The first confirmed case, 21 August 2024, combined three violations. A private online retailer was fined THB 7,000,000 in total: no Data Protection Officer despite holding data on 100,000-plus customers (Section 41, via Section 82, up to THB 1,000,000), inadequate security that let a call-centre scam network exploit customer data (Section 37(1), via Section 83, up to THB 3,000,000), and failing to report the breach to the PDPC within the required window (also under Section 37, via Section 83, up to THB 3,000,000).
By 1 August 2025, a law firm bulletin reported at least five more cases in a single announcement, about THB 14.5 million that round, taking the running total of PDPC fines since enforcement began to beyond THB 21 million. Named cases included a government agency and its software vendor after a roughly 200,000-record breach caused by weak security and no data-processing agreement, a private hospital and its contractor over mishandled patient records and a delayed report, a cosmetics company fined THB 2.5 million after a leak exploited by scam operators, and a toy company and its processor fined a combined THB 3.5 million after a reservation-system breach exposing about 200,000 records. The smaller figures in that round are approximate, rounded in the reporting bulletin rather than confirmed against the PDPC's own published decision text.
The pattern across every confirmed case is the same: an actual breach with real harm, usually feeding scam or fraud, combined with a missing DPO, a late or missing breach report, or weak security. No confirmed case found in our research was a fine issued purely for a cookie-consent or privacy-notice wording problem, absent an underlying breach. Read that as where the real risk sits: security, DPO coverage and breach reporting, not banner copy.