PDPA Compliance Audit + DPO Advisory
PDPA Compliance Audit + DPO Advisory · § Compliance
Quick Answer
PDPA Audit + remediation + DPO retainer THB 45,000–150,000 — 20-point gap analysis, ROPA drafting, Privacy Notice, Consent forms, Vendor DPAs, staff training, DPO appointment (internal or outsourced).
Timeline: Audit 1–2 weeks · Remediation 3–4 weeks · Training 1 day · Monthly DPO retainer · Total 6–8 weeks to full compliance
Official fee: No government filing fees (breach fines up to THB 5M + 1 year criminal exposure)
Legal Basis
Personal Data Protection Act B.E. 2562 (fully effective 1 June 2022) — PDPC enforcement, fines up to THB 5M per violation.
Who Needs This
Any organization handling customer/employee data — HR, marketing, CRM, e-commerce, hospitals, schools, foreign SaaS serving Thai users.
Required Documents
- Inventory of systems holding personal data (CRM, HR, marketing)
- Employment contracts + vendor / cloud contracts
- Current Privacy Notice + Consent forms
- Data-flow diagrams
- Executive contact list for DPO
Common Pitfalls
- Assuming a website Privacy Notice is enough — ROPA + DPA + purpose-based Consent required
- Cross-border transfers without SCC/Adequacy → violates Section 28
- Using consent as legal basis for employees — revocable anytime; better to use 'contract' or 'legitimate interest'
- Skipping DPO appointment when required (large-scale sensitive data, monitoring) → fines up to THB 1M
Typical Use-cases
- Hospitals / clinics (sensitive health data)
- Schools / universities (student data)
- E-commerce with CRM ≥ 10,000 records
- Multinationals transferring data to overseas HQ
FAQ
- Does every company need a DPO?
- No — only (1) government agencies, (2) firms whose core activity is monitoring (hotels, security), or (3) firms processing sensitive data at scale (hospitals). Outsourced DPO recommended anyway at THB 5,000–15,000/month.
- What if we receive a complaint?
- PDPC gives 30 days to respond with explanation + ROPA + Impact Assessment. Timely remediation usually results in a warning only. We act as your response agent.
- How is GDPR different from PDPA?
- 80% structurally similar. PDPA fines lower (THB 5M vs EUR 20M / 4% turnover). PDPA requires 'without delay' breach notification, not GDPR's 72-hour rule.
- Is cookie consent required?
- Yes for tracking cookies (analytics, ads, remarketing). Strictly-necessary cookies exempt. We provide a Cookie Banner script + GTM Consent Mode configuration.
Other Company & Licensing Services
Request a quote — Call 083-249-4999 · LINE @NYC168 · contact@ilc.ltd






