Data Breach Response (72-hour Notification)
รับมือเหตุข้อมูลรั่ว (Data Breach 72-hr Response) · § Litigation
Quick Answer
48-hour emergency retainer THB 150,000 — war-room set-up, materiality assessment, PDPC e-Portal notification draft, data-subject notice, media handling, and evidence preservation for criminal proceedings.
Timeline: T+0 kickoff · T+24h draft notice · T+48h submit to PDPC · T+72h complete filing · T+30d post-incident report.
Official fee: PDPC e-Portal filing is free.
Legal Basis
PDPA §37(4) and PDPC Breach Notification Rules 2022 — notify PDPC within 72 hours; where the risk to data subjects is high, notify affected individuals as well.
Who Needs This
Organisations facing ransomware, phishing, insider leaks, API data exposure, misconfigured S3 buckets, or credential-stuffing incidents.
Required Documents
- Incident details (logs, timeline)
- Count of affected data subjects
- Types of data leaked (name, ID, financial, health)
- Initial remediation measures
Common Pitfalls
- Waiting to finish investigation before notifying PDPC — >72h triggers fines
- Going public before notifying data subjects — trust damage
- Deleting logs to hide the trail — additional criminal offence
Typical Use-cases
- Ecommerce hit by credential stuffing affecting 500,000 customers
- Hospital ransomware compromising medical records
- SaaS discovers a misconfigured S3 bucket exposing customer data
FAQ
- When does the 72-hour clock start?
- From the moment you become aware of the incident — not from when it actually occurred.
- Must every incident be reported to data subjects?
- Only where risk to rights is high (§37(4) para 2) — encryption or pseudonymisation may exempt notice.
- Maximum fine?
- THB 5m (§83) plus 2× punitive damages under §78.
Other Legal Services
Request a quote — Call 083-249-4999 · LINE @NYC168 · contact@ilc.ltd






