Bidda Sovereign Intelligence · 10,099 Verified Nodes · 39 Sovereign Pillars

Thailand Personal Data Protection Act B.E. 2562 (2019) - PDPC Enforcement and Data Subject Rights

Thailand's Personal Data Protection Act B.E. 2562 (PDPA), published in the Royal Gazette on 27 May 2019, received Royal Assent on 24 May 2019. The PDPA…

What Thailand Personal Data Protection Act B.E. 2562 (2019) - PDPC Enforcement and Data Subject Rights requires

Thailand's Personal Data Protection Act B.E. 2562 (PDPA), published in the Royal Gazette on 27 May 2019, received Royal Assent on 24 May 2019. The PDPA was originally scheduled to enter into full force on 27 May 2020, but implementation was delayed by royal decrees issued during the COVID-19 pandemic. The full PDPA entered into force on 1 June 2022. The PDPA is Thailand's first comprehensive personal data protection law and was significantly influenced by the EU General Data Protection Regulation (GDPR), adopting broadly similar legal bases, data subject rights, and enforcement mechanisms adapted for the Thai legal and regulatory context. The governing body is the Personal Data Protection Committee (PDPC - คณะกรรมการคุ้มครองข้อมูลส่วนบุคคล), established under the PDPA to issue regulations, provide guidance, and oversee enforcement. The PDPA applies to data controllers and data processors in Thailand, as well as to overseas entities offering goods or services to data subjects in Thailand or monitoring the behaviour of data subjects in Thailand (extraterritorial reach). Key features: (1) Six lawful bases for processing: consent, contract performance, vital interests, legitimate interests, legal obligation, and public interest/official authority - mirroring GDPR Art. 6 bases; (2) Sensitive personal data - data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade union membership, genetic data, and biometric data - processed only with explicit consent or in limited exceptions; (3) Data subject rights: access, correction, deletion/erasure, restriction of processing, data portability, objection, and the right not to be subject to automated decision-making; (4) Mandatory breach notification - data controllers must notify the PDPC within 72 hours of becoming aware of a personal data breach; affected data subjects must be notified without undue delay where the breach is likely to result in high risk to their rights and freedoms; (5) Data Protection Officer (DPO) - required for large-scale processing, sensitive data processing, or public authority processing; (6) Consent requirements - consent must be freely given, specific, informed, and unambiguous; withdrawal of consent must be as easy as giving it; (7) Administrative fines - up to THB 5 million per violation; (8) Criminal penalties - imprisonment up to 1 year and/or fine up to THB 1 million for intentional violations; up to 6 months and/or THB 500,000 for negligent violations; (9) Civil liability - data subjects may claim compensation for damages arising from PDPA violations. Thailand does not yet have EU GDPR adequacy recognition. The PDPC Secretariat (สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล - SPDPC) at pdpc.or.th handles regulatory guidance, complaints, and breach notifications.

Pillar: Data Protection & Privacy · Authority: Personal Data Protection Committee (PDPC - คณะกรรมการคุ้มครองข้อมูลส่วนบุคคล, Thailand) · Version: 1.0.0 · Last updated:

Primary source: https://www.pdpc.or.th/

SHA-256 integrity: e6cbe98032d575e0a4b74b69c14eb17d4aa58b370cbcd3376e15bc60a3f7ab8a

Primary Citations — 6 traced to source

  • Personal Data Protection Act B.E. 2562 (PDPA, Thailand) - Royal Assent 24 May 2019; published Royal Gazette 27 May 2019; full force 1 June 2022 (delayed from 2020 by COVID royal decrees); six lawful bases: consent, contract, vital interests, legal obligation, public task, legitimate interests; sensitive data: racial/ethnic origin, political opinions, religious beliefs, sexual behaviour, criminal records, health, disability, trade union membership, genetic data, biometric data; 72-hour PDPC breach notification; DPO mandatory for large-scale or sensitive data processing; administrative fines up to THB 5 million; criminal penalties up to THB 1 million; data subject rights: access, rectification, erasure, restriction, portability, objection, no automated decision-making; 30-day response deadline
  • Personal Data Protection Committee (PDPC - คณะกรรมการคุ้มครองข้อมูลส่วนบุคคล, Thailand) - governing body established under PDPA; issues subordinate regulations and guidance; oversees PDPA enforcement; PDPC Secretariat (SPDPC) at pdpc.or.th handles breach notifications, complaints, DPO registration, and regulatory guidance; published guidance on lawful basis, consent, sensitive data, DPO, breach notification, and privacy notices

+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.