PDPA Thailand
Personal Data Protection Act of Thailand
PDPA Thailand is a compliance framework from Thailand with 15 domains and 38 controls that map to 137 other frameworks. The largest domains are Thailand PDPA Sections 19 to 26: Consent and Lawful Basis (8 controls), Thailand PDPA Sections 30 to 36: Data Subject Rights (7 controls), Thailand PDPA Sections 37 to 40: Security, Breach and Processor Duties (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
Breach and Enforcement
| Code | Title |
|---|---|
| PDPATH-8 | Data Breach Notification, Complaints, Compliance, Enforcement |
Consent
| Code | Title |
|---|---|
| PDPATH-2 | Consent Requirements and Special Consent for Sensitive Data |
Governance and Lifecycle
| Code | Title |
|---|---|
| PDPATH-7 | DPO, Records of Processing, Retention, Marketing, Training |
High-Risk Processing
| Code | Title |
|---|---|
| PDPATH-4 | DPIA, Privacy by Design, Children's Data |
Individual Rights
| Code | Title |
|---|---|
| PDPATH-3 | Data Subject Rights, Automated Decisions, Accuracy |
Scope and Lawful Basis
| Code | Title |
|---|---|
| PDPATH-1 | Scope, Extra-Territorial Application, Lawful Basis, and Notice |
Security
| Code | Title |
|---|---|
| PDPATH-5 | Security Measures and Data Protection |
Thailand PDPA Sections 19 to 26: Consent and Lawful Basis
| Code | Title |
|---|---|
| Section 19 | Lawful Basis and Consent Requirements |
| Section 20 | Consent for Minors |
| Section 21 | Purpose Limitation |
| Section 22 | Data Minimisation |
| Section 23 | Privacy Notice Requirements |
| Section 24 | Lawful Bases Other Than Consent |
| Section 25 | Historical and Pre-PDPA Data |
| Section 26 | Sensitive Personal Data |
Thailand PDPA Sections 27 to 29: Disclosure and Cross-Border Transfer
| Code | Title |
|---|---|
| Section 27 | Disclosure to Third Parties |
| Section 28 | Cross-Border Data Transfer |
| Section 29 | Intra-Group Transfer Rules |
Thailand PDPA Sections 30 to 36: Data Subject Rights
| Code | Title |
|---|---|
| Section 30 | Right of Access |
| Section 31 | Right to Data Portability |
| Section 32 | Right to Object |
| Section 33 | Right to Erasure |
| Section 34 | Right to Restriction of Processing |
| Section 35 | Right to Rectification |
| Section 36 | Retention and Deletion |
Thailand PDPA Sections 37 to 40: Security, Breach and Processor Duties
| Code | Title |
|---|---|
| Section 37 | Controller Security Obligations |
| Section 37(4) | Breach Notification to Data Subjects |
| Section 39 | Record of Processing Activities (RoPA) |
| Section 40 | Processor Obligations |
Thailand PDPA Sections 41 to 43: Data Protection Officer and PDPC
| Code | Title |
|---|---|
| Section 41 | Appointment of Data Protection Officer |
| Section 42 | DPO Duties |
| Section 43 | PDPC Authority and Powers |
Thailand PDPA Sections 5 to 7: Scope and Representative
Thailand PDPA Sections 95: Transition and Complaints
| Code | Title |
|---|---|
| Section 95 | Effective Date and Enforcement |
| Section 95(2) | Complaint Handling |
Transfer and Processor Management
| Code | Title |
|---|---|
| PDPATH-6 | Cross-Border Transfer and Processor Engagement |
Your Compliance Coverage
If you comply with PDPA Thailand, you already cover:
Turkey KVKK
16%
6 controls mapped
Compare →Privacy Act 2020
16%
6 controls mapped
Compare →Privacy Act 1988 (Australia)
16%
6 controls mapped
Compare →+ 134 more: Personal Data Act (personopplysningsloven) (16%), Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) (16%)
See all 137 mapped frameworks ↓Maps to 137 other frameworks
What is PDPA Thailand and who does it apply to?
PDPA Thailand is a compliance framework from Thailand with 15 domains and 38 controls. Personal Data Protection Act of Thailand It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does PDPA Thailand actually require?
PDPA Thailand has 38 controls organised across 15 domains. The largest domains are Thailand PDPA Sections 19 to 26: Consent and Lawful Basis (8 controls), Thailand PDPA Sections 30 to 36: Data Subject Rights (7 controls), Thailand PDPA Sections 37 to 40: Security, Breach and Processor Duties (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of PDPA Thailand do I already cover?
PDPA Thailand maps to 137 other compliance frameworks. The top mapping partners are Turkey KVKK (16% coverage), Privacy Act 2020 (16% coverage), Privacy Act 1988 (Australia) (16% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement PDPA Thailand?
Start your PDPA Thailand compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PDPA Thailand requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 38 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required