Home / PDPA Compliance · ภาษาไทย
Thailand PDPA Compliance & Outsourced DPO
End-to-end PDPA rollout with legal opinion, technical mapping, and ongoing DPO representation.
Quick Answer
SME rollout THB 65,000 / 2 weeks · Enterprise THB 350,000+· Outsourced DPO retainer THB 25,000/month. Avoid THB 5M administrative fines.
Services
- ✓ PDPA gap assessment & audit
- ✓ Records of Processing Activities (RoPA)
- ✓ Privacy Notice (TH + EN)
- ✓ Consent form drafting
- ✓ DPA vendor templates
- ✓ Cross-border SCC (EU, US, JP)
- ✓ Data Protection Officer (DPO) outsourcing
- ✓ Breach response playbook & drills
- ✓ Staff training (workshop + e-learning)
- ✓ PDPC representation & filings
FAQ
- Who must comply with Thailand PDPA?
- Every business (Thai-registered or foreign) that processes personal data of individuals in Thailand — including HR data, customer databases, marketing lists, and website analytics. Fully enforced since 1 June 2022 by the PDPC.
- Penalties?
- Administrative fines up to THB 5,000,000 per violation, criminal fines up to THB 1,000,000 + 1-year imprisonment for directors, and civil damages up to 2× actual loss.
- What we deliver?
- PDPA gap assessment, Records of Processing Activities (RoPA), Privacy Notice (TH+EN), consent forms, DPA templates with vendors, cross-border transfer contracts (SCC), DPO outsourcing, staff training, and breach response playbook.
- Cost & timeline?
- SME package THB 65,000 (2 weeks). Mid-market THB 180,000 (4–6 weeks). Enterprise THB 350,000+ with 12-month DPO retainer THB 25,000/month.
Contact: 083-249-4999 · LINE @NYC168 · contact@ilc.ltd
The scope question decides whether the rest matters
The Personal Data Protection Act B.E. 2562 (2019) came into full force on 1 June 2022 after two postponements. It applies to a data controller or processor in Thailand, and it also reaches organisations outside Thailand where they offer goods or services to data subjects in Thailand, or monitor their behaviour in Thailand. A foreign company with no Thai entity can therefore be in scope through its website and its marketing, and where it is, it must appoint a representative in Thailand.
Personal data is defined broadly: any information relating to an identified or identifiable natural person, excluding data of the deceased. A separate and stricter category — sensitive personal data — covers racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade union information, genetic and biometric data. Handling that category on the wrong legal basis is where the most serious exposure sits, and biometric attendance systems are the example we see most often in Thai workplaces.
The Act is closely modelled on the EU General Data Protection Regulation, and organisations with a mature GDPR programme start well ahead. They are not finished, however. The PDPA's consent formalities, its criminal provisions and its Thai-language notice expectations differ enough that a translated GDPR notice is not a compliant PDPA notice.
Lawful bases and the consent trap
- Consent must be explicit, freely given, informed, presented separately from other terms, and as easy to withdraw as to give. Bundled acceptance inside general terms and conditions does not meet this standard.
- Because consent is fragile, contractual necessity, legal obligation, vital interests, public task and legitimate interests are frequently the better bases for routine processing such as payroll and customer fulfilment.
- Legitimate interests must be balanced against the data subject's rights, and the assessment should be documented at the time, not reconstructed after a complaint.
- Sensitive personal data requires explicit consent or one of the narrower statutory exceptions; employment-related exceptions are limited and should not be assumed.
- Consent obtained before the Act took effect can continue to be relied on only where it satisfies the Act's requirements for the same purposes; legacy consent should be audited rather than presumed valid.
The obligations that generate visible work
| Obligation | What it means in practice | Where organisations fall short |
|---|---|---|
| Privacy notice | Purpose, basis, retention, recipients, rights, contact | English-only notice for a Thai-facing service |
| Records of processing activities | Documented inventory of what is processed and why | Maintained once at project time and never updated |
| Data subject rights handling | Access, rectification, erasure, restriction, portability, objection | No defined intake channel or response deadline |
| Data Protection Officer | Required in the cases specified in section 41 | Assumed unnecessary without documenting the assessment |
| Processor agreements | Written terms controlling processors and sub-processors | Vendors engaged on purchase orders with no data terms |
| Breach notification | Notify the Office of the PDPC within 72 hours where required, and data subjects for high risk | No detection or escalation path, so the clock is missed |
| Cross-border transfer | Adequate protection or a recognised mechanism | Cloud tooling adopted by departments without transfer analysis |
Enforcement exposure and how a programme is sequenced
The Act carries three distinct kinds of liability. Administrative fines run up to five million baht for the most serious contraventions. Civil liability includes compensation and the possibility of punitive damages of up to twice the actual damage. Criminal provisions attach to certain misuses of sensitive data and to disclosure by those who obtained data in the course of duty, with imprisonment and fines, and directors can be exposed where the offence was committed with their consent or through their neglect. That third category is why PDPA is a board-level topic in Thailand rather than an IT topic.
A workable programme is sequenced, not simultaneous. Map the data first, because every later decision depends on knowing what you hold. Fix the lawful bases and rewrite the notices second, since those are what a regulator or complainant sees first. Then close the contractual gaps with processors, stand up the rights-request and breach processes, and only then invest in tooling. Organisations that buy a consent platform before mapping their data almost always end up rebuilding it.
Common mistakes and how we avoid them
More questions we are asked
- Do we need a DPO?
