back to dlvx thailand

thailand / pdpa compliance guide

does thailand's pdpa apply to your website? yes, almost always.

no general small business exemption, no personal use carve out for a commercial site, and a real extraterritorial test that catches a foreign run website serving thai visitors. this page reads straight off the act's own english translation: what section applies, what the penalties actually are, and what is still genuinely unsettled, cookies included.

this is an independent reading of the personal data protection act, not a cookie banner sales page. the word cookie never appears anywhere in the act, and thailand has no dedicated cookie law the way the eu has the eprivacy directive sitting next to gdpr. most pages on this topic are published by cookie consent vendors asserting a hard consent rule they cannot cite in the act or in any pdpc notification. we read all 96 sections instead of guessing, we say plainly what the act does and does not say, and where the law itself is unsettled we say so and point to a thai data protection lawyer rather than pick a side. pdpa governance work is part of every ai and website project we ship in bangkok, and this page is the reference we hand a client before that conversation, not a pitch for it.

general information, not legal advice. for anything specific to your business, a live data breach, or a pdpc complaint, talk to a thai data protection lawyer.

ask a pdpa question

00 . the short answer

straight answers, checked 14 september 2026.

01

does the pdpa apply to my business?

Almost certainly. The base rule in Section 5 covers any collection, use or disclosure of personal data by a controller or processor located in Thailand, and there is no general small-business exemption. The only real relief is a narrow exemption from formal record keeping under Section 39, and it does not touch consent, security or breach notification. Section 4(1)'s personal or household exemption does not cover a commercial website: running a business is not personal or household activity, even for a sole trader.

02

what happens if we get this wrong?

It runs across three tiers: criminal (up to 1 year in prison and THB 1,000,000, and it can reach a director or manager personally), administrative (fines up to THB 5,000,000 per provision, cumulative across provisions in one incident), and civil (compensation plus punitive damages up to 2x). The first confirmed PDPC fine, in August 2024, already totalled THB 7,000,000 by combining three provisions in one case. Every confirmed case to date followed an actual data breach, not a cookie banner wording problem.

03

do we need a cookie consent banner?

The Act does not specify one, and never mentions cookies at all. Whether ordinary analytics can rely on Section 24(5)'s legitimate interest basis, or needs Section 19 consent, is genuinely unsettled: no PDPC guidance answers it either way. Several cookie-consent vendors assert consent is always required, without citing a PDPC instrument that says so, and they sell the banner that answer implies you need.

04

what deadline actually applies to a data subject request?

Only two clocks in the Act carry an explicit day count: 30 days to answer a valid access request (Section 30), and 30 days to notify someone when you collected their data from a third party (Section 25). Erasure, restriction, objection and portability requests have no stated deadline in the text, unlike GDPR's uniform one-month window across every right.

01 . who is covered

the base rule, the extraterritorial test, and the exemptions that do not apply to you.

base rule: section 5extraterritorial test: section 5, para. twopersonal exemption: section 4(1)sme relief: record keeping only, section 39

The base rule catches almost everyone. Section 5 paragraph one applies the Act to any collection, use or disclosure of personal data by a data controller or processor located in Thailand, regardless of where the actual processing takes place. If your company is registered or based in Thailand and you run a website that collects any personal data, you are inside the Act by default.

The extraterritorial test catches a foreign-run website too. If the controller or processor is outside Thailand, Section 5 paragraph two still applies the Act to their processing of a data subject who is in Thailand, if either they offer goods or services to that person in Thailand, paid or not, or they monitor that person's behaviour where it takes place in Thailand. This is the test that reaches a foreign-run website serving Thai visitors or customers. The consequence, under Section 37(5), is a duty to appoint a Thailand-based representative in writing, with no limitation of liability. A narrow exemption from that representative duty exists under Section 38, for a public authority or for a business that does not touch Section 26 sensitive data and does not hold a 'large amount' of personal data as defined in a separate Committee notification. We could not verify the exact numeric threshold for that 'large amount' test in our research, so we are not publishing a figure here; ask a lawyer to check it against your own data volumes.

