Skip to the content
Global Data RulesData governance rules, country by country

Thailand

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Thailand — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

Thailand does not make you keep personal data inside the country. But data cannot leave until you have picked a legal route and written it down. The regulator never published a list of approved destination countries. So consent and written safeguards do all the work. A foreign company selling into Thailand needs a named representative living there. Getting it wrong can mean fines, double damages, and in the worst cases jail.

Data governance in Thailand

The eight things that decide how you handle data about people in Thailand. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The privacy law reaches a company with no office in Thailand. It applies if you offer goods or services to people who are in Thailand. It also applies if you track what those people do. Payment does not matter. A free service counts. There is no revenue or staff number below which you escape. A foreign company caught this way must appoint a representative in writing. That person must be physically in Thailand. They can be held answerable, with no cap on liability.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, in most cases. Thailand does not make you keep a copy of personal data inside the country. But data cannot simply leave. You must first have a legal route. The regulator has never published a list of approved destination countries. So the 'this country is safe enough' route does not work. Everyone falls back on informed consent, contract necessity, approved group-wide rules, or their own written safeguards. Several industries add a second gate on top. Those are described below.

Ways to send data out:
Official 'this country is safe' decision · Approved group rules · Standard contract clauses

What to do: Get the paperwork for one of the routes below signed before any data leaves Thailand.

Sending data out of the country

There is no permission slip to apply for and no list of banned countries. You pick a route and write it down before the data moves. Your options are these. The destination is judged to have good enough protection. Or one of six exceptions in the law applies, such as informed consent. Or you use group-wide rules certified by the regulator. Or you use your own written safeguards that a person in Thailand could actually enforce. The 'good enough country' route does not work, because the regulator has published no approved list. So the safeguards route and consent do all the work.

Ways to send data out:
Official 'this country is safe' decision · Approved group rules · Standard contract clauses · Explicit consent · Needed for a contract · To save someone’s life · Important public interest

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

The Office of the Personal Data Protection Committee, usually shortened to PDPC. It sits under the Ministry of Digital Economy and Society. It is real and staffed. It has a serving Secretary-General. It runs walk-in complaint centres in five provinces and opened another in Ubon Ratchathani on 17 August 2026. It is carrying out Cabinet-level instructions on data breaches. Complaints are decided by an Expert Committee. That committee can order you to stop, order you to fix things, and impose fines itself. Other regulators cover their own areas: the cyber-security agency for critical infrastructure, the central bank for payments, and the electronic transactions agency for digital platforms.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

Thailand pushes in both directions at once. The minimum: anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days. An official can order that stretched to as much as two years. The maximum: the privacy law makes you build a system that actually deletes personal data. That happens once your stated keeping period runs out, or once you no longer need the data. When the two collide, the keep-it duty wins. The delete duty has written exceptions for complying with law and for defending legal claims.

What you have to do here:
Keep logs · Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count three deadlines, not one. First, tell the privacy regulator about a personal data breach without delay, and within 72 hours of finding out. You can skip this only if the breach carries no risk to people. If the risk to people is high, you must also tell them without delay, with advice on what to do. Second, if you run critical information infrastructure, report a significant cyber threat to the national cyber-security agency and to your own industry regulator. Staying silent without good reason is itself an offence. Third, banks and telecoms operators. If you suspect technology crime, push customer account and transaction data into a shared government-run system immediately.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things are not in the brochure. Children: Thailand needs a parent's consent for a child aged ten or under. It needs it for older teenagers too, unless the law lets a minor act alone. And a person is a minor in Thailand until twenty. Jail is possible for misusing sensitive data. You owe compensation even if you were not careless, and a court can add up to double on top. A foreign company must put a named human in Thailand with unlimited authority. And the 90-day log rule catches ordinary businesses that just offer guest wi-fi.

What you have to do here:
Get a parent's consent for children · Appoint a representative · Keep logs
What it costs if you get it wrong:
Criminal liability · Claims by individuals

What's changing next

Nothing in the next twelve months looks like a new law. What is moving is how far enforcement reaches. The privacy regulator is opening walk-in centres in eight provinces during 2026, covering all five regions. That means more complaints will actually get filed. The Cabinet decided on 11 August 2026 to require multi-factor login protection across government, to stop leaked passwords turning into data breaches. The ministry is pushing the same expectation across all twenty ministries. The bigger risk is not new law. It is the powers the government already holds and can use without warning.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Payments

Cloud and outsourcing rules

Official name: พระราชบัญญัติระบบการชำระเงิน พ.ศ. ๒๕๖๐ (Payment Systems Act B.E. 2560) · Government Gazette Vol. 134, Part 110 Kor, page 1, 18 October 2017; sections 24 and 25 · Act of parliament

In forceYes, with paperwork

Payments is not a rule about where data must be stored. It is a permission gate. The Payment Systems Act gives the Bank of Thailand express power to set rules on a payment operator's outsourcing. It can also set rules on how the operator keeps and discloses users' personal data, and require records to be held for inspection.

