PDPA: Personal Data Protection Act B.E. 2562 (2019)

Reviewed by ThaiLawOnline, a licensed Thai law firm practising in Thailand since 2006. Thai lawyer of record: Wichuda Atthamethakon, LL.M., Thai Bar Licence 3149/2556.

Last updated on September 5, 2026

The PDPA (พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562, the Personal Data Protection Act B.E. 2562 (2019), sometimes written Thai PDPA or Thailand PDPA) is Thailand’s general data protection law, modelled on the European GDPR and fully in force since 1 June 2022. It regulates anyone who collects, uses or discloses information about an identifiable living person, requires a lawful basis for doing so, gives the individual rights over the data, and backs those rules with fines, damages and, for sensitive data, prison. A foreigner meets it as a business owner, an employer, a landlord and as the person whose passport is being photocopied.

What the Act requires of a data controller

Scope. The Act binds a data controller (who decides why and how data is used) and a data processor (who handles it on the controller’s instructions) established in Thailand, and by Section 5 also those abroad who offer goods or services to people in Thailand or monitor their behaviour. Purely personal or household use is outside it.

Lawful basis and sensitive data. Personal data may be collected only with consent or on another basis the Act lists: performance of a contract, a legal obligation, vital interests, a public task or the controller’s legitimate interests. Section 26 treats data on race, ethnicity, political opinion, religion, sexual behaviour, criminal record, health, disability, trade union membership, genetic and biometric data as sensitive, needing explicit consent unless a narrow exception applies. Controllers must tell people what is collected and why, keep it secure, notify the regulator of a breach within 72 hours, and honour requests to access, correct, delete or port the data.

Where a foreigner meets the PDPA in practice

Running a business. A Thai company with customers, staff or a website needs a privacy notice, consent wording for marketing, a record of processing (small businesses are partly exempt), contracts with processors such as payroll providers, and a data protection officer if it monitors people on a large scale or handles sensitive data as a core activity. Transfers abroad, including to a foreign head office, are allowed under Section 28 only to countries with adequate protection or under safeguards such as binding corporate rules or standard contract clauses.

As a landlord, host or condominium. Copying a tenant’s passport to file a TM30 rests on a legal obligation and needs no consent, but keeping the copy for years, or a condominium juristic person sharing CCTV footage or resident lists, does not. The regulator is the Personal Data Protection Committee under the Ministry of Digital Economy and Society.

Penalties and how the PDPA differs from other laws

Administrative fines of up to 5,000,000 baht per breach are imposed by the Committee. Civil claims by the person affected allow the court to award punitive damages of up to twice the actual damage. Criminal liability under Section 79 attaches to unlawful use or disclosure of sensitive data that causes damage or is done for gain: up to 1 year’s imprisonment, a fine of up to 1,000,000 baht, or both, and where a company commits the offence its responsible director is liable unless it can be shown they were not involved.

The PDPA is not the Computer Crime Act, which punishes hacking and false content online, and it is not defamation, which concerns reputation. A leaked customer list is a PDPA matter; a false post about a customer is defamation; breaking into the database is computer crime.

Frequently asked questions

Does the PDPA apply to a small business or a foreign company in Thailand?

Yes to both. Any business in Thailand that holds personal data about customers or staff is a data controller, and Section 5 extends the Act to foreign companies that sell to or monitor people in Thailand. Small businesses get limited relief, mainly from the duty to keep a record of processing, not from the Act itself.

What are the penalties under the Thai PDPA?

Administrative fines of up to 5,000,000 baht per breach, civil damages including punitive damages of up to twice the actual loss, and for unlawful use of sensitive data up to 1 year in prison and a fine of up to 1,000,000 baht. Directors can be personally liable for a company’s offence.

Can a landlord in Thailand keep a copy of my passport under the PDPA?

The landlord may copy the passport to meet legal obligations such as the TM30 notification and to perform the lease, without separate consent. Keeping it beyond that purpose, sharing it or using it for anything else needs a lawful basis, and the tenant can ask what is held and request its deletion once the purpose has ended.

See also: Computer Crime Act, Defamation, TM30, Director, corporate criminal liability in Thailand and business law in Thailand.

Thai Law Updates, free by email

Plain-English updates on Thai law changes that affect foreigners: property, visas, marriage, business and wills. One short email a month from a firm practicing since 2006. No spam, unsubscribe anytime.

Scroll to Top
WhatsApp LINE Call Book