There is no carve-out for a sole trader or a foreign-owned Thai company. The Act binds any natural person or juristic person acting as a controller or processor, on the same terms as any other Thailand-based entity. The one personal exemption, Section 4(1), covers collecting data 'for personal benefit or household activity' only, and that does not extend to a sole trader running a commercial website: that is business activity, not personal or household use.

There is no general small-business exemption either. The only real relief is a narrow exemption from keeping a formal Record of Processing Activities under Section 39 (and the mirrored processor duty in Section 40(3)), for a controller or processor that qualifies as a 'small organization' under a PDPC notification. That exemption does not apply if you are required to have a DPO, your processing risks data subjects' rights, your processing is not occasional, or you process Section 26 sensitive data. The exact employee and revenue bands for the 'small organization' test sit in a separate ministerial regulation that our research could not confirm precisely enough to publish as fact, so we are leaving the numbers out here rather than guessing; a lawyer can check your specific numbers against the regulation.

02 . penalties, precisely

three tiers, and a real number bigger than the headline maximum.

tier 01

criminal liability

up to 1 year in prison, up to thb 1,000,000, or both

sections 79 to 81

  • 6 months and thb 500,000 for a section 26 sensitive-data violation likely to cause harm or humiliation (section 79, para. one)
  • 1 year and thb 1,000,000 if done for unlawful benefit, the maximum criminal penalty in the act (section 79, para. two)
  • 6 months and thb 500,000 for anyone who unlawfully discloses data they learned through their official duties (section 80)
  • a director or manager can be personally punished if the offence came from their order, or their failure to instruct compliance (section 81)

tier 02

administrative fines

up to thb 5,000,000 per provision

sections 82 to 89

  • up to thb 1,000,000 for privacy notice, access process, record keeping or dpo process failures (section 82)
  • up to thb 3,000,000 for broader processing violations, no legal basis, unlawful disclosure, unlawful cross-border transfer, ignoring a marketing objection, or weak security (section 83)
  • up to thb 5,000,000 for violations involving section 26 sensitive data, the single highest per-provision fine in the act (section 84)
  • sections 85 to 87 mirror the same three tiers for a data processor

tier 03

civil liability

actual compensation, plus up to 2x in punitive damages

sections 77 and 78

  • near strict liability: you compensate for damage regardless of intent or negligence, with narrow defences like force majeure (section 77)
  • a court can add punitive damages up to two times the actual compensation, at its discretion (section 78)
  • a claim is barred 3 years after the data subject knew of the damage and your identity, or 10 years after the act, whichever comes first

thb 5,000,000 is the correct per-provision maximum, and it is also the number almost every article quotes as the pdpa fine. it understates a real case: a single breach usually trips more than one provision at once, and the fines are cumulative across provisions. the first confirmed enforcement case already totalled thb 7,000,000 by combining three provisions in one incident, see the enforcement record below.

03 . enforcement, so far

every confirmed fine follows an actual breach, not a cookie banner.

first fine: 21 august 2024amount: thb 7,000,000running total by 1 aug 2025: over thb 21,000,000pattern: a breach plus a missing control

The first confirmed case, 21 August 2024, combined three violations. A private online retailer was fined THB 7,000,000 in total: no Data Protection Officer despite holding data on 100,000-plus customers (Section 41, via Section 82, up to THB 1,000,000), inadequate security that let a call-centre scam network exploit customer data (Section 37(1), via Section 83, up to THB 3,000,000), and failing to report the breach to the PDPC within the required window (also under Section 37, via Section 83, up to THB 3,000,000).

By 1 August 2025, a law firm bulletin reported at least five more cases in a single announcement, about THB 14.5 million that round, taking the running total of PDPC fines since enforcement began to beyond THB 21 million. Named cases included a government agency and its software vendor after a roughly 200,000-record breach caused by weak security and no data-processing agreement, a private hospital and its contractor over mishandled patient records and a delayed report, a cosmetics company fined THB 2.5 million after a leak exploited by scam operators, and a toy company and its processor fined a combined THB 3.5 million after a reservation-system breach exposing about 200,000 records. The smaller figures in that round are approximate, rounded in the reporting bulletin rather than confirmed against the PDPC's own published decision text.

