Thailand
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Thailand — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Thailand does not make you keep personal data inside the country. But data cannot leave until you have picked a legal route and written it down. The regulator never published a list of approved destination countries. So consent and written safeguards do all the work. A foreign company selling into Thailand needs a named representative living there. Getting it wrong can mean fines, double damages, and in the worst cases jail.
Data governance in Thailand
The eight things that decide how you handle data about people in Thailand. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The privacy law reaches a company with no office in Thailand. It applies if you offer goods or services to people who are in Thailand. It also applies if you track what those people do. Payment does not matter. A free service counts. There is no revenue or staff number below which you escape. A foreign company caught this way must appoint a representative in writing. That person must be physically in Thailand. They can be held answerable, with no cap on liability.
- What you have to do here:
- Appoint a representative
Personal Data Protection Act B.E. 2562 (2019), section 5. The Act applies to any company in Thailand that decides how personal data is used, or that handles data for someone else. That is true wherever the data is actually handled. It also applies to a company outside Thailand in two cases. One, you offer goods or services to people in Thailand, whether or not they pay. Two, you monitor the behaviour of people in Thailand. Section 37(5) applies if the second paragraph of section 5 catches you. You must appoint a written representative located in the Kingdom, authorised to act for you 'without any limitation of liability'. Section 38 exempts only two groups. State agencies named by the Committee. And companies whose business does not involve sensitive data and does not handle personal data at the scale the Committee sets under section 41(2). Separately, the Royal Decree on Digital Platform Services treats a foreign platform as serving Thai users in four cases. If it displays in Thai. If it uses a .th or .ไทย domain. If it accepts Thai baht. Or if it names Thai law as the governing law. Those operators must tell the Electronic Transactions Development Agency before they start. They must also appoint a written point of contact located in Thailand.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 5, 37(5) and 38
mdes.go.th
“ในกรณีที่ผู้ควบคุมข้อมูลส่วนบุคคลหรือผู้ประมวลผลข้อมูลส่วนบุคคลอยู่นอกราชอาณาจักร พระราชบัญญัตินี้ให้ใช้บังคับแก่การเก็บรวบรวม ใช้ หรือเปิดเผยข้อมูลส่วนบุคคลของเจ้าของข้อมูลส่วนบุคคลซึ่งอยู่ในราชอาณาจักร”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development Agency (official English translation)Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022), sections 5, 8 and 11
etda.or.th
“the operator shall appoint, in writing, a point of contact to perform duties to coordinate with the Agency in the Kingdom. The point of contact performing such duties must be located within the Kingdom”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyDigital platform law library: the Royal Decree, Electronic Transactions Commission notifications and ETDA notifications 1/2566 to 7/2568
etda.or.th
Link checked 18 August 2026
Where the data is allowed to live
Yes, in most cases. Thailand does not make you keep a copy of personal data inside the country. But data cannot simply leave. You must first have a legal route. The regulator has never published a list of approved destination countries. So the 'this country is safe enough' route does not work. Everyone falls back on informed consent, contract necessity, approved group-wide rules, or their own written safeguards. Several industries add a second gate on top. Those are described below.
- Ways to send data out:
- Official 'this country is safe' decision · Approved group rules · Standard contract clauses
Section 28 of the Personal Data Protection Act says the destination country or international organisation must have an adequate personal data protection standard. That is judged against criteria the Personal Data Protection Committee publishes under section 16(5). Six exceptions let you transfer anyway. Complying with a law. Consent, where you have told the person the destination's protection is not adequate. Necessity for a contract with the person, or for steps before a contract. A contract made with someone else for the person's benefit. Protecting life, body or health where the person cannot give consent. And carrying out an important public-interest task. Section 29 adds two more routes that skip section 28 entirely. First, a group-wide personal data protection policy, reviewed and certified by the Office. Second, 'appropriate safeguards' that make the person's rights enforceable and give them real legal remedies, following rules the Committee publishes. INDUSTRY RULES ON TOP. (1) Banking and payments. Section 24 of the Payment Systems Act B.E. 2560 (2017) gives the Bank of Thailand express power to set binding rules on a payment operator's outsourced service providers. It can also set rules on how users' personal data is kept and disclosed. Section 25 makes operators keep records, accounts and evidence on the Bank's terms so it can inspect them. So a decision to use an offshore cloud turns into a conversation with the Bank. Rating: data can leave only if conditions are met (2) Government. State bodies are steered onto Thai government data-centre and cloud arrangements. That comes from the Act on Government Administration and Service Delivery in Digital Format B.E. 2562 (2019) and from Cabinet-level digital-government policy. Rating: data can leave only if conditions are met, close to Thai hosting by default. (3) Telecoms and any 'service provider'. The Computer Crime Act makes you keep computer traffic data for at least 90 days, in a form officials can get at. That pulls logs into Thailand, or at least into two places at once. It is not written as a rule about where data must be stored. (4) Banking and telecoms together. The technological-crime emergency decree makes both disclose and exchange customer account and transaction data. That happens through a central system run under the Ministry of Digital Economy and Society. That data flows inward, not outward. (5) Health, insurance, securities and mapping. We looked for firm rules on where data must stay and found none we could verify from a government source. See the 'unconfirmed' list. Do not read that as a finding that no rule exists.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 28 and 29
mdes.go.th
“ในกรณีที่ผู้ควบคุมข้อมูลส่วนบุคคลส่งหรือโอนข้อมูลส่วนบุคคลไปยังต่างประเทศ ประเทศปลายทางหรือองค์การระหว่างประเทศที่รับข้อมูลส่วนบุคคลต้องมีมาตรฐานการคุ้มครองข้อมูลส่วนบุคคลที่เพียงพอ”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Payment Systems Act B.E. 2560 (2017), sections 24(6), 24(7) and 25 — Bank of Thailand power over outsourcing and over retention and disclosure of users' personal data
mdes.go.th
Link checked 18 August 2026
- Official sourceBank of ThailandPayment Systems Act B.E. 2560 (2017) — official English translation
bot.or.th
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Act on Government Administration and Service Delivery in Digital Format B.E. 2562 (2019), section 12 — data governance duties on state agencies
mdes.go.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023), Government Gazette Vol. 140 Part 18 Kor, 16 March 2023
etda.or.th
“มาตรา ๔ ... ให้สถาบันการเงินและผู้ประกอบธุรกิจ มีหน้าที่เปิดเผยหรือแลกเปลี่ยนข้อมูลเกี่ยวกับบัญชีและธุรกรรมของลูกค้า”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Thailand.
