Personal Data Protection Act (PDPA) compliance
In short
The Personal Data Protection Act B.E. 2562 (2019) governs the collection, use and disclosure of personal data in Thailand. Organisations need a lawful basis for processing, notice to data subjects, security measures, a route for data-subject requests, and controls on transfers and on processors.
Start with a data map rather than a policy. Knowing what data you hold, where it sits, who can reach it and why it was collected makes every later document — notice, consent form, processor agreement, retention schedule — a short exercise instead of a guess.
Cross-border transfers and vendor relationships are where most exposure sits in practice. Contracts with processors should state the purpose, the security measures and what happens to the data at the end of the engagement.
What we need from you
- List of systems and vendors that hold personal data
- Existing privacy notice, consent forms and HR documents
- Countries the data is transferred to, if any
- Who inside the organisation owns data protection decisions
Watch out
Consent is not the only lawful basis, and over-using it creates a right to withdraw that can break an operational process.
Reviewed as of 2026-08-04. General guidance only, not case-specific advice and not a guarantee of outcome. Government fees, conditions and processing times are set by the responsible authority and can change. This site does not publish prices — please ask our staff.
ให้เจ้าหน้าที่ตรวจขอบเขตงานและเอกสารก่อนเริ่ม
สอบถามรายละเอียดและเงื่อนไขได้ทางโทรศัพท์ LINE หรืออีเมล