Cross-Border Data Transfer
Personal Data Protection Act B.E. 2562 (2019) — cross-border transfer of personal data
Thailand · June 1, 2022 (PDPA); the two transfer Notifications enforceable from March 24, 2024
The statute contemplates two routes and, in practice, only one of them works. s. 28 permits transfer to destinations the PDPC has recognised as having adequate data protection — but no list of adequate countries has been published, so this route is currently theoretical. That pushes essentially every transfer onto s. 29, which requires appropriate safeguards, elaborated by the PDPC's December 2023 Notification: binding corporate rules for intra-group transfers, which must be approved by the PDPC before use, or other appropriate safeguards with enforceable data subject rights and remedies. A business assuming Thailand works like the GDPR — check the adequacy list first, fall back to clauses — should invert the order. Marked 'verified' on the structure; confirm whether an adequacy list has since been issued before designing around its absence.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.