Sending data out of the country
There is no permission slip to apply for and no list of banned countries. You pick a route and write it down before the data moves. Your options are these. The destination is judged to have good enough protection. Or one of six exceptions in the law applies, such as informed consent. Or you use group-wide rules certified by the regulator. Or you use your own written safeguards that a person in Thailand could actually enforce. The 'good enough country' route does not work, because the regulator has published no approved list. So the safeguards route and consent do all the work.
- Ways to send data out:
- Official 'this country is safe' decision · Approved group rules · Standard contract clauses · Explicit consent · Needed for a contract · To save someone’s life · Important public interest
The model is case-by-case self-assessment, with the regulator deciding the hard cases. Section 28 paragraph two says this. Where there is a question about whether a destination's standard is adequate, the Personal Data Protection Committee decides. It can revisit that decision on new evidence. You do not need approval before an ordinary transfer. There is no filing and no register. The only route that needs approval first is the group-wide rules route in section 29 paragraph one. There, the Office reviews and certifies a group policy. Section 29 paragraph three does most of the work. Where there is no Committee decision on the destination and no certified group policy, you may still transfer. You need appropriate safeguards in place, following rules and methods the Committee publishes. IMPORTANT GAP. The Committee has issued further notifications filling out sections 28 and 29. We could not open the regulator's own website, because it blocks automated access. We could not find a government-hosted copy of those notifications. So we confirm that they exist, but not what they say. See 'unconfirmed'. Penalties for picking the wrong route are graded. Up to three million baht for ordinary personal data. Up to five million baht where sensitive data is involved.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 28, 29, 83, 84 and 87
mdes.go.th
“มาตรา ๘๗ ผู้ประมวลผลข้อมูลส่วนบุคคลผู้ใดส่งหรือโอนข้อมูลส่วนบุคคลตามมาตรา ๒๖ ... ต้องระวางโทษปรับทางปกครองไม่เกินห้าล้านบาท”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommitteeOffice of the Personal Data Protection Committee — official website
pdpc.or.th
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
The Office of the Personal Data Protection Committee, usually shortened to PDPC. It sits under the Ministry of Digital Economy and Society. It is real and staffed. It has a serving Secretary-General. It runs walk-in complaint centres in five provinces and opened another in Ubon Ratchathani on 17 August 2026. It is carrying out Cabinet-level instructions on data breaches. Complaints are decided by an Expert Committee. That committee can order you to stop, order you to fix things, and impose fines itself. Other regulators cover their own areas: the cyber-security agency for critical infrastructure, the central bank for payments, and the electronic transactions agency for digital platforms.
We rate enforcement as active, on the following evidence, verified on 18 August 2026. The Ministry's own newsroom of 17 August 2026 names Pol. Col. Surapong Plengkham as Secretary-General of the Office of the Personal Data Protection Committee. It records that the Office already runs public service centres in five provinces, expanding to eight during 2026 across all five regions. It also records a Cabinet decision of 11 August 2026. That approved a government-wide approach to stopping personal data leaks caused by stolen login details, using multi-factor authentication. So this is an agency with a chair, a budget, offices around the country and a policy job. It is not a paper body. Under sections 72 and 90 of the Act, the Expert Committee handles complaints. It can try mediation. It can order you to fix something or to stop. It can impose fines directly, taking into account how serious the conduct was and how big your business is. Unpaid fines are collected under the administrative procedure law. HONEST LIMIT. We could not reach the regulator's own website, because it blocks automated access. So we could not count or quote individual enforcement decisions. The 'active' rating rests on evidence about the institution, not on a verified list of decisions.
