply for and no banned-country list. You pick a route and document it before the data moves. The routes are: the destination is judged to have good enough protection; one of six statutory exceptions such as informed consent; group-wide rules certified by the regulator; or your own written safeguards that a person in Thailand could actually enforce. The 'good enough country' route is dead on arrival because the regulator has published no approved list, so in practice the safeguards route and consent do all the work.

Medium confidenceApproval each timeOfficial 'this country is safe' decisionApproved group rulesStandard contract clausesExplicit consentNeeded for a contractSomeone's life is at riskImportant public interest

Who enforces the rules in Thailand, and what can they do?

The Office of the Personal Data Protection Committee, usually shortened to PDPC, sits under the Ministry of Digital Economy and Society. It is real and staffed: it has a serving Secretary-General, it runs walk-in complaint centres in five provinces and opened another in Ubon Ratchathani on 17 August 2026, and it is executing Cabinet-level instructions on data breaches. Complaints are decided by an Expert Committee that can order you to stop, order you to fix things, and impose fines itself. Other regulators run their own lanes: the cyber-security agency for critical infrastructure, the central bank for payments, and the electronic transactions agency for digital platforms.

Medium confidenceActiveRegulator

How long do I have to keep the data?

Thailand pushes in both directions at once. The floor: anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days, and an official can order that stretched to as much as two years. The ceiling: the privacy law makes you build a system that actually deletes personal data once your stated retention period runs out or the data is no longer needed. When the two collide, the keep-it duty wins, because the delete duty has a written carve-out for complying with law and for defending legal claims.

High confidenceKeep logsKeep data for a minimum periodDelete data after a periodTraffic and access logs

What happens if there is a breach?

Count three clocks, not one. First: tell the privacy regulator about a personal data breach without delay and within 72 hours of becoming aware, unless the breach carries no risk to people; if the risk to people is high you must also tell the affected individuals, with advice on what to do, without delay. Second: if you run critical information infrastructure, a significant cyber threat must be reported to the national cyber-security agency and to your own sector regulator, and silence without good reason is itself an offence. Third: if you are a bank or a telecoms operator and you suspect technology crime, you must push customer account and transaction data into a shared government-run system immediately.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Thailand?

Five things that are not in the brochure. Children: Thailand needs a parent's consent for a child aged ten or under, and for older teenagers too unless the act is one the law lets a minor do alone — and a person is a minor in Thailand until twenty. Jail is on the table for misusing sensitive data. You owe compensation even if you were not careless, and a court can add up to double on top. A foreign company must put a named human in Thailand with unlimited authority. And the 90-day log rule catches ordinary businesses that just offer guest wi-fi.

High confidenceGet a parent's consent for childrenCriminal liabilityClaims by individualsAppoint a local representativeKeep logs

What is changing soon in Thailand?

Nothing in the next twelve months looks like a new statute. What is moving is enforcement reach. The privacy regulator is opening walk-in centres in eight provinces during 2026 to cover all five regions, which means more complaints will actually get filed. The Cabinet decided on 11 August 2026 to require multi-factor login protection across government to stop leaked passwords turning into data breaches, and the ministry is pushing the same expectation across all twenty ministries. The bigger risk is not new law but switches the government already holds and can flip without warning.

Medium confidenceIn force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    4 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules3 rules

พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. ๒๕๖๒ (Personal Data Protection Act B.E. 2562)

Act of parliament · Government Gazette Vol. 136, Part 69 Kor, page 52, 27 May 2019

In forceYes, with paperwork

Thailand's general privacy law. It reaches foreign companies that sell to or monitor people in Thailand, requires a representative inside Thailand, allows data to leave only through a named route, gives people 72-hour breach notice, and backs it with administrative fines, criminal liability and double damages.

In force since 28 May 2019But only enforceable from 1 June 2022

Enforced by Office of the Personal Data Protection Committee

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Standard contract clauses, Explicit consent, Needed for a contract, Someone's life is at risk, Important public interest

High confidence

พระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. ๒๕๕๐ (Computer-Related Crime Act B.E. 2550), section 26

Act of parliament · Computer-Related Crime Act B.E. 2550 (2007) as amended by Act (No. 2) B.E. 2560 (2017), section 26

In forceYes, with paperwork

Anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days, and an official can order that stretched to two years for a named provider. The duty catches ordinary businesses with guest wi-fi, not just telecoms carriers.