- Section 41 sets out the cases where appointment is mandatory, including certain public-body activity, large-scale regular monitoring, and core activity involving sensitive data. Where it is not mandatory, document the assessment that reached that conclusion.
- How long may we retain personal data?
- The Act does not set fixed periods. Retention must be tied to purpose and to any specific statutory retention rule, such as accounting and tax record obligations, and the periods should be published in the notice.
- Is a foreign company without a Thai entity in scope?
- It can be, where it offers goods or services to data subjects in Thailand or monitors their behaviour there. In-scope foreign controllers must appoint a representative in Thailand.
- What must happen after a breach?
- Assess risk immediately. Where notification is required, notify the Office of the PDPC within 72 hours of becoming aware, and notify affected data subjects where the risk to their rights is high.
- What do you deliver on a PDPA engagement?
- Data mapping, records of processing, bilingual notices and consent wording, processor clauses, rights-request and breach playbooks, and staff briefing materials in Thai and English.
Knowledge bases behind every service
7 knowledge bases, 4,882 keywords and 3,057 answered questions written by our lawyers and translators. Free to read, no sign-up.
- Master Service Hub — every service we file
The cross-service index: certified translation, interpreting, visa/work permit/BOI, tax-legal-estate, cross-border M&A, aviation & maritime, and holding-company structuring.
Scoped quote after a free consultation by phone, LINE or email
1,000 keywords · 649 questions · 10 clusters
- Certified translation — every language
Certified translation across civil, academic, corporate, contractual, financial, medical, technical and IP documents — with the Notary → MFA → embassy legalization chain handled end to end.
Thai–English THB 500–1,200/page · other languages THB 800–2,500/page
1,000 keywords · 500 questions · 16 clusters
- Thai MFA consular legalization
Thai MFA legalization workflow: fees, turnaround, inbound foreign documents, and how the chain connects to destination-country apostille requirements.
THB 200/stamp (3 working days) · express THB 400/stamp
882 keywords · 500 questions · 16 clusters
Official sources
The information on this page follows the official sources below. Always check the latest version before you file.
- กรมการกงสุล — บริการรับรองเอกสาร (นิติกรณ์)— กระทรวงการต่างประเทศ
- สำนักงานตรวจคนเข้าเมือง — วีซ่า รายงานตัว 90 วัน TM.30— Immigration Bureau
- กรมการปกครอง — ทะเบียนราษฎร ทะเบียนครอบครัว— Department of Provincial Administration
- สภาทนายความในพระบรมราชูปถัมภ์ — ทนายความผู้ทำคำรับรองลายมือชื่อและเอกสาร— Lawyers Council of Thailand
- สำนักงานคณะกรรมการกฤษฎีกา — ฐานข้อมูลกฎหมายไทย— Office of the Council of State
Related services
Most document work runs across several steps — jump straight to the next one you need.
- Certified translation
- Consular legalization
- Notary Public
- Thailand visa
- Full service index
- Knowledge index
For an exact quote and turnaround, call, LINE or email our team on any business day.
Expert reviewed: This page is written and checked by practitioners with 15+ years of hands-on filing experience, sourced from the responsible authorities and signed off by a second reviewer before publication — meet the team · editorial policy
Not sure which service you need? Read the guides
Each guide answers first, then explains: decision criteria, comparison tables, the real process and the mistakes we see most often.
- Choosing a certified translation provider
How to pick a translator accepted by consular, embassy and receiving bodies
- Services for expats living in Thailand
Signature certification, residence, marriage and everyday paperwork
- Notary Public and consular legalization
The correct order of steps before sending documents abroad
- Choosing the right visa and work permit
Compare visa categories and the documents each one needs translated
- Translation by language
English, Chinese, Japanese, European, Arabic, Russian and embassy rules
- Specialized translation
Contracts, financial statements, MSDS, ISO and BOI filings
Talk to us first: 083-249-4999 · LINE @NYC168 · contact@ilc.ltd
Frequently asked questions
- Can a foreigner own 100% of a Thai company?
- Generally no for activities listed in the Foreign Business Act, where majority foreign ownership requires a Foreign Business Licence, a BOI promotion, or treaty rights such as the US–Thailand Treaty of Amity. Manufacturing and certain export activities are largely open, and BOI-promoted activities can permit full foreign ownership together with land-holding and visa privileges, so the right structure depends on the specific activity.
- What is the minimum registered capital for a Thai company?
- There is no general statutory minimum for a Thai-majority company, but practical thresholds apply: THB 2 million of paid-up registered capital per foreign work permit, or THB 1 million if the foreigner is married to a Thai national, and THB 3 million per foreign shareholder for a Foreign Business Licence. Capital should therefore be planned around the visa and work-permit outcome you need, not the incorporation minimum.
- How long does company registration take?
- Registration at the Department of Business Development can be completed within one to three working days once the name reservation, shareholder documents and company objectives are ready, and the VAT registration and social security registration follow afterwards. The realistic end-to-end timeline including bank account opening is two to six weeks, with the bank account usually being the slowest step for foreign directors.
- What ongoing accounting obligations does a Thai company have?
- Every Thai company must keep statutory accounts, file monthly withholding tax (PND 1, 3, 53) and VAT (PP 30) returns by the middle of the following month, file the half-year corporate income tax return (PND 51) and the annual return (PND 50), and have its financial statements audited by a Thai CPA and filed with the DBD each year. Dormant companies are not exempt — nil returns and an audited statement are still required.