Sources
- Official sourceMinistry of Digital Economy and SocietyDeputy Minister opens the southern Isan PDPA Center, 17 August 2026 — names the Secretary-General of the Personal Data Protection Committee Office and records the Cabinet resolution of 11 August 2026 on multi-factor authentication
mdes.go.th
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 72 and 90 — powers of the Expert Committee to order and to fine
mdes.go.th
“มาตรา ๙๐ คณะกรรมการผู้เชี่ยวชาญมีอำนาจสั่งลงโทษปรับทางปกครอง”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Cybersecurity Act B.E. 2562 (2019), section 57 — reporting line to the National Cyber Security Agency and the sector regulator
mdes.go.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyDigital platform law library: the Royal Decree, Electronic Transactions Commission notifications and ETDA notifications 1/2566 to 7/2568
etda.or.th
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommitteeOffice of the Personal Data Protection Committee — official website
pdpc.or.th
Link checked 18 August 2026
How long you must keep it — and when to delete it
Thailand pushes in both directions at once. The minimum: anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days. An official can order that stretched to as much as two years. The maximum: the privacy law makes you build a system that actually deletes personal data. That happens once your stated keeping period runs out, or once you no longer need the data. When the two collide, the keep-it duty wins. The delete duty has written exceptions for complying with law and for defending legal claims.
- What you have to do here:
- Keep logs · Keep data for a minimum period · Delete data after a period
MINIMUM. Computer-Related Crime Act B.E. 2550 (2007), section 26. A service provider must keep computer traffic data for at least ninety days from the date the data enters the computer system. Where necessary, an official may order a particular provider to keep traffic data for longer than ninety days, up to a maximum of two years. Getting this wrong carries a fine of up to five hundred thousand baht (about 15,000 US dollars). 'Service provider' is defined broadly. It catches businesses that merely give other people internet access. That is why hotels, co-working spaces and offices with guest wi-fi are caught. MAXIMUM. Personal Data Protection Act section 37(3). You must put in place a system that checks and then erases or destroys personal data. That happens when the keeping period ends. Or when the data is no longer relevant or goes beyond what you need it for. Or when the person asks, or withdraws consent. There are exceptions. They cover freedom of expression, the public-interest and research grounds in sections 24(1), 24(4) and 26(5), establishing, exercising or defending legal claims, and complying with law. Section 39 separately makes your record of data uses state the keeping period for each category. NOT VERIFIED. Two general business minimums are widely relied on in Thailand. Five years of accounting records under the Accounting Act. Five years of tax documents under the Revenue Code. We did not open a government copy of either. See 'unconfirmed'.
Sources
- Official sourceMinistry of Digital Economy and Society (Office of the Council of State consolidated text)Computer-Related Crime Act B.E. 2550 (2007) as amended, section 26 — ninety-day traffic data retention, extendable to two years by order
mdes.go.th
“มาตรา ๒๖ ผู้ให้บริการต้องเก็บรักษาข้อมูลจราจรทางคอมพิวเตอร์ไว้ไม่น้อยกว่าเก้าสิบวันนับแต่วันที่ข้อมูลนั้นเข้าสู่ระบบคอมพิวเตอร์ แต่ในกรณีจำเป็น พนักงานเจ้าหน้าที่จะสั่งให้...เกินเก้าสิบวันแต่ไม่เกินสองปี”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 37(3) and 39 — duty to erase and duty to record retention periods
mdes.go.th
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count three deadlines, not one. First, tell the privacy regulator about a personal data breach without delay, and within 72 hours of finding out. You can skip this only if the breach carries no risk to people. If the risk to people is high, you must also tell them without delay, with advice on what to do. Second, if you run critical information infrastructure, report a significant cyber threat to the national cyber-security agency and to your own industry regulator. Staying silent without good reason is itself an offence. Third, banks and telecoms operators. If you suspect technology crime, push customer account and transaction data into a shared government-run system immediately.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
DEADLINE 1 - Personal Data Protection Act section 37(4). Tell the Office without delay, and where possible within seventy-two hours of finding out. You can skip this if the breach is unlikely to risk people's rights and freedoms. Where the risk is high, also tell the person affected, without delay, along with what you are doing to put it right. The detail of the notice and its exceptions is set by Committee notification. DEADLINE 2 - Cybersecurity Act B.E. 2562 (2019) section 57. If a significant cyber threat hits a critical information infrastructure organisation's systems, that organisation must report it. The report goes to the Office of the National Cyber Security Committee and to its own regulator or supervisor. It must also carry out the required response steps. Failing to report without a reasonable excuse carries a fine of up to two hundred thousand baht (about 6,000 US dollars). DEADLINE 3 - Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023) section 4, as amended in 2025. Where there is reasonable suspicion of technology crime, financial institutions and business operators must disclose or exchange customer account and transaction data among themselves. That goes through a system run under the Ministry of Digital Economy and Society. The three sets of rules have different triggers, different recipients and different deadlines. One incident can start all three at once.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), section 37(4) — 72-hour breach notification
mdes.go.th
“แจ้งเหตุการละเมิดข้อมูลส่วนบุคคลแก่สำนักงานโดยไม่ชักช้าภายในเจ็ดสิบสองชั่วโมงนับแต่ทราบเหตุเท่าที่จะสามารถกระทำได้”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Cybersecurity Act B.E. 2562 (2019), section 57 and the related penalty provision
mdes.go.th
“มาตรา ๕๗ เมื่อมีเหตุภัยคุกคามทางไซเบอร์เกิดขึ้นอย่างมีนัยสำคัญต่อระบบของหน่วยงานโครงสร้างพื้นฐานสำคัญทางสารสนเทศ ให้...รายงานต่อสำนักงานและหน่วยงานควบคุมหรือกำกับดูแล”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023), Government Gazette Vol. 140 Part 18 Kor, 16 March 2023
etda.or.th
“มาตรา ๔ ... ให้สถาบันการเงินและผู้ประกอบธุรกิจ มีหน้าที่เปิดเผยหรือแลกเปลี่ยนข้อมูลเกี่ยวกับบัญชีและธุรกรรมของลูกค้า”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes (No. 2) B.E. 2568 (2025), Government Gazette Vol. 142 Part 27 Kor, 12 April 2025
etda.or.th
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things are not in the brochure. Children: Thailand needs a parent's consent for a child aged ten or under. It needs it for older teenagers too, unless the law lets a minor act alone. And a person is a minor in Thailand until twenty. Jail is possible for misusing sensitive data. You owe compensation even if you were not careless, and a court can add up to double on top. A foreign company must put a named human in Thailand with unlimited authority. And the 90-day log rule catches ordinary businesses that just offer guest wi-fi.
