Back to Frameworks

PDPA Thailand

Thailand
v2022
15 domains
38 controls

Personal Data Protection Act of Thailand

Verified

PDPA Thailand is a compliance framework from Thailand with 15 domains and 38 controls that map to 137 other frameworks. The largest domains are Thailand PDPA Sections 19 to 26: Consent and Lawful Basis (8 controls), Thailand PDPA Sections 30 to 36: Data Subject Rights (7 controls), Thailand PDPA Sections 37 to 40: Security, Breach and Processor Duties (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (15)

Breach and Enforcement

1 controls
Controls in the Breach and Enforcement domain of PDPA Thailand1 controls
CodeTitle
PDPATH-8Data Breach Notification, Complaints, Compliance, Enforcement

Consent

1 controls
Controls in the Consent domain of PDPA Thailand1 controls
CodeTitle
PDPATH-2Consent Requirements and Special Consent for Sensitive Data

Governance and Lifecycle

1 controls
Controls in the Governance and Lifecycle domain of PDPA Thailand1 controls
CodeTitle
PDPATH-7DPO, Records of Processing, Retention, Marketing, Training

High-Risk Processing

1 controls
Controls in the High-Risk Processing domain of PDPA Thailand1 controls
CodeTitle
PDPATH-4DPIA, Privacy by Design, Children's Data

Individual Rights

1 controls
Controls in the Individual Rights domain of PDPA Thailand1 controls
CodeTitle
PDPATH-3Data Subject Rights, Automated Decisions, Accuracy

Scope and Lawful Basis

1 controls
Controls in the Scope and Lawful Basis domain of PDPA Thailand1 controls
CodeTitle
PDPATH-1Scope, Extra-Territorial Application, Lawful Basis, and Notice

Security

1 controls
Controls in the Security domain of PDPA Thailand1 controls
CodeTitle
PDPATH-5Security Measures and Data Protection

Thailand PDPA Sections 19 to 26: Consent and Lawful Basis

8 controls
Controls in the Thailand PDPA Sections 19 to 26: Consent and Lawful Basis domain of PDPA Thailand8 controls
CodeTitle
Section 19Lawful Basis and Consent Requirements
Section 20Consent for Minors
Section 21Purpose Limitation
Section 22Data Minimisation
Section 23Privacy Notice Requirements
Section 24Lawful Bases Other Than Consent
Section 25Historical and Pre-PDPA Data
Section 26Sensitive Personal Data

Thailand PDPA Sections 27 to 29: Disclosure and Cross-Border Transfer

3 controls
Controls in the Thailand PDPA Sections 27 to 29: Disclosure and Cross-Border Transfer domain of PDPA Thailand3 controls
CodeTitle
Section 27Disclosure to Third Parties
Section 28Cross-Border Data Transfer
Section 29Intra-Group Transfer Rules

Thailand PDPA Sections 30 to 36: Data Subject Rights

7 controls
Controls in the Thailand PDPA Sections 30 to 36: Data Subject Rights domain of PDPA Thailand7 controls
CodeTitle
Section 30Right of Access
Section 31Right to Data Portability
Section 32Right to Object
Section 33Right to Erasure
Section 34Right to Restriction of Processing
Section 35Right to Rectification
Section 36Retention and Deletion

Thailand PDPA Sections 37 to 40: Security, Breach and Processor Duties

4 controls
Controls in the Thailand PDPA Sections 37 to 40: Security, Breach and Processor Duties domain of PDPA Thailand4 controls
CodeTitle
Section 37Controller Security Obligations
Section 37(4)Breach Notification to Data Subjects
Section 39Record of Processing Activities (RoPA)
Section 40Processor Obligations

Thailand PDPA Sections 41 to 43: Data Protection Officer and PDPC

3 controls
Controls in the Thailand PDPA Sections 41 to 43: Data Protection Officer and PDPC domain of PDPA Thailand3 controls
CodeTitle
Section 41Appointment of Data Protection Officer
Section 42DPO Duties
Section 43PDPC Authority and Powers

