Skip to main content

Thailand PDPA

Thailand Personal Data Protection Act B.E. 2562 (2019)

Thailand's GDPR-style law. Health data requires explicit consent. First major fine (THB 7M) August 2024. Draft Royal Decree on AI proposes EU-style risk classification.

Jurisdiction

Thailand

Enacted

May 27, 2019

Effective

Jun 1, 2022

Enforcement

Personal Data Protection Committee (PDPC)

Thailand PDPC

Why It Matters

Active enforcement. Draft AI Royal Decree would add EU-style risk classification.

Recent Developments

First major fine THB 7M (Aug 2024). Draft AI Royal Decree proposes prohibited AI and high-risk classification.

Who Must Comply

  • Data controllers/processors in Thailand
  • Foreign entities processing Thai residents' data

Safety Provisions

  • Section 26: Sensitive data (health) requires explicit consent
  • Section 27: Children's data restrictions
  • Automated decision-making transparency
  • Cross-border transfer restrictions
  • 72-hour breach notification

Compliance & Enforcement

Penalties

THB 5M; criminal (up to 1yr)

Criminal liability

View on map

Thailand

Focus Areas

Mental health & crisis
Child safety
Active safeguards required

Compliance Help

Requires explicit consent for health data; children's safeguards; 72-hour breach notification; cross-border mechanisms.

See how NOPE helps

Cite This

APA

Thailand. (2019). Thailand Personal Data Protection Act B.E. 2562 (2019).

Related Regulations

In Effect BN

Brunei PDPO

Brunei's personal data protection order requiring DPIA and imposing penalties up to 10% Brunei turnover or $1M.

In Effect IN

India DPDP Act

STRICTEST children's provisions in APAC. Children = under 18; verifiable parental consent MANDATORY; PROHIBITION on tracking, behavioral monitoring, targeted advertising to children.

In Effect ID

Indonesia PP 17/2025

Indonesia's comprehensive child online protection regulation establishing age-appropriate design requirements for electronic systems accessible to children. Most granular age classification globally (5 groups). Requires risk assessments, privacy-by-default, parental consent, DPIAs, and prohibits data profiling of children. First of its kind in Asia and Global South.

In Effect CN

China CSL Amendments

First major revision of China's foundational Cybersecurity Law since 2017. Introduces formal AI governance provisions, significantly increases penalties, and expands extraterritorial application to all cybersecurity violations.

In Effect NP

Nepal AI Policy

Nepal national AI policy establishing governance framework and development priorities. Creates AI Governance Council (chaired by Minister for Communications and IT), AI Regulation Council, National AI Centre, and AI Regulatory Authority. Six pillars including ethics, human resource development, and sectoral application.

In Effect PK

Pakistan AI Policy

Pakistan's national AI roadmap establishing six strategic pillars: AI Innovation Ecosystem, Awareness and Readiness, Research and Development, Infrastructure, Governance, and International Cooperation. Creates National AI Fund (NAIF), Centres of Excellence in 7 cities, and targets training 200,000 individuals annually.

Last updated February 17, 2026. Verify against primary sources before relying on this information.