In force since 16 April 2018

Enforced by Bank of Thailand

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Banking

Payment data rules

Official name: พระราชกำหนดมาตรการป้องกันและปราบปรามอาชญากรรมทางเทคโนโลยี พ.ศ. ๒๕๖๖ (Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566), as amended by (No. 2) B.E. 2568 · Government Gazette Vol. 140, Part 18 Kor, page 1, 16 March 2023; amended Vol. 142, Part 27 Kor, page 5, 12 April 2025 · Act of parliament

In forceYes, with paperwork

Banks, payment operators and telecoms companies must hand customer account and transaction data into a central government-run exchange whenever technology crime is suspected. This makes data flow inward, and it overrides normal confidentiality. It was widened by emergency decree in April 2025, without going through Parliament first.

In force since 17 March 2023

Enforced by Ministry of Digital Economy and Society

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
E-commerce

E-commerce data rules

Official name: พระราชกฤษฎีกาการประกอบธุรกิจบริการแพลตฟอร์มดิจิทัลที่ต้องแจ้งให้ทราบ พ.ศ. ๒๕๖๕ (Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565) · Government Gazette Vol. 139, Part 78 Kor, page 17, 23 December 2022 · Directly binding regulation

In forceYes, with paperwork

A platform run entirely from abroad can still count as serving Thai users. That happens if it shows Thai text, uses a Thai domain, takes Thai baht, or picks Thai law. Above modest revenue or 5,000 monthly users it must notify the electronic transactions agency before launch and keep a named contact person inside Thailand.

In force since 21 August 2023

Enforced by Electronic Transactions Development Agency

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. ๒๕๖๒ (Personal Data Protection Act B.E. 2562) · Government Gazette Vol. 136, Part 69 Kor, page 52, 27 May 2019 · Act of parliament

In forceYes, with paperwork

Thailand's general privacy law. It reaches foreign companies that sell to or monitor people in Thailand. It makes you have a representative inside Thailand. Data may leave only through a named route. You must report breaches within 72 hours. It is backed by fines from the regulator, criminal liability and double damages.

In force since 28 May 2019Enforced from 1 June 2022

Enforced by Office of the Personal Data Protection Committee

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Standard contract clauses, Explicit consent, Needed for a contract, To save someone’s life, Important public interest

Telecoms rules

Official name: พระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. ๒๕๕๐ (Computer-Related Crime Act B.E. 2550), section 26 · Computer-Related Crime Act B.E. 2550 (2007) as amended by Act (No. 2) B.E. 2560 (2017), section 26 · Act of parliament

In forceYes, with paperwork

Anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days. An official can order a named provider to keep them for up to two years. The duty catches ordinary businesses with guest wi-fi, not just telecoms carriers.

In force since 18 July 2007

Enforced by Ministry of Digital Economy and Society

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Cyber security rules

Official name: พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์ พ.ศ. ๒๕๖๒ (Cybersecurity Act B.E. 2562) · Government Gazette Vol. 136, Part 69 Kor, page 20, 27 May 2019 · Act of parliament

In forceYes, with paperwork

Organisations named as critical information infrastructure must report significant cyber threats. The report goes both to the national cyber-security agency and to their own industry regulator. Staying quiet without good reason is itself punishable.

In force since 28 May 2019

Enforced by National Cyber Security Agency

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.)

    General personal data protection law

    Operational. The Ministry of Digital Economy and Society's own newsroom of 17 August 2026 names Pol. Col. Surapong Plengkham as Secretary-General. It records public service centres already running in five provinces, expanding to eight during 2026. It also records the Office carrying out a Cabinet decision of 11 August 2026 on breach prevention. Complaints are decided by an Expert Committee, which can mediate, order you to fix something or to stop, and impose fines. Caveat: the Office's own website blocks automated access, so we could not count individual enforcement decisions.

  • กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม (ดีอี)

    Parent ministry; computer crime, technological-crime decree, digital government

    Operational and publishing daily. Verified 18 August 2026 from its own newsroom and law library. That library hosts the Government Gazette texts of the privacy, cyber-security, computer crime and payment systems laws.

  • สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์ (สพธอ.)

    Digital platform services, electronic transactions, social media crime-prevention measures

    Aggressively operational. Its published law library shows a steady stream of binding notifications from 1/2566 (2023) through 7/2568 (2025). It also has guidance dated 2/2569 (2026). Some notifications name specific marketplace and ride-hailing platforms for heavier duties.

  • สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ (สกมช.)

    Critical information infrastructure and cyber incident response

    Site reachable on 18 August 2026. It advertises a 24-hour threat reporting centre (ThaiCERT) and advisory services for critical infrastructure. We did not verify a public list of enforcement actions.

  • ธนาคารแห่งประเทศไทย (ธปท.)

    Banks and regulated payment service providers

    Operational; its laws and announcements portal and notification database were reachable on 18 August 2026. Its data-related powers over payment operators come from sections 24 and 25 of the Payment Systems Act.

  • สำนักงาน กสทช.

    Telecommunications and broadcasting licensees

    The regulator exists and its site responded on 18 August 2026. But it blocks automated access, so we could not read any of its notifications. We record its subscriber-data rules as unverified, not as absent.

