#
Comprehensive omnibus statute fully in force since 1 June 2022 with an operational regulator (PDPC) and multiple sub-legislative instruments issued.
Sub-modules (5)
Regulator And AuthorityGreen
The PDPC (Committee) and its Office hold advisory and enforcement authority, with an Expert Committee empowered to investigate and sanction violations.
Claims (1):
- The Personal Data Protection Committee (PDPC) is tasked with advisory and enforcement powers under the PDPA.
Act And InstrumentsGreen
PDPA plus four sub-legislative instruments (security measures, ROPA criteria, SME ROPA exemption, administrative fines criteria) and multiple Royal Decrees form the instrument set.
Claims (2):
- The PDPA came into full effect on 1 June 2022, following two prior enforcement suspensions, as Thailand's first comprehensive private-sector data protection law.
- Four secondary laws accompany the PDPA covering appropriate security measures, ROPA criteria, an SME ROPA exemption, and criteria for administrative fines and orders, effective between June and December 2022.
Material ScopeAmber
Material scope excludes designated state-security-related public authorities and provides sector carve-outs for legislative bodies and credit bureaus.
Claims (2):
- The PDPA excludes from its scope public authorities whose duties concern state security, including financial security, public safety, money-laundering prevention/suppression, forensic science, or cybersecurity.
- The PDPA provides exceptions for legislative bodies and credit bureau companies, which remain governed by pre-existing sectoral regulation alongside the PDPA.
Territorial ScopeGreen
Extraterritorial application mirrors GDPR Art.3 style targeting/monitoring tests.
Claims (1):
- The PDPA mirrors GDPR's extraterritorial applicability, applying to controllers and processors outside Thailand that process personal data of data subjects in Thailand or offer goods/services to, or monitor the behaviour of, such data subjects.
Regulator Registration And FilingAmber
No general controller registration/filing regime was identified; obligations instead run through mandatory Records of Processing Activities (ROPA) accessible to the PDPC on request, subject to an SME exemption. Searches run: 'Thailand PDPA registration filing controller', 'Thailand PDPC register of controllers' — no dedicated registration portal or filing mandate located distinct from ROPA-keeping duties.
Claims (1):
- In lieu of a general registration/filing regime, PDPA controllers and processors must prepare and maintain Records of Processing Activities (ROPA) that must be readily accessible and promptly presented to the Office of the PDPC on request.
Key findings (3)
- PDPA fully in force since 1 June 2022 with operational PDPC and four sub-legislative instruments; material-scope carve-outs and territorial extraterritoriality confirmed. — source on file
- PDPA fully in force since 1 June 2022 with operational PDPC and four sub-legislative instruments; material-scope carve-outs and territorial extraterritoriality confirmed. — source on file
- PDPA fully in force since 1 June 2022 with operational PDPC and four sub-legislative instruments; material-scope carve-outs and territorial extraterritoriality confirmed. — source on file
Regulator & Framework
The Personal Data Protection Committee opened a public consultation in March 2026 on six priority guideline areas: lawful bases for processing, security and breach notification, data protection officer obligations, marketing, records of processing activity, and data collection practice. This is an active guideline-development process signalling forthcoming subordinate instruments across a broad span of the PDPA's operative provisions, though no draft text from the consultation has been located this cycle.
Outlook
The consultation's outcome, expected around the fourth quarter of 2026, is the marker to watch; it would clarify several PDPA obligations that currently rest on general statutory language rather than detailed subordinate guidance.
Sources and claims (7)
- UncertainOneTrust DataGuidance — The Personal Data Protection Committee (PDPC) is tasked with advisory and enforcement powers under the PDPA.observed
- UncertainOneTrust DataGuidance — The PDPA came into full effect on 1 June 2022, following two prior enforcement suspensions, as Thailand's first comprehensive private-sector data protection law.observed
- UncertainOneTrust DataGuidance — Four secondary laws accompany the PDPA covering appropriate security measures, ROPA criteria, an SME ROPA exemption, and criteria for administrative fines and orders, effective between June and December 2022.observed
- UncertainOneTrust DataGuidance — The PDPA excludes from its scope public authorities whose duties concern state security, including financial security, public safety, money-laundering prevention/suppression, forensic science, or cybersecurity.observed
- UncertainOneTrust DataGuidance — The PDPA provides exceptions for legislative bodies and credit bureau companies, which remain governed by pre-existing sectoral regulation alongside the PDPA.observed
- UncertainOneTrust DataGuidance — The PDPA mirrors GDPR's extraterritorial applicability, applying to controllers and processors outside Thailand that process personal data of data subjects in Thailand or offer goods/services to, or monitor the behaviour of, such data subjects.observed
- UncertainInternational Association of Privacy Professionals (IAPP) — In lieu of a general registration/filing regime, PDPA controllers and processors must prepare and maintain Records of Processing Activities (ROPA) that must be readily accessible and promptly presented to the Office of the PDPC on request.observed