WorldPrivacyAtlas
Laws by country

Cross-Border Data Transfer

Personal Data Protection Act B.E. 2562 (2019) — cross-border transfer of personal data

Thailand PDPA ss. 28-29

Thailand · June 1, 2022 (PDPA); the two transfer Notifications enforceable from March 24, 2024

The statute contemplates two routes and, in practice, only one of them works. s. 28 permits transfer to destinations the PDPC has recognised as having adequate data protection — but no list of adequate countries has been published, so this route is currently theoretical. That pushes essentially every transfer onto s. 29, which requires appropriate safeguards, elaborated by the PDPC's December 2023 Notification: binding corporate rules for intra-group transfers, which must be approved by the PDPC before use, or other appropriate safeguards with enforceable data subject rights and remedies. A business assuming Thailand works like the GDPR — check the adequacy list first, fall back to clauses — should invert the order. Marked 'verified' on the structure; confirm whether an adequacy list has since been issued before designing around its absence.

PDPA B.E. 2562 (2019), ss. 28-29; PDPC Notifications on criteria for personal data transferred to third countries under s. 28 and under s. 29, published in the Royal Gazette December 25, 2023Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.