Thailand PDPA Sections 5 to 7: Scope and Representative

3 controls
Controls in the Thailand PDPA Sections 5 to 7: Scope and Representative domain of PDPA Thailand3 controls
CodeTitle
Section 5Extraterritorial Application
Section 6Definitions and Scope of Personal Data
Section 7Local Representative Requirement

Thailand PDPA Sections 95: Transition and Complaints

2 controls
Controls in the Thailand PDPA Sections 95: Transition and Complaints domain of PDPA Thailand2 controls
CodeTitle
Section 95Effective Date and Enforcement
Section 95(2)Complaint Handling

Transfer and Processor Management

1 controls
Controls in the Transfer and Processor Management domain of PDPA Thailand1 controls
CodeTitle
PDPATH-6Cross-Border Transfer and Processor Engagement

Your Compliance Coverage

If you comply with PDPA Thailand, you already cover:

+ 134 more: Personal Data Act (personopplysningsloven) (16%), Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) (16%)

See all 137 mapped frameworks ↓

Maps to 137 other frameworks

38 total controls
Turkey KVKK
6 source controls mapped|3 target controls covered
16%
Privacy Act 2020
6 source controls mapped|6 target controls covered
16%
Privacy Act 1988 (Australia)
6 source controls mapped|7 target controls covered
16%
Personal Data Act (personopplysningsloven)
6 source controls mapped|6 target controls covered
16%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
6 source controls mapped|23 target controls covered
16%
GDPR
6 source controls mapped|10 target controls covered
16%
Bahrain PDPL
6 source controls mapped|13 target controls covered
16%
Barbados Data Protection Act 2019
6 source controls mapped|7 target controls covered
16%
16%
South Korea PIPA
6 source controls mapped|5 target controls covered
16%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
6 source controls mapped|9 target controls covered
16%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
5 source controls mapped|3 target controls covered
13%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
5 source controls mapped|3 target controls covered
13%
Russia Federal Law on Personal Data (152-FZ)
5 source controls mapped|2 target controls covered
13%
13%
Azerbaijan Law on Personal Data (2010)
5 source controls mapped|4 target controls covered
13%
ISO/IEC 23894:2023
5 source controls mapped|5 target controls covered
13%
NIST Privacy Framework
5 source controls mapped|6 target controls covered
13%
FTC GLBA Safeguards Rule (16 CFR Part 314)
4 source controls mapped|3 target controls covered
11%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
4 source controls mapped|6 target controls covered
11%
ISO/IEC 27400:2022
4 source controls mapped|7 target controls covered
11%
South Korea ISMS-P
4 source controls mapped|8 target controls covered
11%
Florida Digital Bill of Rights (FDBR)
4 source controls mapped|2 target controls covered
11%
NIST SP 800-190
4 source controls mapped|6 target controls covered
11%
ISO 27017
4 source controls mapped|6 target controls covered
11%
ASD Strategies to Mitigate Cyber Security Incidents
4 source controls mapped|4 target controls covered
11%
ISO 27018
4 source controls mapped|7 target controls covered
11%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
4 source controls mapped|4 target controls covered
11%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
4 source controls mapped|5 target controls covered
11%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
3 source controls mapped|2 target controls covered
8%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
3 source controls mapped|4 target controls covered
8%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
3 source controls mapped|1 target controls covered
8%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
3 source controls mapped|2 target controls covered
8%
Armenia Law on Protection of Personal Data (2015)
3 source controls mapped|3 target controls covered
8%
Azure Security Benchmark
3 source controls mapped|1 target controls covered
8%
Australian Privacy Principles (APPs)
3 source controls mapped|4 target controls covered
8%
APPI
3 source controls mapped|9 target controls covered
8%
UK Open Banking Standard
3 source controls mapped|5 target controls covered
8%
ISO/IEC 29134:2023
3 source controls mapped|1 target controls covered
8%
