WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Personal Data Protection Act B.E. 2562 (2019) — data breach notification

Thailand PDPA s. 37(4)

Thailand · June 1, 2022 (PDPA in force); reporting Notification effective from its December 15, 2022 publication

Notify the PDPC without undue delay and, where feasible, within 72 hours of becoming aware. The Thai regime adds two features the GDPR lacks: an explicit outer limit — if 72 hours cannot be met, notification must still be made as soon as possible and no later than 15 days from awareness, with an explanation of the unavoidable circumstances that caused the delay — and an express exemption where the incident poses no risk to individuals' rights and freedoms. Affected data subjects must be notified, together with remedial measures, where the breach carries a high risk to their rights and freedoms. The PDPC clarified in early 2025 that the 72 hours run from the point the controller reasonably believes a breach has occurred following a preliminary assessment.

PDPA B.E. 2562 (2019), s. 37(4); PDPC Notification on Criteria and Method for Reporting Personal Data Breaches B.E. 2565 (2022), published in the Government Gazette December 15, 2022Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.