- What you have to do here:
- Get a parent's consent for children · Appoint a representative · Keep logs
- What it costs if you get it wrong:
- Criminal liability · Claims by individuals
TRAP 1 - children. Section 20 of the Personal Data Protection Act. This covers a minor who has not reached majority by marriage. It also has to be someone not treated as of age under section 27 of the Civil and Commercial Code. For them, you also need consent from the person with parental power. The exception is where the minor may consent alone under sections 22, 23 or 24 of that Code. And where the minor is not over ten years old, you must get consent from the person with parental power. Majority in Thailand is twenty. So the group needing a parental check is far wider than the thirteen or sixteen most global products are built for. The same rule applies to withdrawing consent, to notices, to rights requests and to complaints. TRAP 2 - criminal, not just a fine from the regulator. Section 79. It is an offence to disclose sensitive data unlawfully, or to send it abroad in breach of section 28. That is if you do it in a way likely to cause another person damage, loss of reputation, insult, hatred or humiliation. The penalty is up to six months in prison, or a fine of up to five hundred thousand baht (about 15,000 US dollars), or both. It rises if you did it to get an unlawful benefit for yourself or someone else. Then it is up to one year in prison, or a fine of up to one million baht (about 30,000 US dollars), or both. The offence can be settled, which changes how it gets negotiated. TRAP 3 - you pay even if you were careful, and a court can double it. Section 77. You must compensate a person for damage caused by breaking the Act, 'whether the act was intentional or negligent or not'. There are only two defences. Force majeure or the person's own act. And acting on an official's lawful order. Section 78 lets the court award punitive damages on top, up to twice the actual amount. The claim runs out three years after the injured person learns of the damage and of who is responsible. TRAP 4 - the in-country representative. Section 37(5) applies to a foreign company caught by section 5 paragraph two. You must appoint, in writing, a representative located in Thailand, authorised to act 'without any limitation of liability'. The exemptions in section 38 are narrow. They cover named state agencies, and businesses that do not handle sensitive data and are not large-scale on criteria the Committee sets. This is not a mailbox job. TRAP 5 - who counts as a 'service provider' for logs. The 90-day traffic data duty in section 26 of the Computer-Related Crime Act applies to anyone providing computer service to other people. It is not just telecoms carriers. The fine reaches five hundred thousand baht. Hotels, landlords, clinics and offices with guest networks are routinely caught. TRAP 6 - digital platforms are caught by look and feel. Under the Royal Decree on Digital Platform Services, a platform run entirely from abroad is treated as serving users in Thailand in four cases. If it displays in Thai. If it uses a .th or .ไทย domain. If it accepts payment in Thai baht. Or if it names Thai law as governing. Advance notice to the Electronic Transactions Development Agency then kicks in above certain sizes. For an individual that is revenue above 1.8 million baht a year (about 55,000 US dollars). For a company it is 50 million baht (about 1.5 million US dollars). It also kicks in above 5,000 average monthly users.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 20, 37(5), 77, 78 and 79
mdes.go.th
“ในกรณีที่ผู้เยาว์มีอายุไม่เกินสิบปี ให้ขอความยินยอมจากผู้ใช้อำนาจปกครองที่มีอำนาจกระทำการแทนผู้เยาว์”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (Office of the Council of State consolidated text)Computer-Related Crime Act B.E. 2550 (2007), section 26 and its penalty — fine of up to five hundred thousand baht
mdes.go.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development Agency (official English translation)Royal Decree on Digital Platform Services B.E. 2565 (2022), sections 5 and 8 — deeming rules and notification thresholds
etda.or.th
“a digital platform service with annual revenue from providing the digital platform service within the Kingdom exceeding one million and eight hundred thousand baht in case the operator is a natural person, or exceeding fifty million baht in case the operator is a juristic person”
Link checked 18 August 2026
What's changing next
Nothing in the next twelve months looks like a new law. What is moving is how far enforcement reaches. The privacy regulator is opening walk-in centres in eight provinces during 2026, covering all five regions. That means more complaints will actually get filed. The Cabinet decided on 11 August 2026 to require multi-factor login protection across government, to stop leaked passwords turning into data breaches. The ministry is pushing the same expectation across all twenty ministries. The bigger risk is not new law. It is the powers the government already holds and can use without warning.
