Est. 2019 · Khon Kaen · Bangkok · Udon · Nong KhaiTHEN
§ Notarial Services Attorney

Licensed Notary Public Attorneys 6 registered

All six attorneys are registered with the Lawyers Council of Thailand under Royal Patronage. Their notarial licences certify signatures and documents for embassies, foreign governments, and international visa applications.

View all licences

Registered Notarial Services Attorney · Lawyers Council of Thailand

Home / PDPA Compliance · ภาษาไทย

Thailand PDPA Compliance & Outsourced DPO

End-to-end PDPA rollout with legal opinion, technical mapping, and ongoing DPO representation.

Quick Answer

SME rollout THB 65,000 / 2 weeks · Enterprise THB 350,000+· Outsourced DPO retainer THB 25,000/month. Avoid THB 5M administrative fines.

Services

  • PDPA gap assessment & audit
  • Records of Processing Activities (RoPA)
  • Privacy Notice (TH + EN)
  • Consent form drafting
  • DPA vendor templates
  • Cross-border SCC (EU, US, JP)
  • Data Protection Officer (DPO) outsourcing
  • Breach response playbook & drills
  • Staff training (workshop + e-learning)
  • PDPC representation & filings

FAQ

Who must comply with Thailand PDPA?
Every business (Thai-registered or foreign) that processes personal data of individuals in Thailand — including HR data, customer databases, marketing lists, and website analytics. Fully enforced since 1 June 2022 by the PDPC.
Penalties?
Administrative fines up to THB 5,000,000 per violation, criminal fines up to THB 1,000,000 + 1-year imprisonment for directors, and civil damages up to 2× actual loss.
What we deliver?
PDPA gap assessment, Records of Processing Activities (RoPA), Privacy Notice (TH+EN), consent forms, DPA templates with vendors, cross-border transfer contracts (SCC), DPO outsourcing, staff training, and breach response playbook.
Cost & timeline?
SME package THB 65,000 (2 weeks). Mid-market THB 180,000 (4–6 weeks). Enterprise THB 350,000+ with 12-month DPO retainer THB 25,000/month.

Contact: 083-249-4999 · LINE @NYC168 · contact@ilc.ltd

The scope question decides whether the rest matters

The Personal Data Protection Act B.E. 2562 (2019) came into full force on 1 June 2022 after two postponements. It applies to a data controller or processor in Thailand, and it also reaches organisations outside Thailand where they offer goods or services to data subjects in Thailand, or monitor their behaviour in Thailand. A foreign company with no Thai entity can therefore be in scope through its website and its marketing, and where it is, it must appoint a representative in Thailand.

Personal data is defined broadly: any information relating to an identified or identifiable natural person, excluding data of the deceased. A separate and stricter category — sensitive personal data — covers racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade union information, genetic and biometric data. Handling that category on the wrong legal basis is where the most serious exposure sits, and biometric attendance systems are the example we see most often in Thai workplaces.

The Act is closely modelled on the EU General Data Protection Regulation, and organisations with a mature GDPR programme start well ahead. They are not finished, however. The PDPA's consent formalities, its criminal provisions and its Thai-language notice expectations differ enough that a translated GDPR notice is not a compliant PDPA notice.

Lawful bases and the consent trap

  • Consent must be explicit, freely given, informed, presented separately from other terms, and as easy to withdraw as to give. Bundled acceptance inside general terms and conditions does not meet this standard.
  • Because consent is fragile, contractual necessity, legal obligation, vital interests, public task and legitimate interests are frequently the better bases for routine processing such as payroll and customer fulfilment.
  • Legitimate interests must be balanced against the data subject's rights, and the assessment should be documented at the time, not reconstructed after a complaint.
  • Sensitive personal data requires explicit consent or one of the narrower statutory exceptions; employment-related exceptions are limited and should not be assumed.
  • Consent obtained before the Act took effect can continue to be relied on only where it satisfies the Act's requirements for the same purposes; legacy consent should be audited rather than presumed valid.

The obligations that generate visible work

ObligationWhat it means in practiceWhere organisations fall short
Privacy noticePurpose, basis, retention, recipients, rights, contactEnglish-only notice for a Thai-facing service
Records of processing activitiesDocumented inventory of what is processed and whyMaintained once at project time and never updated
Data subject rights handlingAccess, rectification, erasure, restriction, portability, objectionNo defined intake channel or response deadline
Data Protection OfficerRequired in the cases specified in section 41Assumed unnecessary without documenting the assessment
Processor agreementsWritten terms controlling processors and sub-processorsVendors engaged on purchase orders with no data terms
Breach notificationNotify the Office of the PDPC within 72 hours where required, and data subjects for high riskNo detection or escalation path, so the clock is missed
Cross-border transferAdequate protection or a recognised mechanismCloud tooling adopted by departments without transfer analysis

Enforcement exposure and how a programme is sequenced

The Act carries three distinct kinds of liability. Administrative fines run up to five million baht for the most serious contraventions. Civil liability includes compensation and the possibility of punitive damages of up to twice the actual damage. Criminal provisions attach to certain misuses of sensitive data and to disclosure by those who obtained data in the course of duty, with imprisonment and fines, and directors can be exposed where the offence was committed with their consent or through their neglect. That third category is why PDPA is a board-level topic in Thailand rather than an IT topic.