COSO Internal Control - Integrated Framework (2013)
3 source controls mapped|4 target controls covered
8%
IEC 62443
3 source controls mapped|7 target controls covered
8%
BSI IT-Grundschutz
3 source controls mapped|10 target controls covered
8%
API 1164
3 source controls mapped|7 target controls covered
8%
ISO 27019
3 source controls mapped|7 target controls covered
8%
NIST Cybersecurity Framework 2.0
3 source controls mapped|6 target controls covered
8%
NIST SP 1800-32
3 source controls mapped|7 target controls covered
8%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
3 source controls mapped|3 target controls covered
8%
Annex 11 to EU GMP - Computerised Systems
3 source controls mapped|3 target controls covered
8%
NIST SP 800-53 Rev 5
3 source controls mapped|12 target controls covered
8%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|7 target controls covered
8%
Regulation on the European Health Data Space (EHDS)
3 source controls mapped|4 target controls covered
8%
ISO 13485
3 source controls mapped|9 target controls covered
8%
ISO/IEC 27011:2024
3 source controls mapped|6 target controls covered
8%
ISO 27799
3 source controls mapped|9 target controls covered
8%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
3 source controls mapped|5 target controls covered
8%
Authorised Economic Operator (AEO) Programmes - Global Standards
3 source controls mapped|3 target controls covered
8%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
2 source controls mapped|1 target controls covered
5%
South Africa Promotion of Access to Information Act (PAIA)
2 source controls mapped|1 target controls covered
5%
TEFCA - Trusted Exchange Framework and Common Agreement
2 source controls mapped|1 target controls covered
5%
Protective Security Policy Framework (PSPF) Release 2024
2 source controls mapped|3 target controls covered
5%
ISO/IEC 29100:2024
2 source controls mapped|3 target controls covered
5%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
2 source controls mapped|2 target controls covered
5%
ISO/IEC 38500:2024 - Governance of IT
2 source controls mapped|1 target controls covered
5%
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
2 source controls mapped|1 target controls covered
5%
ITU-T X.805 - Security Architecture for End-to-End Communications
2 source controls mapped|2 target controls covered
5%
EASA Part-IS - Information Security in Aviation
2 source controls mapped|5 target controls covered
5%
ISO 20000-1
2 source controls mapped|3 target controls covered
5%
PCI P2PE
2 source controls mapped|5 target controls covered
5%
PCI SSF
2 source controls mapped|5 target controls covered
5%
ITIL 4
2 source controls mapped|2 target controls covered
5%
FFIEC IT Examination Handbook
2 source controls mapped|5 target controls covered
5%
NFPA 1600 - Standard on Continuity, Emergency, and Crisis Management
2 source controls mapped|2 target controls covered
5%
PCI PIN Security
2 source controls mapped|5 target controls covered
5%
Canada ITSG-33 - IT Security Risk Management
2 source controls mapped|1 target controls covered
5%
ISO 28001:2007 Supply Chain Security Management
2 source controls mapped|2 target controls covered
5%
APRA CPS 230 Operational Risk Management
2 source controls mapped|2 target controls covered
5%
ISO/IEC 27010:2015
2 source controls mapped|4 target controls covered
5%
ASIS SPC.1-2009 - Organizational Resilience Standard
2 source controls mapped|2 target controls covered
5%
FFIEC Cybersecurity Assessment Tool (CAT)
2 source controls mapped|3 target controls covered
5%
Nebraska Data Privacy Act
2 source controls mapped|2 target controls covered
5%
ISO 26000:2010
2 source controls mapped|1 target controls covered
5%
5%
ISO 22000
2 source controls mapped|2 target controls covered
5%
ISO 45001
2 source controls mapped|2 target controls covered
5%
Paraguay Law on Protection of Personal Data (Law No. 6534/2020)
2 source controls mapped|1 target controls covered
5%
ISO/IEC 25012:2008 - Data Quality Model
2 source controls mapped|3 target controls covered
5%
Singapore AI Governance Framework
2 source controls mapped|1 target controls covered
5%
ICAO Annex 17 - Aviation Security (AVSEC)
2 source controls mapped|2 target controls covered
5%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
2 source controls mapped|2 target controls covered
5%