LANDING IN THE NEXT TWELVE MONTHS. (1) The Personal Data Protection Committee Office is expanding its regional PDPA Centers from five provinces to eight during 2026, covering all five regions. The Deputy Minister announced this on 17 August 2026, with the Office's Secretary-General present. (2) The Cabinet decision of 11 August 2026 is being put into effect. It covers preventing personal data leaks caused by stolen login details, using multi-factor authentication. The Minister has also said he plans to raise personal data protection and cyber-risk measures across all twenty ministries. POWERS ALREADY HELD THAT COULD CHANGE THINGS WITH NO CONSULTATION. (a) Section 28 read with section 16(5). The Committee sets the criteria for judging whether a destination country's protection is good enough, and decides disputed cases. One decision that a widely used destination is not good enough would kill transfers relying on that route overnight. The criteria could also be relaxed the same way. (b) Section 26 of the Computer-Related Crime Act. An official may order any named service provider to keep traffic data for longer than ninety days, up to two years. That is case by case, with no rule-making needed. (c) The Royal Decree on Digital Platform Services. It lets the Electronic Transactions Commission and the Agency add named platforms to the heavier duty tiers by notification. Notifications 4/2568, 6/2568 and 7/2568 have already named marketplace platforms, and 2/2568 named ride-hailing platforms. So the mechanism is live and in regular use. (d) The technology-crime rules sit in an emergency decree. The executive can amend that without going through Parliament first. It already did, in April 2025. So bank and telecoms data-sharing duties can be widened quickly. (e) Sections 38 and 41. The Committee can define by notification which businesses are 'large scale' and so must appoint a data protection officer and a representative. Moving that line moves thousands of companies in or out. WE COULD NOT VERIFY: whether any bill amending the Personal Data Protection Act is before Parliament. Nor whether Thailand has taken any further step toward the Global Cross-Border Privacy Rules system. See 'unconfirmed'.
Sources
- Official sourceMinistry of Digital Economy and SocietyDeputy Minister opens the southern Isan PDPA Center, 17 August 2026 — names the Secretary-General of the Personal Data Protection Committee Office and records the Cabinet resolution of 11 August 2026 on multi-factor authentication
mdes.go.th
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019), sections 16(5), 28, 38 and 41 — the standing powers behind the dormant switches
mdes.go.th
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and Society (Office of the Council of State consolidated text)Computer-Related Crime Act B.E. 2550 (2007), section 26 — official power to extend log retention to two years
mdes.go.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyDigital platform law library: the Royal Decree, Electronic Transactions Commission notifications and ETDA notifications 1/2566 to 7/2568
etda.or.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes (No. 2) B.E. 2568 (2025), Government Gazette Vol. 142 Part 27 Kor, 12 April 2025
etda.or.th
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: พระราชบัญญัติระบบการชำระเงิน พ.ศ. ๒๕๖๐ (Payment Systems Act B.E. 2560) · Government Gazette Vol. 134, Part 110 Kor, page 1, 18 October 2017; sections 24 and 25 · Act of parliament
Payments is not a rule about where data must be stored. It is a permission gate. The Payment Systems Act gives the Bank of Thailand express power to set rules on a payment operator's outsourcing. It can also set rules on how the operator keeps and discloses users' personal data, and require records to be held for inspection.
Enforced by Bank of Thailand
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Written vendor contractSection 24(6). The Bank of Thailand may set binding criteria on a regulated operator's use of outside service providers. That is what brings cloud and offshore arrangements under its control.
- Keep data for a minimum periodSection 24(7) and section 25. The Bank may set how users' personal data is kept and disclosed. Operators must keep data, accounts, documents and evidence about the business for inspection on the Bank's terms.
- Independent auditSection 25 exists so the Bank can inspect. The problem is an offshore arrangement that gets in the way of inspection, not the transfer itself.
What it costs if you get it wrong
- Loss of your licenceOperating or continuing to operate a regulated payment service in breach of Bank of Thailand criteria.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Payment Systems Act B.E. 2560 (2017), sections 24 and 25 — Thai Government Gazette text
mdes.go.th
“มาตรา ๒๔ ให้ ธปท. มีอำนาจประกาศกำหนดหลักเกณฑ์ ... (๖) การใช้บริการจากบุคคลภายนอก (๗) การเก็บรักษาและการเปิดเผยข้อมูลส่วนบุคคลของผู้ใช้บริการ”
Link checked 18 August 2026
- Official sourceBank of ThailandPayment Systems Act B.E. 2560 (2017) — official English translation
bot.or.th
Link checked 18 August 2026
- Official sourceBank of ThailandLaws and announcements index, including the Bank of Thailand's notification and circular database
bot.or.th
Link checked 18 August 2026
Payment data rules
Official name: พระราชกำหนดมาตรการป้องกันและปราบปรามอาชญากรรมทางเทคโนโลยี พ.ศ. ๒๕๖๖ (Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566), as amended by (No. 2) B.E. 2568 · Government Gazette Vol. 140, Part 18 Kor, page 1, 16 March 2023; amended Vol. 142, Part 27 Kor, page 5, 12 April 2025 · Act of parliament
Banks, payment operators and telecoms companies must hand customer account and transaction data into a central government-run exchange whenever technology crime is suspected. This makes data flow inward, and it overrides normal confidentiality. It was widened by emergency decree in April 2025, without going through Parliament first.
