Révisé par ThaiLawOnline, un cabinet d'avocats thaïlandais agréé exerçant en Thaïlande depuis 2006. Avocate thaïlandaise en charge du dossier : Wichuda Atthamethakon, LL.M., licence du barreau thaïlandais 3149/2556.
Dernière mise à jour le 5 septembre 2026
Le PDPA (พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562, the Personal Data Protection Act B.E. 2562 (2019), sometimes written Thai PDPA ou Thailand PDPA) is Thailand’s general data protection law, modelled on the European GDPR and fully in force since 1 June 2022. It regulates anyone who collects, uses or discloses information about an identifiable living person, requires a lawful basis for doing so, gives the individual rights over the data, and backs those rules with fines, dégâts and, for sensitive data, prison. A foreigner meets it as a business owner, an employer, a landlord and as the person whose passport is being photocopied.
Table des matières
What the Act requires of a data controller
Scope. The Act binds a data controller (who decides why and how data is used) and a data processor (who handles it on the controller’s instructions) established in Thailand, and by Section 5 also those abroad who offer goods or services to people in Thailand or monitor their behaviour. Purely personal or household use is outside it.
Lawful basis and sensitive data. Personal data may be collected only with consent or on another basis the Act lists: performance of a contract, a legal obligation, vital interests, a public task or the controller’s legitimate interests. Section 26 treats data on race, ethnicity, political opinion, religion, sexual behaviour, criminal record, health, disability, trade union membership, genetic and biometric data as sensitive, needing explicit consent unless a narrow exception applies. Controllers must tell people what is collected and why, keep it secure, notify the regulator of a breach within 72 hours, and honour requests to access, correct, delete or port the data.
Where a foreigner meets the PDPA in practice
Running a business. A Thai company with customers, staff or a website needs a privacy notice, consent wording for marketing, a record of processing (small businesses are partly exempt), contracts with processors such as payroll providers, and a data protection officer if it monitors people on a large scale or handles sensitive data as a core activity. Transfers abroad, including to a foreign head office, are allowed under Section 28 only to countries with adequate protection or under safeguards such as binding corporate rules or standard contract clauses.
As a landlord, host or condominium. Copying a tenant’s passport to file a TM30 rests on a legal obligation and needs no consent, but keeping the copy for years, or a condominium juristic person sharing CCTV footage or resident lists, does not. The regulator is the Personal Data Protection Committee under the Ministry of Digital Economy and Society.
Penalties and how the PDPA differs from other laws
Administrative fines of up to 5,000,000 baht per breach are imposed by the Committee. Civil claims by the person affected allow the court to award punitive damages of up to twice the actual damage. Criminal liability under Section 79 attaches to unlawful use or disclosure of sensitive data that causes damage or is done for gain: up to 1 year’s imprisonment, a fine of up to 1,000,000 baht, or both, and where a company commits the offence its responsible director is liable unless it can be shown they were not involved.
The PDPA is not the Loi sur la cybercriminalité, which punishes hacking and false content online, and it is not defamation, which concerns reputation. A leaked customer list is a PDPA matter; a false post about a customer is defamation; breaking into the database is computer crime.
Foire aux questions
Does the PDPA apply to a small business or a foreign company in Thailand?
Yes to both. Any business in Thailand that holds personal data about customers or staff is a data controller, and Section 5 extends the Act to foreign companies that sell to or monitor people in Thailand. Small businesses get limited relief, mainly from the duty to keep a record of processing, not from the Act itself.
What are the penalties under the Thai PDPA?
Administrative fines of up to 5,000,000 baht per breach, civil damages including punitive damages of up to twice the actual loss, and for unlawful use of sensitive data up to 1 year in prison and a fine of up to 1,000,000 baht. Directors can be personally liable for a company’s offence.
Can a landlord in Thailand keep a copy of my passport under the PDPA?
The landlord may copy the passport to meet legal obligations such as the TM30 notification and to perform the lease, without separate consent. Keeping it beyond that purpose, sharing it or using it for anything else needs a lawful basis, and the tenant can ask what is held and request its deletion once the purpose has ended.
Voir aussi : Loi sur la cybercriminalité, Diffamation, TM30, Director, responsabilité pénale des entreprises en Thaïlande ET le droit des affaires en Thaïlande.
Actualités juridiques thaïlandaises, gratuites par courriel
Des informations claires et concises sur les changements législatifs thaïlandais concernant les étrangers : propriété, visas, mariage, affaires et testaments. Un court courriel par mois, envoyé par un cabinet d’avocats établi depuis 2006. Zéro spam, désabonnement possible à tout moment.