The pattern across every confirmed case is the same: an actual breach with real harm, usually feeding scam or fraud, combined with a missing DPO, a late or missing breach report, or weak security. No confirmed case found in our research was a fine issued purely for a cookie-consent or privacy-notice wording problem, absent an underlying breach. Read that as where the real risk sits: security, DPO coverage and breach reporting, not banner copy.

04 . what your website needs

the section 23 privacy notice, as a checklist.

requirement: section 23when: before or at collectionformat: not specifieditems required: six

Section 23 sets out exactly what has to be in your privacy notice, given to the data subject before or at the time you collect their data, unless they already know it. Six things, checkable against your own site right now:

  • 01

    why you are collecting it. the purpose or purposes, including any purpose you rely on without consent under section 24.

  • 02

    whether it is required. whether giving the data is required by law or contract, and what happens if the person does not provide it.

  • 03

    what, and for how long. what data is collected, and the retention period, or the retention standard you apply if you cannot give a fixed period.

  • 04

    who else sees it. the categories of people or organisations the data may be disclosed to.

  • 05

    who to contact. your own contact details, plus your representative or dpo where you have one.

  • 06

    their rights. a plain statement of the data subject's rights: withdrawal of consent, access, portability, objection, erasure, restriction, rectification, and complaint.

05 . cookies and analytics

the word cookie does not appear anywhere in the act.

cookie-specific law: nonedefault rule: consent, section 19listed alternative: legitimate interest, section 24(5)settled for analytics: no

We read all 96 sections of the primary Act text directly for this page, and the word cookie never appears once. Thailand has no ePrivacy-style statute sitting next to the PDPA the way the EU does. Cookie compliance here is the Act's general consent and legitimate-interest rules applied to cookies, not a codified cookie regime with a mandated banner format.

Section 19 sets consent as the default: no collection, use or disclosure without the data subject's consent, unless another provision allows it. Section 24(5) is one of those provisions: it lets a controller skip consent when processing is 'necessary for legitimate interests,' unless overridden by the data subject's fundamental rights, structurally close to GDPR's Article 6(1)(f).

Whether ordinary analytics or ad pixels, Google Analytics or a Meta Pixel, can rely on Section 24(5), or need Section 19 consent instead, is genuinely not settled by the text, and we found no PDPC notification that answers it either way. Several cookie-consent vendors state flatly that only strictly necessary cookies can skip consent, but none of them cite a PDPC instrument saying so, and they sell the banner that answer implies you need. That is not proof they are wrong, it is a reason to treat it as a vendor's claim rather than settled law until a lawyer or the PDPC says otherwise.

A practical, cautious default while this stays unsettled: strictly functional or session cookies with no personal identifier are the lowest-risk case. Anything that ties browsing to an identifiable person, including through a third party like Google or Meta, is the higher-risk case, and asking for consent there is the conservative choice, not a house rule we are asserting as law. Ask a Thai data protection lawyer about your own setup before you decide either way.

06 . data subject rights

one real 30-day deadline, and several rights with no stated deadline at all.

access, section 30: 30 daysthird-party source notice, section 25: 30 dayserasure, objection, portability: no stated deadlinegdpr comparison: one month for everything

Only two clocks in the Act carry an explicit day count. A valid access request under Section 30 must be answered within 30 days, and a refusal must be recorded with reasons. If you collected data from a source other than the data subject, Section 25 requires you to notify them within 30 days of collection, or at first contact or first disclosure if that comes sooner.

Every other right runs without a stated deadline. Objection, including to direct marketing (Section 32), requires you to segregate the data immediately once it is raised, but sets no day count for a full response. Erasure (Section 33) and restriction (Section 34) have no stated deadline either; if you ignore a valid request the remedy is a complaint to the expert committee, which can order compliance. Rectification (Sections 35 to 36) follows the same pattern: no deadline, but a recorded reason if you refuse. Portability (Section 31) states no deadline at all.

This is a genuine, checkable difference from GDPR, which gives a uniform one-month response window across every data subject right under Article 12(3). Treating every PDPA request as if it carries the same GDPR-style one-month clock is a common and understandable mistake worth correcting: only access requests and third-party-source notices actually have one.