Enforced by Ministry of Digital Economy and Society
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Report cyber incidentsSection 4. This applies where there is reasonable suspicion of technological crime. Financial institutions and business operators must then disclose or exchange customer account and transaction data among themselves. That goes through a system run under the Ministry of Digital Economy and Society.
- Do not hand data to foreign authorities on demandThe duty runs inward. Banking secrecy and ordinary privacy objections are not an excuse for withholding data from the government-run exchange.
What it costs if you get it wrong
- Criminal liabilityThe Decree carries criminal provisions, including for mule accounts and SIM cards; we did not verify the exact tariffs from the gazette text during this run.
Sources
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023), Government Gazette Vol. 140 Part 18 Kor, 16 March 2023
etda.or.th
“มาตรา ๔ ... ให้สถาบันการเงินและผู้ประกอบธุรกิจ มีหน้าที่เปิดเผยหรือแลกเปลี่ยนข้อมูลเกี่ยวกับบัญชีและธุรกรรมของลูกค้า”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyEmergency Decree on Measures for the Prevention and Suppression of Technological Crimes (No. 2) B.E. 2568 (2025), Government Gazette Vol. 142 Part 27 Kor, 12 April 2025
etda.or.th
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyDigital platform law library: the Royal Decree, Electronic Transactions Commission notifications and ETDA notifications 1/2566 to 7/2568
etda.or.th
Link checked 18 August 2026
E-commerce data rules
Official name: พระราชกฤษฎีกาการประกอบธุรกิจบริการแพลตฟอร์มดิจิทัลที่ต้องแจ้งให้ทราบ พ.ศ. ๒๕๖๕ (Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565) · Government Gazette Vol. 139, Part 78 Kor, page 17, 23 December 2022 · Directly binding regulation
A platform run entirely from abroad can still count as serving Thai users. That happens if it shows Thai text, uses a Thai domain, takes Thai baht, or picks Thai law. Above modest revenue or 5,000 monthly users it must notify the electronic transactions agency before launch and keep a named contact person inside Thailand.
Enforced by Electronic Transactions Development Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notify — applies at: Annual Thai revenue above 1,800,000 baht for an individual operator or above 50,000,000 baht for a company, or more than 5,000 average monthly active users in ThailandSection 8. Prior notification to the Electronic Transactions Development Agency before starting; annual re-notification and change notifications thereafter.
- Appoint a representativeSection 11. A written point of contact must be appointed and must be located in Thailand. The Decree says this does not by itself require establishing a business in Thailand.
- Tell people what you doTerms and conditions must be published to users, and changes notified, under Electronic Transactions Commission notifications.
- Keep records of how you use dataAnnual reporting of operating information to the Agency.
What it costs if you get it wrong
- Order to stopOperating a notifiable digital platform service without notification, or failing to comply with the heavier duties imposed on named marketplace and ride-hailing platforms.
Sources
- Official sourceElectronic Transactions Development Agency (official English translation)Royal Decree on Digital Platform Services B.E. 2565 (2022), sections 5, 8 and 11 — official English translation published by the regulator
etda.or.th
“The digital platform is displayed, in whole or in part, in the Thai language ... shall be deemed to have provided services to users located within the Kingdom”
Link checked 18 August 2026
- Official sourceElectronic Transactions Development AgencyDigital platform law library: the Royal Decree, Electronic Transactions Commission notifications and ETDA notifications 1/2566 to 7/2568
etda.or.th
Link checked 18 August 2026
Cloud and outsourcing rules (Government)
Official name: พระราชบัญญัติการบริหารงานและการให้บริการภาครัฐผ่านระบบดิจิทัล พ.ศ. ๒๕๖๒ (Act on Government Administration and Service Delivery in Digital Format B.E. 2562) · Government Gazette Vol. 136, Part 67 Kor, page 57, 22 May 2019; section 12 · Act of parliament
Thai state bodies run under their own data governance law, not the ordinary commercial rules. They are steered onto Thai government cloud and data centre arrangements. From August 2026 the Cabinet has also required multi-factor login protection across government. That is to stop stolen passwords becoming data breaches.
Enforced by Ministry of Digital Economy and Society
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep records of how you use dataSection 12. Every state agency must operate agency-level data governance and act in accordance with it, so that government data can be integrated and shared.
- Secure the dataCabinet decision of 11 August 2026. It approved a government-wide approach to preventing personal data leaks caused by stolen login details, using multi-factor authentication.
- Prove the data stays under local controlGovernment computing work is steered onto Thai government data centre and cloud arrangements. We could not verify the current cloud policy text from a government source.
