{
  "node_id": "th-pdpa-2019",
  "title": "Thailand Personal Data Protection Act B.E. 2562 (2019) - PDPC Enforcement and Data Subject Rights",
  "domain": "Data Protection & Privacy",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "Thailand's Personal Data Protection Act B.E. 2562 (PDPA), published in the Royal Gazette on 27 May 2019, received Royal Assent on 24 May 2019. The PDPA was originally scheduled to enter into full force on 27 May 2020, but implementation was delayed by royal decrees issued during the COVID-19 pandemic. The full PDPA entered into force on 1 June 2022. The PDPA is Thailand's first comprehensive personal data protection law and was significantly influenced by the EU General Data Protection Regulation (GDPR), adopting broadly similar legal bases, data subject rights, and enforcement mechanisms adapted for the Thai legal and regulatory context. The governing body is the Personal Data Protection Committee (PDPC - คณะกรรมการคุ้มครองข้อมูลส่วนบุคคล), established under the PDPA to issue regulations, provide guidance, and oversee enforcement. The PDPA applies to data controllers and data processors in Thailand, as well as to overseas entities offering goods or services to data subjects in Thailand or monitoring the behaviour of data subjects in Thailand (extraterritorial reach). Key features: (1) Six lawful bases for processing: consent, contract performance, vital interests, legitimate interests, legal obligation, and public interest/official authority - mirroring GDPR Art. 6 bases; (2) Sensitive personal data - data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade union membership, genetic data, and biometric data - processed only with explicit consent or in limited exceptions; (3) Data subject rights: access, correction, deletion/erasure, restriction of processing, data portability, objection, and the right not to be subject to automated decision-making; (4) Mandatory breach notification - data controllers must notify the PDPC within 72 hours of becoming aware of a personal data breach; affected data subjects must be notified without undue delay where the breach is likely to result in high risk to their rights and freedoms; (5) Data Protection Officer (DPO) - required for large-scale processing, sensitive data processing, or public authority processing; (6) Consent requirements - consent must be freely given, specific, informed, and unambiguous; withdrawal of consent must be as easy as giving it; (7) Administrative fines - up to THB 5 million per violation; (8) Criminal penalties - imprisonment up to 1 year and/or fine up to THB 1 million for intentional violations; up to 6 months and/or THB 500,000 for negligent violations; (9) Civil liability - data subjects may claim compensation for damages arising from PDPA violations. Thailand does not yet have EU GDPR adequacy recognition. The PDPC Secretariat (สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล - SPDPC) at pdpc.or.th handles regulatory guidance, complaints, and breach notifications.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-27001-2022",
    "iso-27701-privacy-information-management"
  ],
  "primary_citations_count": 6
}