07 . breach notification

notify the pdpc without delay, and within 72 hours where feasible.

who: the office of the pdpcwhen: without delay, feasible within 72 hourstrigger: risk to rights and freedomshigh risk: notify the data subjects too

Section 37(4) requires a data controller to notify the Office of the PDPC of a personal data breach without delay, and where feasible within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the people affected.

If the breach is likely to cause a high risk, you also have to notify the affected data subjects and tell them what remedial steps you have taken, without delay. There is no 72-hour figure attached to that second notification, only 'without delay.'

A data processor's duty is narrower: notify the controller of any breach it detects (Section 40(2)). The processor does not notify the PDPC directly; that stays the controller's job.

08 . sending data overseas

the rule that matters if you use google analytics or an overseas host.

default rule: adequate destination, section 28group alternative: certified policy, section 29compliance deadline: 24 march 2024adequacy whitelist: not confirmed in our research

Almost every website sends data overseas without thinking about it, through analytics, ad platforms, or an overseas host. Section 28 says a controller may only transfer personal data to a destination the Committee has found has adequate protection standards, unless a specific exception applies: legal compliance requires it, the data subject consented after being told the destination is inadequate, it is necessary to perform a contract with them or take pre-contract steps at their request, it is necessary under a contract with a third party for their benefit, it is needed to prevent a danger to life, body or health when they cannot consent, or it serves a substantial public interest.

Section 29 gives a group-transfer alternative: an Office-certified Personal Data Protection Policy, similar in shape to GDPR's binding corporate rules, or, absent both an adequacy finding and a certified policy, 'suitable protection measures' guaranteeing enforceable rights and real remedies. The PDPC issued cross-border transfer notifications in December 2023, with a compliance deadline of 24 March 2024.

What we could not confirm in our research, and did not want to guess at: whether the Committee has published a specific list of 'adequate' countries that includes, say, the EU or the US, which matters enormously if your stack runs on Google Analytics, Meta ads, or an overseas host. That is a real open question, not a settled fact either way, and exactly the kind of thing to bring to a Thai data protection lawyer for your specific vendor list rather than assume from a blog post, including this one.

09 . pdpa versus gdpr

close enough to confuse you, different in five ways that change what you do.

fines: flat caps, not turnovercriminal exposure: real, section 81punitive damages: capped at 2xdeadlines: not uniform

None of this is a ranking of which law is stricter overall, it is the list of places where copying a GDPR checklist onto a Thai business gets something wrong.

  • 01

    fines are flat, not turnover-based. pdpa caps at thb 5,000,000 per provision. gdpr can reach eur 20 million or 4% of global turnover, whichever is higher. a small thai business faces a smaller absolute number, but one that can still be existential for it.

  • 02

    personal criminal exposure is real here. section 81 can put a director or manager in prison for up to a year if the offence came from their order or their failure to instruct compliance. gdpr leaves criminal sanctions to individual eu member states and has no direct equivalent built in.

  • 03

    punitive damages exist, capped at 2x. section 78 lets a thai court award up to two times actual compensation. gdpr's article 82 is compensatory only, no punitive multiplier.

  • 04

    no cookie law sits next to the pdpa. the eu layers a specific eprivacy regime on top of gdpr with codified cookie-banner practice. thai cookie compliance is genuinely less settled in law.

  • 05

    the deadlines are not uniform. gdpr gives one month across every data subject right. pdpa gives 30 days for access and third-party notice only, and states no deadline for erasure, restriction, objection or portability.

10 . common mistakes

five ways a thai business gets this wrong on its own website.

most common: cookie banner as the whole planmost costly: assuming a fixed ceilingmost missed: the two real deadlinessource: the enforcement record itself

Drawn from the confirmed enforcement record and the sections above, not a generic checklist.

  • 01

    cookie banner up, everything else ignored. every confirmed pdpc fine to date has been for the substance, a breach, a missing dpo, a late report, not for cookie-banner wording.

  • 02

    assuming 'we're too small to be covered.' the only real small-business relief is a narrow exemption from formal record keeping. it does not touch consent, security or breach notification, and a sole trader running a commercial site is not covered by the personal or household exemption either.