What it costs if you get it wrong
- Order to stopAdministrative direction rather than fines; non-compliance is handled through the digital-government governance chain.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Act on Government Administration and Service Delivery in Digital Format B.E. 2562 (2019), section 12
mdes.go.th
“มาตรา ๑๒ ... ให้หน่วยงานของรัฐจัดทำธรรมาภิบาลข้อมูลภาครัฐในระดับหน่วยงาน”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and SocietyDeputy Minister opens the southern Isan PDPA Center, 17 August 2026 — names the Secretary-General of the Personal Data Protection Committee Office and records the Cabinet resolution of 11 August 2026 on multi-factor authentication
mdes.go.th
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. ๒๕๖๒ (Personal Data Protection Act B.E. 2562) · Government Gazette Vol. 136, Part 69 Kor, page 52, 27 May 2019 · Act of parliament
Thailand's general privacy law. It reaches foreign companies that sell to or monitor people in Thailand. It makes you have a representative inside Thailand. Data may leave only through a named route. You must report breaches within 72 hours. It is backed by fines from the regulator, criminal liability and double damages.
Enforced by Office of the Personal Data Protection Committee
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Standard contract clauses, Explicit consent, Needed for a contract, To save someone’s life, Important public interest
What you have to do
- Put a transfer safeguard in placeSections 28 and 29. No list of approved countries has been published. So that route does not work, and you fall back on consent, contract necessity, certified group rules, or your own appropriate safeguards.
- Report breaches to the regulator — within 72 hoursSection 37(4). Report without delay, and where possible within 72 hours of finding out. You can skip it if the breach is unlikely to risk people's rights and freedoms.
- Tell affected peopleSection 37(4). Where the breach is a high risk to people, tell them without delay, and say what they should do.
- Appoint a representativeSection 37(5). A foreign company must appoint a written representative located in Thailand, authorised with no cap on liability. Section 38 has narrow exemptions.
- Keep records of how you use dataSections 39 and 40(3). Your records of how you use data must state the keeping period for each category. The Committee can excuse small businesses by notification. That does not apply if you handle sensitive data or use personal data more than occasionally.
- Delete data after a periodSection 37(3). You must have a system that actually erases or destroys data once the keeping period ends or you no longer need it.
- Get a parent's consent for childrenSection 20. You always need a parent's consent at age ten or under. You need it for older minors too, unless the Civil and Commercial Code lets the minor act alone. Majority in Thailand is twenty.
- Written vendor contractSection 40 paragraph two. If someone else handles data for you, you must have a written agreement controlling what they do.
- Secure the dataSection 37(1). Security measures must meet the minimum standard the Committee publishes and must be reviewed as technology changes.
What it costs if you get it wrong
- Fixed maximum fine: 5,000,000 baht — about $155 thousandSection 84: mishandling sensitive data, or sending sensitive data abroad outside sections 28 or 29. Section 83 caps ordinary transfer and processing breaches at 3,000,000 baht; section 82 caps record and notice failures at 1,000,000 baht.
- Criminal liability: 1 year imprisonment and/or 1,000,000 baht — about $30 thousandSection 79: unlawful disclosure or transfer of sensitive data likely to cause damage or humiliation; the higher tier applies where done for unlawful benefit. Compoundable offence.
- Claims by individuals: actual damages plus up to 2x punitiveSections 77 and 78: liability regardless of intent or negligence, with punitive damages up to twice actual damages; three-year limitation.
- Order to stop: prohibition and rectification ordersSection 72: the Expert Committee may order a controller or processor to fix conduct or to stop conduct causing damage.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Personal Data Protection Act B.E. 2562 (2019) — full Government Gazette text
mdes.go.th
“มาตรา ๓๗ ... (๔) แจ้งเหตุการละเมิดข้อมูลส่วนบุคคลแก่สำนักงานโดยไม่ชักช้าภายในเจ็ดสิบสองชั่วโมง”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommitteeOffice of the Personal Data Protection Committee — official website
pdpc.or.th
Link checked 18 August 2026
Telecoms rules
Official name: พระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. ๒๕๕๐ (Computer-Related Crime Act B.E. 2550), section 26 · Computer-Related Crime Act B.E. 2550 (2007) as amended by Act (No. 2) B.E. 2560 (2017), section 26 · Act of parliament
Anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days. An official can order a named provider to keep them for up to two years. The duty catches ordinary businesses with guest wi-fi, not just telecoms carriers.
Enforced by Ministry of Digital Economy and Society
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep logs — 3 monthsAt least ninety days from the moment the data enters the computer system. A competent official may order a named provider to keep it longer, up to two years.
What it costs if you get it wrong
- Fixed maximum fine: 500,000 baht — about $15 thousandA service provider that fails to comply with section 26.
Sources
- Official sourceMinistry of Digital Economy and Society (Office of the Council of State consolidated text)Computer-Related Crime Act B.E. 2550 (2007), section 26, consolidated text published by the Ministry of Digital Economy and Society
mdes.go.th
Link checked 18 August 2026
Cyber security rules
Official name: พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์ พ.ศ. ๒๕๖๒ (Cybersecurity Act B.E. 2562) · Government Gazette Vol. 136, Part 69 Kor, page 20, 27 May 2019 · Act of parliament
Organisations named as critical information infrastructure must report significant cyber threats. The report goes both to the national cyber-security agency and to their own industry regulator. Staying quiet without good reason is itself punishable.