In force since 18 July 2007

Enforced by Ministry of Digital Economy and Society

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์ พ.ศ. ๒๕๖๒ (Cybersecurity Act B.E. 2562)

Act of parliament · Government Gazette Vol. 136, Part 69 Kor, page 20, 27 May 2019

In forceYes, with paperwork

Organisations designated as critical information infrastructure must report significant cyber threats both to the national cyber-security agency and to their own sector regulator, and staying quiet without good reason is itself punishable.

In force since 28 May 2019

Enforced by National Cyber Security Agency

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules4 rules

พระราชบัญญัติระบบการชำระเงิน พ.ศ. ๒๕๖๐ (Payment Systems Act B.E. 2560)

Act of parliament · Government Gazette Vol. 134, Part 110 Kor, page 1, 18 October 2017; sections 24 and 25 · Payments

In forceYes, with paperwork

Payments is not a hard residency wall but it is a permission gate. The Payment Systems Act gives the Bank of Thailand express power to set rules on a payment operator's outsourcing and on how it keeps and discloses users' personal data, and to require records to be held for inspection.

In force since 16 April 2018

Enforced by Bank of Thailand

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

พระราชกำหนดมาตรการป้องกันและปราบปรามอาชญากรรมทางเทคโนโลยี พ.ศ. ๒๕๖๖ (Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566), as amended by (No. 2) B.E. 2568

Act of parliament · Government Gazette Vol. 140, Part 18 Kor, page 1, 16 March 2023; amended Vol. 142, Part 27 Kor, page 5, 12 April 2025 · Banking

In forceYes, with paperwork

Banks, payment operators and telecoms companies must hand customer account and transaction data into a central government-run exchange whenever technology crime is suspected. It is an inward data-sharing mandate that overrides normal confidentiality, and it was widened by emergency decree in April 2025 without going through Parliament first.

In force since 17 March 2023

Enforced by Ministry of Digital Economy and Society

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

พระราชกฤษฎีกาการประกอบธุรกิจบริการแพลตฟอร์มดิจิทัลที่ต้องแจ้งให้ทราบ พ.ศ. ๒๕๖๕ (Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565)

Directly binding regulation · Government Gazette Vol. 139, Part 78 Kor, page 17, 23 December 2022 · E-commerce

In forceYes, with paperwork

A platform run entirely from abroad is treated as serving Thai users if it merely shows Thai text, uses a Thai domain, takes Thai baht, or picks Thai law. Above modest revenue or 5,000 monthly users it must notify the electronic transactions agency before launch and keep a named contact person inside Thailand.

In force since 21 August 2023

Enforced by Electronic Transactions Development Agency

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.)

    General personal data protection law

    Operational. The Ministry of Digital Economy and Society's own newsroom of 17 August 2026 names Pol. Col. Surapong Plengkham as Secretary-General, records public service centres already running in five provinces with expansion to eight during 2026, and records the Office executing a Cabinet resolution of 11 August 2026 on breach prevention. Complaints are decided by an Expert Committee which may mediate, order rectification or prohibition, and impose administrative fines. Caveat: the Office's own website could not be opened during this run because it sits behind a bot challenge, so individual enforcement decisions were not counted.

  • กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม (ดีอี)

    Parent ministry; computer crime, technological-crime decree, digital government

    Operational and publishing daily. Verified 18 August 2026 from its own newsroom and law library, which hosts the Government Gazette texts of the privacy, cyber-security, computer crime and payment systems statutes.

  • สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์ (สพธอ.)

    Digital platform services, electronic transactions, social media crime-prevention measures

    Aggressively operational. Its published law library shows a continuous stream of binding notifications from 1/2566 (2023) through 7/2568 (2025) and guidance dated 2/2569 (2026), including notifications naming specific marketplace and ride-hailing platforms for heavier duties.

  • สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ (สกมช.)

    Critical information infrastructure and cyber incident response

    Site reachable on 18 August 2026 and advertising a 24-hour threat reporting centre (ThaiCERT) and critical-infrastructure advisory services. We did not verify a public list of enforcement actions.

  • ธนาคารแห่งประเทศไทย (ธปท.)

    Banks and regulated payment service providers

    Operational; its laws and announcements portal and notification database were reachable on 18 August 2026. Its data-related powers over payment operators come from sections 24 and 25 of the Payment Systems Act.

  • สำนักงาน กสทช.

    Telecommunications and broadcasting licensees

    The regulator exists and its site responded on 18 August 2026, but it is behind a bot challenge and we could not read any of its notifications during this run. Its subscriber-data rules are therefore recorded as unverified, not as absent.

  • สำนักงาน ก.ล.ต.