  • สำนักงาน ก.ล.ต.

    Securities and derivatives intermediaries, digital asset businesses

    The regulator exists and responds, but we could not read its regulation pages. We record its technology-risk and outsourcing rules as unverified.

  • สำนักงานคณะกรรมการกำกับและส่งเสริมการประกอบธุรกิจประกันภัย (คปภ.)

    Life and non-life insurers and intermediaries

    The regulator exists and its site responded. We record insurance industry data rules as unverified.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The text, dates and exact requirements of the Personal Data Protection Committee's subordinate notifications on cross-border transfer under sections 28 and 29

    We could not confirm what the regulator's detailed rules on sending data abroad actually say. The main law in sections 28 and 29 is verified from the Government Gazette text. But the regulator's own website blocks automated access, and we found no government-hosted copy of those notifications elsewhere. Check them with the regulator before you design a transfer route.

  • The date the main operative chapters of the Personal Data Protection Act actually began to bite, recorded here as 1 June 2022

    We could not confirm the date the main chapters of the Act started to apply, recorded here as 1 June 2022. The Act's own section 2 delayed chapters 2, 3, 5, 6 and 7, plus sections 95 and 96, by one year from publication. Royal decrees then extended that delay twice. We verified section 2 from the Government Gazette text but could not open a government copy of those royal decrees. So the date is carried forward without a government link.

  • Whether the Personal Data Protection Committee has published any list or decision naming countries with an adequate protection standard

    We found no list of countries the Committee treats as safe enough, but we could not read the regulator's site to be sure. Checked 18 August 2026. This record assumes that route cannot be used. If a list has been published, sending data abroad is much easier than described here. Check with the regulator.

  • The number, size and subject matter of enforcement decisions and administrative fines issued by the Personal Data Protection Committee to date

    We could not confirm how many enforcement decisions or fines the Committee has issued, or how large they were. Decisions are published on the regulator's own site, which we could not open. Our 'active' rating rests on other evidence: a named Secretary-General, regional service centres, and Cabinet-level tasking.

  • Whether the Bank of Thailand's current notifications require prior approval for offshore outsourcing or offshore cloud by financial institutions and payment operators

    We could not confirm whether the Bank of Thailand's current rules require approval before a financial firm uses offshore outsourcing or offshore cloud. The power to set such rules is verified from sections 24 and 25 of the Payment Systems Act. We record this as a permission gate with medium confidence. If you are a payment operator, ask the Bank.

  • Whether securities firms, insurers or telecoms licensees are subject to any keeping data in the country or offshore-storage restriction

    We could not confirm the rules for securities firms, insurers and telecoms licensees. We could not read a single one of their notifications on 18 August 2026. If you work in these industries, check with your regulator before you rely on this.

  • Whether Thailand has a restriction on surveying, mapping or geospatial data leaving the country

    We could not confirm whether Thailand restricts survey, mapping or geospatial data leaving the country. The national geo-informatics and survey bodies (gistda.or.th, rtsd.mi.th) did not respond to us. We reached no conclusion either way. If you handle mapping data, check with them first.

  • Whether health records are subject to any storage or transfer restriction beyond the general privacy law

    We could not confirm whether health records face extra rules on storage or transfer. The National Health Commission Office site dropped our connection and the Ministry of Public Health site refused it. The confidentiality rule in the National Health Act is well known, but we could not verify it from a government source. So this record claims no health rule. If you handle patient data, check before you rely on that.

  • The current text of Thailand's government cloud policy, including whether it mandates domestic hosting for classified government workloads

    We could not confirm the current text of Thailand's government cloud policy. The Digital Government Development Agency site (dga.or.th) blocks automated access. This record relies on the Act on Government Administration and Service Delivery in Digital Format, which is verified. It describes the push toward Thai hosting as practice, not as a verified legal duty.

  • The five-year retention floors for accounting records and tax documents

    We could not confirm the five-year minimums for accounting records and tax documents. These are the two figures most commonly cited in Thailand. But we did not open a government copy of the Accounting Act or the Revenue Code. Check both before you set your keeping periods.

  • Whether any bill amending the Personal Data Protection Act is currently before Parliament, and Thailand's current status in the Global Cross-Border Privacy Rules system

    We could not confirm whether any bill amending the Personal Data Protection Act is before Parliament. We also could not confirm Thailand's current standing in the Global Cross-Border Privacy Rules system. We could not search the parliamentary bill tracker or the regulator's international pages. Check both if a change would affect your plans.

  • Exact criminal penalty tariffs under the technological-crime emergency decree

    We could not confirm the exact criminal penalties under the technological-crime emergency decree. The official gazette PDF uses an old Thai font that turns to garbled text beyond the first page. We could read only the enabling wording in section 4 and the gazette dates.

  • The Thai baht to US dollar conversions used throughout this record

    We converted at roughly 32 baht to the dollar, to give you a sense of scale. We did not check a live exchange rate. Treat every dollar figure as an approximation, not a legal threshold.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.