Data Security & Breach Notification
Personal Data Protection Act B.E. 2562 (2019) — data breach notification
Thailand · June 1, 2022 (PDPA in force); reporting Notification effective from its December 15, 2022 publication
Notify the PDPC without undue delay and, where feasible, within 72 hours of becoming aware. The Thai regime adds two features the GDPR lacks: an explicit outer limit — if 72 hours cannot be met, notification must still be made as soon as possible and no later than 15 days from awareness, with an explanation of the unavoidable circumstances that caused the delay — and an express exemption where the incident poses no risk to individuals' rights and freedoms. Affected data subjects must be notified, together with remedial measures, where the breach carries a high risk to their rights and freedoms. The PDPC clarified in early 2025 that the 72 hours run from the point the controller reasonably believes a breach has occurred following a preliminary assessment.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.