  • 03

    quoting 'up to thb 5 million' as an absolute per-incident ceiling. the first confirmed case already totalled thb 7 million by combining fines across three provisions in one incident.

  • 04

    assuming analytics and ad pixels are automatically fine under 'legitimate interest.' whether section 24(5) covers them is genuinely unsettled, and separately, sending that data overseas is its own question under section 28.

  • 05

    missing the two deadlines that actually exist while assuming a general gdpr-style one month applies to everything. only access requests and third-party-source notices carry a stated 30-day clock.

11 . questions we get asked

the ones that come up every week.

01

does the pdpa apply if we are a small business or a sole trader?

Yes for the substantive duties. The only relief is the narrow record-keeping exemption under Section 39, and even that has conditions: no mandatory DPO, occasional processing, no sensitive data. The personal or household exemption in Section 4(1) does not cover a business website. The exact bands for which businesses count as 'small' for that exemption sit in a separate regulation we could not verify precisely enough to publish here, so ask a lawyer to check your specific numbers against it.

02

does the pdpa apply to a foreign company with no office in thailand?

Yes, if it offers goods or services to a data subject in Thailand, paid or not, or monitors that person's behaviour taking place in Thailand (Section 5, paragraph two). It then also has to appoint a Thailand-based representative in writing, with no limitation of liability (Section 37(5)).

03

do we need a data protection officer?

Only if one of three triggers applies under Section 41: you are a public authority as separately designated, your activities require regular monitoring because you hold a large amount of personal data as defined by a Committee notification (we could not verify the exact numeric threshold), or your core activity involves Section 26 sensitive data. If none apply, there is no mandatory DPO duty, though having someone responsible is still good practice.

04

what is the actual deadline to respond to a data access request?

30 days under Section 30, with any refusal recorded and reasoned. This is one of only two rights in the Act with a stated deadline, the other being the 30-day notice for data collected from a third-party source under Section 25.

05

do we legally have to run a cookie consent banner?

The Act never mentions cookies and specifies no banner format. Whether ordinary analytics needs consent under Section 19, or can rely on legitimate interest under Section 24(5), is genuinely unsettled. Asking for consent on anything that identifies a person is the cautious choice, not something the text states as a requirement in terms.

06

what is the actual fine if we get this wrong?

Up to THB 1,000,000 for notice, access-process, record-keeping or DPO failures, up to THB 3,000,000 for broader processing violations, and up to THB 5,000,000 for anything involving sensitive data, all per provision and cumulative across provisions in one incident. The first confirmed case totalled THB 7,000,000 that way. Criminal exposure adds up to 1 year in prison, and civil claims can add punitive damages up to 2x actual compensation.

07

who enforces the pdpa?

The Personal Data Protection Committee (PDPC), a government body under the Ministry of Digital Economy and Society, supported by its Office as secretariat. Its public compliance portal is gppc.pdpc.or.th.

08

can we use google analytics or host our site overseas?

Yes, but it is a cross-border transfer under Sections 28 and 29, which requires an adequate destination, a certified group policy, or suitable protection measures. We could not confirm whether the Committee has published a specific list of adequate countries covering the EU or the US, so check your specific vendor stack with a lawyer rather than assume.

09

is this page legal advice?

No. It is a plain reading of the Act's own English translation and the confirmed enforcement record, general information for a business owner to start from. For anything specific to your business, a live PDPC matter, or a breach, talk to a Thai data protection lawyer.

12 . keep reading

where to go next.

next step

read the act yourself, or bring us the specific question.

everything above is a general reading of the act and the confirmed enforcement record, not legal advice for your specific business. if you want a second pair of eyes on your own privacy notice, your cookie setup, or where your data actually goes, email us the question, and if it needs a signature on a compliance opinion, we will say so and point you to a thai data protection lawyer rather than pretend we are one. the ai integration page carries the pdpa governance pack we build alongside every ai project in bangkok, priced and scoped.

general information, not legal advice. for anything specific to your business, a live data breach, or a pdpc complaint, talk to a thai data protection lawyer.

Last updated .