Enforced by National Cyber Security Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidentsSection 57. A critical information infrastructure organisation must report a significant cyber threat. The report goes to the National Cyber Security Agency and to its own regulator or supervisor. It must also carry out the required response.
- Hold a security certificateCritical information infrastructure organisations must meet the standards and assessments set by the national cyber-security committee.
What it costs if you get it wrong
- Fixed maximum fine: 200,000 baht — about $6 thousandFailure to report under section 57 without reasonable cause.
Sources
- Official sourceMinistry of Digital Economy and Society (official Royal Gazette copy)Cybersecurity Act B.E. 2562 (2019), section 57 and its penalty provision
mdes.go.th
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The text, dates and exact requirements of the Personal Data Protection Committee's subordinate notifications on cross-border transfer under sections 28 and 29
We could not confirm what the regulator's detailed rules on sending data abroad actually say. The main law in sections 28 and 29 is verified from the Government Gazette text. But the regulator's own website blocks automated access, and we found no government-hosted copy of those notifications elsewhere. Check them with the regulator before you design a transfer route.
The date the main operative chapters of the Personal Data Protection Act actually began to bite, recorded here as 1 June 2022
We could not confirm the date the main chapters of the Act started to apply, recorded here as 1 June 2022. The Act's own section 2 delayed chapters 2, 3, 5, 6 and 7, plus sections 95 and 96, by one year from publication. Royal decrees then extended that delay twice. We verified section 2 from the Government Gazette text but could not open a government copy of those royal decrees. So the date is carried forward without a government link.
Whether the Personal Data Protection Committee has published any list or decision naming countries with an adequate protection standard
We found no list of countries the Committee treats as safe enough, but we could not read the regulator's site to be sure. Checked 18 August 2026. This record assumes that route cannot be used. If a list has been published, sending data abroad is much easier than described here. Check with the regulator.
The number, size and subject matter of enforcement decisions and administrative fines issued by the Personal Data Protection Committee to date
We could not confirm how many enforcement decisions or fines the Committee has issued, or how large they were. Decisions are published on the regulator's own site, which we could not open. Our 'active' rating rests on other evidence: a named Secretary-General, regional service centres, and Cabinet-level tasking.
Whether the Bank of Thailand's current notifications require prior approval for offshore outsourcing or offshore cloud by financial institutions and payment operators
We could not confirm whether the Bank of Thailand's current rules require approval before a financial firm uses offshore outsourcing or offshore cloud. The power to set such rules is verified from sections 24 and 25 of the Payment Systems Act. We record this as a permission gate with medium confidence. If you are a payment operator, ask the Bank.
Whether securities firms, insurers or telecoms licensees are subject to any keeping data in the country or offshore-storage restriction
We could not confirm the rules for securities firms, insurers and telecoms licensees. We could not read a single one of their notifications on 18 August 2026. If you work in these industries, check with your regulator before you rely on this.
Whether Thailand has a restriction on surveying, mapping or geospatial data leaving the country
We could not confirm whether Thailand restricts survey, mapping or geospatial data leaving the country. The national geo-informatics and survey bodies (gistda.or.th, rtsd.mi.th) did not respond to us. We reached no conclusion either way. If you handle mapping data, check with them first.
Whether health records are subject to any storage or transfer restriction beyond the general privacy law
We could not confirm whether health records face extra rules on storage or transfer. The National Health Commission Office site dropped our connection and the Ministry of Public Health site refused it. The confidentiality rule in the National Health Act is well known, but we could not verify it from a government source. So this record claims no health rule. If you handle patient data, check before you rely on that.
The current text of Thailand's government cloud policy, including whether it mandates domestic hosting for classified government workloads
We could not confirm the current text of Thailand's government cloud policy. The Digital Government Development Agency site (dga.or.th) blocks automated access. This record relies on the Act on Government Administration and Service Delivery in Digital Format, which is verified. It describes the push toward Thai hosting as practice, not as a verified legal duty.
The five-year retention floors for accounting records and tax documents
We could not confirm the five-year minimums for accounting records and tax documents. These are the two figures most commonly cited in Thailand. But we did not open a government copy of the Accounting Act or the Revenue Code. Check both before you set your keeping periods.
Whether any bill amending the Personal Data Protection Act is currently before Parliament, and Thailand's current status in the Global Cross-Border Privacy Rules system
We could not confirm whether any bill amending the Personal Data Protection Act is before Parliament. We also could not confirm Thailand's current standing in the Global Cross-Border Privacy Rules system. We could not search the parliamentary bill tracker or the regulator's international pages. Check both if a change would affect your plans.
Exact criminal penalty tariffs under the technological-crime emergency decree
We could not confirm the exact criminal penalties under the technological-crime emergency decree. The official gazette PDF uses an old Thai font that turns to garbled text beyond the first page. We could read only the enabling wording in section 4 and the gazette dates.
The Thai baht to US dollar conversions used throughout this record
We converted at roughly 32 baht to the dollar, to give you a sense of scale. We did not check a live exchange rate. Treat every dollar figure as an approximation, not a legal threshold.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.