A workable programme is sequenced, not simultaneous. Map the data first, because every later decision depends on knowing what you hold. Fix the lawful bases and rewrite the notices second, since those are what a regulator or complainant sees first. Then close the contractual gaps with processors, stand up the rights-request and breach processes, and only then invest in tooling. Organisations that buy a consent platform before mapping their data almost always end up rebuilding it.

Common mistakes and how we avoid them

Relying on consent for payroll and HR processing
Employment processing generally rests on contractual necessity and legal obligation. Consent from an employee is rarely freely given and is fragile if withdrawn.
Publishing an English-only privacy notice for a Thai audience
Provide a Thai-language notice; informed means understood by the data subject you are addressing.
Deploying biometric attendance without a sensitive-data basis
Assess the basis and offer a non-biometric alternative; biometric data is in the stricter category.
Treating a translated GDPR pack as compliance
Re-map to PDPA definitions, consent formalities and notification timelines; the frameworks are similar, not identical.

More questions we are asked

Do we need a DPO?
Section 41 sets out the cases where appointment is mandatory, including certain public-body activity, large-scale regular monitoring, and core activity involving sensitive data. Where it is not mandatory, document the assessment that reached that conclusion.
How long may we retain personal data?
The Act does not set fixed periods. Retention must be tied to purpose and to any specific statutory retention rule, such as accounting and tax record obligations, and the periods should be published in the notice.
Is a foreign company without a Thai entity in scope?
It can be, where it offers goods or services to data subjects in Thailand or monitors their behaviour there. In-scope foreign controllers must appoint a representative in Thailand.
What must happen after a breach?
Assess risk immediately. Where notification is required, notify the Office of the PDPC within 72 hours of becoming aware, and notify affected data subjects where the risk to their rights is high.
What do you deliver on a PDPA engagement?
Data mapping, records of processing, bilingual notices and consent wording, processor clauses, rights-request and breach playbooks, and staff briefing materials in Thai and English.

7 knowledge bases, 4,882 keywords and 3,057 answered questions written by our lawyers and translators. Free to read, no sign-up.

  • Master Service Hub — every service we file

    The cross-service index: certified translation, interpreting, visa/work permit/BOI, tax-legal-estate, cross-border M&A, aviation & maritime, and holding-company structuring.

    Scoped quote after a free consultation by phone, LINE or email

    1,000 keywords · 649 questions · 10 clusters

  • Certified translation — every language

    Certified translation across civil, academic, corporate, contractual, financial, medical, technical and IP documents — with the Notary → MFA → embassy legalization chain handled end to end.

    Thai–English THB 500–1,200/page · other languages THB 800–2,500/page

    1,000 keywords · 500 questions · 16 clusters

  • Thai MFA consular legalization

    Thai MFA legalization workflow: fees, turnaround, inbound foreign documents, and how the chain connects to destination-country apostille requirements.

    THB 200/stamp (3 working days) · express THB 400/stamp

    882 keywords · 500 questions · 16 clusters

Browse the full knowledge index →

Expert reviewed: This page is written and checked by practitioners with 15+ years of hands-on filing experience, sourced from the responsible authorities and signed off by a second reviewer before publication — meet the team · editorial policy

Not sure which service you need? Read the guides

Each guide answers first, then explains: decision criteria, comparison tables, the real process and the mistakes we see most often.

Talk to us first: 083-249-4999 · LINE @NYC168 · contact@ilc.ltd

Frequently asked questions

Can a foreigner own 100% of a Thai company?
Generally no for activities listed in the Foreign Business Act, where majority foreign ownership requires a Foreign Business Licence, a BOI promotion, or treaty rights such as the US–Thailand Treaty of Amity. Manufacturing and certain export activities are largely open, and BOI-promoted activities can permit full foreign ownership together with land-holding and visa privileges, so the right structure depends on the specific activity.
What is the minimum registered capital for a Thai company?
There is no general statutory minimum for a Thai-majority company, but practical thresholds apply: THB 2 million of paid-up registered capital per foreign work permit, or THB 1 million if the foreigner is married to a Thai national, and THB 3 million per foreign shareholder for a Foreign Business Licence. Capital should therefore be planned around the visa and work-permit outcome you need, not the incorporation minimum.
How long does company registration take?
Registration at the Department of Business Development can be completed within one to three working days once the name reservation, shareholder documents and company objectives are ready, and the VAT registration and social security registration follow afterwards. The realistic end-to-end timeline including bank account opening is two to six weeks, with the bank account usually being the slowest step for foreign directors.
What ongoing accounting obligations does a Thai company have?
Every Thai company must keep statutory accounts, file monthly withholding tax (PND 1, 3, 53) and VAT (PP 30) returns by the middle of the following month, file the half-year corporate income tax return (PND 51) and the annual return (PND 50), and have its financial statements audited by a Thai CPA and filed with the DBD each year. Dormant companies are not exempt — nil returns and an audited statement are still required.

More on Company Registration, Accounting & BOIAll FAQs