    Securities and derivatives intermediaries, digital asset businesses

    Regulator exists and responds, but its regulation pages could not be read during this run. Its technology-risk and outsourcing rules are recorded as unverified.

  • สำนักงานคณะกรรมการกำกับและส่งเสริมการประกอบธุรกิจประกันภัย (คปภ.)

    Life and non-life insurers and intermediaries

    Regulator exists and its site responded, but its law library renders only with JavaScript and could not be read during this run. Insurance-sector data rules are recorded as unverified.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The text, dates and exact requirements of the Personal Data Protection Committee's subordinate notifications on cross-border transfer under sections 28 and 29

    The regulator's own website at pdpc.or.th is behind a Cloudflare bot challenge and returned 403 to every attempt on 18 August 2026, including through a text-rendering proxy. No government-hosted mirror of these notifications could be located. The statutory framework in sections 28 and 29 is verified from the Government Gazette text; the implementing detail is not.

  • The date the main operative chapters of the Personal Data Protection Act actually began to bite, recorded here as 1 June 2022

    The Act's own section 2 delays Chapters 2, 3, 5, 6 and 7 and sections 95 and 96 by one year from publication, and that delay was then extended twice by royal decree. We verified section 2 from the Government Gazette text but could not open a government copy of the postponement royal decrees during this run, so the 1 June 2022 date is carried forward without a verified backlink.

  • Whether the Personal Data Protection Committee has published any list or decision naming countries with an adequate protection standard

    We found no such list, but we could not read the regulator's site, so this is 'not found, checked 18 August 2026' and not a finding that no list exists. The record assumes the adequacy route is unusable in practice; if a list has been published, the transfer picture is materially more permissive.

  • The number, size and subject matter of enforcement decisions and administrative fines issued by the Personal Data Protection Committee to date

    Decisions are published on the regulator's own site, which we could not open. The 'active' enforcement rating rests on institutional evidence — a named Secretary-General, regional service centres, Cabinet-level tasking — rather than on a verified decision count.

  • Whether the Bank of Thailand's current notifications require prior approval for offshore outsourcing or offshore cloud by financial institutions and payment operators

    The statutory power is verified from sections 24 and 25 of the Payment Systems Act, but the Bank's notification database renders only with JavaScript and its document URLs could not be resolved during this run. The rule is therefore recorded as a permission gate with medium confidence rather than as a specific approval requirement.

  • Whether securities firms, insurers or telecoms licensees are subject to any data localisation or offshore-storage restriction

    The Securities and Exchange Commission, the Office of Insurance Commission and the National Broadcasting and Telecommunications Commission all sit behind bot challenges or JavaScript-only law libraries. We could not read a single one of their notifications on 18 August 2026. Absence from this record is a gap in our access, not evidence of absence in law.

  • Whether Thailand has a restriction on surveying, mapping or geospatial data leaving the country

    The national geo-informatics and survey bodies (gistda.or.th, rtsd.mi.th) did not resolve from this environment. No conclusion either way was reached.

  • Whether health records are subject to any storage or transfer restriction beyond the general privacy law

    The National Health Commission Office site reset the connection and the Ministry of Public Health site returned 403. The confidentiality rule in the National Health Act is well known but was not verified from a government source this run, so no health rule is asserted.

  • The current text of Thailand's government cloud policy, including whether it mandates domestic hosting for classified government workloads

    The Digital Government Development Agency site (dga.or.th) is behind a bot challenge. The record relies on the Act on Government Administration and Service Delivery in Digital Format, which is verified, and describes the cloud steer as practice rather than as a verified legal mandate.

  • The five-year retention floors for accounting records and tax documents

    These are the two floors most commonly cited in Thai practice, but we did not open a government copy of the Accounting Act or the Revenue Code during this run and therefore do not assert them as verified.

  • Whether any bill amending the Personal Data Protection Act is currently before Parliament, and Thailand's current status in the Global Cross-Border Privacy Rules system

    The parliamentary bill tracker and the regulator's international pages could not be searched. Web search quota for this session was exhausted before Thailand-specific searching began, so discovery relied entirely on direct fetching of government sites.

  • Exact criminal penalty tariffs under the technological-crime emergency decree

    The gazette PDF is embedded with a legacy Thai font that extracts as mojibake beyond the first page, so only the enabling provision in section 4 and the gazette dates could be read reliably.

  • The Thai baht to US dollar conversions used throughout this record

    Converted at roughly 32 baht to the dollar for reader orientation. No live rate was checked. Treat every dollar figure as an approximation, not a legal threshold.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.