Jurisdiction Guides / Asia-Pacific
Thailand Privacy & Data Protection Laws
Every regime below can apply to a business handling Thailand residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Closely modeled on the GDPR. Section 5 applies the Act to controllers and processors located in Thailand regardless of where processing occurs, and extraterritorially to controllers and processors outside Thailand where the activities involve offering goods or services to data subjects in Thailand (payment required or not) or monitoring their behavior taking place in Thailand. Section 4 excludes personal/family-use processing, certain public-authority security functions, the courts, credit bureaus operating under their own act, and House/Senate proceedings. Foreign controllers in scope must appoint a Thailand-based representative. Enforcement sits with the Personal Data Protection Committee and its office (PDPC), which became operationally active after the June 2022 in-force date; penalties combine administrative fines, civil punitive damages, and criminal liability for sensitive-data misuse.
Children & Minors Protections · 1
Thailand's age line is not 13, 16 or 18 — it is 20, because s. 20 keys consent to the Civil and Commercial Code's age of majority. That produces a three-tier scheme with no analogue elsewhere in this dataset. A data subject aged 20 or over consents for themselves. Below 10, consent must come from the holder of parental responsibility. Between 10 and 20, the PDPC's guidelines expect consent from BOTH the minor and their legal guardian, except where the consent relates to an act the minor is permitted to perform under the Civil and Commercial Code. s. 20 also covers incompetent and quasi-incompetent persons, whose custodian or curator consents on their behalf. A business applying a GDPR-style 16-or-over rule will systematically under-collect consent for Thai users aged 16 to 19. Marked 'check': the primary text is Thai-language and the three tiers were triangulated across independent legal-reference sources and PDPC guideline summaries.
Cross-Border Data Transfer · 1
The statute contemplates two routes and, in practice, only one of them works. s. 28 permits transfer to destinations the PDPC has recognised as having adequate data protection — but no list of adequate countries has been published, so this route is currently theoretical. That pushes essentially every transfer onto s. 29, which requires appropriate safeguards, elaborated by the PDPC's December 2023 Notification: binding corporate rules for intra-group transfers, which must be approved by the PDPC before use, or other appropriate safeguards with enforceable data subject rights and remedies. A business assuming Thailand works like the GDPR — check the adequacy list first, fall back to clauses — should invert the order. Marked 'verified' on the structure; confirm whether an adequacy list has since been issued before designing around its absence.
Data Security & Breach Notification · 1
Notify the PDPC without undue delay and, where feasible, within 72 hours of becoming aware. The Thai regime adds two features the GDPR lacks: an explicit outer limit — if 72 hours cannot be met, notification must still be made as soon as possible and no later than 15 days from awareness, with an explanation of the unavoidable circumstances that caused the delay — and an express exemption where the incident poses no risk to individuals' rights and freedoms. Affected data subjects must be notified, together with remedial measures, where the breach carries a high risk to their rights and freedoms. The PDPC clarified in early 2025 that the 72 hours run from the point the controller reasonably believes a breach has occurred following a preliminary assessment.
Other Asia-Pacific jurisdictions