Thailand PDPA
Thailand Personal Data Protection Act B.E. 2562 (2019), effective June 2022.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (20)
Accountability
| Code | Title |
|---|---|
| Section 39 | Record of Processing Activities (RoPA) |
Breach Response
| Code | Title |
|---|---|
| Section 37(4) | Breach Notification to Data Subjects |
Consent
| Code | Title |
|---|---|
| Section 20 | Consent for Minors |
Cross-Border Transfers
| Code | Title |
|---|---|
| Section 28 | Cross-Border Data Transfer |
| Section 29 | Intra-Group Transfer Rules |
Data Subject Rights
| Code | Title |
|---|---|
| Section 30 | Right of Access |
| Section 31 | Right to Data Portability |
| Section 32 | Right to Object |
| Section 33 | Right to Erasure |
| Section 34 | Right to Restriction of Processing |
| Section 35 | Right to Rectification |
| Section 95(2) | Complaint Handling |
Disclosure
| Code | Title |
|---|---|
| Section 27 | Disclosure to Third Parties |
Enforcement
| Code | Title |
|---|---|
| Section 95 | Effective Date and Enforcement |
Governance
| Code | Title |
|---|---|
| Section 41 | Appointment of Data Protection Officer |
| Section 42 | DPO Duties |
| Section 7 | Local Representative Requirement |
Lawful Basis
| Code | Title |
|---|---|
| Section 19 | Lawful Basis and Consent Requirements |
| Section 24 | Lawful Bases Other Than Consent |
Penalties
| Code | Title |
|---|---|
| Sections 71-76 | Civil Liability and Punitive Damages |
| Sections 77-90 | Administrative Fines |
| Sections 79-81 | Criminal Liability for Unlawful Disclosure |
Processing Principles
| Code | Title |
|---|---|
| Section 21 | Purpose Limitation |
| Section 22 | Data Minimisation |
Processor Management
| Code | Title |
|---|---|
| Section 40 | Processor Obligations |
Regulator
| Code | Title |
|---|---|
| Section 43 | PDPC Authority and Powers |
Retention
| Code | Title |
|---|---|
| Section 36 | Retention and Deletion |
Risk Management
| Code | Title |
|---|---|
| PDPC Notification (DPIA) | Data Protection Impact Assessment |
Scope and Definitions
| Code | Title |
|---|---|
| Section 5 | Extraterritorial Application |
| Section 6 | Definitions and Scope of Personal Data |
Security
| Code | Title |
|---|---|
| PDPC Notification (Security Standards) | Minimum Security Standards |
| Section 37 | Controller Security Obligations |
Sensitive Data
| Code | Title |
|---|---|
| Section 26 | Sensitive Personal Data |
Transition
| Code | Title |
|---|---|
| Section 25 | Historical and Pre-PDPA Data |
Transparency
| Code | Title |
|---|---|
| Section 23 | Privacy Notice Requirements |
Frequently Asked Questions
What is Thailand PDPA?
Thailand PDPA is a compliance framework from Thailand with 20 domains and 35 controls. Thailand Personal Data Protection Act B.E. 2562 (2019), effective June 2022. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Thailand PDPA have?
Thailand PDPA has 35 controls organised across 20 domains. The largest domains are Data Subject Rights (7 controls), Governance (3 controls), Penalties (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Thailand PDPA map to?
Thailand PDPA does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with Thailand PDPA compliance?
Start your Thailand PDPA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Thailand PDPA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required