ISO 27005
2 source controls mapped|4 target controls covered
5%
FBI CJIS Security Policy
2 source controls mapped|3 target controls covered
5%
Voluntary Principles on Security and Human Rights (VPs)
1 source controls mapped|1 target controls covered
3%
Singapore Cybersecurity Act 2018
1 source controls mapped|1 target controls covered
3%
ISO/IEC 30111:2019
1 source controls mapped|1 target controls covered
3%
ISO 22320:2018
1 source controls mapped|3 target controls covered
3%
Papua New Guinea National Cybersecurity Policy & Cybercrime Act (2016)
1 source controls mapped|1 target controls covered
3%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|1 target controls covered
3%
APRA CPS 234
1 source controls mapped|2 target controls covered
3%
NIST SP 800-171
1 source controls mapped|1 target controls covered
3%
FedRAMP High
1 source controls mapped|1 target controls covered
3%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
3%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
3%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
3%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
3%
ISO 14001
1 source controls mapped|1 target controls covered
3%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|1 target controls covered
3%
ISO/SAE 21434
1 source controls mapped|7 target controls covered
3%
ISO 27043
1 source controls mapped|7 target controls covered
3%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|2 target controls covered
3%
IATA Operational Safety Audit (IOSA) Standards Manual
1 source controls mapped|1 target controls covered
3%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
1 source controls mapped|2 target controls covered
3%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|1 target controls covered
3%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
1 source controls mapped|1 target controls covered
3%
ISO 19011
1 source controls mapped|2 target controls covered
3%
3%
ISO 31000:2018
1 source controls mapped|2 target controls covered
3%
OWASP SAMM
1 source controls mapped|1 target controls covered
3%
FIDO2 / WebAuthn
1 source controls mapped|1 target controls covered
3%
ISO/IEC 27003:2017
1 source controls mapped|2 target controls covered
3%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|2 target controls covered
3%
ISO 22313:2020 - Guidance on Business Continuity Management Systems
1 source controls mapped|1 target controls covered
3%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|2 target controls covered
3%
ISO/IEC 27031:2011
1 source controls mapped|1 target controls covered
3%
ISO 26262:2018 - Functional Safety for Road Vehicles
1 source controls mapped|1 target controls covered
3%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
3%
ISO 31000
1 source controls mapped|3 target controls covered
3%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
3%
Kuwait National Cybersecurity Framework
1 source controls mapped|1 target controls covered
3%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|2 target controls covered
3%
Section 508 - ICT Accessibility (Revised)
1 source controls mapped|2 target controls covered
3%
ISO 8000 - Data Quality
1 source controls mapped|1 target controls covered
3%

What is PDPA Thailand and who does it apply to?

PDPA Thailand is a compliance framework from Thailand with 15 domains and 38 controls. Personal Data Protection Act of Thailand It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does PDPA Thailand actually require?

PDPA Thailand has 38 controls organised across 15 domains. The largest domains are Thailand PDPA Sections 19 to 26: Consent and Lawful Basis (8 controls), Thailand PDPA Sections 30 to 36: Data Subject Rights (7 controls), Thailand PDPA Sections 37 to 40: Security, Breach and Processor Duties (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of PDPA Thailand do I already cover?

PDPA Thailand maps to 137 other compliance frameworks. The top mapping partners are Turkey KVKK (16% coverage), Privacy Act 2020 (16% coverage), Privacy Act 1988 (Australia) (16% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement PDPA Thailand?

Start your PDPA Thailand compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PDPA Thailand requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 38 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required