Back to Frameworks

Thailand PDPA

Thailand
20 domains
35 controls

Thailand Personal Data Protection Act B.E. 2562 (2019), effective June 2022.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (20)

Accountability

1 controls
Controls in the Accountability domain of Thailand PDPA1 controls
CodeTitle
Section 39Record of Processing Activities (RoPA)

Breach Response

1 controls
Controls in the Breach Response domain of Thailand PDPA1 controls
CodeTitle
Section 37(4)Breach Notification to Data Subjects

Consent

1 controls
Controls in the Consent domain of Thailand PDPA1 controls
CodeTitle
Section 20Consent for Minors

Cross-Border Transfers

2 controls
Controls in the Cross-Border Transfers domain of Thailand PDPA2 controls
CodeTitle
Section 28Cross-Border Data Transfer
Section 29Intra-Group Transfer Rules

Data Subject Rights

7 controls
Controls in the Data Subject Rights domain of Thailand PDPA7 controls
CodeTitle
Section 30Right of Access
Section 31Right to Data Portability
Section 32Right to Object
Section 33Right to Erasure
Section 34Right to Restriction of Processing
Section 35Right to Rectification
Section 95(2)Complaint Handling

Disclosure

1 controls
Controls in the Disclosure domain of Thailand PDPA1 controls
CodeTitle
Section 27Disclosure to Third Parties

Enforcement

1 controls
Controls in the Enforcement domain of Thailand PDPA1 controls
CodeTitle
Section 95Effective Date and Enforcement

Governance

3 controls
Controls in the Governance domain of Thailand PDPA3 controls
CodeTitle
Section 41Appointment of Data Protection Officer
Section 42DPO Duties
Section 7Local Representative Requirement

Lawful Basis

2 controls
Controls in the Lawful Basis domain of Thailand PDPA2 controls
CodeTitle
Section 19Lawful Basis and Consent Requirements
Section 24Lawful Bases Other Than Consent

Penalties

3 controls
Controls in the Penalties domain of Thailand PDPA3 controls
CodeTitle
Sections 71-76Civil Liability and Punitive Damages
Sections 77-90Administrative Fines
Sections 79-81Criminal Liability for Unlawful Disclosure

Processing Principles

2 controls
Controls in the Processing Principles domain of Thailand PDPA2 controls
CodeTitle
Section 21Purpose Limitation
Section 22Data Minimisation

Processor Management

1 controls
Controls in the Processor Management domain of Thailand PDPA1 controls
CodeTitle
Section 40Processor Obligations

Regulator

1 controls
Controls in the Regulator domain of Thailand PDPA1 controls
CodeTitle
Section 43PDPC Authority and Powers

Retention

1 controls
Controls in the Retention domain of Thailand PDPA1 controls
CodeTitle
Section 36Retention and Deletion

Risk Management

1 controls
Controls in the Risk Management domain of Thailand PDPA1 controls
CodeTitle
PDPC Notification (DPIA)Data Protection Impact Assessment

Scope and Definitions

2 controls
Controls in the Scope and Definitions domain of Thailand PDPA2 controls
CodeTitle
Section 5Extraterritorial Application
Section 6Definitions and Scope of Personal Data

Security

2 controls
Controls in the Security domain of Thailand PDPA2 controls
CodeTitle
PDPC Notification (Security Standards)Minimum Security Standards
Section 37Controller Security Obligations

Sensitive Data

1 controls
Controls in the Sensitive Data domain of Thailand PDPA1 controls
CodeTitle
Section 26Sensitive Personal Data

Transition

1 controls
Controls in the Transition domain of Thailand PDPA1 controls
CodeTitle
Section 25Historical and Pre-PDPA Data

Transparency

1 controls
Controls in the Transparency domain of Thailand PDPA1 controls
CodeTitle
Section 23Privacy Notice Requirements

Frequently Asked Questions

What is Thailand PDPA?

Thailand PDPA is a compliance framework from Thailand with 20 domains and 35 controls. Thailand Personal Data Protection Act B.E. 2562 (2019), effective June 2022. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Thailand PDPA have?

Thailand PDPA has 35 controls organised across 20 domains. The largest domains are Data Subject Rights (7 controls), Governance (3 controls), Penalties (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Thailand PDPA map to?

Thailand PDPA does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with Thailand PDPA compliance?

Start your Thailand PDPA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Thailand PDPA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required